Eliminar Virus, posible infección


#9

Hola de nuevo @Huesoro

Primero, mis discúlpas por la tardanza

Ahora, vamos a utilizar la herramienta Dr. Web CureIt. Para poder utilizarlo de forma correcta, por favor, lee el manual del mismo ubicado en el enlace indicado aquí -> https://forospyware.com/t/publicado-manual-dr-web-curelt/127

Nos colocas el reporte generado por dicho programa en tu próxima respuesta (en el mismo manual aparece cómo ubicarlo y adjuntarlo) y nos comentas cómo sigue el problema

Saludos


#10

Okay, por accidente instale advanced sistem care, pero pense que era confiable lo mencionaban en la página de windows, necesitaba actualizar los drivers de la computadora, entonces son todas las amenazas de ese programa, pero esas son recientes y las viejas, aqui dejo el informe

Total 219772741570 bytes in 409253 files scanned (584507 objects)
Total 409155 files (584234 objects) are clean
Total 123 files (150 objects) are infected
Total 124 files are raised error condition
Scan time is 02:33:54.106

-----------------------------------------------------------------------------
Start curing
-----------------------------------------------------------------------------

C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\vcl120.bpl - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\sqlite3.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\rtl120.bpl - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\rgfpctlextend.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\Pub\PubMonitor.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\PluginHelper.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\OFCommon.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\rgfpctl.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\HomepageSvc.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\HardwareLib.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\GetProcessDLL.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\filectl.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\datastate.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\cpuidsdk.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\fctlextend.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\CPUIDInterface.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys - quarantined, reboot required
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys - quarantined, reboot required
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win10_x64.sys - quarantined
C:\program files (x86)\iobit\advanced systemcare\ascextmenu_64.dll - quarantined, reboot required
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R1JB9YO.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R3RHZI9.bpl - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R2CK3NT.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R48KAGL.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R23CJM5.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R74FHBQ.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R4LBWVU.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R5796WM.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R6TJTCX.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R8UM8L2.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R99RK3V.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R7JU6V4.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RA91W3D.bpl - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R9ZKLZA.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R8TEAMK.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RD0XMIU.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RDKADPZ.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RFQ109L.bpl - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RGUU7IA.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RDBGZL3.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RK6QL0R.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RDK4ON2.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RKB4JXV.bpl - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RHN37V4.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RLSODQ7.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RL4ZK20.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RNTNUGG.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RMB6UYV.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RQ0EQI2.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RLK37FJ.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RS77Y1X.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$ROTK886.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RT6NDPB.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RTGUWIN.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RSUP16X.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RY7VRJF.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RVHVQXR.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RZHA8RQ.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RTR5J3U.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RZ8GY2N.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$R3128LS\AutoUpdate.dat - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RSFEDQY.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\FF_SPNativeMessage.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\PluginInstall.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\SPUpdate.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\SPNativeMessage.exe - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\Adblock\js\google_gpt.js - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\Adblock\js\google_show_ads.js - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\Adblock\js\ijElement.js - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\BrowerProtect\ASCUrlScanner.dll - quarantined
C:\$Recycle.Bin\S-1-5-21-767254285-3586098769-3745675886-1001\$RV10VRE\BrowerProtect\ASCPlugin_Protection.dll - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\About.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\dataexchange.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\diskinfo.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\DiskScan.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\InfoHelp.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\JumpListDll.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\DriverClean.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\libssl-1_1.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\LocalLang.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\libcrypto-1_1.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\sdcore.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\Scanner.dll - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\SendBugReportNew.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\SoftUpdateTip.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\smBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\Pub\PubMonitorBox.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win7_x64.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_x86.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileControl.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_ia64\AscFileControl.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_ia64\AscFileFilter.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_ia64\AscRegistryFilter.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_ia64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_x86\AscFileControl.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_x86\AscFileFilter.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_x86\AscRegistryFilter.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_x86\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_amd64\AscFileControl.sys - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_amd64\AscFileFilter.sys - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_ia64\AscFileFilter.sys - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_amd64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_ia64\AscFileControl.sys - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_amd64\AscRegistryFilter.sys - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_ia64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_ia64\AscRegistryFilter.sys - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_x86\AscFileControl.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_x86\AscFileFilter.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\wlh_amd64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_x86\AscRegistryFilter.sys - quarantined
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win7_x86\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\wlh_x86\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\wnet_amd64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\wnet_x86\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\wxp_amd64\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\wxp_x86\RegistryDefragBootTime.exe - fatal error occured
C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\xp_amd64\RegistryDefragBootTime.exe - fatal error occured
C:\Users\rkale\AppData\Local\Temp\is-SG7OR.tmp\RdZone.dll - quarantined
C:\Users\rkale\AppData\Local\Temp\is-SG7OR.tmp\Setup.exe - quarantined

Por seguridad y quitar el virus de IObit escanee con adwcleaner, dejo el reporte porque veo cosas aparte del de IO

# -------------------------------
# Start:    01-08-2019
# Duration: 00:00:07
# OS:       Windows 10 Home Single Language
# Cleaned:  16
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\ProgramData\IObit\Advanced SystemCare
Deleted       C:\Program Files (x86)\IObit\Advanced SystemCare
Deleted       C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted       C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\Users\rkale\AppData\LocalLow\IObit\Advanced SystemCare
Deleted       C:\Users\rkale\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKLM\Software\Wow6432Node\IObit\RealTimeProtector
Deleted       HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
Deleted       HKLM\Software\Wow6432Node\IOBIT\ASC
Deleted       HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted       HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\Software\Wow6432Node\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted       HKLM\Software\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted       HKLM\Software\Wow6432Node\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted       HKLM\Software\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1578 octets] - [03/01/2019 19:00:20]
AdwCleaner[C00].txt - [1668 octets] - [03/01/2019 19:53:42]
AdwCleaner[S01].txt - [1388 octets] - [05/01/2019 19:37:31]
AdwCleaner[C01].txt - [1574 octets] - [05/01/2019 19:43:08]
AdwCleaner[S02].txt - [1510 octets] - [07/01/2019 17:32:29]
AdwCleaner[S03].txt - [3091 octets] - [08/01/2019 10:07:58]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C03].txt ##########


No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1578 octets] - [03/01/2019 19:00:20]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Disculpe la tardanza, pero si tardan muchoo en hacer los análisis y bueno, el problema del arranque no lo entiendo cada vez aumenta, el día de hoy tardó dos minutos en iniciar, gracias


#11

Hola de nuevo @Huesoro

Una duda, el antivirus que tienes (Eset) ¿Es original o pirata?

Ahora, sobre Iobit, esos programas de dicha empresa es famoso por instalar sus cosillas extras en los PC, por lo que no recomendamos su uso.

Sobre los controladores, es mejor utilizar el programa AIDA64 debido a que entrega bastante información del hardware que tenemos instalado en el equipo (al finalizar el tema, dejaré el enlace de descarga de la versión demostración de dicho programa) y, con esos datos, podemos ir a la página web del fabricante y ver si hay controladores actualizados

Vamos a ver qué programas tienes instalado en el equipo para ver si hay algo de Iobit que podamos eliminar o que no haya sido borrado por los programas instalados, para eso, realiza lo siguiente:

  1. Descarga CCleaner y lo instalas según su manual (enlace del manual de CCleaner -> CCleaner. Manual de uso simple y avanzado (en el manual se puede encontrar el enlace de descarga de dicho programa))
  2. Una vez instalado CCleaner, abre dicho programa y haces clic en Herramientas >> Desinstalar programas
  3. Una vez abierto el apartado de desinstalar programas, haz clic en Guardar en un archivo de texto…
  4. Guardas el archivo de texto con el nombre que nos viene por defecto (install.txt) y lo guardas en el Escritorio (ésto es importante)
  5. Una vez creado dicho archivo, abres el mismo y copia y pega el contenido de dicho archivo en tu próxima respuesta

Saludos


#12

El Eset es original, tengo la versión de prueba durante 20 días más y lo uso junto con el malware bites. Acabo de encender la computadora y realmente mejoró, encendió en menos de 20 segundos, pero para el tipo de computadora aun es lento y se trabo al iniciar sesión. Supongo que cada escaneo va mejorando la cosa :smile: Dejo la lista de programas instalados:

|Alarmas y reloj|Microsoft Corporation|31/12/2018||10.1811.3241.0|
|---|---|---|---|---|
|Alcor Micro USB Card Reader Driver|Alcor Micro Corp.|15/08/2017|2.31 MB|20.24.401.14520|
|ASUS Battery Health Charging|ASUS|15/08/2017|4.97 MB|1.0.0004|
|ASUS Device Activation|ASUSTeK COMPUTER INC.|28/12/2018|429 KB|1.0.4.0|
|ASUS Live Update|ASUS|15/08/2017|5.85 MB|3.4.3|
|ASUS PTP Driver|ASUS|15/08/2017|7.24 MB|11.0.17|
|ASUS Splendid Video Enhancement Technology|ASUS|15/08/2017|22.5 MB|3.19.0004|
|ASUS USB Charger Plus|ASUS|15/08/2017|31.3 MB|4.2.0|
|ASUS ZenLink|ASUSTeK COMPUTER INC.|31/12/2018||1.0.7.0|
|ATK Package|ASUS|15/08/2017|8.24 MB|1.0.0051|
|AudioWizard|ICEpower a/s|15/08/2017|27.2 MB|1.0.5.20|
|Battle.net|Blizzard Entertainment|31/12/2018|||
|Brawlhalla|Blue Mammoth Games|05/01/2019|||
|Calculadora|Microsoft Corporation|31/12/2018||10.1811.3241.0|
|CCleaner|Piriform|01/01/2019||5.51|
|Centro de comentarios|Microsoft Corporation|31/12/2018||1.1805.2331.0|
|Conexant HD Audio|Conexant|28/12/2018||8.66.77.57|
|Conexant SmartAudio|Conexant Systems|28/12/2018|31.1 MB|6.0.275.0|
|Contactos|Microsoft Corporation|07/01/2019||10.1811.3343.0|
|Correo y Calendario|Microsoft Corporation|31/12/2018||16005.11029.20108.0|
|Counter-Strike: Global Offensive|Valve|05/01/2019|||
|CyberLink PhotoDirector 5|CyberLink Corp.|28/12/2018|404 MB|5.0.5.6515|
|CyberLink PowerDirector 12|CyberLink Corp.|28/12/2018|783 MB|12.0.4010.0|
|Cámara|Microsoft Corporation|31/12/2018||2018.824.60.0|
|Darwin Project|Scavengers Studio|05/01/2019|||
|Destiny 2|Blizzard Entertainment|31/12/2018|||
|Device Setup|ASUSTek COMPUTER INC.|04/05/2017|3.40 MB|2.2.7|
|Diablo III|Blizzard Entertainment|05/01/2019|||
|El tiempo|Microsoft Corporation|31/12/2018||4.28.3242.0|
|ESET Security|ESET, spol. s r.o.|31/12/2018|125 MB|12.0.31.0|
|Extensiones de contenido multimedia web|Microsoft Corporation|31/12/2018||1.0.13321.0|
|Fotos|Microsoft Corporation|31/12/2018||2018.18091.17210.0|
|Google Chrome|Google Inc.|30/12/2018||71.0.3578.98|
|Grabadora de voz|Microsoft Corporation|31/12/2018||10.1811.3242.0|
|Groove Música|Microsoft Corporation|31/12/2018||10.18102.10531.0|
|HEVC Video Extensions from Device Manufacturer|Microsoft Corporation|05/01/2019||1.0.13209.0|
|Host de la experiencia de Store|Microsoft Corporation|31/12/2018||11810.1001.10.0|
|Instalador de aplicación|Microsoft Corporation|31/12/2018||1.0.20921.0|
|Intel(R) Dynamic Platform and Thermal Framework|Intel Corporation|28/12/2018||8.2.11003.3588|
|Intel(R) Management Engine Components|Intel Corporation|15/08/2017||11.6.0.1050|
|Intel(R) PRO/Wireless Driver||28/12/2018|||
|Intel(R) Processor Graphics|Intel Corporation|28/12/2018||22.20.16.4708|
|Intel(R) Rapid Storage Technology|Intel Corporation|15/08/2017||15.2.7.1042|
|Intel(R) Serial IO|Intel Corporation|15/08/2017||30.100.1724.2|
|Intel(R) Wireless Bluetooth(R)|Intel Corporation|15/08/2017|7.86 MB|19.50.1|
|Intel® PROSet/Wireless Software|Intel Corporation|31/12/2018||19.50.0|
|Malwarebytes versión 3.6.1.2711|Malwarebytes|31/12/2018|193 MB|3.6.1.2711|
|Mapas|Microsoft Corporation|31/12/2018||5.1811.3233.0|
|Mensajes|Microsoft Corporation|31/12/2018||4.1810.2922.0|
|Mi Office|Microsoft Corporation|31/12/2018||17.10314.31700.1000|
|Microsoft Office 365 - es-es|Microsoft Corporation|31/12/2018||16.0.11029.20108|
|Microsoft OneDrive|Microsoft Corporation|28/12/2018|112 MB|18.222.1104.0007|
|Microsoft Pay|Microsoft Corporation|28/12/2018||2.1.18009.0|
|Microsoft Solitaire Collection|Microsoft Studios|31/12/2018||4.2.11280.0|
|Microsoft Sticky Notes|Microsoft Corporation|31/12/2018||3.1.46.0|
|Microsoft Store|Microsoft Corporation|31/12/2018||11810.1001.12.0|
|Microsoft Visual C++ 2005 Redistributable|Microsoft Corporation|15/08/2017|4.89 MB|8.0.59193|
|Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17|Microsoft Corporation|15/08/2017|13.2 MB|9.0.30729|
|Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148|Microsoft Corporation|15/08/2017|10.1 MB|9.0.30729.4148|
|Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219|Microsoft Corporation|15/08/2017|13.8 MB|10.0.40219|
|Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219|Microsoft Corporation|15/08/2017|11.1 MB|10.0.40219|
|Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005|Microsoft Corporation|28/12/2018|20.5 MB|12.0.21005.1|
|Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005|Microsoft Corporation|28/12/2018|17.1 MB|12.0.21005.1|
|Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020|Microsoft Corporation|31/12/2018|23.6 MB|14.13.26020.0|
|Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020|Microsoft Corporation|31/12/2018|20.1 MB|14.13.26020.0|
|MyASUS-Service Center|ASUSTeK COMPUTER INC.|31/12/2018||3.3.11.0|
|Netflix|Netflix, Inc.|31/12/2018||6.89.355.0|
|NVIDIA Controlador de gráficos 417.35|NVIDIA Corporation|31/12/2018||417.35|
|NVIDIA GeForce Experience 3.16.0.140|NVIDIA Corporation|31/12/2018||3.16.0.140|
|NVIDIA Software del sistema PhysX 9.18.0907|NVIDIA Corporation|31/12/2018||9.18.0907|
|Obtener ayuda|Microsoft Corporation|31/12/2018||10.1706.12921.0|
|OneNote|Microsoft Corporation|31/12/2018||16001.11126.20076.0|
|Overwatch|Blizzard Entertainment|31/12/2018|||
|Paint 3D|Microsoft Corporation|31/12/2018||5.1811.20017.0|
|Paquete de experiencia local en español (España)|Microsoft Corporation|31/12/2018||17134.17.26.0|
|Películas y TV|Microsoft Corporation|31/12/2018||10.18102.12011.0|
|PhotoDirector|CyberLink Corp.|28/12/2018|404 MB|5.0.5.6515|
|Planes de datos móviles|Microsoft Corporation|31/12/2018||5.1809.2571.0|
|PowerDirector|CyberLink Corp.|28/12/2018|783 MB|12.0.4010.0|
|Print 3D|Microsoft Corporation|31/12/2018||3.1.2612.0|
|Razer Chroma SDK Core Components|Razer Inc.|03/01/2019||2.10.0|
|Razer Synapse|Razer Inc.|31/12/2018|28.0 MB|2.21.21.1|
|Skype|Skype|31/12/2018||14.36.52.0|
|Spotify|Spotify AB|31/12/2018||1.0.96.181.gf6bc1b6b|
|Steam|Valve Corporation|30/12/2018||2.10.91.91|
|Sugerencias|Microsoft Corporation|31/12/2018||6.15.12641.0|
|The Binding of Isaac: Rebirth|Nicalis, Inc.|31/12/2018|||
|Update for Windows 10 for x64-based Systems (KB4023057)|Microsoft Corporation|30/12/2018|1.01 MB|2.52.0.0|
|Visor 3D|Microsoft Corporation|31/12/2018||5.1811.27012.0|
|Vulkan Run Time Libraries 1.0.42.0|LunarG, Inc.|28/12/2018|1.66 MB|1.0.42.0|
|Windows Driver Package - ASUS (AsusPTPDrv) HIDClass  (02/16/2017 11.0.0.15)|ASUS|28/12/2018||02/16/2017 11.0.0.15|
|WinFlash|ASUSTeK COMPUTER INC.|15/08/2017|3.95 MB|3.2.2|
|WinRAR 5.61 (64-bit)|win.rar GmbH|31/12/2018||5.61.0|
|Wondershare Filmora9(Build 9.0.4)|Wondershare Software|06/01/2019|758 MB||
|Wondershare Helper Compact 2.5.2|Wondershare|06/01/2019|6.61 MB|2.5.2|
|WPS Office|Zhuhai Kingsoft Office Software Co.,Ltd|31/12/2018||10.2.5832.0|
|Xbox|Microsoft Corporation|31/12/2018||44.44.7002.0|
|Xbox Game bar|Microsoft Corporation|31/12/2018||1.36.7001.0|
|Xbox Game Speech Window|Microsoft Corporation|31/12/2018||1.21.13002.0|
|Xbox gaming overlay|Microsoft Corporation|31/12/2018||1.16.1012.0|
|Xbox Identity Provider|Microsoft Corporation|31/12/2018||12.46.25001.0|
|Xbox Live|Microsoft Corporation|31/12/2018||1.24.10001.0|

#13

el que tengo señalado y el {4a7c4306…} son normales?


#14

Hola de nuevo @Huesoro

No te preocupes por esas claves, debido a que son las entradas que se muestran (o deberían mostrarse) en el menú contextual que aparece al hacer clic derecho con el mouse. Sobre la clave que señalas, ésta permite abrir una ventana de PowerShell en la carpeta que se tiene abierta en ese momento (que, al parecer, dicha función se encuentra desactivada por defecto). Sobre la otra entrada que empieza con {4a7c4306…} admito desconocer su función, aunque parece que está relacionada con algún PUP que debiste haber tenido instalado

Sobre los programas de Iobit, por lo indicado en el reporte colocado, no he visto rastros de los mismos, aunque siempre éstos programas deja sus rastros en el equipo y son algo difícultosos eliminarlos

Veamos qué más tienes en el equipo, para eso, realiza lo siguiente, en el orden indicado:

  1. Ejecuta el CCleaner y realiza lo siguiente:
  • Abres Ccleaner en la pestaña limpiador dejas como esta configurada predeterminadamente, haces clic en analizar esperas que termine :arrow_forward: clic en ejecutar limpiador
  • Clic en la pestaña Registro :arrow_forward: clic en buscar problemas esperas que termine :arrow_forward: clic en Reparar Seleccionadas y haces una copia de seguridad
  • Vuelves a darle clic en buscar problemas hasta que no encuentre ninguno.
  1. Desactiva Temporalmente tu antivirus y cualquier programa de seguridad.

  2. Descarga a Tu Escritorio >> Esto es muy importante<<.,Fabar Recovery Scan Tool, considerando la versión adecuada para tu equipo. (32 o 64 bits) :arrow_forward: ¿Cómo saber si mi Windows es de 32 o 64 bits? y realiza lo siguiente:

  • Doble clic para ejecutar Frst.exe. En la ventana del Disclaimer, presiona Yes.

  • En la nueva ventana que se abre, presiona el botón Scan y espera a que concluya el análisis.

  • Se abrirán dos (2) archivos (Logs), Frst.txt y Addition.txt, que estarán grabados en Tu escritorio.

En Tu próxima respuesta, copias y pegas los dos reportes Frst.txt y Addition.txt de FRST

Nota: Si el/los reportes solicitados no entraran en una sola respuesta porque superan la cantidad de caracteres permitidos, puedes utilizar dos o mas respuestas para pegarlos completamente.

Nos comentas si tienes dudas o problemas en utilizar algunas de las herramientas indicadas

Saludos


#18

Hola de nuevo @Huesoro

Ejecutaste mal el FRST, porque dicho programa debes ejecutarlo desde el Escritorio y no desde otra carpeta.

Por favor, mueve el ejecutable del FRST al escritorio. Una vez hecho lo anterior, repite nuevamente los pasos indicados anteriormente para poder generar los reportes.

Nos colocas los nuevos reportes que generará el programa (FRST.txt y Addition.txt) y nos comentas si tuviste algún problema al realizar algunos de los pasos indicados

Saludos


#19

He vuelto a hacer el escaneo y aqui dejo los resultados de Adittion.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09.01.2019 01
Ran by rkale (10-01-2019 06:53:04)
Running from C:\Users\rkale\OneDrive\Escritorio
Windows 10 Home Single Language Version 1803 17134.472 (X64) (2018-12-28 07:16:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-767254285-3586098769-3745675886-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-767254285-3586098769-3745675886-503 - Limited - Disabled)
Invitado (S-1-5-21-767254285-3586098769-3745675886-501 - Limited - Disabled)
rkale (S-1-5-21-767254285-3586098769-3745675886-1001 - Administrator - Enabled) => C:\Users\rkale
WDAGUtilityAccount (S-1-5-21-767254285-3586098769-3745675886-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: ESET Security (Disabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: ESET Security (Disabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Actualización de NVIDIA 34.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 34.0.0.0 - NVIDIA Corporation) Hidden
Alcor Micro USB Card Reader Driver (HKLM-x32\...\{AB4E4E64-6DA2-4E43-969E-83ACB1F57BB6}) (Version: 20.24.401.14520 - Alcor Micro Corp.) Hidden
Alcor Micro USB Card Reader Driver (HKLM-x32\...\InstallShield_{AB4E4E64-6DA2-4E43-969E-83ACB1F57BB6}) (Version: 20.24.401.14520 - Alcor Micro Corp.)
ASUS Battery Health Charging (HKLM-x32\...\{3A7E73B6-3A04-49ED-811E-CC39F7EA2E34}) (Version: 1.0.0004 - ASUS)
ASUS Device Activation (HKLM-x32\...\{9C4B0706-9F9A-47BF-B417-0A111FC52B04}) (Version: 1.0.4.0 - ASUSTeK COMPUTER INC.)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.4.3 - ASUS)
ASUS PTP Driver (HKLM-x32\...\{7618E419-9124-4E6C-9AF4-487A6DDEC1C5}) (Version: 11.0.17 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.19.0004 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.2.0 - ASUS)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0051 - ASUS)
AudioWizard (HKLM-x32\...\{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.5.20 - ICEpower a/s)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
CCleaner (HKLM\...\CCleaner) (Version: 5.51 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.77.57 - Conexant)
Conexant SmartAudio (HKLM\...\SAII) (Version: 6.0.275.0 - Conexant Systems)
CyberLink PhotoDirector 5 (HKLM\...\{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6515 - CyberLink Corp.) Hidden
CyberLink PhotoDirector 5 (HKLM-x32\...\InstallShield_{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}) (Version: 5.0.5.6515 - CyberLink Corp.)
CyberLink PowerDirector 12 (HKLM\...\{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4010.0 - CyberLink Corp.) Hidden
CyberLink PowerDirector 12 (HKLM-x32\...\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.4010.0 - CyberLink Corp.)
Destiny 2 (HKLM-x32\...\Destiny 2) (Version:  - Blizzard Entertainment)
Device Setup (HKLM-x32\...\{8D6B05E0-F457-408C-9D13-549334D8FAE1}) (Version: 2.2.7 - ASUSTek COMPUTER INC.)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 417.35 - NVIDIA Corporation) Hidden
ESET Security (HKLM\...\{F1544F11-BFCC-43CC-9D0C-169A7E99369E}) (Version: 12.0.31.0 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Intel(R) Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\...\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.11003.3588 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1050 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4708 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.7.1042 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1724.2 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{7B11A2EA-168E-442A-809E-5F8908A7504F}) (Version: 19.50.1 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{66614300-cd9b-4a62-8b18-c97e9562dc3e}) (Version: 19.50.0 - Intel Corporation)
Malwarebytes versión 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
Microsoft Office 365 - es-es (HKLM\...\O365HomePremRetail - es-es) (Version: 16.0.11029.20108 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 18.151.0729.0013 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\OneDriveSetup.exe) (Version: 18.222.1104.0007 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.12 - NVIDIA Corporation) Hidden
NVIDIA Controlador de gráficos 417.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 417.35 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.16.0.140 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.16.0.140 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.18.0907 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.18.0907 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0C0A-1000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden
Overwatch (HKLM-x32\...\Overwatch) (Version:  - Blizzard Entertainment)
Panel de control de NVIDIA 417.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 417.35 - NVIDIA Corporation) Hidden
Razer Chroma SDK Core Components (HKLM-x32\...\Razer Chroma SDK) (Version: 2.10.0 - Razer Inc.)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.)
Spotify (HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.0.42.0 (HKLM\...\VulkanRT1.0.42.0) (Version: 1.0.42.0 - LunarG, Inc.)
Windows Driver Package - ASUS (AsusPTPDrv) HIDClass  (02/16/2017 11.0.0.15) (HKLM\...\A8E4A577EC626B57BB07598D138EB24D150DD5BA) (Version: 02/16/2017 11.0.0.15 - ASUS)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.2 - ASUSTeK COMPUTER INC.)
WinRAR 5.61 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH)
Wondershare Filmora9(Build 9.0.4) (HKLM\...\Wondershare Filmora9_is1) (Version:  - Wondershare Software)
Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-11-29] (ESET)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (Alexander Roshal)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-11-29] (ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0d8b06fa651db23a\igfxDTCM.dll [2017-06-25] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-12-11] (NVIDIA Corporation)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2018-11-29] (ESET)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02F21CA5-2FD8-4DF0-BAE0-C323C8D1D1D7} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2016-11-14] (ASUSTek Computer Inc.)
Task: {09BBDEDF-BE2D-4C19-B47F-DF8994106E04} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-12-06] (NVIDIA Corporation)
Task: {0FCAF04B-5322-4B9D-A167-6515EF1099BB} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-12-06] (NVIDIA Corporation)
Task: {1C1ECAC8-D3FA-49D8-ABF1-794967A332A8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-12-10] (Piriform Software Ltd)
Task: {1CFDAB75-A821-483C-9466-3D440CC92DDA} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-12-06] (NVIDIA Corporation)
Task: {1E010F0B-F339-4A3F-931C-57995DB21A44} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {29A5A349-ACF5-45A2-A0BE-65056F5489AC} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: {33D5B54E-CD7F-4BE3-9825-CBAA5B476C04} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2016-11-14] (ASUSTek Computer Inc.)
Task: {39EFAE8F-69AE-489F-A554-E1AA1BEB7F20} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-12-10] (Piriform Ltd)
Task: {3A4B2B1D-E1A0-4B46-85AE-E10A33A2247E} - System32\Tasks\Microsoft\Windows\Conexant\SA2 => C:\Program Files\CONEXANT\SAII\SACpl.exe [2017-06-07] (Conexant Systems, Inc.)
Task: {40E4B5E4-4805-4B60-AAFB-DE4608B3A78A} - System32\Tasks\ASC12_SkipUac_rkale => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {42112656-C474-43D6-B4E2-96EA233F9A46} - System32\Tasks\Microsoft\Office\Microsoft Office Touchless Attach Notification => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-12-07] (Microsoft Corporation)
Task: {4471035F-A587-4071-82BC-840E5E1C7101} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-30] (Google Inc.)
Task: {46D7E90C-ED91-4AA7-B784-948C79127A7C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-30] (Google Inc.)
Task: {4F0C2601-B6E8-45A3-A449-9612058B0421} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] ()
Task: {519F7172-E91D-4461-AB01-62BED6FA97C9} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-10-13] (Intel(R) Corporation)
Task: {5E962C0F-7DCF-4315-80AD-B81A3B6B0EF4} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [2018-12-31] (Microsoft Corporation)
Task: {5F6B77B4-B37F-4156-8FAA-16CA16CBBD2B} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-12-06] (NVIDIA Corporation)
Task: {61BACA71-6E29-49F4-9BE0-1AF68F37CC9E} - System32\Tasks\ASC12_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
Task: {61F4D7BF-025A-42C6-A71E-D3DCB15D0FE0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-12-07] (Microsoft Corporation)
Task: {6D960F11-165E-4181-9F8C-B9AB9899460F} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] ()
Task: {7B263E5B-F1E5-4A58-B64C-42294387A589} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-12-06] (NVIDIA Corporation)
Task: {9B551EFC-5F55-4C70-9D58-C366E53F8568} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2016-11-14] (ASUSTek Computer Inc.)
Task: {A0EDD631-559F-4312-982B-680028F95FE9} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-12-31] (Microsoft Corporation)
Task: {A273C43D-09FE-4427-A715-3E51A617ADEF} - System32\Tasks\Update Checker => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe [2016-08-01] ()
Task: {AE1028B2-F09D-477D-8FE9-0EAE251B8A1F} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-12-31] (Microsoft Corporation)
Task: {B00047C4-61FF-452C-9CE2-4173BA8D4612} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-12-06] (NVIDIA Corporation)
Task: {B82AA30F-0A88-4E2D-BDB7-469D3701C4E0} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [2018-12-31] (Microsoft Corporation)
Task: {BA7D041D-6A41-474F-B51C-663580D47D27} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-12-06] (NVIDIA Corporation)
Task: {CB17402D-849B-488A-9FB2-54E15AC1849D} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2016-11-09] (ASUSTek COMPUTER INC.)
Task: {D15116EB-2717-4683-B571-0DDB3D91953A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-12-06] (NVIDIA Corporation)
Task: {D504DBDC-2CD4-419B-BDB1-0ABC30403C47} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-12-07] (Microsoft Corporation)
Task: {D7333C47-1711-45F8-883C-EED8D7A4D6C3} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-12-06] (NVIDIA Corporation)
Task: {DAEC9258-C8C4-4D14-A663-6DF9E2092251} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-12-06] (NVIDIA Corporation)
Task: {DB4EC612-B239-4640-BFF5-6FCF36814A6C} - System32\Tasks\Microsoft\Windows\Conexant\AFA => C:\Program Files\CONEXANT\cAudioFilterAgent\SACpl.exe [2016-07-05] (Conexant Systems, Inc.)
Task: {DC69B6C7-325B-47A9-86D9-D84F776C68BD} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2016-10-12] (ASUS)
Task: {EDB4BB21-1E48-42E0-9EA3-B97722698721} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-12-06] (NVIDIA Corporation)
Task: {F001E16A-67F9-4F58-9761-D4E1672F96D3} - System32\Tasks\ASUS Battery Health Charging Notification => C:\Program Files (x86)\ASUS\ASUS Battery Health Charging\BhcMgr.exe [2017-04-26] (ASUSTek Computer Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-04-26 21:16 - 2018-04-26 21:16 - 000165576 _____ () C:\WINDOWS\system32\IntelWifiIhv06.dll
2017-08-15 21:24 - 2014-04-14 19:59 - 000389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2017-08-15 20:55 - 2018-12-06 04:11 - 001315208 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2018-04-11 17:34 - 2018-04-11 17:34 - 000491744 ____N () C:\Windows\System32\InputHost.dll
2018-04-11 17:34 - 2018-04-11 17:34 - 000472064 ____N () C:\Windows\ShellExperiences\TileControl.dll
2018-12-02 00:12 - 2018-11-08 20:17 - 002759680 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-12-20 23:24 - 2018-12-14 00:50 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-12-30 23:26 - 2018-12-11 23:11 - 005237216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libglesv2.dll
2018-12-30 23:26 - 2018-12-11 23:11 - 000117216 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\libegl.dll
2018-06-15 06:33 - 2018-06-15 06:33 - 003912608 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll
2018-06-15 06:33 - 2018-06-15 06:33 - 002506680 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll
2017-01-15 14:36 - 2017-01-15 14:36 - 001243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-08-15 20:55 - 2018-12-06 04:11 - 001033096 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-10-12 23:17 - 2016-10-12 23:17 - 000033280 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll
2016-10-12 23:17 - 2016-10-12 23:17 - 000125440 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll
2016-10-12 23:17 - 2016-10-12 23:17 - 000029184 _____ () C:\Program Files (x86)\ASUS\Splendid\VideoEnhance.dll
2018-12-31 16:59 - 2018-12-31 16:59 - 088824552 _____ () C:\Users\rkale\AppData\Roaming\Spotify\libcef.dll
2018-12-31 16:59 - 2018-12-31 16:59 - 004239592 _____ () C:\Users\rkale\AppData\Roaming\Spotify\libglesv2.dll
2018-12-31 16:59 - 2018-12-31 16:59 - 000098024 _____ () C:\Users\rkale\AppData\Roaming\Spotify\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\rkale\AppData\Local\Temp:$DATA​ [16]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 15:03 - 2017-03-18 15:01 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Razer Chroma SDK\bin;C:\Program Files\Razer Chroma SDK\bin;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Users\rkale\AppData\Local\Microsoft\WindowsApps
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\rkale\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\asus.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run: => "Wondershare Helper Compact.exe"
HKLM\...\StartupApproved\Run32: => "SecurityHealth"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\StartupApproved\Run: => "Advanced SystemCare 12"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{72766302-7BBC-4E95-B908-0E5192907E7E}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
FirewallRules: [{2FD04007-5B9B-441E-95F4-715FAE9D5275}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
FirewallRules: [{D239D397-205D-4EB8-882C-0943D39BC01D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
FirewallRules: [{B2F9765D-2F8B-46FE-B5DE-252F278B720D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
FirewallRules: [{4C940CE4-A4A0-42B8-8D59-90142242D3F3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation)
FirewallRules: [{E6AECB41-DA09-4CB3-A6FC-6BB6A2AD3C71}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve Corporation)
FirewallRules: [{1151AE38-3F7E-41BB-859D-3D9FFF417D25}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation)
FirewallRules: [{AFCAE573-C781-4143-8EC8-A453A0EBC73D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe ()
FirewallRules: [{D105C564-F7C1-41C3-8761-D84F433C6EA5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe ()
FirewallRules: [{6B89936B-3129-40A5-96EF-165DDAF4FA53}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
FirewallRules: [{2C106629-DE1D-4029-93E1-8DFC1F2A5E9B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
FirewallRules: [{A7B58F46-1D97-40DB-99C8-A7FECE07E9D0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
FirewallRules: [{F3EF0333-B582-430F-ACEB-6396AEDEC178}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation)
FirewallRules: [{C1088BF4-FF25-4140-A054-B1E5B0D52583}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation)
FirewallRules: [{79353945-373F-4EDF-B612-203A09BB4A93}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation)
FirewallRules: [TCP Query User{7C9F4FD3-1CF7-419E-A565-6B1BB5638C8A}C:\users\rkale\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\rkale\appdata\roaming\spotify\spotify.exe (Spotify Ltd)
FirewallRules: [UDP Query User{ACBE3268-0607-4A54-8105-0156F244D35D}C:\users\rkale\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\rkale\appdata\roaming\spotify\spotify.exe (Spotify Ltd)
FirewallRules: [{2E84096D-716E-4EDA-9CAB-068880B7991E}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
FirewallRules: [{AE2915AC-AD28-4D26-83BE-9332449088AA}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
FirewallRules: [TCP Query User{7D2E4E4E-9FC5-49E8-9324-B8C185453ABC}C:\program files (x86)\destiny 2\destiny2.exe] => (Allow) C:\program files (x86)\destiny 2\destiny2.exe (Bungie)
FirewallRules: [UDP Query User{676D4980-69A8-4D6B-9B4E-F16FD81BDF56}C:\program files (x86)\destiny 2\destiny2.exe] => (Allow) C:\program files (x86)\destiny 2\destiny2.exe (Bungie)
FirewallRules: [TCP Query User{6D06394A-C150-46F5-A563-61033908192A}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe (Blizzard Entertainment)
FirewallRules: [UDP Query User{32DEBA69-10B6-4CBC-92B6-5DE5092EA437}C:\program files (x86)\overwatch\overwatch.exe] => (Allow) C:\program files (x86)\overwatch\overwatch.exe (Blizzard Entertainment)
FirewallRules: [{5B331624-7892-4518-BC35-99C8D11FCBDB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe ()
FirewallRules: [{72D5439D-11F8-4035-91C9-D9A1C32C6F0E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Brawlhalla\Brawlhalla.exe ()
FirewallRules: [{69CB3173-C9D3-43BB-B5FB-CF3489AC3BB8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Darwin Project\Darwin.exe (EasyAntiCheat Ltd)
FirewallRules: [{81D343B1-4137-45BA-881E-7845C9A27BD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Darwin Project\Darwin.exe (EasyAntiCheat Ltd)
FirewallRules: [{FB97FE61-F391-46F7-8C89-4029E0A0DE39}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Darwin Project\Darwin\Binaries\Win64\Darwin-Win64-Shipping.exe (Epic Games, Inc.)
FirewallRules: [{8A771E49-1248-4CE6-99C4-8F87783CCAD2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Darwin Project\Darwin\Binaries\Win64\Darwin-Win64-Shipping.exe (Epic Games, Inc.)
FirewallRules: [{AB3E93D2-0054-4811-9DF1-86987D7E713B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe ()
FirewallRules: [{0B203BC1-B10E-43D2-A565-C3F3D8EBAE7F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe ()

==================== Restore Points =========================

07-01-2019 23:07:17 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/08/2019 05:20:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: Explorer.EXE, versión: 10.0.17134.165, marca de tiempo: 0x4031a9f8
Nombre del módulo con errores: lockcontroller.dll, versión: 10.0.17134.1, marca de tiempo: 0x91308da5
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00000000000105d1
Identificador del proceso con errores: 0x4ec
Hora de inicio de la aplicación con errores: 0x01d4a76cd1f93a05
Ruta de acceso de la aplicación con errores: C:\WINDOWS\Explorer.EXE
Ruta de acceso del módulo con errores: C:\WINDOWS\system32\lockcontroller.dll
Identificador del informe: 582523c5-ea6b-4b6b-9ab3-fe2138f3dc25
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (01/08/2019 10:12:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa SearchUI.exe, versión 10.0.17134.472, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, comprueba el historial de problemas en la sección Seguridad y mantenimiento del Panel de control.

Identificador de proceso: 1874

Hora de inicio: 01d4a76ceaea7fe8

Hora de finalización: 4294967295

Ruta de la aplicación: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe

Identificador de informe: 4ec94189-657b-404e-a9a8-26bdf2351652

Nombre completo de paquete con errores: Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy

Identificador de aplicación relativa del paquete con errores: CortanaUI

Error: (01/08/2019 06:14:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: mbamtray.exe, versión: 3.1.0.1662, marca de tiempo: 0x5c070ada
Nombre del módulo con errores: mbamtray.exe, versión: 3.1.0.1662, marca de tiempo: 0x5c070ada
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0001e65a
Identificador del proceso con errores: 0x18e0
Hora de inicio de la aplicación con errores: 0x01d4a70b8b1114be
Ruta de acceso de la aplicación con errores: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
Ruta de acceso del módulo con errores: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
Identificador del informe: 1dc808c4-347f-41ee-8b7e-558edb707616
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (01/07/2019 11:09:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

Details:
AddWin32ServiceFiles: Unable to back up image of service Advanced SystemCare Service 12 since QueryServiceConfig API failed

System Error:
El sistema no puede encontrar el archivo especificado.
.

Error: (01/07/2019 11:09:42 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

Details:
AddLegacyDriverFiles: Unable to back up image of binary iobit_monitor_server.

System Error:
El sistema no puede encontrar el archivo especificado.
.

Error: (01/07/2019 10:37:55 PM) (Source: ESENT) (EventID: 455) (User: )
Description: SettingSyncHost (8652,R,98) {FEB7BEA1-D7FF-47FD-8A53-2E5B6750B84C}: Error -1811 (0xfffff8ed) al abrir un archivo de registro C:\Users\rkale\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb00006.log.

Error: (01/07/2019 09:13:54 PM) (Source: Steam Client Service) (EventID: 1) (User: )
Description: Error: Failed to add firewall exception for C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe

Error: (01/07/2019 08:46:13 PM) (Source: COM) (EventID: 10031) (User: )
Description: Se realizó una comprobación de directiva de anulación de serialización al anular la serialización de un objeto con serialización personalizada; se rechazó la clase {41FD88F7-F295-4D39-91AC-A85F3149A05B}


System errors:
=============
Error: (01/10/2019 06:50:43 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-DHSQV9L)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario DESKTOP-DHSQV9L\rkale con SID (S-1-5-21-767254285-3586098769-3745675886-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/10/2019 06:48:39 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-DHSQV9L)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario DESKTOP-DHSQV9L\rkale con SID (S-1-5-21-767254285-3586098769-3745675886-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/10/2019 06:48:23 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/10/2019 06:45:47 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 y APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/10/2019 06:45:47 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 y APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/10/2019 06:45:42 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/09/2019 07:02:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 y APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (01/09/2019 07:02:11 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 y APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.


Windows Defender:
===================================
Date: 2018-12-31 02:15:22.681
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.283.1896.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.15500.2
Código de error: 0x80070422
Descripción del error: No se puede iniciar el servicio, porque está deshabilitado o porque no tiene dispositivos habilitados asociados a él. 

Date: 2018-12-31 00:11:33.230
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.283.1896.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.15500.2
Código de error: 0x80070422
Descripción del error: No se puede iniciar el servicio, porque está deshabilitado o porque no tiene dispositivos habilitados asociados a él. 

Date: 2018-12-30 23:46:50.615
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80070422
Descripción del error: No se puede iniciar el servicio, porque está deshabilitado o porque no tiene dispositivos habilitados asociados a él. 

Date: 2018-12-28 04:35:08.670
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x8024402c
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2018-12-28 02:30:08.177
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 0.0.0.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión de motor actual: 
Versión de motor anterior: 0.0.0.0
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

CodeIntegrity:
===================================

Date: 2019-01-01 13:33:35.235
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\nvswcfilter.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-01-01 13:33:35.179
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-01-01 13:33:32.986
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\iaStorA.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-7200U CPU @ 2.50GHz
Percentage of memory in use: 42%
Total physical RAM: 8075.11 MB
Available physical RAM: 4647.94 MB
Total Virtual: 8075.11 MB
Available Virtual: 4559.48 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:930.46 GB) (Free:748.15 GB) NTFS

\\?\Volume{b91a3017-6113-4013-a077-dd834cc8c1b8}\ (RECOVERY) (Fixed) (Total:0.78 GB) (Free:0.39 GB) NTFS
\\?\Volume{5c0d7466-eccd-4e47-b14b-f087e6d43691}\ (SYSTEM) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 245A7C14)

Partition: GPT.

==================== End of Addition.txt ============================

#20

Y aqui el de Frst. txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09.01.2019 01
Ran by rkale (administrator) on DESKTOP-DHSQV9L (10-01-2019 06:48:57)
Running from C:\Users\rkale\OneDrive\Escritorio
Loaded Profiles: rkale (Available Profiles: rkale)
Platform: Windows 10 Home Single Language Version 1803 17134.472 (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0d8b06fa651db23a\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Battery Health Charging\AsBhcSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\UIUSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe
(Microsoft Corporation) C:\Program Files\rempl\sedlauncher.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Battery Health Charging\BhcMgr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek COMPUTER INC.) C:\Program Files (x86)\ASUS\APRP\aprp.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_0d8b06fa651db23a\igfxEM.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Microsoft Corporation) C:\Windows\System32\DeviceCensus.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [177928 2018-11-29] (ESET)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-30] (Google Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{15434da6-c7e3-445b-b1e8-ada55c7f47d3}: [DhcpNameServer] 40.53.1.12
Tcpip\..\Interfaces\{47b1814a-6ee6-428d-9d33-2772419d4cb4}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus17win10.msn.com/?pc=ASTE
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus17win10.msn.com/?pc=ASTE
SearchScopes: HKU\S-1-5-21-767254285-3586098769-3745675886-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-767254285-3586098769-3745675886-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2018-12-31] (Microsoft Corporation)

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-12-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2018-12-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-30] (Google Inc.)

Chrome: 
=======
CHR Profile: C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default [2019-01-10]
CHR Extension: (Presentaciones) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-30]
CHR Extension: (Documentos) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-30]
CHR Extension: (Google Drive) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-30]
CHR Extension: (YouTube) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-30]
CHR Extension: (Hojas de cálculo) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-30]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-30]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-30]
CHR Extension: (Gmail) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-12-30]
CHR Extension: (Chrome Media Router) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-30]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AsBhcService; C:\Program Files (x86)\ASUS\ASUS Battery Health Charging\AsBhcSrv.exe [114360 2016-10-20] (ASUSTek Computer Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9646240 2018-12-07] (Microsoft Corporation)
S3 DevActSvc; C:\Program Files (x86)\ASUS\ASUS Device Activation\DevActSvc.exe [326032 2018-06-05] ()
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [802432 2019-01-05] (EasyAntiCheat Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2302160 2018-11-29] (ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2302160 2018-11-29] (ESET)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [2210936 2017-02-05] (Intel Corporation)
R2 ibtsiva; C:\WINDOWS\System32\ibtsiva.exe [550568 2018-05-02] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [630048 2016-10-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [196200 2017-01-15] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-02-14] ()
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [787336 2018-12-06] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [787336 2018-12-06] (NVIDIA Corporation)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [439936 2018-01-09] (Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [943232 2018-01-09] (Razer Inc.)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 SAService; C:\WINDOWS\system32\SAsrv.exe [416576 2016-10-27] (Conexant Systems, Inc.)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 UIUService; C:\WINDOWS\SysWOW64\UIUSrv.exe [105984 2018-12-28] (Conexant Systems, Inc.) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-11] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [107136 2018-09-20] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3743648 2017-02-14] (Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-04-26] (Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-04-26] (Apple Inc.)
R3 AsusPTPDrv; C:\WINDOWS\System32\drivers\AsusPTPFilter.sys [99304 2017-03-08] (ASUS Corporation)
S3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [46944 2018-09-17] (Corsair)
S3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [23392 2018-09-17] (Corsair)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [67976 2017-02-05] (Intel Corporation)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [143448 2018-11-29] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15872 2018-10-17] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [188832 2018-10-17] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [109864 2018-10-17] (ESET)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [355208 2017-02-05] (Intel Corporation)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [31120 2016-12-19] (ASUS)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [198168 2018-04-19] (Intel Corporation)
U5 Netwtw04; C:\Windows\System32\Drivers\Netwtw04.sys [7617792 2017-02-26] (Intel Corporation)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [8743448 2018-04-26] (Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_f6a5393a9f02318c\nvlddmkm.sys [20424640 2018-12-17] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2018-10-25] (NVIDIA Corporation)
S3 NVSWCFilter; C:\WINDOWS\System32\drivers\nvswcfilter.sys [45152 2018-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [70024 2018-10-01] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [74576 2018-11-29] (NVIDIA Corporation)
S3 rzbtendpt; C:\WINDOWS\System32\drivers\rzbtendpt.sys [51912 2015-08-13] (Razer Inc)
S3 rzdaendpt; C:\WINDOWS\System32\drivers\rzdaendpt.sys [43720 2015-08-13] (Razer Inc)
S3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc)
S3 rzhnet; C:\WINDOWS\System32\Drivers\rzhnet.sys [29912 2015-08-13] (Razer Inc)
S3 rzjstk; C:\WINDOWS\System32\drivers\rzjstk.sys [36568 2015-08-13] (Razer Inc)
S3 rzkeypadendpt; C:\WINDOWS\System32\drivers\rzkeypadendpt.sys [46280 2015-08-13] (Razer Inc)
S3 rzmpos; C:\WINDOWS\System32\drivers\rzmpos.sys [48840 2015-08-13] (Razer Inc)
S3 rzp1endpt; C:\WINDOWS\System32\drivers\rzp1endpt.sys [52424 2015-08-13] (Razer Inc)
S3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [44232 2015-08-13] (Razer Inc)
S3 rzvmouse; C:\WINDOWS\System32\drivers\rzvmouse.sys [42712 2015-08-13] (Razer Inc)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (QUALCOMM Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-11] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-11] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-11] (Microsoft Corporation)
S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-09 17:54 - 2019-01-09 17:54 - 000000000 ____D C:\Users\rkale\Downloads\FRST-OlderVersion
2019-01-09 17:52 - 2019-01-09 17:52 - 000003550 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1
2019-01-09 17:52 - 2019-01-09 17:52 - 000003540 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2
2019-01-08 18:28 - 2019-01-08 18:29 - 116982632 _____ C:\Users\rkale\Downloads\Mi video2.mp4
2019-01-08 18:22 - 2019-01-08 18:23 - 053540776 _____ C:\Users\rkale\Downloads\Mi video1.mp4
2019-01-08 17:58 - 2019-01-08 17:59 - 107329311 _____ C:\Users\rkale\Downloads\Esto Es México - Paisajes Cultura [Vídeo HD].mp4
2019-01-08 17:26 - 2019-01-08 17:26 - 000000000 ____D C:\Users\rkale\AppData\Local\ElevatedDiagnostics
2019-01-07 18:04 - 2019-01-07 18:04 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-01-07 18:03 - 2019-01-07 18:03 - 137260640 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-01-07 17:55 - 2019-01-07 17:55 - 000972904 _____ C:\Users\rkale\Downloads\filmora_setup_full1081 (1).exe
2019-01-07 17:51 - 2019-01-08 01:22 - 000000000 ____D C:\Users\rkale\Doctor Web
2019-01-07 17:51 - 2019-01-07 17:51 - 000000000 ____D C:\ProgramData\Doctor Web
2019-01-07 17:46 - 2019-01-07 17:50 - 182811344 _____ C:\Users\rkale\Downloads\cureit.exe
2019-01-07 17:42 - 2019-01-07 17:43 - 101249024 _____ C:\WINDOWS\system32\config\COMPONENTS.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 113516544 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000864256 _____ C:\WINDOWS\system32\config\DEFAULT.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000045056 _____ C:\WINDOWS\system32\config\SAM.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2019-01-07 17:37 - 2019-01-08 10:08 - 000000000 ____D C:\Users\rkale\AppData\LocalLow\IObit
2019-01-07 17:37 - 2019-01-07 17:37 - 000003114 _____ C:\WINDOWS\System32\Tasks\ASC12_PerformanceMonitor
2019-01-07 17:37 - 2019-01-07 17:37 - 000002908 _____ C:\WINDOWS\System32\Tasks\ASC12_SkipUac_rkale
2019-01-07 17:37 - 2019-01-07 17:37 - 000000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled
2019-01-07 17:37 - 2019-01-07 17:37 - 000000000 ____D C:\ProgramData\ProductData
2019-01-07 17:37 - 2019-01-07 17:37 - 000000000 ____D C:\ProgramData\{F86B0233-9A85-4589-8AAF-524CC4F8211B}
2019-01-07 17:36 - 2019-01-08 10:08 - 000000000 ____D C:\Users\rkale\AppData\Roaming\IObit
2019-01-07 17:36 - 2019-01-08 10:08 - 000000000 ____D C:\ProgramData\IObit
2019-01-06 10:21 - 2019-01-06 10:21 - 034628417 _____ C:\Users\rkale\Downloads\Mi video.mp4
2019-01-06 09:43 - 2019-01-06 09:43 - 000000000 ____D C:\Users\rkale\AppData\Local\FNativeWebEngineExe
2019-01-06 09:43 - 2019-01-06 09:43 - 000000000 ____D C:\Users\rkale\.QtWebEngineProcess
2019-01-06 09:43 - 2019-01-06 09:43 - 000000000 ____D C:\Users\rkale\.FNativeWebEngineExe
2019-01-06 09:42 - 2019-01-06 09:43 - 000000000 ____D C:\ProgramData\Wondershare
2019-01-06 09:42 - 2019-01-06 09:42 - 000000000 ____D C:\Users\rkale\AppData\Roaming\NVIDIA
2019-01-06 09:40 - 2019-01-06 09:40 - 000000000 ____D C:\Users\rkale\AppData\Local\Wondershare
2019-01-06 09:40 - 2019-01-06 09:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2019-01-06 09:38 - 2019-01-08 18:31 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Wondershare Filmora 9
2019-01-06 09:38 - 2019-01-08 17:31 - 000000000 ____D C:\ProgramData\Wondershare Filmora
2019-01-06 09:38 - 2019-01-06 09:38 - 000000000 ____D C:\Program Files\Wondershare
2019-01-06 09:36 - 2019-01-06 09:36 - 000972904 _____ C:\Users\rkale\Downloads\filmora_setup_full1081.exe
2019-01-05 22:53 - 2019-01-05 22:53 - 000000000 ____D C:\Users\rkale\AppData\Local\UnrealEngine
2019-01-05 22:53 - 2019-01-05 22:53 - 000000000 ____D C:\Users\rkale\AppData\Local\Darwin
2019-01-05 22:52 - 2019-01-05 22:52 - 000000000 ____D C:\Users\rkale\AppData\Roaming\EasyAntiCheat
2019-01-05 22:52 - 2019-01-05 22:52 - 000000000 ____D C:\Program Files (x86)\EasyAntiCheat
2019-01-05 22:52 - 2010-06-02 04:55 - 000527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2019-01-05 22:52 - 2010-06-02 04:55 - 000518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2019-01-05 22:52 - 2010-06-02 04:55 - 000239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2019-01-05 22:52 - 2010-06-02 04:55 - 000176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2019-01-05 22:52 - 2010-06-02 04:55 - 000077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2019-01-05 22:52 - 2010-06-02 04:55 - 000074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2019-01-05 22:52 - 2010-05-26 11:41 - 002526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2019-01-05 22:52 - 2010-05-26 11:41 - 002106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2019-01-05 22:52 - 2010-05-26 11:41 - 001907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2019-01-05 22:52 - 2010-05-26 11:41 - 001868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2019-01-05 22:52 - 2010-02-04 10:01 - 000022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2019-01-05 22:52 - 2009-09-04 17:44 - 000517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2019-01-05 22:52 - 2009-09-04 17:44 - 000515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2019-01-05 22:52 - 2009-09-04 17:44 - 000238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2019-01-05 22:52 - 2009-09-04 17:44 - 000176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2019-01-05 22:52 - 2009-09-04 17:44 - 000073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2019-01-05 22:52 - 2009-09-04 17:44 - 000069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 005554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 005501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 002582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 002475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 001974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 000523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 000285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2019-01-05 22:52 - 2009-09-04 17:29 - 000235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2019-01-05 22:52 - 2009-03-16 14:18 - 000521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2019-01-05 22:52 - 2009-03-16 14:18 - 000517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2019-01-05 22:52 - 2009-03-16 14:18 - 000235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2019-01-05 22:52 - 2009-03-16 14:18 - 000174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2019-01-05 22:52 - 2009-03-16 14:18 - 000024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2019-01-05 22:52 - 2009-03-16 14:18 - 000022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2019-01-05 22:52 - 2009-03-09 15:27 - 005425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2019-01-05 22:52 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2019-01-05 22:52 - 2009-03-09 15:27 - 002430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2019-01-05 22:52 - 2009-03-09 15:27 - 001846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2019-01-05 22:52 - 2009-03-09 15:27 - 000520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2019-01-05 22:52 - 2009-03-09 15:27 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2019-01-05 22:52 - 2008-10-27 10:04 - 000023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2019-01-05 22:52 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2019-01-05 22:52 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2019-01-05 22:52 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2019-01-05 22:52 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2019-01-05 22:52 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2019-01-05 22:52 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2019-01-05 22:52 - 2008-07-31 10:41 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2019-01-05 22:52 - 2008-07-31 10:41 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2019-01-05 22:52 - 2008-07-31 10:41 - 000072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2019-01-05 22:52 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2019-01-05 22:52 - 2008-07-31 10:40 - 000513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2019-01-05 22:52 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2019-01-05 22:52 - 2008-07-10 11:01 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2019-01-05 22:52 - 2008-07-10 11:00 - 004992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2019-01-05 22:52 - 2008-07-10 11:00 - 003851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2019-01-05 22:52 - 2008-07-10 11:00 - 001942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2019-01-05 22:52 - 2008-07-10 11:00 - 001493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2019-01-05 22:52 - 2008-07-10 11:00 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2019-01-05 22:52 - 2008-05-30 14:19 - 000511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2019-01-05 22:52 - 2008-05-30 14:19 - 000507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2019-01-05 22:52 - 2008-05-30 14:18 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2019-01-05 22:52 - 2008-05-30 14:18 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2019-01-05 22:52 - 2008-05-30 14:17 - 000068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2019-01-05 22:52 - 2008-05-30 14:17 - 000065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2019-01-05 22:52 - 2008-05-30 14:17 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2019-01-05 22:52 - 2008-05-30 14:16 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2019-01-05 22:52 - 2008-05-30 14:11 - 004991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2019-01-05 22:52 - 2008-05-30 14:11 - 003850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2019-01-05 22:52 - 2008-05-30 14:11 - 001941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2019-01-05 22:52 - 2008-05-30 14:11 - 001491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2019-01-05 22:52 - 2008-05-30 14:11 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2019-01-05 22:52 - 2008-05-30 14:11 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2019-01-05 22:52 - 2008-03-05 16:04 - 000489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2019-01-05 22:52 - 2008-03-05 16:03 - 000479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2019-01-05 22:52 - 2008-03-05 16:03 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2019-01-05 22:52 - 2008-03-05 16:03 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2019-01-05 22:52 - 2008-03-05 16:00 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2019-01-05 22:52 - 2008-03-05 16:00 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2019-01-05 22:52 - 2008-03-05 15:56 - 004910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2019-01-05 22:52 - 2008-03-05 15:56 - 003786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2019-01-05 22:52 - 2008-03-05 15:56 - 001860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2019-01-05 22:52 - 2008-03-05 15:56 - 001420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2019-01-05 22:52 - 2008-02-05 23:07 - 000529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2019-01-05 22:52 - 2008-02-05 23:07 - 000462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2019-01-05 22:52 - 2007-10-22 03:40 - 000411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2019-01-05 22:52 - 2007-10-22 03:39 - 000267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2019-01-05 22:52 - 2007-10-22 03:37 - 000021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2019-01-05 22:52 - 2007-10-22 03:37 - 000017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2019-01-05 22:52 - 2007-10-12 15:14 - 005081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2019-01-05 22:52 - 2007-10-12 15:14 - 003734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2019-01-05 22:52 - 2007-10-12 15:14 - 002006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2019-01-05 22:52 - 2007-10-12 15:14 - 001374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2019-01-05 22:52 - 2007-10-02 09:56 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2019-01-05 22:52 - 2007-10-02 09:56 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2019-01-05 22:52 - 2007-07-20 00:57 - 000411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2019-01-05 22:52 - 2007-07-20 00:57 - 000267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2019-01-05 22:52 - 2007-07-19 18:14 - 005073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2019-01-05 22:52 - 2007-07-19 18:14 - 003727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2019-01-05 22:52 - 2007-07-19 18:14 - 001985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2019-01-05 22:52 - 2007-07-19 18:14 - 001358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2019-01-05 22:52 - 2007-07-19 18:14 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2019-01-05 22:52 - 2007-07-19 18:14 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2019-01-05 22:52 - 2007-06-20 20:49 - 000409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2019-01-05 22:52 - 2007-06-20 20:46 - 000266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2019-01-05 22:52 - 2007-05-16 16:45 - 004496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2019-01-05 22:52 - 2007-05-16 16:45 - 003497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2019-01-05 22:52 - 2007-05-16 16:45 - 001401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2019-01-05 22:52 - 2007-05-16 16:45 - 001124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2019-01-05 22:52 - 2007-05-16 16:45 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2019-01-05 22:52 - 2007-05-16 16:45 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2019-01-05 22:52 - 2007-04-04 18:55 - 000403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2019-01-05 22:52 - 2007-04-04 18:55 - 000261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2019-01-05 22:52 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2019-01-05 22:52 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
2019-01-05 22:52 - 2007-03-15 16:57 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2019-01-05 22:52 - 2007-03-15 16:57 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2019-01-05 22:52 - 2007-03-12 16:42 - 004494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2019-01-05 22:52 - 2007-03-12 16:42 - 003495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2019-01-05 22:52 - 2007-03-12 16:42 - 001400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2019-01-05 22:52 - 2007-03-12 16:42 - 001123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2019-01-05 22:51 - 2007-03-05 12:42 - 000017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2019-01-05 22:51 - 2007-03-05 12:42 - 000015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2019-01-05 22:51 - 2007-01-24 15:27 - 000393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2019-01-05 22:51 - 2007-01-24 15:27 - 000255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2019-01-05 22:51 - 2006-12-08 12:02 - 000251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2019-01-05 22:51 - 2006-12-08 12:00 - 000390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2019-01-05 22:51 - 2006-11-29 13:06 - 004398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2019-01-05 22:51 - 2006-11-29 13:06 - 003426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2019-01-05 22:51 - 2006-11-29 13:06 - 000469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2019-01-05 22:51 - 2006-11-29 13:06 - 000440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2019-01-05 22:51 - 2006-09-28 16:05 - 003977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2019-01-05 22:51 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2019-01-05 22:51 - 2006-09-28 16:05 - 000237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2019-01-05 22:51 - 2006-09-28 16:04 - 000364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2019-01-05 22:51 - 2006-07-28 09:31 - 000083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2019-01-05 22:51 - 2006-07-28 09:30 - 000363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2019-01-05 22:51 - 2006-07-28 09:30 - 000236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2019-01-05 22:51 - 2006-07-28 09:30 - 000062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2019-01-05 22:51 - 2006-05-31 07:24 - 000230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2019-01-05 22:51 - 2006-05-31 07:22 - 000354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2019-01-05 22:51 - 2006-03-31 12:41 - 003927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2019-01-05 22:51 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2019-01-05 22:51 - 2006-03-31 12:40 - 000352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2019-01-05 22:51 - 2006-03-31 12:39 - 000229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2019-01-05 22:51 - 2006-03-31 12:39 - 000083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2019-01-05 22:51 - 2006-03-31 12:39 - 000062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2019-01-05 22:51 - 2006-02-03 08:43 - 003830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2019-01-05 22:51 - 2006-02-03 08:43 - 002332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2019-01-05 22:51 - 2006-02-03 08:42 - 000355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2019-01-05 22:51 - 2006-02-03 08:42 - 000230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2019-01-05 22:51 - 2006-02-03 08:41 - 000016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2019-01-05 22:51 - 2006-02-03 08:41 - 000014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2019-01-05 22:51 - 2005-12-05 18:09 - 003815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2019-01-05 22:51 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2019-01-05 22:51 - 2005-07-22 19:59 - 003807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2019-01-05 22:51 - 2005-07-22 19:59 - 002319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2019-01-05 22:51 - 2005-05-26 15:34 - 003767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2019-01-05 22:51 - 2005-05-26 15:34 - 002297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2019-01-05 22:51 - 2005-03-18 17:19 - 003823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2019-01-05 22:51 - 2005-03-18 17:19 - 002337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2019-01-05 22:51 - 2005-02-05 19:45 - 003544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2019-01-05 22:51 - 2005-02-05 19:45 - 002222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2019-01-05 20:15 - 2019-01-09 18:07 - 000046188 _____ C:\Users\rkale\Downloads\Addition.txt
2019-01-05 20:13 - 2019-01-10 06:48 - 000000000 ____D C:\FRST
2019-01-05 20:13 - 2019-01-09 18:07 - 000128974 _____ C:\Users\rkale\Downloads\FRST.txt
2019-01-05 20:06 - 2019-01-05 20:06 - 002326304 _____ (Malwarebytes Corporation) C:\Users\rkale\Downloads\mb-check-3.1.10.1000.exe
2019-01-05 16:52 - 2019-01-05 16:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2019-01-05 16:38 - 2019-01-05 17:50 - 000000000 ____D C:\Program Files (x86)\Diablo III
2019-01-05 00:33 - 2019-01-05 01:13 - 000000438 _____ C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job
2019-01-05 00:33 - 2019-01-05 00:33 - 000003910 _____ C:\WINDOWS\System32\Tasks\Driver Easy Scheduled Scan
2019-01-05 00:33 - 2019-01-05 00:33 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Easeware
2019-01-05 00:33 - 2019-01-05 00:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy
2019-01-04 23:45 - 2019-01-04 23:45 - 000001552 _____ C:\Users\rkale\OneDrive\Documentos\archivo.txt
2019-01-04 23:27 - 2019-01-04 23:27 - 007954761 _____ C:\Users\rkale\Downloads\vidio.mp4
2019-01-04 22:14 - 2019-01-04 22:14 - 000046827 _____ C:\Users\rkale\Downloads\WhatsApp Ptt 2019-01-04 at 8.32.30 PM.ogg
2019-01-04 22:14 - 2019-01-04 22:14 - 000011669 _____ C:\Users\rkale\Downloads\WhatsApp Ptt 2019-01-04 at 8.22.24 PM.ogg
2019-01-04 20:04 - 2019-01-04 23:31 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Audacity
2019-01-04 20:02 - 2019-01-04 20:02 - 024210616 _____ (Audacity Team ) C:\Users\rkale\Downloads\audacity-win-2.1.0.exe
2019-01-04 19:31 - 2019-01-04 19:31 - 000354400 _____ C:\Users\rkale\OneDrive\Documentos\WhatsApp Audio 2019-01-04 at 7.31.25 PM.mp4
2019-01-04 18:49 - 2019-01-04 18:49 - 000207885 _____ C:\Users\rkale\Downloads\WhatsApp Audio 2019-01-04 at 6.49.40 PM.mp4
2019-01-04 18:46 - 2019-01-08 17:30 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Grabaciones de sonido
2019-01-03 20:44 - 2019-01-03 20:44 - 000000000 ____D C:\Program Files\Razer Chroma SDK
2019-01-03 20:44 - 2019-01-03 20:44 - 000000000 ____D C:\Program Files (x86)\Razer Chroma SDK
2019-01-03 20:40 - 2019-01-03 20:40 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Bungie
2019-01-03 20:12 - 2019-01-03 20:12 - 007666296 _____ (ESET spol. s r.o.) C:\Users\rkale\Downloads\esetonlinescanner_esl.exe
2019-01-03 20:12 - 2019-01-03 20:12 - 000000000 ____D C:\Users\rkale\AppData\Local\ESET
2019-01-03 18:58 - 2019-01-03 19:53 - 000000000 ____D C:\AdwCleaner
2019-01-03 18:51 - 2019-01-03 18:51 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2019-01-01 13:09 - 2019-01-01 13:10 - 003299200 _____ C:\Users\rkale\Downloads\ZHPCleaner.exe
2019-01-01 12:43 - 2019-01-10 06:48 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-01-01 12:43 - 2019-01-01 12:43 - 000002888 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2019-01-01 12:43 - 2019-01-01 12:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-01-01 12:43 - 2019-01-01 12:43 - 000000000 ____D C:\Program Files\CCleaner
2019-01-01 12:39 - 2019-01-01 12:42 - 019299120 _____ (Piriform Software Ltd) C:\Users\rkale\Downloads\ccsetup551.exe
2018-12-31 19:11 - 2018-12-31 19:11 - 000000000 ___HD C:\OneDriveTemp
2018-12-31 19:07 - 2018-12-31 19:07 - 000319024 _____ C:\active_protection.txt
2018-12-31 19:07 - 2018-12-31 19:07 - 000035928 _____ C:\url_setting_definitions.txt
2018-12-31 18:50 - 2018-12-31 18:50 - 000000000 ____D C:\Users\rkale\AppData\Local\mbam
2018-12-31 18:49 - 2018-12-31 18:49 - 000000000 ____D C:\Users\rkale\AppData\Local\mbamtray
2018-12-31 18:48 - 2018-12-31 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-12-31 18:48 - 2018-12-31 18:48 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-12-31 18:48 - 2018-12-31 18:48 - 000000000 ____D C:\Program Files\Malwarebytes
2018-12-31 18:48 - 2018-12-04 08:09 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-12-31 18:47 - 2018-12-31 18:48 - 081227760 _____ (Malwarebytes ) C:\Users\rkale\Downloads\mb3-setup-consumer-3.6.1.2711-1.0.508-1.0.8211.exe
2018-12-31 18:46 - 2018-12-31 18:46 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\rkale\Downloads\rkill.exe
2018-12-31 18:40 - 2018-12-31 18:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2018-12-31 18:40 - 2018-12-31 18:40 - 000000000 ____D C:\ProgramData\ESET
2018-12-31 18:40 - 2018-12-31 18:40 - 000000000 ____D C:\Program Files\ESET
2018-12-31 18:37 - 2018-12-31 18:37 - 005455480 _____ (ESET) C:\Users\rkale\Downloads\eset_nod32_antivirus_live_installer.exe
2018-12-31 18:12 - 2018-12-31 18:12 - 000000000 ____D C:\Users\rkale\AppData\Roaming\WinRAR
2018-12-31 18:11 - 2018-12-31 18:11 - 003253552 _____ (Alexander Roshal) C:\Users\rkale\Downloads\winrar-x64-561es.exe
2018-12-31 18:11 - 2018-12-31 18:11 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-12-31 18:11 - 2018-12-31 18:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-12-31 18:11 - 2018-12-31 18:11 - 000000000 ____D C:\Program Files\WinRAR
2018-12-31 17:21 - 2018-12-31 17:22 - 007320272 _____ (Malwarebytes) C:\Users\rkale\Downloads\adwcleaner_7.2.6.0.exe
2018-12-31 17:18 - 2019-01-03 20:47 - 000000000 ____D C:\ProgramData\Razer
2018-12-31 17:18 - 2019-01-03 20:45 - 000000000 ____D C:\Program Files (x86)\Razer
2018-12-31 17:18 - 2018-12-31 17:18 - 000000000 ____D C:\Users\rkale\AppData\Local\Razer
2018-12-31 17:18 - 2018-12-31 17:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2018-12-31 17:16 - 2018-12-31 17:16 - 027035616 _____ (Razer Inc.) C:\Users\rkale\Downloads\Razer_Synapse_Installer_v2.21.21.1.exe
2018-12-31 17:06 - 2018-12-31 17:06 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Soda PDF Files
2018-12-31 17:06 - 2018-12-31 17:06 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Overwatch
2018-12-31 17:06 - 2018-12-31 17:06 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Heroes of the Storm
2018-12-31 17:06 - 2018-12-31 17:06 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Exposicion de mamá
2018-12-31 17:06 - 2018-12-31 17:06 - 000000000 ____D C:\Users\rkale\OneDrive\Documentos\Diablo III
2018-12-31 17:00 - 2019-01-10 06:50 - 000000000 ____D C:\Users\rkale\AppData\Local\Spotify
2018-12-31 16:59 - 2018-12-31 16:59 - 000001838 _____ C:\Users\rkale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-12-31 16:58 - 2019-01-10 06:50 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Spotify
2018-12-31 16:58 - 2018-12-31 16:58 - 000742216 _____ (Spotify Ltd) C:\Users\rkale\Downloads\SpotifySetup.exe
2018-12-31 16:58 - 2018-12-31 16:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Overwatch
2018-12-31 15:43 - 2019-01-08 18:51 - 000000000 ____D C:\Program Files (x86)\Overwatch
2018-12-31 15:16 - 2018-12-31 15:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Destiny 2
2018-12-31 14:43 - 2019-01-09 17:58 - 000000000 ____D C:\Users\rkale\AppData\Local\CrashDumps
2018-12-31 02:27 - 2019-01-05 00:22 - 000000000 ____D C:\Program Files (x86)\Destiny 2
2018-12-31 02:26 - 2018-12-31 02:26 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2018-12-31 02:26 - 2018-12-17 00:18 - 000978128 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2018-12-31 02:26 - 2018-12-17 00:18 - 000978128 _____ C:\WINDOWS\system32\vulkan-1.dll
2018-12-31 02:26 - 2018-12-17 00:18 - 000845008 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2018-12-31 02:26 - 2018-12-17 00:18 - 000845008 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2018-12-31 02:26 - 2018-12-17 00:18 - 000552032 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2018-12-31 02:26 - 2018-12-17 00:18 - 000456800 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2018-12-31 02:26 - 2018-12-17 00:18 - 000267984 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2018-12-31 02:26 - 2018-12-17 00:18 - 000267984 _____ C:\WINDOWS\system32\vulkaninfo.exe
2018-12-31 02:26 - 2018-12-17 00:18 - 000243408 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2018-12-31 02:26 - 2018-12-17 00:18 - 000243408 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2018-12-31 02:26 - 2018-12-17 00:16 - 002003600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2018-12-31 02:26 - 2018-12-17 00:16 - 001512080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2018-12-31 02:26 - 2018-12-17 00:16 - 001461024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2018-12-31 02:26 - 2018-12-17 00:16 - 001126144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2018-12-31 02:26 - 2018-12-17 00:16 - 000631232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2018-12-31 02:26 - 2018-12-17 00:16 - 000521472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2018-12-31 02:26 - 2018-12-17 00:15 - 040261192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2018-12-31 02:26 - 2018-12-17 00:15 - 035157064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2018-12-31 02:26 - 2018-12-17 00:15 - 004946336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2018-12-31 02:26 - 2018-12-17 00:15 - 004316760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2018-12-31 02:26 - 2018-12-17 00:15 - 002017752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6441735.dll
2018-12-31 02:26 - 2018-12-17 00:15 - 001468504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6441735.dll
2018-12-31 02:26 - 2018-12-17 00:13 - 015909552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2018-12-31 02:26 - 2018-12-17 00:13 - 013204120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2018-12-31 02:26 - 2018-12-17 00:13 - 001167400 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2018-12-31 02:26 - 2018-12-17 00:13 - 000914400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2018-12-31 02:26 - 2018-12-17 00:13 - 000794632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2018-12-31 02:26 - 2018-12-17 00:13 - 000637480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2018-12-31 02:26 - 2018-12-17 00:12 - 019714256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2018-12-31 02:26 - 2018-12-17 00:12 - 016990072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2018-12-31 02:26 - 2018-12-17 00:12 - 004258800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2018-12-31 02:26 - 2018-12-11 05:00 - 000048148 _____ C:\WINDOWS\system32\nvinfo.pb
2018-12-31 02:25 - 2019-01-08 19:30 - 000000000 ____D C:\Users\rkale\AppData\Local\Battle.net
2018-12-31 02:25 - 2019-01-05 19:52 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Battle.net
2018-12-31 02:25 - 2019-01-03 22:21 - 000000000 ____D C:\Users\rkale\AppData\Local\Blizzard Entertainment
2018-12-31 02:24 - 2018-12-31 02:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2018-12-31 02:22 - 2018-12-31 02:25 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-12-31 02:22 - 2018-12-31 02:22 - 000000000 ____D C:\Users\rkale\AppData\Local\Blizzard
2018-12-31 02:21 - 2018-12-31 02:21 - 004703728 _____ (Blizzard Entertainment) C:\Users\rkale\Downloads\Battle.net-Setup.exe
2018-12-31 02:21 - 2018-12-31 02:21 - 000000000 ____D C:\ProgramData\Battle.net
2018-12-31 02:15 - 2019-01-06 09:42 - 000000000 ____D C:\Users\rkale\AppData\Local\NVIDIA
2018-12-31 02:15 - 2018-12-31 02:15 - 000000000 ____D C:\Users\rkale\ansel
2018-12-31 02:14 - 2018-12-31 02:14 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000004106 _____ C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000003976 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000003926 _____ C:\WINDOWS\System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000003926 _____ C:\WINDOWS\System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000003926 _____ C:\WINDOWS\System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-31 02:14 - 2018-12-31 02:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-12-31 02:11 - 2018-12-31 02:12 - 114076760 _____ (NVIDIA Corporation) C:\Users\rkale\Downloads\GeForce_Experience_v3.16.0.140.exe
2018-12-31 01:16 - 2018-12-31 01:16 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2018-12-31 01:14 - 2018-12-31 01:14 - 000002491 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000002454 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000002403 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2018-12-31 01:14 - 2018-12-31 01:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Herramientas de Microsoft Office 2016
2018-12-30 23:56 - 2018-12-30 23:56 - 000000000 ____D C:\Users\rkale\AppData\Local\OneDrive
2018-12-30 23:52 - 2018-12-30 23:53 - 000000000 ____D C:\Users\rkale\AppData\Local\Steam
2018-12-30 23:52 - 2018-12-30 23:52 - 000000000 ____D C:\Users\rkale\AppData\Local\CEF
2018-12-30 23:50 - 2019-01-09 17:59 - 000000000 ____D C:\Program Files (x86)\Steam
2018-12-30 23:50 - 2018-12-30 23:50 - 001573568 _____ C:\Users\rkale\Downloads\SteamSetup.exe
2018-12-30 23:50 - 2018-12-30 23:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2018-12-30 23:32 - 2018-12-30 23:32 - 000000000 ____D C:\Users\rkale\AppData\Local\DBG
2018-12-30 23:26 - 2018-12-30 23:26 - 000002373 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-30 23:25 - 2018-12-30 23:33 - 000000000 ____D C:\Users\rkale\AppData\Local\Google
2018-12-30 23:25 - 2018-12-30 23:26 - 000000000 ____D C:\Program Files (x86)\Google
2018-12-30 23:25 - 2018-12-30 23:25 - 000003620 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-12-30 23:25 - 2018-12-30 23:25 - 000003496 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-12-30 23:20 - 2018-12-30 23:20 - 000000000 ____D C:\Users\rkale\AppData\Local\Comms
2018-12-30 23:17 - 2018-12-30 23:17 - 000000000 ____D C:\Program Files\rempl
2018-12-28 14:51 - 2018-12-31 15:20 - 000000000 ____D C:\Users\rkale\AppData\Local\PlaceholderTileLogoFolder
2018-12-28 14:50 - 2018-12-28 14:50 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-767254285-3586098769-3745675886-1001
2018-12-28 14:46 - 2019-01-03 18:20 - 000000000 ___RD C:\Users\rkale\OneDrive
2018-12-28 14:44 - 2018-12-28 14:44 - 000000000 ____D C:\Users\rkale\AppData\Local\Conexant
2018-12-28 14:42 - 2019-01-10 06:48 - 000000200 _____ C:\Users\rkale\AppData\Roaming\sp_data.sys

#21

y aqui la parte dos de frst

2018-12-28 14:42 - 2018-12-30 23:14 - 000000000 ____D C:\ProgramData\USBChargerPlus
2018-12-28 14:41 - 2018-12-28 14:41 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Macromedia
2018-12-28 14:40 - 2018-12-31 02:16 - 000000000 ____D C:\Users\rkale\AppData\Local\NVIDIA Corporation
2018-12-28 14:40 - 2018-12-28 14:56 - 000000000 ____D C:\Users\rkale\AppData\Local\D3DSCache
2018-12-28 14:40 - 2018-12-28 14:41 - 000000000 ____D C:\Users\rkale\AppData\Local\Crashpad
2018-12-28 14:40 - 2018-12-28 14:40 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-12-28 14:39 - 2018-12-28 14:39 - 000000000 ___HD C:\Users\rkale\MicrosoftEdgeBackups
2018-12-28 14:39 - 2018-12-28 14:39 - 000000000 ____D C:\Users\rkale\AppData\Local\MicrosoftEdge
2018-12-28 14:38 - 2018-12-28 14:38 - 000000000 ____D C:\Users\rkale\AppData\Local\Publishers
2018-12-28 14:37 - 2019-01-10 06:45 - 000000000 __SHD C:\Users\rkale\IntelGraphicsProfiles
2018-12-28 14:37 - 2019-01-08 10:03 - 000000000 ___RD C:\Users\rkale\3D Objects
2018-12-28 14:37 - 2018-12-31 14:43 - 000000000 ____D C:\Users\rkale\AppData\Local\Packages
2018-12-28 14:37 - 2018-12-28 14:39 - 000000000 ____D C:\Users\rkale\AppData\Local\ConnectedDevicesPlatform
2018-12-28 14:37 - 2018-12-28 14:37 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Intel
2018-12-28 14:37 - 2018-12-28 14:37 - 000000000 ____D C:\Users\rkale\AppData\Roaming\Adobe
2018-12-28 14:37 - 2018-12-28 14:37 - 000000000 ____D C:\Users\rkale\AppData\Local\VirtualStore
2018-12-28 14:35 - 2019-01-08 19:36 - 000000000 ____D C:\Users\rkale
2018-12-28 14:35 - 2018-12-28 14:50 - 000002399 _____ C:\Users\rkale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-12-28 14:35 - 2018-12-28 14:35 - 000000020 ___SH C:\Users\rkale\ntuser.ini
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Reciente
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Plantillas
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Mis documentos
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Menú Inicio
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Impresoras
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Entorno de red
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Datos de programa
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\Configuración local
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\AppData\Local\Historial
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\AppData\Local\Datos de programa
2018-12-28 14:35 - 2018-12-28 14:35 - 000000000 _SHDL C:\Users\rkale\AppData\Local\Archivos temporales de Internet
2018-12-28 01:16 - 2019-01-08 16:23 - 005349780 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-12-28 01:15 - 2019-01-08 18:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-12-28 01:15 - 2018-12-31 02:14 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-28 01:15 - 2018-12-31 02:14 - 000003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-28 01:15 - 2018-12-31 02:14 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-28 01:15 - 2018-12-31 02:14 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-12-28 01:15 - 2018-12-30 23:26 - 000000000 ____D C:\WINDOWS\System32\Tasks\ASUSTek Computer Inc
2018-12-28 01:15 - 2018-12-28 01:15 - 000003118 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2018-12-28 01:15 - 2018-12-28 01:15 - 000002968 _____ C:\WINDOWS\System32\Tasks\Update Checker
2018-12-28 01:15 - 2018-12-28 01:15 - 000002924 _____ C:\WINDOWS\System32\Tasks\ATK Package 36D18D69AFC3
2018-12-28 01:15 - 2018-12-28 01:15 - 000002340 _____ C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus
2018-12-28 01:15 - 2018-12-28 01:15 - 000002330 _____ C:\WINDOWS\System32\Tasks\ASUS Battery Health Charging Notification
2018-12-28 01:15 - 2018-12-28 01:15 - 000002214 _____ C:\WINDOWS\System32\Tasks\ATK Package A22126881260
2018-12-28 01:15 - 2018-12-28 01:15 - 000001984 _____ C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Reciente
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Plantillas
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Mis documentos
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Menú Inicio
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Impresoras
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Entorno de red
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Datos de programa
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\Configuración local
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\AppData\Local\Historial
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\AppData\Local\Datos de programa
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default\AppData\Local\Archivos temporales de Internet
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Historial
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Datos de programa
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Archivos temporales de Internet
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\Default User
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Users\All Users
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\ProgramData\Plantillas
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\ProgramData\Menú Inicio
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\ProgramData\Escritorio
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\ProgramData\Documentos
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\ProgramData\Datos de programa
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Program Files\Archivos comunes
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Documents and Settings
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 _SHDL C:\Archivos de programa
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 ____D C:\WINDOWS\System32\Tasks\ASUS
2018-12-28 01:15 - 2018-12-28 01:15 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-12-28 01:14 - 2018-12-28 01:14 - 000023076 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-12-28 01:12 - 2018-04-11 17:33 - 002752000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-12-28 01:07 - 2018-12-28 01:07 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-12-28 00:45 - 2018-12-28 00:45 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-12-28 00:20 - 2019-01-10 06:47 - 000000000 ____D C:\ProgramData\NVIDIA
2018-12-28 00:20 - 2018-12-31 02:34 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-12-28 00:20 - 2018-12-31 02:31 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-12-28 00:20 - 2018-12-28 00:20 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2018-12-28 00:20 - 2018-12-11 01:08 - 005338320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2018-12-28 00:20 - 2018-12-11 01:08 - 002620456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2018-12-28 00:20 - 2018-12-11 01:08 - 001767920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2018-12-28 00:20 - 2018-12-11 01:08 - 000651248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2018-12-28 00:20 - 2018-12-11 01:08 - 000450600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2018-12-28 00:20 - 2018-12-11 01:08 - 000124968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2018-12-28 00:20 - 2018-12-11 01:08 - 000082800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2018-12-28 00:20 - 2018-12-10 20:57 - 008459772 _____ C:\WINDOWS\system32\nvcoproc.bin
2018-12-28 00:20 - 2018-12-10 05:29 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2018-12-28 00:19 - 2018-12-28 00:19 - 000001963 _____ C:\ProgramData\Microsoft\Windows\Start Menu\SmartAudio.lnk
2018-12-28 00:19 - 2018-12-28 00:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2018-12-28 00:18 - 2016-10-27 18:14 - 000416576 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe
2018-12-28 00:18 - 2016-10-27 18:14 - 000416576 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\SASrv.exe
2018-12-28 00:18 - 2015-07-31 19:29 - 000004664 _____ C:\WINDOWS\system32\Drivers\CxSfPt.DAT
2018-12-28 00:18 - 2014-10-20 16:54 - 000207576 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
2018-12-28 00:17 - 2018-12-28 14:45 - 000000000 ____D C:\ProgramData\Conexant
2018-12-28 00:15 - 2018-12-31 02:32 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-12-28 00:15 - 2018-12-28 00:56 - 000000000 ____D C:\Program Files\Intel
2018-12-28 00:15 - 2018-12-28 00:52 - 000000000 ___HD C:\Intel
2018-12-28 00:15 - 2018-12-28 00:18 - 000000000 ____D C:\ProgramData\UIU
2018-12-28 00:15 - 2018-12-28 00:18 - 000000000 ____D C:\Program Files\CONEXANT
2018-12-28 00:15 - 2018-12-28 00:16 - 001705080 _____ (TODO: <Company name>) C:\WINDOWS\SysWOW64\RebootPrompt.exe
2018-12-28 00:15 - 2018-12-28 00:15 - 000105984 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\UIUSrv.exe
2018-12-28 00:15 - 2018-12-28 00:15 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_esif_umdf2_02_00_00.Wdf
2018-12-28 00:15 - 2018-12-28 00:15 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_esif_lf_01011.Wdf
2018-12-28 00:15 - 2018-12-28 00:15 - 000000000 ____D C:\WINDOWS\system32\Intel
2018-12-28 00:15 - 2018-12-28 00:15 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2018-12-28 00:12 - 2018-12-28 00:12 - 000000000 ____D C:\ProgramData\USOShared
2018-12-28 00:08 - 2019-01-08 17:20 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-12-28 00:08 - 2018-12-28 00:08 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-12-28 00:07 - 2019-01-08 08:39 - 000235032 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-12-27 14:13 - 2018-12-28 01:02 - 000000000 ____D C:\WINDOWS\ASUS
2018-12-27 14:12 - 2018-12-27 14:12 - 000000000 ____D C:\WINDOWS\InfusedApps
2018-12-27 14:11 - 2019-01-07 17:47 - 000000000 ____D C:\WINDOWS\Panther
2018-12-27 14:07 - 2018-12-27 14:07 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-12-27 14:07 - 2018-12-27 14:07 - 000000000 ____D C:\WINDOWS\Setup
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-12-27 14:04 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-12-27 14:04 - 2019-01-08 08:17 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-12-27 14:04 - 2019-01-08 08:17 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-12-27 14:04 - 2019-01-08 08:17 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-12-27 14:04 - 2019-01-08 08:17 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-12-27 14:04 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-12-27 14:04 - 2018-12-28 01:02 - 000000000 ____D C:\WINDOWS\OCR
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2018-12-27 14:04 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2018-12-27 14:03 - 2018-12-27 14:03 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-12-27 14:03 - 2018-12-27 14:03 - 000000000 ____D C:\Program Files\MSBuild
2018-12-27 14:03 - 2018-12-27 14:03 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-12-27 14:03 - 2018-12-27 14:03 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-12-27 13:58 - 2019-01-08 16:23 - 000694660 _____ C:\WINDOWS\system32\perfh01F.dat
2018-12-27 13:58 - 2019-01-08 16:23 - 000144206 _____ C:\WINDOWS\system32\perfc01F.dat
2018-12-27 13:58 - 2018-12-27 13:56 - 000290418 _____ C:\WINDOWS\system32\perfi01F.dat
2018-12-27 13:58 - 2018-12-27 13:56 - 000039162 _____ C:\WINDOWS\system32\perfd01F.dat
2018-12-27 13:57 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\SysWOW64\tr
2018-12-27 13:57 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\tr
2018-12-27 13:49 - 2019-01-08 16:23 - 000766614 _____ C:\WINDOWS\system32\prfh0816.dat
2018-12-27 13:49 - 2019-01-08 16:23 - 000152038 _____ C:\WINDOWS\system32\prfc0816.dat
2018-12-27 13:49 - 2018-12-27 13:47 - 000341398 _____ C:\WINDOWS\system32\prfi0816.dat
2018-12-27 13:49 - 2018-12-27 13:47 - 000042740 _____ C:\WINDOWS\system32\prfd0816.dat
2018-12-27 13:48 - 2018-12-27 13:48 - 000000000 ____D C:\WINDOWS\SysWOW64\pt
2018-12-27 13:48 - 2018-12-27 13:48 - 000000000 ____D C:\WINDOWS\system32\pt
2018-12-27 13:41 - 2019-01-08 16:23 - 000752216 _____ C:\WINDOWS\system32\prfh0416.dat
2018-12-27 13:41 - 2019-01-08 16:23 - 000148534 _____ C:\WINDOWS\system32\prfc0416.dat
2018-12-27 13:41 - 2018-12-27 13:39 - 000328664 _____ C:\WINDOWS\system32\prfi0416.dat
2018-12-27 13:41 - 2018-12-27 13:39 - 000040858 _____ C:\WINDOWS\system32\prfd0416.dat
2018-12-27 13:33 - 2019-01-08 16:23 - 000780362 _____ C:\WINDOWS\system32\perfh00C.dat
2018-12-27 13:33 - 2019-01-08 16:23 - 000149378 _____ C:\WINDOWS\system32\perfc00C.dat
2018-12-27 13:33 - 2018-12-27 13:33 - 000000000 ____D C:\WINDOWS\SysWOW64\fr
2018-12-27 13:33 - 2018-12-27 13:33 - 000000000 ____D C:\WINDOWS\system32\fr
2018-12-27 13:33 - 2018-12-27 13:32 - 000351124 _____ C:\WINDOWS\system32\perfi00C.dat
2018-12-27 13:33 - 2018-12-27 13:32 - 000040694 _____ C:\WINDOWS\system32\perfd00C.dat
2018-12-27 13:25 - 2019-01-08 16:23 - 000789180 _____ C:\WINDOWS\system32\perfh00A.dat
2018-12-27 13:25 - 2019-01-08 16:23 - 000155760 _____ C:\WINDOWS\system32\perfc00A.dat
2018-12-27 13:25 - 2018-12-27 13:24 - 000346834 _____ C:\WINDOWS\system32\perfi00A.dat
2018-12-27 13:25 - 2018-12-27 13:24 - 000043954 _____ C:\WINDOWS\system32\perfd00A.dat
2018-12-27 13:24 - 2018-12-27 13:24 - 000000000 ____D C:\WINDOWS\SysWOW64\es
2018-12-27 13:24 - 2018-12-27 13:24 - 000000000 ____D C:\WINDOWS\system32\es
2018-12-27 13:10 - 2018-12-27 13:58 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2018-12-27 13:10 - 2018-12-27 13:58 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2018-12-27 13:10 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2018-12-27 13:10 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2018-12-27 13:10 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\winrm
2018-12-27 13:10 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\WCN
2018-12-27 13:10 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\slmgr
2018-12-27 13:10 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2018-12-27 13:10 - 2018-12-27 13:10 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2018-12-27 13:10 - 2018-12-27 13:10 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2018-12-27 13:10 - 2018-12-27 13:10 - 000000000 ____D C:\WINDOWS\system32\ar
2018-12-27 13:10 - 2018-12-27 13:10 - 000000000 ____D C:\WINDOWS\system32\0409
2018-12-27 13:09 - 2018-12-27 13:09 - 000000000 ____D C:\WINDOWS\DigitalLocker
2018-12-27 13:04 - 2018-11-30 22:01 - 000835688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-12-27 13:04 - 2018-11-30 22:01 - 000179808 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-12-27 13:01 - 2018-12-27 12:53 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2018-12-27 13:01 - 2018-12-27 12:53 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2018-12-27 13:00 - 2018-12-27 14:11 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-12-27 13:00 - 2018-12-27 12:52 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2018-12-27 13:00 - 2018-12-27 12:52 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2018-12-27 13:00 - 2018-12-27 12:52 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2018-12-27 13:00 - 2018-12-27 12:52 - 000017346 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2018-12-27 13:00 - 2018-12-27 12:52 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2018-12-27 13:00 - 2018-12-27 12:52 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2018-12-27 12:59 - 2019-01-10 06:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-12-27 12:59 - 2019-01-09 19:15 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-12-27 12:59 - 2019-01-09 17:58 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-12-27 12:59 - 2019-01-08 10:16 - 000000000 ___RD C:\Program Files (x86)
2018-12-27 12:59 - 2019-01-08 08:20 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2018-12-27 12:59 - 2019-01-08 08:18 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-12-27 12:59 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\TextInput
2018-12-27 12:59 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-12-27 12:59 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-12-27 12:59 - 2019-01-08 08:18 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ___SD C:\WINDOWS\system32\UNP
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\setup
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-12-27 12:59 - 2019-01-08 08:16 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-12-27 12:59 - 2019-01-08 08:15 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-12-27 12:59 - 2019-01-08 08:15 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-12-27 12:59 - 2019-01-08 08:15 - 000000000 ____D C:\WINDOWS\ShellComponents
2018-12-27 12:59 - 2019-01-08 08:15 - 000000000 ____D C:\WINDOWS\Provisioning
2018-12-27 12:59 - 2019-01-08 08:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-12-27 12:59 - 2019-01-08 08:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-12-27 12:59 - 2019-01-08 08:14 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-12-27 12:59 - 2019-01-08 08:14 - 000000000 ____D C:\Program Files\Windows Defender
2018-12-27 12:59 - 2019-01-08 08:14 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-12-27 12:59 - 2019-01-08 08:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2018-12-27 12:59 - 2019-01-07 17:36 - 000000000 ___HD C:\Program Files\WindowsApps
2018-12-27 12:59 - 2018-12-31 21:47 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-12-27 12:59 - 2018-12-31 18:40 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-12-27 12:59 - 2018-12-31 12:09 - 000000000 ____D C:\WINDOWS\appcompat
2018-12-27 12:59 - 2018-12-31 01:16 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-12-27 12:59 - 2018-12-28 14:35 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-12-27 12:59 - 2018-12-28 01:15 - 000000000 ____D C:\WINDOWS\Registration
2018-12-27 12:59 - 2018-12-28 01:15 - 000000000 ____D C:\Program Files\windows nt
2018-12-27 12:59 - 2018-12-28 01:12 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2018-12-27 12:59 - 2018-12-28 01:03 - 000000000 ____D C:\WINDOWS\system32\spool
2018-12-27 12:59 - 2018-12-28 00:20 - 000000000 ____D C:\WINDOWS\Help
2018-12-27 12:59 - 2018-12-28 00:12 - 000000000 ____D C:\ProgramData\USOPrivate
2018-12-27 12:59 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2018-12-27 12:59 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\system32\MUI
2018-12-27 12:59 - 2018-12-27 14:04 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2018-12-27 12:59 - 2018-12-27 13:57 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2018-12-27 12:59 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\SysWOW64\com
2018-12-27 12:59 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2018-12-27 12:59 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-12-27 12:59 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\system32\com
2018-12-27 12:59 - 2018-12-27 13:56 - 000000000 ____D C:\WINDOWS\IME
2018-12-27 12:59 - 2018-12-27 13:56 - 000000000 ____D C:\Program Files\Common Files\system
2018-12-27 12:59 - 2018-12-27 13:40 - 000000000 ___SD C:\WINDOWS\system32\dsc
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2018-12-27 12:59 - 2018-12-27 13:01 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ___SD C:\WINDOWS\system32\Nui
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\ta-lk
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\my-mm
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\icsxml
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\ias
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\downlevel
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\DDFs
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2018-12-27 12:59 - 2018-12-27 13:00 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 __SHD C:\Program Files\Windows Sidebar
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 __RSD C:\WINDOWS\media
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 __RHD C:\Users\Public\Libraries
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ___HD C:\WINDOWS\LanguageOverlayCache
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Web
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\WaaS
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Vss
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\tracing
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\TAPI
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SystemResources
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SystemApps
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\winevt
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\ras
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\IME
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\hydrogen
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\DriverState
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\System
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SKB
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\ServiceState
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\security
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\schemas
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\SchCache
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Resources
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\rescache
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\PLA
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Performance
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\ModemLogs
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\L2Schemas
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\InputMethod
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\IdentityCRL
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Globalization
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Cursors
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\Branding
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\addins
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files\Windows Security
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files\Windows Portable Devices
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files\Common Files\Services
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files (x86)\windows nt
2018-12-27 12:59 - 2018-12-27 12:59 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2018-12-27 12:59 - 2018-12-27 12:52 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2018-12-27 12:56 - 2019-01-09 17:58 - 000000000 ____D C:\WINDOWS\INF
2018-12-27 12:40 - 2019-01-08 01:41 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-12-27 11:30 - 2019-01-08 18:38 - 118489088 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-12-27 11:30 - 2019-01-08 18:38 - 021757952 _____ C:\WINDOWS\system32\config\SYSTEM
2018-12-27 11:30 - 2019-01-08 18:38 - 001048576 _____ C:\WINDOWS\system32\config\DEFAULT
2018-12-27 11:30 - 2019-01-08 18:38 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-12-27 11:30 - 2019-01-08 18:38 - 000065536 _____ C:\WINDOWS\system32\config\SAM
2018-12-27 11:30 - 2019-01-08 18:38 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY
2018-12-27 11:30 - 2018-12-30 23:48 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-12-27 11:30 - 2018-12-27 13:57 - 000000000 ____D C:\WINDOWS\servicing
2018-12-27 11:30 - 2018-12-27 12:59 - 000000000 ____D C:\WINDOWS\system32\SMI
2018-12-27 11:05 - 2018-12-27 15:06 - 000000000 ___HD C:\$SysReset
2018-12-20 23:24 - 2018-12-14 06:24 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-12-20 23:24 - 2018-12-14 01:29 - 006567472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-12-20 23:24 - 2018-12-14 01:29 - 001130760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-12-20 23:24 - 2018-12-14 01:25 - 001035256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-12-20 23:24 - 2018-12-14 01:23 - 001221432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-12-20 23:24 - 2018-12-14 01:23 - 001029944 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-12-20 23:24 - 2018-12-14 01:23 - 000566568 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-12-20 23:24 - 2018-12-14 01:23 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-12-20 23:24 - 2018-12-14 01:23 - 000076088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2018-12-20 23:24 - 2018-12-14 01:22 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-12-20 23:24 - 2018-12-14 01:22 - 007520104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-12-20 23:24 - 2018-12-14 01:21 - 001457240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-12-20 23:24 - 2018-12-14 01:21 - 001257672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-12-20 23:24 - 2018-12-14 01:21 - 001140480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-12-20 23:24 - 2018-12-14 01:21 - 001098064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-12-20 23:24 - 2018-12-14 01:21 - 000982912 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-12-20 23:24 - 2018-12-14 01:13 - 005775872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-12-20 23:24 - 2018-12-14 01:12 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-12-20 23:24 - 2018-12-14 01:10 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-12-20 23:24 - 2018-12-14 01:07 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-12-20 23:24 - 2018-12-14 00:55 - 003396608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-12-20 23:24 - 2018-12-14 00:55 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-12-20 23:24 - 2018-12-14 00:54 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2018-12-20 23:24 - 2018-12-14 00:54 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-12-20 23:24 - 2018-12-14 00:54 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-12-20 23:24 - 2018-12-14 00:53 - 007573504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-12-20 23:24 - 2018-12-14 00:52 - 002173440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-12-20 23:24 - 2018-12-14 00:52 - 001826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2018-12-20 23:24 - 2018-12-14 00:51 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-12-20 23:24 - 2018-12-14 00:50 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-12-20 23:24 - 2018-12-13 23:34 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2018-12-12 18:06 - 2018-12-08 06:42 - 004527800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-12-12 18:06 - 2018-12-08 06:42 - 001616824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2018-12-12 18:06 - 2018-12-08 06:29 - 013572608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-12-12 18:06 - 2018-12-08 06:28 - 012710400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-12-12 18:06 - 2018-12-08 06:25 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-12-12 18:06 - 2018-12-08 02:07 - 005625352 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-12-12 18:06 - 2018-12-08 02:06 - 001017168 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-12-12 18:06 - 2018-12-08 02:05 - 007436216 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-12-12 18:06 - 2018-12-08 02:04 - 002371296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-12-12 18:06 - 2018-12-08 01:49 - 025855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-12-12 18:06 - 2018-12-08 01:45 - 006043496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-12-12 18:06 - 2018-12-08 01:42 - 022715392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-12-12 18:06 - 2018-12-08 01:41 - 007057408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2018-12-12 18:06 - 2018-12-08 01:40 - 004710912 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-12-12 18:06 - 2018-12-08 01:40 - 004384768 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-12-12 18:06 - 2018-12-08 01:38 - 022016000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-12-12 18:06 - 2018-12-08 01:33 - 019405312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-12-12 18:05 - 2018-12-08 06:47 - 001048712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2018-12-12 18:05 - 2018-12-08 06:42 - 001634944 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-12-12 18:05 - 2018-12-08 06:41 - 002394960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-12-12 18:05 - 2018-12-08 06:40 - 001454648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-12-12 18:05 - 2018-12-08 06:28 - 006586880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-12-12 18:05 - 2018-12-08 06:28 - 004708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-12-12 18:05 - 2018-12-08 06:27 - 005657600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-12-12 18:05 - 2018-12-08 06:25 - 011902976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-12-12 18:05 - 2018-12-08 06:23 - 003649024 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-12-12 18:05 - 2018-12-08 06:23 - 002892288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-12-12 18:05 - 2018-12-08 06:23 - 001856512 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-12-12 18:05 - 2018-12-08 06:23 - 001661440 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-12-12 18:05 - 2018-12-08 06:22 - 001469952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-12-12 18:05 - 2018-12-08 06:22 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-12-12 18:05 - 2018-12-08 02:06 - 000491416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-12-12 18:05 - 2018-12-08 02:05 - 002822656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-12-12 18:05 - 2018-12-08 02:05 - 002463384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-12-12 18:05 - 2018-12-08 02:05 - 001935008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-12-12 18:05 - 2018-12-08 02:05 - 001209888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-12-12 18:05 - 2018-12-08 02:05 - 000594224 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-12-12 18:05 - 2018-12-08 02:04 - 004404720 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-12-12 18:05 - 2018-12-08 02:04 - 001943328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-12-12 18:05 - 2018-12-08 02:04 - 001188512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-12-12 18:05 - 2018-12-08 02:04 - 000416024 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2018-12-12 18:05 - 2018-12-08 01:47 - 000861744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-12-12 18:05 - 2018-12-08 01:47 - 000785760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-12-12 18:05 - 2018-12-08 01:46 - 002331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-12-12 18:05 - 2018-12-08 01:46 - 001989040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-12-12 18:05 - 2018-12-08 01:46 - 000457056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2018-12-12 18:05 - 2018-12-08 01:45 - 004789952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-12-12 18:05 - 2018-12-08 01:45 - 002307240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2018-12-12 18:05 - 2018-12-08 01:45 - 001805656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-12-12 18:05 - 2018-12-08 01:45 - 001620472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-12-12 18:05 - 2018-12-08 01:45 - 001379816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-12-12 18:05 - 2018-12-08 01:45 - 001011872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-12-12 18:05 - 2018-12-08 01:42 - 009084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll

#22
2018-12-12 18:05 - 2018-12-08 01:38 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-12-12 18:05 - 2018-12-08 01:38 - 002739200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-12-12 18:05 - 2018-12-08 01:37 - 002825728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2018-12-12 18:05 - 2018-12-08 01:36 - 003381248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2018-12-12 18:05 - 2018-12-08 01:36 - 003090432 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-12-12 18:05 - 2018-12-08 01:36 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2018-12-12 18:05 - 2018-12-08 01:36 - 001768448 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-12-12 18:05 - 2018-12-08 01:36 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-12-12 18:05 - 2018-12-08 01:36 - 000566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-12-12 18:05 - 2018-12-08 01:35 - 002126336 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2018-12-12 18:05 - 2018-12-08 01:35 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-12-12 18:05 - 2018-12-08 01:35 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-12-12 18:05 - 2018-12-08 01:34 - 001023488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2018-12-12 18:05 - 2018-12-08 01:34 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2018-12-12 18:05 - 2018-12-08 01:33 - 002904064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-12-12 18:05 - 2018-12-08 01:33 - 001457152 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2018-12-12 18:05 - 2018-12-08 01:33 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2018-12-12 18:05 - 2018-12-08 01:33 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-12-12 18:05 - 2018-12-08 01:33 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2018-12-12 18:05 - 2018-12-08 01:32 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-12-12 18:05 - 2018-12-08 01:32 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-12-12 18:05 - 2018-12-08 01:30 - 006647296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2018-12-12 18:05 - 2018-12-08 01:30 - 002966528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-12-12 18:05 - 2018-12-08 01:29 - 005883904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2018-12-12 18:05 - 2018-12-08 01:29 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-12-12 18:05 - 2018-12-08 01:28 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2018-12-12 18:05 - 2018-12-08 01:27 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-12-12 18:05 - 2018-12-08 01:24 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-12-12 18:04 - 2018-12-08 06:47 - 000645320 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-12-12 18:04 - 2018-12-08 06:46 - 000549760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2018-12-12 18:04 - 2018-12-08 06:41 - 000481880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-12-12 18:04 - 2018-12-08 06:22 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-12-12 18:04 - 2018-12-08 02:07 - 001328632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2018-12-12 18:04 - 2018-12-08 02:07 - 001063416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-12-12 18:04 - 2018-12-08 02:06 - 000777512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-12-12 18:04 - 2018-12-08 02:06 - 000433168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-12-12 18:04 - 2018-12-08 02:05 - 000793592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-12-12 18:04 - 2018-12-08 02:05 - 000130312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-12-12 18:04 - 2018-12-08 02:04 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-12-12 18:04 - 2018-12-08 02:04 - 000268280 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-12-12 18:04 - 2018-12-08 02:04 - 000260800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-12-12 18:04 - 2018-12-08 01:46 - 000665224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-12-12 18:04 - 2018-12-08 01:38 - 000419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
2018-12-12 18:04 - 2018-12-08 01:37 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-12-12 18:04 - 2018-12-08 01:34 - 001535488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-12-12 18:04 - 2018-12-08 01:34 - 000693248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2018-12-12 18:04 - 2018-12-08 01:34 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-12-12 18:04 - 2018-12-08 01:34 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2018-12-12 18:04 - 2018-12-08 01:33 - 000823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2018-12-12 18:04 - 2018-12-08 01:32 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-12-12 18:04 - 2018-12-08 01:28 - 000391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-12-12 18:04 - 2018-12-08 01:27 - 002449408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2018-12-12 18:04 - 2018-12-08 01:27 - 001986560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2018-12-12 18:04 - 2018-12-08 01:26 - 000848384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2018-12-12 18:04 - 2018-12-08 01:25 - 000978944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2018-12-12 18:04 - 2018-12-08 01:25 - 000856576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2018-12-12 18:04 - 2018-12-08 01:24 - 000795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2018-12-12 18:03 - 2018-12-08 06:39 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2018-12-12 18:03 - 2018-12-08 06:23 - 000471040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2018-12-12 18:03 - 2018-12-08 02:12 - 000272408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-12-12 18:03 - 2018-12-08 02:12 - 000269336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-12-12 18:03 - 2018-12-08 02:12 - 000092688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2018-12-12 18:03 - 2018-12-08 02:06 - 000709936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-12-12 18:03 - 2018-12-08 02:06 - 000249088 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2018-12-12 18:03 - 2018-12-08 02:05 - 001018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2018-12-12 18:03 - 2018-12-08 02:05 - 000706040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-12-12 18:03 - 2018-12-08 02:05 - 000421176 _____ (Microsoft Corporation) C:\WINDOWS\system32\xbgmengine.dll
2018-12-12 18:03 - 2018-12-08 02:05 - 000413920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-12-12 18:03 - 2018-12-08 02:05 - 000171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-12-12 18:03 - 2018-12-08 02:05 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fileinfo.sys
2018-12-12 18:03 - 2018-12-08 02:04 - 002590296 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2018-12-12 18:03 - 2018-12-08 02:04 - 001150312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-12-12 18:03 - 2018-12-08 02:04 - 000885760 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-12-12 18:03 - 2018-12-08 02:04 - 000527160 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-12-12 18:03 - 2018-12-08 02:04 - 000413176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-12-12 18:03 - 2018-12-08 02:04 - 000375608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-12-12 18:03 - 2018-12-08 02:04 - 000335672 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2018-12-12 18:03 - 2018-12-08 02:04 - 000158624 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-12-12 18:03 - 2018-12-08 02:04 - 000128824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2018-12-12 18:03 - 2018-12-08 02:04 - 000058168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
2018-12-12 18:03 - 2018-12-08 02:04 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2018-12-12 18:03 - 2018-12-08 01:46 - 001397104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-12-12 18:03 - 2018-12-08 01:46 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-12-12 18:03 - 2018-12-08 01:45 - 000567256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-12-12 18:03 - 2018-12-08 01:45 - 000356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-12-12 18:03 - 2018-12-08 01:45 - 000129296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-12-12 18:03 - 2018-12-08 01:38 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2018-12-12 18:03 - 2018-12-08 01:38 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
2018-12-12 18:03 - 2018-12-08 01:37 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2018-12-12 18:03 - 2018-12-08 01:37 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2018-12-12 18:03 - 2018-12-08 01:37 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2018-12-12 18:03 - 2018-12-08 01:37 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2018-12-12 18:03 - 2018-12-08 01:37 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2018-12-12 18:03 - 2018-12-08 01:37 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2018-12-12 18:03 - 2018-12-08 01:36 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2018-12-12 18:03 - 2018-12-08 01:36 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-12-12 18:03 - 2018-12-08 01:36 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2018-12-12 18:03 - 2018-12-08 01:36 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mmcss.sys
2018-12-12 18:03 - 2018-12-08 01:35 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-12-12 18:03 - 2018-12-08 01:33 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2018-12-12 18:03 - 2018-12-08 01:32 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2018-12-12 18:03 - 2018-12-08 01:32 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-12-12 18:03 - 2018-12-08 01:32 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-12-12 18:03 - 2018-12-08 01:29 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-12-12 18:03 - 2018-12-08 01:28 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-12-12 18:03 - 2018-12-08 01:27 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-12-12 18:03 - 2018-12-08 01:27 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2018-12-12 18:03 - 2018-12-08 01:27 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2018-12-12 18:03 - 2018-12-08 01:26 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2018-12-12 18:03 - 2018-12-08 01:25 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2018-12-12 18:03 - 2018-12-08 01:25 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2018-12-12 18:03 - 2018-12-08 01:25 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2018-12-12 18:03 - 2018-12-08 01:24 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2018-12-12 18:02 - 2018-12-08 06:29 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-12-12 18:02 - 2018-12-08 06:27 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storqosflt.sys
2018-12-12 18:02 - 2018-12-08 06:27 - 000068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2018-12-12 18:02 - 2018-12-08 06:27 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2018-12-12 18:02 - 2018-12-08 06:23 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-12-12 18:02 - 2018-12-08 01:39 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnsruprov.dll
2018-12-12 18:02 - 2018-12-08 01:38 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageLiveTileTask.exe
2018-12-12 18:02 - 2018-12-08 01:38 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2018-12-12 18:02 - 2018-12-08 01:38 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2018-12-12 18:02 - 2018-12-08 01:37 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataUsageHandlers.dll
2018-12-12 18:02 - 2018-12-08 01:37 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2018-12-12 18:02 - 2018-12-08 01:36 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2018-12-12 18:02 - 2018-12-08 01:30 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2018-12-12 18:02 - 2018-12-08 01:29 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2018-12-12 18:02 - 2018-12-08 01:28 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-12-12 18:02 - 2018-12-08 01:24 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-08 10:03 - 2017-08-15 20:38 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-12-31 02:23 - 2017-08-15 20:54 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-12-31 02:14 - 2017-08-15 20:43 - 000000000 ____D C:\ProgramData\Package Cache
2018-12-31 02:09 - 2017-05-04 11:27 - 000000000 ____D C:\WINDOWS\Log
2018-12-31 01:12 - 2017-08-15 21:42 - 000000000 ____D C:\Program Files\Microsoft Office
2018-12-30 23:36 - 2017-08-15 21:29 - 000000000 ____D C:\Program Files\mcafee
2018-12-30 23:36 - 2017-08-15 21:28 - 000000000 ____D C:\ProgramData\McAfee
2018-12-30 23:26 - 2017-05-04 11:24 - 000000000 ____D C:\Program Files (x86)\ASUS
2018-12-28 14:38 - 2017-08-15 21:46 - 000002491 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2018-12-28 14:38 - 2017-08-15 21:46 - 000002472 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2018-12-28 14:38 - 2017-08-15 21:46 - 000002454 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2018-12-28 14:38 - 2017-08-15 21:46 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2018-12-28 14:38 - 2017-08-15 21:46 - 000002399 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2018-12-28 14:36 - 2017-08-15 20:44 - 000000000 ____D C:\ProgramData\Intel
2018-12-28 01:14 - 2017-03-18 15:03 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-12-28 01:03 - 2017-08-15 21:05 - 000000000 ___HD C:\WINDOWS\system32\WLANProfiles
2018-12-28 01:03 - 2017-08-15 21:00 - 000000000 ____D C:\WINDOWS\UCI
2018-12-28 01:02 - 2017-08-15 21:24 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector 12
2018-12-28 01:02 - 2017-08-15 21:21 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PhotoDirector 5
2018-12-28 01:02 - 2017-08-15 21:17 - 000000000 ____D C:\ProgramData\Temp
2018-12-28 01:02 - 2017-08-15 21:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower
2018-12-28 01:02 - 2017-08-15 21:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2018-12-28 01:02 - 2017-03-18 20:32 - 000000000 ____D C:\WINDOWS\HoloShell
2018-12-28 01:01 - 2017-08-15 21:24 - 000000000 ____D C:\Program Files (x86)\Cyberlink
2018-12-28 01:01 - 2017-08-15 21:17 - 000000000 ____D C:\ProgramData\install_clap
2018-12-28 01:01 - 2017-08-15 21:17 - 000000000 ____D C:\ProgramData\CyberLink
2018-12-28 01:01 - 2017-08-15 21:14 - 000000000 ____D C:\Program Files (x86)\ICEpower
2018-12-28 01:01 - 2017-08-15 21:08 - 000000000 ____D C:\ProgramData\AmUStor
2018-12-28 01:01 - 2017-08-15 21:08 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2018-12-28 01:01 - 2017-08-15 21:08 - 000000000 ____D C:\Program Files (x86)\AmUStor
2018-12-28 01:01 - 2017-08-15 20:48 - 000000000 ____D C:\Program Files (x86)\Intel
2018-12-28 01:00 - 2017-08-15 21:42 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-12-28 00:56 - 2017-08-15 21:20 - 000000000 ____D C:\Program Files\CyberLink
2018-12-28 00:56 - 2017-08-15 21:08 - 000000000 ____D C:\Program Files\DIFX
2018-12-28 00:52 - 2017-08-15 21:04 - 000000000 ____D C:\Program Files\Common Files\Intel
2018-12-28 00:52 - 2017-05-04 11:27 - 000000000 ____D C:\eSupport
2018-12-17 00:12 - 2018-12-05 19:38 - 004999920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2018-12-11 05:00 - 2017-08-15 20:55 - 000001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat

==================== Files in the root of some directories =======

2018-12-28 14:42 - 2019-01-10 06:48 - 000000200 _____ () C:\Users\rkale\AppData\Roaming\sp_data.sys

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-12-28 00:07

==================== End of FRST.txt ============================

#23

Hola de nuevo @Huesoro

Revisaremos qué hay en los reportes

Por favor, mientras te ayudamos, no hagas modificaciones, instales o ejecutes otros programas que no sean los indicados por nosotros

Saludos


#24

Buenas noches, habeis encontrado algo? Necesito usar la computadora para unos trabajos y como.dijeron que no podia ejecutar programas…


#25

Hola de nuevo @Huesoro

Primero, discúlpa por la demora

Una duda ¿Instalaste alguna vez algún programa convertidor llamado “Wondershare” por causualidad?

Nos comentas

Saludos


#26

Si, pero este lo instale posterior a la infección, es un editor de video, fue de la pagina oficial, para el programa Filmora 9


#27

Hola de nuevo @Huesoro

Una duda

  1. ¿Es tu PC un ASUS? Si es así ¿Utilizaste los medios del fabricante para llevar a cabo el proceso?
  2. ¿Has formateado el disco duro externo? Si fué así ¿Fué antes de abrir el tema?
  3. ¿Aún aparece ese mensaje que nos indicaste al principio luego de (ese que el disco era propiedad de S-1-5-21-767254285-3586098769-3745675886-1001)? Si formateaste el disco externo ¿Ese mensaje volvió a aparecer?
  4. ¿Utilizaste ese disco externo para mover datos al disco duro después del formateo del equipo?

Nos comentas

Saludos


#28

Para el formateo use el de windows, no sabia que Asus tenia opción de formateo.

Si, el disco externo lo formatee antes de abrir el tema

No habia vuelto a conectar el disco al pc hasta que me lo pidieron y realmente no lo cheque, pero cuando lo formatee en otra pc no aparecía

Y no, no pase datos al disco duro


#29

Hola de nuevo @Huesoro

Ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
Start
CreateRestorePoint:
CloseProcesses:

HKLM-x32\...\Run: [] => [X]
SearchScopes: HKU\S-1-5-21-767254285-3586098769-3745675886-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-767254285-3586098769-3745675886-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
CHR Extension: (Chrome Media Router) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-30]
S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd)
2019-01-07 17:42 - 2019-01-07 17:43 - 101249024 _____ C:\WINDOWS\system32\config\COMPONENTS.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 113516544 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000864256 _____ C:\WINDOWS\system32\config\DEFAULT.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000045056 _____ C:\WINDOWS\system32\config\SAM.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2019-01-07 17:37 - 2019-01-08 10:08 - 000000000 ____D C:\Users\rkale\AppData\LocalLow\IObit
2019-01-07 17:36 - 2019-01-08 10:08 - 000000000 ____D C:\Users\rkale\AppData\Roaming\IObit
2019-01-07 17:36 - 2019-01-08 10:08 - 000000000 ____D C:\ProgramData\IObit
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {40E4B5E4-4805-4B60-AAFB-DE4608B3A78A} - System32\Tasks\ASC12_SkipUac_rkale => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {61BACA71-6E29-49F4-9BE0-1AF68F37CC9E} - System32\Tasks\ASC12_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\StartupApproved\Run: => "Advanced SystemCare 12"
AlternateDataStreams: C:\Users\rkale\AppData\Local\Temp:$DATA [16]

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.


#30

Buenas tardes, lo he hecho, pero no me permitía iniciar en modo seguro con conexión así que tuve que guardar el código antes y posterior hacer el reinicio, no se si esto afecte pero fue la única manera que encontré, eso que reinicie varias veces y no me dejaba buscar redes. El reinicia ha tardado como un minuto, volveré a reiniciar y comento como va, el disco sigue al 100%

Fix result of Farbar Recovery Scan Tool (x64) Version: 09.01.2019 01
Ran by rkale (17-01-2019 18:03:28) Run:1
Running from C:\Users\rkale\OneDrive\Escritorio
Loaded Profiles: rkale (Available Profiles: rkale)
Boot Mode: Safe Mode (with Networking)
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:

HKLM-x32\...\Run: [] => [X]
SearchScopes: HKU\S-1-5-21-767254285-3586098769-3745675886-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-767254285-3586098769-3745675886-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
CHR Extension: (Chrome Media Router) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-30]
S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19589208 2018-12-10] (Piriform Software Ltd)
2019-01-07 17:42 - 2019-01-07 17:43 - 101249024 _____ C:\WINDOWS\system32\config\COMPONENTS.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 113516544 _____ C:\WINDOWS\system32\config\SOFTWARE.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000864256 _____ C:\WINDOWS\system32\config\DEFAULT.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000045056 _____ C:\WINDOWS\system32\config\SAM.iobit
2019-01-07 17:42 - 2019-01-07 17:42 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY.iobit
2019-01-07 17:37 - 2019-01-08 10:08 - 000000000 ____D C:\Users\rkale\AppData\LocalLow\IObit
2019-01-07 17:36 - 2019-01-08 10:08 - 000000000 ____D C:\Users\rkale\AppData\Roaming\IObit
2019-01-07 17:36 - 2019-01-08 10:08 - 000000000 ____D C:\ProgramData\IObit
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
Task: {40E4B5E4-4805-4B60-AAFB-DE4608B3A78A} - System32\Tasks\ASC12_SkipUac_rkale => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: {61BACA71-6E29-49F4-9BE0-1AF68F37CC9E} - System32\Tasks\ASC12_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\...\StartupApproved\Run: => "Advanced SystemCare 12"
AlternateDataStreams: C:\Users\rkale\AppData\Local\Temp:$DATA [16]

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
END
*****************

Error: Restore point can only be created in normal mode.
Processes closed successfully.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKU\S-1-5-21-767254285-3586098769-3745675886-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-767254285-3586098769-3745675886-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
CHR Extension: (Chrome Media Router) - C:\Users\rkale\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-30] => Error: No automatic fix found for this entry.
HKLM\System\CurrentControlSet\Services\cpuz143 => removed successfully
cpuz143 => service removed successfully
"HKU\S-1-5-21-767254285-3586098769-3745675886-1001\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Smart Cleaning" => removed successfully
C:\WINDOWS\system32\config\COMPONENTS.iobit => moved successfully
C:\WINDOWS\system32\config\SOFTWARE.iobit => moved successfully
C:\WINDOWS\system32\config\DEFAULT.iobit => moved successfully
C:\WINDOWS\system32\config\SAM.iobit => moved successfully
C:\WINDOWS\system32\config\SECURITY.iobit => moved successfully
C:\Users\rkale\AppData\LocalLow\IObit => moved successfully
C:\Users\rkale\AppData\Roaming\IObit => moved successfully
C:\ProgramData\IObit => moved successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\CLSID\{B298D29A-A6ED-11DE-BA8C-A68E55D89593} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\CLSID\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{40E4B5E4-4805-4B60-AAFB-DE4608B3A78A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40E4B5E4-4805-4B60-AAFB-DE4608B3A78A}" => removed successfully
C:\WINDOWS\System32\Tasks\ASC12_SkipUac_rkale => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC12_SkipUac_rkale" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{61BACA71-6E29-49F4-9BE0-1AF68F37CC9E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{61BACA71-6E29-49F4-9BE0-1AF68F37CC9E}" => removed successfully
C:\WINDOWS\System32\Tasks\ASC12_PerformanceMonitor => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASC12_PerformanceMonitor" => removed successfully
"HKU\S-1-5-21-767254285-3586098769-3745675886-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Advanced SystemCare 12" => removed successfully
"HKU\S-1-5-21-767254285-3586098769-3745675886-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 12" => not found
C:\Users\rkale\AppData\Local\Temp => ":$DATA" ADS could not remove.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-767254285-3586098769-3745675886-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-767254285-3586098769-3745675886-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

Error en la operaci¢n. No hay ning£n adaptador permitido para 
esta operaci¢n.

========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

Unable to connect to BITS - 0x8007043c

========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 27767394 B
Java, Flash, Steam htmlcache => 25208152 B
Windows/system/drivers => 2501678 B
Edge => 11177253 B
Chrome => 371647437 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 37 B
systemprofile32 => 14316375 B
LocalService => 8228 B
LocalService => 0 B
NetworkService => 0 B
NetworkService => 0 B
rkale => 1377146316 B

RecycleBin => 584125 B
EmptyTemp: => 1.7 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:04:24 ====

#31

He reiniciado y ha tardado 5 minutoos! El disco volvio a mantenerse al 100% los primeros 3 minutos y decayo a menos de 20 y al iniciar chrome sube a a 100 o cualquier otra app. Acabo de encontrar algo extraño en el pc al buscar malware

en esa carpeta se encuentran muchos archivos con ese codigo y los nombres de todaaas las aplicaciones y si busco en sus propiedades son de un usuario desconocido todas los archivos aparecen con ese usuario.