Error en una dll que afecta todo

Hola Dos dias llevo con este `problema “no se encuentra el punto de entrada del procedimiento rtunsubcribewnfstatenotification dek la biblioteca de cinculo dinamicos ntdll.dll” He reallizado de todo , limpia sistema, reinstalar libreria, reintalar distribuciondes de C ++ etc , todo comenzo de un dia para otro word no abrio y empezo a salir ese mensajene, desintale oficce y al intalarlo de nuevo salta el error , con algunos ejecutables funciona y con otros no se puede hacer nada , me estoy quedando sin opciones .

Alguna Idea de por que ocurre este problema y como solucionarlo

Hola @WALLY

Comentanos cual es tu Sistema Operativo?

Es exactamente así el error como lo cite en negritas?


Realiza lo siguiente:

1.- Descarga Minitoolbox by Farbar.

  • Lo ejecutas,
  • Marcas todas las casillas.
  • Presiona en “Go”

Nos pegas el reporte en tu próxima respuesta-

Guía : ¿Como Pegar reportes en el Foro?

Salu2-

Ran by walter (administrator) on 19-05-2019 at 23:30:10
Running from "C:\Users\walter\Desktop"
Microsoft Windows 7 Ultimate  Service Pack 1 (X86)
Model: GF7100/7050PVT-M3 Manufacturer: ECS
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Configuraci�n IP de Windows

Se vaci� correctamente la cach� de resoluci�n de DNS.

========================= IE Proxy Settings: ============================== 

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ============================== 

"network.proxy.backup.ftp", ""
"network.proxy.backup.ftp_port", 0
"network.proxy.backup.socks", ""
"network.proxy.backup.socks_port", 0
"network.proxy.backup.ssl", ""
"network.proxy.backup.ssl_port", 0
"network.proxy.ftp", "23.22.72.17"
"network.proxy.ftp_port", 80
"network.proxy.http", "23.22.72.17"
"network.proxy.http_port", 80
"network.proxy.share_proxy_settings", true
"network.proxy.socks", "23.22.72.17"
"network.proxy.socks_port", 80
"network.proxy.ssl", "23.22.72.17"
"network.proxy.ssl_port", 80
"network.proxy.type", 0

"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================
127.0.0.1       localhost
========================= IP Configuration: ================================

DGE-560T Gigabit PCI Express Ethernet Adapter. = Conexión de área local 2 (Connected)
NVIDIA nForce Ethernet  = Conexión de área local (Hardware not present)
VPN Client Adapter - VPN = VPN - VPN Client (Hardware not present)
Bluetooth PAN Network Adapter = Conexión de área local 4 (Media disconnected)


# ----------------------------------
# Configuraci¢n de IPv4
# ----------------------------------
pushd interface ipv4

reset


popd
# Fin de la configuraci¢n de IPv4



Configuraci¢n IP de Windows

   Nombre de host. . . . . . . . . : walter-PC
   Sufijo DNS principal  . . . . . : 
   Tipo de nodo. . . . . . . . . . : h¡brido
   Enrutamiento IP habilitado. . . : no
   Proxy WINS habilitado . . . . . : no

Adaptador de Ethernet Conexi¢n de  rea local 2:

   Sufijo DNS espec¡fico para la conexi¢n. . : 
   Descripci¢n . . . . . . . . . . . . . . . : DGE-560T Gigabit PCI Express Ethernet Adapter.
   Direcci¢n f¡sica. . . . . . . . . . . . . : 0C-B6-D2-B2-B5-02
   DHCP habilitado . . . . . . . . . . . . . : s¡
   Configuraci¢n autom tica habilitada . . . : s¡
   V¡nculo: direcci¢n IPv6 local. . . : fe80::24da:2865:57ab:c4d3%19(Preferido) 
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.29(Preferido) 
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Concesi¢n obtenida. . . . . . . . . . . . : domingo, 19 de mayo de 2019 17:40:51
   La concesi¢n expira . . . . . . . . . . . : lunes, 20 de mayo de 2019 0:10:51
   Puerta de enlace predeterminada . . . . . : 192.168.0.1
   Servidor DHCP . . . . . . . . . . . . . . : 192.168.0.1
   IAID DHCPv6 . . . . . . . . . . . . . . . : 403486418
   DUID de cliente DHCPv6. . . . . . . . . . : 00-01-00-01-1F-18-B3-27-00-1E-90-86-40-6C
   Servidores DNS. . . . . . . . . . . . . . : 200.83.1.4
                                       190.160.0.14
                                       200.30.192.15
   NetBIOS sobre TCP/IP. . . . . . . . . . . : habilitado

Adaptador de Ethernet Conexi¢n de  rea local 4:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 
   Descripci¢n . . . . . . . . . . . . . . . : Bluetooth PAN Network Adapter
   Direcci¢n f¡sica. . . . . . . . . . . . . : 00-03-0D-00-00-01
   DHCP habilitado . . . . . . . . . . . . . : s¡
   Configuraci¢n autom tica habilitada . . . : s¡

Adaptador de t£nel isatap.{3100BEF9-6842-40A2-AC20-26F7B775D9E3}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 
   Descripci¢n . . . . . . . . . . . . . . . : Adaptador ISATAP de Microsoft #3
   Direcci¢n f¡sica. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP habilitado . . . . . . . . . . . . . : no
   Configuraci¢n autom tica habilitada . . . : s¡

Adaptador de t£nel isatap.{09E2B554-A267-4EF9-9D36-06A3CA8CFD8E}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 
   Descripci¢n . . . . . . . . . . . . . . . : Adaptador ISATAP de Microsoft #5
   Direcci¢n f¡sica. . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP habilitado . . . . . . . . . . . . . : no
   Configuraci¢n autom tica habilitada . . . : s¡
Servidor:  resolver01.vtr.net
Address:  200.83.1.4

Nombre:  google.com
Addresses:  2800:3f0:4003:803::200e
	  216.58.222.174


Haciendo ping a google.com [216.58.222.174] con 32 bytes de datos:
Respuesta desde 216.58.222.174: bytes=32 tiempo=35ms TTL=55
Respuesta desde 216.58.222.174: bytes=32 tiempo=14ms TTL=55

Estad¡sticas de ping para 216.58.222.174:
    Paquetes: enviados = 2, recibidos = 2, perdidos = 0
    (0% perdidos),
Tiempos aproximados de ida y vuelta en milisegundos:
    M¡nimo = 14ms, M ximo = 35ms, Media = 24ms
Servidor:  resolver01.vtr.net
Address:  200.83.1.4

Nombre:  yahoo.com
Addresses:  2001:4998:58:1836::11
	  2001:4998:c:1023::5
	  2001:4998:58:1836::10
	  2001:4998:44:41d::4
	  2001:4998:44:41d::3
	  2001:4998:c:1023::4
	  72.30.35.10
	  72.30.35.9
	  98.138.219.232
	  98.138.219.231
	  98.137.246.7
	  98.137.246.8


Haciendo ping a yahoo.com [72.30.35.9] con 32 bytes de datos:
Respuesta desde 72.30.35.9: bytes=32 tiempo=150ms TTL=42
Respuesta desde 72.30.35.9: bytes=32 tiempo=167ms TTL=42

Estad¡sticas de ping para 72.30.35.9:
    Paquetes: enviados = 2, recibidos = 2, perdidos = 0
    (0% perdidos),
Tiempos aproximados de ida y vuelta en milisegundos:
    M¡nimo = 150ms, M ximo = 167ms, Media = 158ms

Haciendo ping a 127.0.0.1 con 32 bytes de datos:
Respuesta desde 127.0.0.1: bytes=32 tiempo<1m TTL=128
Respuesta desde 127.0.0.1: bytes=32 tiempo<1m TTL=128

Estad¡sticas de ping para 127.0.0.1:
    Paquetes: enviados = 2, recibidos = 2, perdidos = 0
    (0% perdidos),
Tiempos aproximados de ida y vuelta en milisegundos:
    M¡nimo = 0ms, M ximo = 0ms, Media = 0ms
===========================================================================
ILista de interfaces
 19...0c b6 d2 b2 b5 02 ......DGE-560T Gigabit PCI Express Ethernet Adapter.
 14...00 03 0d 00 00 01 ......Bluetooth PAN Network Adapter
  1...........................Software Loopback Interface 1
 15...00 00 00 00 00 00 00 e0 Adaptador ISATAP de Microsoft #3
 16...00 00 00 00 00 00 00 e0 Adaptador ISATAP de Microsoft #5
===========================================================================

IPv4 Tabla de enrutamiento
===========================================================================
Rutas activas:
Destino de red        M scara de red   Puerta de enlace   Interfaz  M‚trica
          0.0.0.0          0.0.0.0      192.168.0.1     192.168.0.29     10
        127.0.0.0        255.0.0.0      En v¡nculo         127.0.0.1    306
        127.0.0.1  255.255.255.255      En v¡nculo         127.0.0.1    306
  127.255.255.255  255.255.255.255      En v¡nculo         127.0.0.1    306
      192.168.0.0    255.255.255.0      En v¡nculo      192.168.0.29    266
     192.168.0.29  255.255.255.255      En v¡nculo      192.168.0.29    266
    192.168.0.255  255.255.255.255      En v¡nculo      192.168.0.29    266
        224.0.0.0        240.0.0.0      En v¡nculo         127.0.0.1    306
        224.0.0.0        240.0.0.0      En v¡nculo      192.168.0.29    266
  255.255.255.255  255.255.255.255      En v¡nculo         127.0.0.1    306
  255.255.255.255  255.255.255.255      En v¡nculo      192.168.0.29    266
===========================================================================
Rutas persistentes:
  Ninguno

IPv6 Tabla de enrutamiento
===========================================================================
Rutas activas:
 Cuando destino de red m‚trica      Puerta de enlace
  1    306 ::1/128                  En v¡nculo
 19    266 fe80::/64                En v¡nculo
 19    266 fe80::24da:2865:57ab:c4d3/128
                                    En v¡nculo
  1    306 ff00::/8                 En v¡nculo
 19    266 ff00::/8                 En v¡nculo
===========================================================================
Rutas persistentes:
  Ninguno
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\system32\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 C:\Windows\system32\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog5 08 C:\Windows\system32\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation)
Catalog5 10 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 22 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 23 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 24 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 25 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 26 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 27 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 28 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 29 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 30 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 31 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 32 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 33 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 34 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 35 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 36 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 37 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 38 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 39 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 40 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 41 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 42 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 43 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 44 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 45 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 46 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 47 C:\Windows\system32\mswsock.dll [231424] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (05/19/2019 11:23:33 PM) (Source: Application Error) (User: )
Description: Nombre de la aplicación con errores: setup.exe_Microsoft Setup Bootstrapper, versión: 16.0.4266.1001, marca de tiempo: 0x55ba163f
Nombre del módulo con errores: KERNELBASE.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a4996cd
Código de excepción: 0xc06d007e
Desplazamiento de errores: 0x0000845d
Id. del proceso con errores: 0xf88
Hora de inicio de la aplicación con errores: 0xsetup.exe_Microsoft Setup Bootstrapper0
Ruta de acceso de la aplicación con errores: setup.exe_Microsoft Setup Bootstrapper1
Ruta de acceso del módulo con errores: setup.exe_Microsoft Setup Bootstrapper2
Id. del informe: setup.exe_Microsoft Setup Bootstrapper3

Error: (05/19/2019 05:50:34 PM) (Source: Application Error) (User: )
Description: Nombre de la aplicación con errores: setup.exe_Microsoft Setup Bootstrapper, versión: 16.0.4266.1001, marca de tiempo: 0x55ba163f
Nombre del módulo con errores: KERNELBASE.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a4996cd
Código de excepción: 0xc06d007e
Desplazamiento de errores: 0x0000845d
Id. del proceso con errores: 0x66c
Hora de inicio de la aplicación con errores: 0xsetup.exe_Microsoft Setup Bootstrapper0
Ruta de acceso de la aplicación con errores: setup.exe_Microsoft Setup Bootstrapper1
Ruta de acceso del módulo con errores: setup.exe_Microsoft Setup Bootstrapper2
Id. del informe: setup.exe_Microsoft Setup Bootstrapper3

Error: (05/19/2019 05:44:10 PM) (Source: Microsoft-Windows-User Profiles Service) (User: walter-PC)
Description: Windows no encuentra el perfil local y está iniciando la sesión con un perfil temporal. Los cambios que se efectúen en este perfil se perderán cuando se cierre la sesión.

Error: (05/19/2019 05:44:10 PM) (Source: Microsoft-Windows-User Profiles Service) (User: walter-PC)
Description: Windows hizo una copia de seguridad de este perfil de usuario. Windows intentará automáticamente usar la copia de seguridad del perfil la próxima vez que este usuario inicie sesión.

Error: (05/19/2019 05:43:03 PM) (Source: Application Error) (User: )
Description: Nombre de la aplicación con errores: Avira.ServiceHost.exe, versión: 1.2.133.21088, marca de tiempo: 0x5cb07b57
Nombre del módulo con errores: KERNELBASE.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a4996cd
Código de excepción: 0xe0434352
Desplazamiento de errores: 0x0000845d
Id. del proceso con errores: 0xf34
Hora de inicio de la aplicación con errores: 0xAvira.ServiceHost.exe0
Ruta de acceso de la aplicación con errores: Avira.ServiceHost.exe1
Ruta de acceso del módulo con errores: Avira.ServiceHost.exe2
Id. del informe: Avira.ServiceHost.exe3

Error: (05/19/2019 05:43:03 PM) (Source: .NET Runtime) (User: )
Description: Aplicación: Avira.ServiceHost.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.IO.FileNotFoundException
   en System.IO.FileSystemWatcher.StartRaisingEvents()
   en System.IO.FileSystemWatcher.set_EnableRaisingEvents(Boolean)
   en Avira.OE.WinCore.FileWatcher.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.BrowserExtensionMonitorBase.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.ChromeBrowserExtensionMonitor.Start()
   en Avira.OE.BrowserExtension.BrowserExtensionsRepository.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.ActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs)
   en System.EventHandler`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].Invoke(System.Object, System.__Canon)
   en Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon)
   en Avira.OE.ServiceHost.SessionManager.Initialize()
   en Avira.OE.ServiceHost.ServiceHost.Initialize()
   en Avira.OE.ServiceHost.Program+<>c__DisplayClass12_0.<OnServiceStart>b__0(System.Object)
   en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   en System.Threading.ThreadPoolWorkQueue.Dispatch()
   en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/19/2019 05:42:44 PM) (Source: Application Error) (User: )
Description: Nombre de la aplicación con errores: Avira.ServiceHost.exe, versión: 1.2.133.21088, marca de tiempo: 0x5cb07b57
Nombre del módulo con errores: KERNELBASE.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a4996cd
Código de excepción: 0xe0434352
Desplazamiento de errores: 0x0000845d
Id. del proceso con errores: 0x17a0
Hora de inicio de la aplicación con errores: 0xAvira.ServiceHost.exe0
Ruta de acceso de la aplicación con errores: Avira.ServiceHost.exe1
Ruta de acceso del módulo con errores: Avira.ServiceHost.exe2
Id. del informe: Avira.ServiceHost.exe3

Error: (05/19/2019 05:42:44 PM) (Source: .NET Runtime) (User: )
Description: Aplicación: Avira.ServiceHost.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.IO.FileNotFoundException
   en System.IO.FileSystemWatcher.StartRaisingEvents()
   en System.IO.FileSystemWatcher.set_EnableRaisingEvents(Boolean)
   en Avira.OE.WinCore.FileWatcher.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.BrowserExtensionMonitorBase.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.ChromeBrowserExtensionMonitor.Start()
   en Avira.OE.BrowserExtension.BrowserExtensionsRepository.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.ActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs)
   en System.EventHandler`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].Invoke(System.Object, System.__Canon)
   en Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon)
   en Avira.OE.ServiceHost.SessionManager.Initialize()
   en Avira.OE.ServiceHost.ServiceHost.Initialize()
   en Avira.OE.ServiceHost.Program+<>c__DisplayClass12_0.<OnServiceStart>b__0(System.Object)
   en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   en System.Threading.ThreadPoolWorkQueue.Dispatch()
   en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/19/2019 05:42:22 PM) (Source: Application Error) (User: )
Description: Nombre de la aplicación con errores: Avira.ServiceHost.exe, versión: 1.2.133.21088, marca de tiempo: 0x5cb07b57
Nombre del módulo con errores: KERNELBASE.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a4996cd
Código de excepción: 0xe0434352
Desplazamiento de errores: 0x0000845d
Id. del proceso con errores: 0xc80
Hora de inicio de la aplicación con errores: 0xAvira.ServiceHost.exe0
Ruta de acceso de la aplicación con errores: Avira.ServiceHost.exe1
Ruta de acceso del módulo con errores: Avira.ServiceHost.exe2
Id. del informe: Avira.ServiceHost.exe3

Error: (05/19/2019 05:42:22 PM) (Source: .NET Runtime) (User: )
Description: Aplicación: Avira.ServiceHost.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.IO.FileNotFoundException
   en System.IO.FileSystemWatcher.StartRaisingEvents()
   en System.IO.FileSystemWatcher.set_EnableRaisingEvents(Boolean)
   en Avira.OE.WinCore.FileWatcher.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.BrowserExtensionMonitorBase.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.ChromeBrowserExtensionMonitor.Start()
   en Avira.OE.BrowserExtension.BrowserExtensionsRepository.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.ActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs)
   en System.EventHandler`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].Invoke(System.Object, System.__Canon)
   en Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon)
   en Avira.OE.ServiceHost.SessionManager.Initialize()
   en Avira.OE.ServiceHost.ServiceHost.Initialize()
   en Avira.OE.ServiceHost.Program+<>c__DisplayClass12_0.<OnServiceStart>b__0(System.Object)
   en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   en System.Threading.ThreadPoolWorkQueue.Dispatch()
   en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()


System errors:
=============
Error: (05/19/2019 05:43:04 PM) (Source: Service Control Manager) (User: )
Description: El servicio Avira Service Host se terminó de manera inesperada. Esto ha sucedido 3 veces.

Error: (05/19/2019 05:42:45 PM) (Source: Service Control Manager) (User: )
Description: El servicio Avira Service Host terminó inesperadamente. Esto se ha repetido 2 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.

Error: (05/19/2019 05:42:25 PM) (Source: Service Control Manager) (User: )
Description: El servicio Avira Service Host terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.

Error: (05/19/2019 05:42:08 PM) (Source: Service Control Manager) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
dsbwncfk

Error: (05/19/2019 05:40:58 PM) (Source: Service Control Manager) (User: )
Description: El servicio DgiVecp no pudo iniciarse debido al siguiente error: 
%%20 = El sistema no puede encontrar el dispositivo especificado.


Error: (05/19/2019 05:35:47 PM) (Source: Service Control Manager) (User: )
Description: El servicio Avira Service Host se terminó de manera inesperada. Esto ha sucedido 3 veces.

Error: (05/19/2019 05:35:27 PM) (Source: Service Control Manager) (User: )
Description: El servicio Avira Service Host terminó inesperadamente. Esto se ha repetido 2 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.

Error: (05/19/2019 05:35:06 PM) (Source: Service Control Manager) (User: )
Description: El servicio Avira Service Host terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.

Error: (05/19/2019 05:34:04 PM) (Source: Service Control Manager) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
dsbwncfk

Error: (05/19/2019 05:33:00 PM) (Source: Service Control Manager) (User: )
Description: El servicio DgiVecp no pudo iniciarse debido al siguiente error: 
%%20 = El sistema no puede encontrar el dispositivo especificado.



Microsoft Office Sessions:
=========================
Error: (05/19/2019 11:23:33 PM) (Source: Application Error)(User: )
Description: setup.exe_Microsoft Setup Bootstrapper16.0.4266.100155ba163fKERNELBASE.dll6.1.7601.240005a4996cdc06d007e0000845df8801d50ebb62cf8ca0C:\Users\walter\Desktop\RESUMEN\OFFICE\Office_Professional_Plus_2016_32bits_Spanish\setup.exeC:\Windows\system32\KERNELBASE.dlla5405650-7aae-11e9-8c3c-00030d000001

Error: (05/19/2019 05:50:34 PM) (Source: Application Error)(User: )
Description: setup.exe_Microsoft Setup Bootstrapper16.0.4266.100155ba163fKERNELBASE.dll6.1.7601.240005a4996cdc06d007e0000845d66c01d50e8ce0769dd0C:\Users\walter\Desktop\RESUMEN\OFFICE\Office_Professional_Plus_2016_32bits_Spanish\setup.exeC:\Windows\system32\KERNELBASE.dll20cd5180-7a80-11e9-8c3c-00030d000001

Error: (05/19/2019 05:44:10 PM) (Source: Microsoft-Windows-User Profiles Service)(User: walter-PC)
Description: 

Error: (05/19/2019 05:44:10 PM) (Source: Microsoft-Windows-User Profiles Service)(User: walter-PC)
Description: 

Error: (05/19/2019 05:43:03 PM) (Source: Application Error)(User: )
Description: Avira.ServiceHost.exe1.2.133.210885cb07b57KERNELBASE.dll6.1.7601.240005a4996cde04343520000845df3401d50e8bd159cd00C:\Program Files\Avira\Launcher\Avira.ServiceHost.exeC:\Windows\system32\KERNELBASE.dll14049a40-7a7f-11e9-8c3c-00030d000001

Error: (05/19/2019 05:43:03 PM) (Source: .NET Runtime)(User: )
Description: Aplicación: Avira.ServiceHost.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.IO.FileNotFoundException
   en System.IO.FileSystemWatcher.StartRaisingEvents()
   en System.IO.FileSystemWatcher.set_EnableRaisingEvents(Boolean)
   en Avira.OE.WinCore.FileWatcher.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.BrowserExtensionMonitorBase.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.ChromeBrowserExtensionMonitor.Start()
   en Avira.OE.BrowserExtension.BrowserExtensionsRepository.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.ActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs)
   en System.EventHandler`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].Invoke(System.Object, System.__Canon)
   en Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon)
   en Avira.OE.ServiceHost.SessionManager.Initialize()
   en Avira.OE.ServiceHost.ServiceHost.Initialize()
   en Avira.OE.ServiceHost.Program+<>c__DisplayClass12_0.<OnServiceStart>b__0(System.Object)
   en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   en System.Threading.ThreadPoolWorkQueue.Dispatch()
   en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/19/2019 05:42:44 PM) (Source: Application Error)(User: )
Description: Avira.ServiceHost.exe1.2.133.210885cb07b57KERNELBASE.dll6.1.7601.240005a4996cde04343520000845d17a001d50e8bc5dba980C:\Program Files\Avira\Launcher\Avira.ServiceHost.exeC:\Windows\system32\KERNELBASE.dll08a7ca00-7a7f-11e9-8c3c-00030d000001

Error: (05/19/2019 05:42:44 PM) (Source: .NET Runtime)(User: )
Description: Aplicación: Avira.ServiceHost.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.IO.FileNotFoundException
   en System.IO.FileSystemWatcher.StartRaisingEvents()
   en System.IO.FileSystemWatcher.set_EnableRaisingEvents(Boolean)
   en Avira.OE.WinCore.FileWatcher.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.BrowserExtensionMonitorBase.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.ChromeBrowserExtensionMonitor.Start()
   en Avira.OE.BrowserExtension.BrowserExtensionsRepository.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.ActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs)
   en System.EventHandler`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].Invoke(System.Object, System.__Canon)
   en Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon)
   en Avira.OE.ServiceHost.SessionManager.Initialize()
   en Avira.OE.ServiceHost.ServiceHost.Initialize()
   en Avira.OE.ServiceHost.Program+<>c__DisplayClass12_0.<OnServiceStart>b__0(System.Object)
   en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   en System.Threading.ThreadPoolWorkQueue.Dispatch()
   en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (05/19/2019 05:42:22 PM) (Source: Application Error)(User: )
Description: Avira.ServiceHost.exe1.2.133.210885cb07b57KERNELBASE.dll6.1.7601.240005a4996cde04343520000845dc8001d50e8b91f8cb70C:\Program Files\Avira\Launcher\Avira.ServiceHost.exeC:\Windows\system32\KERNELBASE.dllfbc49840-7a7e-11e9-8c3c-00030d000001

Error: (05/19/2019 05:42:22 PM) (Source: .NET Runtime)(User: )
Description: Aplicación: Avira.ServiceHost.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.IO.FileNotFoundException
   en System.IO.FileSystemWatcher.StartRaisingEvents()
   en System.IO.FileSystemWatcher.set_EnableRaisingEvents(Boolean)
   en Avira.OE.WinCore.FileWatcher.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.BrowserExtensionMonitorBase.Start(System.String, System.String)
   en Avira.OE.BrowserExtension.ChromeBrowserExtensionMonitor.Start()
   en Avira.OE.BrowserExtension.BrowserExtensionsRepository.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.Start()
   en Avira.OE.BrowserExtension.BrowserExtensions.ActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs)
   en System.EventHandler`1[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].Invoke(System.Object, System.__Canon)
   en Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon)
   en Avira.OE.ServiceHost.SessionManager.Initialize()
   en Avira.OE.ServiceHost.ServiceHost.Initialize()
   en Avira.OE.ServiceHost.Program+<>c__DisplayClass12_0.<OnServiceStart>b__0(System.Object)
   en System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   en System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   en System.Threading.ThreadPoolWorkQueue.Dispatch()
   en System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()


CodeIntegrity Errors:
===================================
  Date: 2018-10-15 18:23:37.767
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-15 18:23:37.690
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-15 18:23:37.582
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-13 13:22:58.324
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-13 13:22:58.309
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-13 13:22:58.309
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-08 22:06:11.771
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-08 22:06:11.755
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-08 21:54:49.101
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

  Date: 2018-10-08 21:54:49.086
  Description: Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Program Files\Phoenix360\System Mechanic\WscRmd.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.


=========================== Installed Programs ============================

µTorrent (HKCU\...\uTorrent) (Version: 3.5.3.44494 - BitTorrent Inc.)
Acronis Disk Director Home (HKLM\...\{9CCC78EF-027E-40E0-9B61-39932C65E3FE}) (Version: 11.0.216 - Acronis)
Activador Windows 7 (HKLM\...\Activador Windows 7) (Version:  - )
Actualización de NVIDIA 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Adobe Creative Cloud (HKLM\...\Adobe Creative Cloud) (Version: 3.9.5.353 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 31.0.0.122 - Adobe Systems Incorporated)
Adobe Flash Player 32 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 32.0.0.101 - Adobe Systems Incorporated)
Adobe PageMaker 7.0 (HKLM\...\Adobe PageMaker 7.0) (Version: 7.0 - Adobe Systems, Inc.)
Adobe Shockwave Player 12.3 (HKLM\...\{3BD13111-2F32-4AB7-B9BB-16E07C9AA894}) (Version: 12.3.4.204 - Adobe Systems, Inc)
Advanced PDF Password Recovery (HKCU\...\Advanced PDF Password Recovery) (Version: 5.0 - ElcomSoft Co. Ltd.)
Advanced RAR Repair v1.2 (HKLM\...\Advanced RAR Repair v1.2) (Version:  - )
AIMP (HKLM\...\AIMP) (Version: v4.50.2058, 27.12.2017 - AIMP DevTeam)
AirDroid 3.3.5.3 (HKLM\...\AirDroid) (Version: 3.3.5.3 - Sand Studio)
Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.5.1 - Sereby Corporation)
AMP Font Viewer (HKLM\...\AMP Font Viewer) (Version:  - )
AnyTrans (HKLM\...\AnyTrans) (Version: 6.3.3.0 - iMobie Inc.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 19.4.2374 - AVAST Software)
Avira (HKLM\...\{2504137A-5E42-4340-8F34-2086B49FBD1A}) (Version: 1.2.133.21088 - Avira Operations GmbH & Co. KG) Hidden
Avira (HKLM\...\{b3f1f775-e558-4660-a503-9129ae9d7310}) (Version: 1.2.133.21088 - Avira Operations GmbH & Co. KG)
Batch Picture Resizer 7.2 (HKLM\...\Batch Picture Resizer_is1) (Version: 7.2 - SoftOrbits)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Camtasia Studio 8 (HKLM\...\{A2A41B60-D51F-4C04-BC94-B4C94F7B6DC0}) (Version: 8.6.0.2054 - TechSmith Corporation)
Capturador de Links versión 2.0 creada por Luciano Aibar (HKLM\...\Capturador de Links_is1) (Version: 2.0 creada por Luciano Aibar - )
Card Reader Patch 1.0 for Windows 7 (HKLM\...\Card Reader Windows 7 Patch_is1) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.48 - Piriform)
Compatibilidad con Aplicaciones de Apple (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Cyotek WebCopy version 1.3.0.405 (HKLM\...\{D5FAF1F8-C903-41b2-AC66-2682A02A78CB}_is1) (Version: 1.3.0.405 - Cyotek Ltd)
Descargador de Video de Apowersoft V6.2.4 (HKLM\...\{b3336f66-e079-4ff6-abdb-51e2fab781d5}_is1) (Version: 6.2.4 - APOWERSOFT LIMITED)
Dexpot (HKCU\...\Dexpot) (Version: 1.6.14 - Dexpot GbR)
DFX (HKLM\...\DFX) (Version: 12.023.0.0 - Power Technology)
DGE-560T Gigabit PCI Express Ethernet Adapter (HKLM\...\{6E01C07D-A44B-406E-A0DC-DEF62181E6E7}) (Version: 7.47.706.2011 - D-Link)
Diagnóstico de impresoras Samsung (HKLM\...\Samsung Printer Diagnostics) (Version: 1.0.0.15 - Samsung Electronics Co., Ltd.)
Direct Video Downloader version 2.12 (HKLM\...\{5FB07C70-45DA-45C9-AAD3-F805D4C463D5}_is1) (Version: 2.12 - Major Share, MajorShare.com)
D-Link DFE-520TX (HKLM\...\{9629C9A1-74F7-4DD0-B99B-9066925E63F8}) (Version:  - D-Link) Hidden
D-Link DFE-520TX (HKLM\...\InstallShield_{9629C9A1-74F7-4DD0-B99B-9066925E63F8}) (Version:  - D-Link)
D-Link DFE-530TX+ (HKLM\...\{2D6A5BD9-FE4B-49CD-8D96-2C4746302A82}) (Version:  - D-Link) Hidden
D-Link DFE-530TX+ (HKLM\...\InstallShield_{2D6A5BD9-FE4B-49CD-8D96-2C4746302A82}) (Version:  - D-Link)
Driver Booster 5 (HKLM\...\Driver Booster_is1) (Version: 5.3.0 - IObit)
Driver Easy 5.6.5 (HKLM\...\DriverEasy_is1) (Version: 5.6.5 - Easeware)
Dropbox (HKLM\...\Dropbox) (Version: 72.4.136 - Dropbox, Inc.)
Dropbox Update Helper (HKLM\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.189.1 - Dropbox, Inc.) Hidden
Duplicate Cleaner Pro 4.0.4 (HKLM\...\Duplicate Cleaner Pro) (Version: 4.0.4 - DigitalVolcano Software Ltd)
DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version:  - DVD Shrink Instal)
DVD2one V2.4.2 (HKLM\...\DVD2one V2) (Version: 2.4.2 - Eximius B.V.)
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version:  - EaseUS)
EaseUS Partition Master 12.5 Trial Edition (HKLM\...\EaseUS Partition Master Trial Edition_is1) (Version:  - EaseUS)
f.lux (HKCU\...\Flux) (Version:  - f.lux Software LLC)
FileASSASSIN (HKLM\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
FindThatWord 0.1 (HKLM\...\{1409F1B5-726C-47D5-9642-A6B4716E2823}_is1) (Version:  - Jonny and Ieuan Jones)
FLOW3D Version 9.3.2 (HKLM\...\{28D7F279-2398-489E-87A9-D03AAAE8ADDA}) (Version: 9.3.2 - Flow Science, Inc.) Hidden
FLOW3D Version 9.3.2 (HKLM\...\InstallShield_{28D7F279-2398-489E-87A9-D03AAAE8ADDA}) (Version: 9.3.2 - Flow Science, Inc.)
Folder Size 3.4.0.0 (HKLM\...\{2DFA85ED-588F-4CE3-A175-29E52C3804A8}_is1) (Version: 3.4.0.0 - MindGems, Inc.)
FormatFactory 3.8.0.0 (HKLM\...\FormatFactory) (Version: 3.8.0.0 - Free Time)
ForSamplingUpdate (HKCU\...\7bec5a913a80bf0f) (Version: 1.3.2.3 - ForSampling)
Foxit PDF Preview Handler (HKLM\...\{6FE22909-D0D6-4111-ABCE-7F8D986C4A2A}) (Version: 1.0.0 - Tim Heuer)
Foxit PhantomPDF Business (HKLM\...\{4699E810-3A23-11E6-97B8-000C2992F709}) (Version: 8.0.0.624 - Foxit Software Inc.)
Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 9.4.1.16828 - Foxit Software Inc.)
Free Sound Recorder v10.8.8 (HKLM\...\Free Sound Recorder_is1) (Version:  - Copyright(C) 2005-2015 FreeSoundRecorder Technologies, Inc.)
Free Video to DVD Converter (HKLM\...\Free Video to DVD Converter_is1) (Version: 5.0.99.823 - Digital Wave Ltd)
Freemake Video Converter versión 4.1.10.1 (HKLM\...\Freemake Video Converter_is1) (Version: 4.1.10.1 - Ellora Assets Corporation)
GeoGebra 5 (HKLM\...\GeoGebra 5) (Version: 5.0.341.0 - International GeoGebra Institute)
Glary Utilities PRO 5.79 (HKLM\...\Glary Utilities 5) (Version: 5.79.0.100 - Glarysoft Ltd)
Google Chrome (HKLM\...\Google Chrome) (Version: 74.0.3729.157 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
GridinSoft Anti-Malware (HKLM\...\GridinSoft Anti-Malware) (Version: 3.1.29 - GridinSoft LLC)
GridMove V1.19.57 (HKLM\...\GridMove_is1) (Version:  - DonationCoder.com)
HandBrake 1.0.7 (HKLM\...\HandBrake) (Version: 1.0.7 - )
HAZARES (HKLM\...\ST6UNST #1) (Version:  - )
HidenGate (HKLM\...\{6AE85624-C2DA-4547-B0EF-8B424A03252B}_is1) (Version: 1.0.0.5 - DLTG)
HiSuite (HKLM\...\Hi Suite) (Version: 9.0.3.300 - Huawei Technologies Co.,Ltd)
ICC for Windows 1.0 beta 9.8.10 (HKLM\...\{CFF71C5A-D887-429C-A1F6-FD395C1823E8}_is1) (Version: 1.0 - Internet Chess Club, Inc.)
IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6099.6 - IDT)
iExplorer 3.7.5.1 (HKLM\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
IHMC Concept Map Tools 2.9.1 - walter (HKLM\...\IHMC Concept Map Tools 2.9.1 - walter) (Version:  - )
IIS 8.0 Express (HKLM\...\{B8FFB7D6-6ABD-47C3-8BAD-86FF5D8F3EDC}) (Version: 8.0.1557 - Microsoft Corporation)
IObit Malware Fighter 5 (HKLM\...\IObit Malware Fighter_is1) (Version: 5.1 - IObit)
Java 8 Update 192 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F32180192F0}) (Version: 8.0.1920.12 - Oracle Corporation)
Java Auto Updater (HKLM\...\{4A03706F-666A-4037-7777-5F2748764D10}) (Version: 2.8.192.12 - Oracle Corporation) Hidden
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Join Multiple DjVu Files Into One Software (HKLM\...\Join Multiple DjVu Files Into One Software_is1) (Version:  - Sobolsoft)
JPEG Recovery Pro 5.0 (HKLM\...\JPEG Recovery Pro5.0) (Version: 5.0 - e.World Technology Limited)
KeyExtender 3.99 (HKLM\...\KeyExtender_is1) (Version:  - EasySoft)
K-Lite Codec Pack 14.5.2 Full (HKLM\...\KLiteCodecPack_is1) (Version: 14.5.2 - KLCP)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version:  - )
Kutools for Word versión 8.9.0 (HKLM\...\{E9A0AD37-5BA2-4E60-85F1-8B785CF2FBF5}_is1) (Version: 8.9.0 - ExtendOffice)
Lupas Rename 2000 v5.0 Release (HKLM\...\Lupas Rename 2000_is1) (Version:  - Ivan Anton Albarracin)
Math Editor version 1.0.6.6 (HKLM\...\{1250D241-20C3-40C9-BBA8-6D537A8021FA}_is1) (Version: 1.0.6.6 - MathiVersity)
MathType 7 (HKLM\...\DSMT7) (Version: 7.1.2 - WIRIS)
Max Recorder (HKLM\...\Max Recorder) (Version: 2.006.0.0 - Silver Vine, LLC)
MEGAsync (HKLM\...\MEGAsync) (Version:  - Mega Limited)
Merlín Generador de Ejercicios (HKLM\...\Merlín Generador de Ejercicios_is1) (Version:  - )
Microsoft .NET Framework 4.7 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{10C4E843-C226-3FDF-9DD6-F4E3275E734D}) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Keyboard Layout Creator 1.4 (HKLM\...\{99E66BC9-E4B6-485F-ABFC-31EFCE36DFDF}) (Version: 1.4.6000 - Microsoft Corp.)
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.3.4604.0120 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{F95C77E7-7194-4EAF-AB58-1E270838ED0C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{DEDD3877-0BDD-4A02-A50B-FCB8E540D308}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61187 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.7523 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61135 (HKLM\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61135 (HKLM\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61135 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM\...\{dd1e9bde-2ad6-4e92-8c07-7d4723eab8b8}) (Version: 12.0.40664.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27027 (HKLM\...\{39e28474-b67b-4209-af1b-e9ad0a83d8ca}) (Version: 14.16.27027.1 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version:  - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.0 (HKLM\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
MiniTool Partition Wizard Free 10.2.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
Movavi Screen Recorder 10 (HKCU\...\Movavi Screen Recorder 10) (Version: 10.3.0 - Movavi)
Mozilla Firefox 64.0 (x86 es-ES) (HKLM\...\Mozilla Firefox 64.0 (x86 es-ES)) (Version: 64.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 64.0 - Mozilla)
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nero Vision (HKLM\...\Nero Vision) (Version:  - )
NetCut 2.1.4 (HKLM\...\NetCut_is1) (Version:  - arcai.com)
NVIDIA Controlador de audio HD 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Controlador de gráficos 309.08 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 309.08 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM\...\{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: 1.00.7325.0 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Office 2016  KMS Activator Ultimate v1.2 Final (HKLM\...\Office 2016  KMS Activator Ultimate v1.2 Final_is1) (Version: v1.2 Final - )
Ontrack EasyRecovery Enterprise (HKLM\...\{AE695CA4-8847-4462-98CC-023874D29E72}_is1) (Version: 11.5.0.0 - Kroll Ontrack Inc.)
OpenAL (HKLM\...\OpenAL) (Version:  - )
Panel de control de NVIDIA 309.08 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 309.08 - NVIDIA Corporation) Hidden
Paquete de controladores de Windows - IDT MEDIA  (11/27/2008 5.10.6099.8) (HKLM\...\7196607E1A8892CB0B39A0ADD6D36FAC68564EFF) (Version: 11/27/2008 5.10.6099.8 - IDT)
Paquete de controladores de Windows - Microsoft (msisadrv) System  (06/21/2006 6.1.7600.16385) (HKLM\...\F7107071B470B397C7CF356FEFEA5750761B2484) (Version: 06/21/2006 6.1.7600.16385 - Microsoft)
Paquete de controladores de Windows - NVIDIA (NVNET) Net  (10/30/2009 73.1.9.1) (HKLM\...\F8F98893BBD0749D6052A2993F0180943FB5E5C3) (Version: 10/30/2009 73.1.9.1 - NVIDIA)
Paquete de controladores de Windows - Ralink Corporation (BlueletAudio) MEDIA  (12/19/2012 9.2.1.0002) (HKLM\...\D32C584A1BE4E34101249FD90E0D04E489A0A05D) (Version: 12/19/2012 9.2.1.0002 - Ralink Corporation)
PDF Password Remover v3.1 (HKLM\...\PDF Password Remover v3.1_is1) (Version:  - VeryPDF.com Inc)
PhotoScape (HKLM\...\PhotoScape) (Version:  - )
Picture Doctor 3.1 (HKLM\...\Picture Doctor_is1) (Version: 3.1 - SoftOrbits)
PSPP (HKLM\...\PSPP) (Version: 0.10.1 - Free Software Foundation, Inc.)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
R for Windows 3.5.0 (HKLM\...\R for Windows 3.5.0_is1) (Version: 3.5.0 - R Core Team)
Rainbow Folders (HKLM\...\{2AEA17BA-FAB3-49D2-BB85-0669D14DC9BC}_is1) (Version: 2.05 - Piotr Chodzinski)
RAR Password Recovery v1.1 RC16 (remove only) (HKLM\...\Intelore - RAR Password Recovery) (Version:  - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8036 - Realtek Semiconductor Corp.)
Remo Recover (HKLM\...\{993DAF7C-A5F8-42EA-81D4-DAE3C9D2D1F7}_is1) (Version: 3.0.0.113 - Remo Software)
Remove Empty Directories version 2.2 (HKLM\...\{06F25DC8-71E2-44E2-805A-F15E15B51C74}_is1) (Version: 2.2 - Jonas John)
Resource Hacker Version 4.5.30 (HKLM\...\ResourceHacker_is1) (Version:  - )
RocketDock 1.3.5 (HKLM\...\RocketDock_is1) (Version:  - Punk Software)
Rybka 4 (HKLM\...\{9CAF9762-B107-4E7B-A459-68F083298C58}) (Version: 12.0.0 - ChessBase) Hidden
Rybka 4 (HKLM\...\{F9683839-1A7F-4874-91B7-64CDF4AC4679}) (Version: 12.0.0 - ChessBase)
Samsung ML-2160 Series (HKLM\...\Samsung ML-2160 Series) (Version: 1.26 (16-08-2017) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Samsung Universal Print Driver 2 XPS (HKLM\...\Samsung Universal Print Driver 2 XPS) (Version: 2.50.04.00 - Samsung Electronics Co., Ltd.)
Scientific Notebook 5.5 (HKLM\...\{E066DE16-50F3-4A8C-953C-E67118894B2F}) (Version: 5.50 - MacKichan Software)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.04.9412 - SoftEther VPN Project)
Sothink SWF Decompiler (HKLM\...\{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1) (Version: 7.4 - SourceTec Software Co., LTD)
Sparkol VideoScribe (HKLM\...\{0998FB32-1208-49AC-A8C8-2B462FE040EF}) (Version: 2.3.2002 - Sparkol) Hidden
Sparkol VideoScribe (HKLM\...\Sparkol VideoScribe 2.3.2002) (Version: 2.3.2002 - Sparkol)
Stellar Phoenix Windows Data Recovery - Home (HKLM\...\Stellar Phoenix Windows Data Recovery - Home_is1) (Version: 6.0.0.1 - Stellar Information Technology Pvt Ltd)
StreamTransport version: 1.0.2.1700 (HKLM\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version:  - )
Syncios Data Transfer 1.6.5 (HKLM\...\{6C4BB520-3416-4D67-B7EA-A9FF6662345F}_is1) (Version: 1.6.5 - Anvsoft, Inc.)
System Mechanic (HKLM\...\{95129D61-FF52-4FA8-A403-3E31FC5D9696}) (Version: 18.0.2.486 - iolo technologies, LLC)
TeamViewer 14 (HKLM\...\TeamViewer) (Version: 14.2.2558 - TeamViewer)
Teleport Pro (HKLM\...\Teleport Pro) (Version: 1.70 - Tennyson Maxwell Information Systems, Inc.)
TL-WN725N_WN723N Controlador (HKLM\...\{3C3F9CEB-2C5A-4A47-8EAA-DA76037546BA}) (Version: 1.3.1 - TP-LINK)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 9.21a - Ghisler Software GmbH)
Total Video Converter 3.61 100319 (HKLM\...\Total Video Converter 3.61_is1) (Version:  - EffectMatrix Inc.)
TotalAudioConverter (HKLM\...\Total Audio Converter_is1) (Version: 5.1 - Softplicity, Inc.)
Turgs MBOX Wizard (HKLM\...\Turgs MBOX Wizard_is1) (Version:  - Turgs)
TweakBit PCRepairKit (HKLM\...\{5AEA8CFE-B238-4D0A-9362-D55F38ECB795}_is1) (Version: 1.8.4.10 - Tweakbit Pty Ltd)
United States (English and Talossan) (HKLM\...\{630CB9BF-D268-4270-B6C9-4C0D5330E4E2}) (Version: 1.0.3.40 - keyboards.jargon-file.org)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
VBA Password Recovery Lastic 1.2 (HKLM\...\VBA Password Recovery Lastic_is1) (Version:  - )
VC80CRTRedist - 8.0.50727.6195 (HKLM\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden
Vector Magic (HKLM\...\Vector Magic) (Version: 1.15 - Vector Magic, Inc.)
VideoCAM Messenger (HKLM\...\{57383270-6F61-4DC8-A9B8-C1745FC29F38}) (Version: 4.21.0.000 - KYE)
Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version:  - )
VirtualDJ 8 (HKLM\...\{5A89A21C-6391-4AFC-8502-66F6F7250125}) (Version: 8.0.2325.0 - Atomix Productions)
Visual MP3 Splitter & Joiner 9.1 (HKLM\...\Visual MP3 Splitter & Joiner_is1) (Version:  - ManiacTools.com)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.6 - VideoLAN)
WallpaperSuite (HKCU\...\WallpaperSuite) (Version: 1.0.0.1 - WallpaperSuite)
WebCopier 5.3 (HKLM\...\{0C72BD21-2BBB-43E6-8EEB-C8BE42FE90E5}_is1) (Version:  - MaximumSoft Corp.)
WhatsApp (HKCU\...\WhatsApp) (Version: 0.2.7315 - WhatsApp)
WinDirStat 1.1.2 (HKCU\...\WinDirStat) (Version:  - )
WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun)
Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinHTTrack Website Copier 3.48-22 (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.48.22 - HTTrack)
WinRAR 5.70 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.0 - win.rar GmbH)
WinThruster (HKLM\...\WinThruster_is1) (Version: 1.79 - solvusoft Corporation)
Wolfram Extras 10.4 (5514075) (HKLM\...\A-WIN-Extras 10.4.1 5514075_is1) (Version: 10.4.1 - Wolfram Research, Inc.)
Wolfram Mathematica 10.4 (M-WIN-L 10.4.1 5514214) (HKLM\...\M-WIN-L 10.4.1 5514214_is1) (Version: 10.4.1 - Wolfram Research, Inc.)
Wolfram Mathematica 11.2 (M-WIN-L 11.2.0 5822651) (HKLM\...\M-WIN-L 11.2.0 5822651_is1) (Version: 11.2.0 - Wolfram Research, Inc.)
WolframScript (A-WIN32-WolframScript 11.2.0 2017091001) (HKLM\...\{90D12C2B-666B-422D-91CF-531112BA0823}) (Version: 11.2.44 - Wolfram Research, Inc.)
Wondershare Data Recovery(Build 6.0.1.9) (HKLM\...\{FEA3976F-D621-45F3-AFBD-E812A1F2F00D}_is1) (Version: 6.0.1.9 - Wondershare Software Co.,Ltd.)
Wondershare Helper Compact 2.5.2 (HKLM\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
ZaraRadio 1.6.2 (HKLM\...\ZaraRadio_is1) (Version:  - ZaraSoft)
ZOOK MBOX to PDF Converter (HKLM\...\ZOOK MBOX to PDF Converter_is1) (Version:  - ZOOK)

========================= Devices: ================================

Name: VPN Client Adapter - VPN
Description: VPN Client Adapter - VPN
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: SoftEther VPN Project
Service: Neo_VPN
Device ID: ROOT\NET\0000
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: NVIDIA nForce Ethernet 
Description: NVIDIA nForce Networking Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: NVNET
Device ID: PCI\VEN_10DE&DEV_07DC&SUBSYS_26491019&REV_A2\3&267A616A&0&78
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


========================= Memory info: ===================================

Percentage of memory in use: 26%
Total physical RAM: 2815.24 MB
Available physical RAM: 2072.56 MB
Total Virtual: 5630.48 MB
Available Virtual: 4483.42 MB

========================= Partitions: =====================================

1 Drive c: (walter) (Fixed) (Total:100.72 GB) (Free:35.35 GB) NTFS
2 Drive d: (210916-1) (Fixed) (Total:910.16 GB) (Free:592.23 GB) NTFS
3 Drive e: (210916-2) (Fixed) (Total:910.16 GB) (Free:353.99 GB) NTFS
4 Drive f: (210916-3) (Fixed) (Total:974.08 GB) (Free:82.17 GB) NTFS
5 Drive g: (ws250709 [musica-video-ima]) (Fixed) (Total:185.55 GB) (Free:32.17 GB) NTFS
6 Drive h: (ws-07-10-2016) (Fixed) (Total:145.84 GB) (Free:98.32 GB) NTFS
7 Drive i: (260614 UTILIDADES) (Fixed) (Total:6.72 GB) (Free:0.82 GB) NTFS
10 Drive l: (280418 FORMULARIOS) (Fixed) (Total:5 GB) (Free:0.63 GB) NTFS
12 Drive o: (WS 18-05-2019) (Fixed) (Total:21.83 GB) (Free:15.69 GB) NTFS

========================= Users: ========================================

Cuentas de usuario de \\WALTER-PC

Administrador            Invitado                 Max Ram                  
UpdatusUser              walter                   
Se ha completado el comando correctamente.

========================= Minidump Files ==================================

C:\Windows\Minidump\051919-21122-01.dmp
========================= Restore Points ==================================

19-05-2019 17:33:28 PCRepairKit punto de restauración

**** End of log ****

edit " no se encuentra el punto de entrada del procedimiento **rtunsubcribewnfstatenotification" de la biblioteca de cinculo dinamicos ntdll.dll”

Se me olvido , mi sistema es win 7 ultimate 32 bits

Hola @WALLY

Dinos que versión de Office tienes instalado actualmente?

Ademas tu Office es legal?

Nos comentas.

Salu2

De partida desintale el OFFice durate mucho tiempo funciono de lujo y no , no era legal de repente de un momento a otro dejo de trabajar , lo desintale pero el problema sigue (el el office 2016)

Hola @WALLY:

No instales Office aun, no por el momento.


Realiza lo siguiente:

1.- Desactiva temporalmente tu antivirus y cualquier programa de seguridad.

2.- Descarga, instala y/o actualiza a las siguientes herramientas:

3.- Ejecutas respetando el orden los pasos:

CCleaner

Usando su opción Limpiador y Registro de acuerdo su Manual:

  • Para borrar Cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos.
  • NO necesitamos este reporte

Malwarebytes

  • No olvides actualizarlo.
  • Lee detenidamente su Manual
  • Realiza un Análisis Personalizado. Seleccionas “Todas las Unidades”
  • Pulsa en “Eliminar Seleccionados” para enviar lo encontrado a la cuarentena.
  • Reinicias el Sistema.
  • En el apartado del manual “Historial” >> Registros de Aplicación >> Scan Log/Registro de Análisis encontrarás el informe del MBAM, que debes copiar y pegar en tu próxima respuesta.

4.- Luego de reiniciar:

Desactiva temporalmente tu antivirus nuevamente y cualquier programa de seguridad.

5.- Descarga Farbar Recovery Scan Tool. en el escritorio, seleccionando la versión adecuada para la arquitectura (32 o 64bits) de su equipo. [size=1] >> Como saber si mi Windows es de 32 o 64 bits.?[/size]

  • Ejecuta FRST.exe.
  • En el mensaje de la ventana del Disclaimer, pulsamos Yes
  • En la ventana principal pulsamos en el botón Scan y esperamos a que concluya el proceso.
  • Se abriran dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

Guía: Como Ejecutar FRST

6.- En tu próxima respuesta, pega los reportes generados.

Guía : ¿Como Pegar reportes en el Foro?

Esperamos esos reporte.

Salu2.

Hola @WALLY

El reporte de Malwarebytes menciona:

Sin acciones por parte del usuario

Lee su Manual, especialmente donde indica como eliminar las infecciones detectadas ya que tienes muchas y aun siguen en tu equipo.

Salu2

Bueno realice todo otra vez , pase vaias veces el Malwarebytes, hasta que me dijo que no habia nada y despues ejecute el otro, posteo los resultados

Malwarebytes
www.malwarebytes.com
(sistema limpio)
____________________

Hola @WALLY

Lamentablemente los reportes están mal pegados, se hace muy difícil analizar los mismos, para no confundirnos los elimine.

Cuando tu seleccionas todo el texto presionas en la comilla " (citar) cuando en realidad debes presionar en la etiqueta de texto preformateado </>

Revisa nuevamente el tema:

Guía : ¿Como Pegar reportes en el Foro?

Y si aun no te das cuenta solo copia y pega que luego yo lo edito, así podremos avanzar.

Salu2

Sorry por el despiste

   Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-05-2019
Ran by walter (administrator) on WALTER-PC (ECS GF7100/7050PVT-M3) (24-05-2019 15:00:44)
Running from C:\Users\walter\Desktop
Loaded Profiles: walter & UpdatusUser &  (Available Profiles: walter & UpdatusUser & Invitado)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Acronis, Inc -> ) C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Arcai.com) [File not signed] C:\Program Files\netcut\services\aips.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
(Digital Wave Ltd -> Digital Wave Ltd.) C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files\Dropbox\Update\DropboxUpdate.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files\Dropbox\Update\Install\{49AB1E3C-2C61-4634-ABAA-1917A5986021}\DropboxClient_73.4.118.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Foxit Software Incorporated -> Foxit Software Inc.) C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitConnectedPDFService.exe
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files\HiSuite\HandSetService\HuaweiHiSuiteService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Mega Limited -> Mega Limited) C:\Users\walter\AppData\Local\MEGAsync\MEGAsync.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\CompatTel\diagtrackrunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\sdclt.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\v114_ECS_D_6207.2V7_6099.8xp_G2.0V_RC_SDC\WDM\stacsv.exe
(Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(NVIDIA Corporation -> ) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Dropbox] => C:\Program Files\Dropbox\Client\Dropbox.exe [5537600 2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [450667 2009-06-11] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2019-04-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [225672 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704224\...\Run: [EEDSpeedLauncher] => C:\Windows\system32\eed_ec.dll [1545216 2015-09-02] () [File not signed]
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [14679256 2019-02-07] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [14679256 2019-02-07] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-3193159865-2815699795-1142240979-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145707266\...\Run: [EEDSpeedLauncher] => C:\Windows\system32\eed_ec.dll [1545216 2015-09-02] () [File not signed]
HKU\S-1-5-18\...\Run: [EEDSpeedLauncher] => C:\Windows\system32\eed_ec.dll [1545216 2015-09-02] () [File not signed]
HKLM\...\Drivers32: [vidc.tscc] => C:\Windows\system32\tsccvid.dll [602624 2014-11-11] (TechSmith Corporation) [File not signed]
HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\system32\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [File not signed]
HKLM\...\Drivers32: [vidc.tsc2] => C:\Windows\system32\tsc2_codec32.dll [234496 2014-08-27] (TechSmith Corporation) [File not signed]
HKLM\Software\...\AppCompatFlags\Custom\iisexpress.exe: [{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb] -> IIS Express Application Compatibility Database for x86
HKLM\Software\...\AppCompatFlags\InstalledSDB\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}: [DatabasePath] -> C:\Windows\AppPatch\Custom\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb [2012-05-29]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\74.0.3729.169\Installer\chrmstp.exe [2019-05-23] (Google LLC -> Google Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\walter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2018-03-08]
ShortcutTarget: MEGAsync.lnk -> C:\Users\walter\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01A59CCC-A585-4189-9603-53867104211A} - System32\Tasks\Driver Booster SkipUAC (walter) => C:\Program Files\IObit\Driver Booster\5.3.0\DriverBooster.exe
Task: {07784A53-AAF2-44B1-BECE-AECF6302DF9C} - \OperaUpdateService -> No File <==== ATTENTION
Task: {0A6468B5-80B8-4556-B8D5-28BEE0DDDCFC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [156968 2019-03-17] (Google Inc -> Google Inc.)
Task: {114429B2-BA48-40B1-BB70-6BA4DAD41D64} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [335872 2019-05-18] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {22D7B07A-FFDA-41E7-A08A-EACBC04462F1} - System32\Tasks\{52FEBD89-FBA4-449E-ACF6-50964B215D16} => msiexec.exe /package "C:\Users\walter\Desktop\Passware.Passware.Kit.Forensic.v13.5.8557.REPACK-BRD\Passware.Passware.Kit.Forensic.v13.5.8557.REPACK-BRD\passware-kit-forensic-32bit.msi"
Task: {2309619D-F02A-428C-85C8-148C4520A8B6} - System32\Tasks\ioloTUDsDownloader => C:\Program Files\Common Files\Phoenix360\ActiveCore\activebridge.exe [679656 2018-09-28] (IOLO TECHNOLOGIES, LLC -> iolo technologies, LLC)
Task: {236633DD-5F9F-4B3B-B3AF-EAB9BA494B24} - System32\Tasks\Opera scheduled Autoupdate 1535737370 => C:\Users\walter\AppData\Local\Programs\Opera\launcher.exe
Task: {2DA390BB-6F5F-447B-B365-73845EDEBF59} - System32\Tasks\{C87AB4CA-1F6E-4E8F-B93C-15AAEAE93580} => C:\Windows\system32\pcalua.exe -a "C:\Users\walter\Downloads\Compressed\Cursor_Installer\Cursor Installer.exe" -d C:\Users\walter\Downloads\Compressed\Cursor_Installer
Task: {32FF3E71-5F16-461C-8344-75A83AB8CAC6} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {3B0DD3DD-C7A1-4221-BA81-D3CCD22D7321} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-07] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3C35D1BA-7EF8-4D00-B944-EFDD2C1D9911} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-18] (Dropbox, Inc -> Dropbox, Inc.)
Task: {45DD7267-F62B-4FAA-BA95-87587F6648EA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14679256 2019-02-07] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {5DA1009A-015C-49C0-B1BD-B08C11301138} - System32\Tasks\GU5SkipUAC => C:\Program Files\Glary Utilities 5\Integrator.exe [897528 2017-06-29] (Glarysoft LTD -> Glarysoft Ltd)
Task: {6660F89E-AA6D-4E1B-9131-5FA119C11A57} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_walter => C:\Program Files\Hard Disk Sentinel\HDSentinel.exe [5458008 2018-07-17] (Janos Mathe -> H.D.S. Hungary)
Task: {6A60BAFF-1FE5-4D17-8BE4-C1E8726E8A17} - System32\Tasks\ActiveSync-SystemMechanic => C:\Program Files\Common Files\Phoenix360\ActiveCore\activebridge.exe [679656 2018-09-28] (IOLO TECHNOLOGIES, LLC -> iolo technologies, LLC)
Task: {7B4E731E-0B25-4875-BCBD-4C8F64958A47} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1983376 2019-04-05] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {8058733E-1769-4FE9-8BC1-D7CDA850AB09} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [156968 2019-03-17] (Google Inc -> Google Inc.)
Task: {85188087-71DA-40B9-88C2-21DED51433A9} - System32\Tasks\Opera scheduled assistant Autoupdate 1547735215 => C:\Users\walter\AppData\Local\Programs\Opera\launcher.exe
Task: {8A95F761-04CD-482A-B3CC-C36935A0B15B} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-3193159865-2815699795-1142240979-1000 => C:\Users\walter\AppData\Local\MEGAsync\MEGAupdater.exe [615160 2019-02-19] (Mega Limited -> Mega Limited)
Task: {AF0CC4C5-7851-4AB8-BF07-F015FF540C11} - System32\Tasks\ioloAVDefsDownloader => C:\Program Files\Phoenix360\System Mechanic\SSDefs.exe [136928 2018-09-28] (IOLO TECHNOLOGIES, LLC -> iolo technologies, LLC)
Task: {AF1E1DD1-BD40-4415-AA74-480623C94119} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_31_0_0_122_Plugin.exe [1454592 2019-05-18] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {B1C36431-8593-4506-B64A-B46764920DC2} - System32\Tasks\ActiveMessenger-SystemMechanic => C:\Program Files\Common Files\Phoenix360\ActiveCore\ActiveBridge.exe [679656 2018-09-28] (IOLO TECHNOLOGIES, LLC -> iolo technologies, LLC)
Task: {B28B9B36-DB2B-4445-9C54-043F1E054BB2} - System32\Tasks\AdobeGCInvoker-1.0-walter-PC-walter => C:\Program Files\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
Task: {B5412D51-22AF-457A-858B-DF8DA15D4E93} - System32\Tasks\{249DCE56-AFA6-4686-BD3A-B8052881FB3D} => C:\Windows\system32\pcalua.exe -a J:\Setup.exe -d J:\
Task: {B8CDB082-F74E-444E-A662-9EC509D5CD7E} - System32\Tasks\GlaryInitialize 5 => C:\Program Files\Glary Utilities 5\Initialize.exe [134648 2017-06-29] (Glarysoft LTD -> Glarysoft Ltd)
Task: {C1FCB802-7CA2-434D-B95F-9E5FE8AC2BFA} - System32\Tasks\ioloSystemShield => C:\Program Files\Phoenix360\System Mechanic\SSTray.exe [655520 2018-09-28] (IOLO TECHNOLOGIES, LLC -> iolo technologies, LLC)
Task: {D59B049B-6A34-474A-8F73-5F5C300CACED} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1951312 2019-04-05] (AVAST Software s.r.o. -> AVAST Software)
Task: {D8205082-44FE-4901-8F33-B14DBC41E54B} - System32\Tasks\ioloActiveCare => C:\Program Files\Phoenix360\System Mechanic\systemmechanic.exe [2403568 2018-09-28] (IOLO TECHNOLOGIES, LLC -> iolo technologies, LLC)
Task: {DE0D1019-EFAF-462E-9833-8816B4BEE198} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2385800 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
Task: {E6E161FE-4D95-4525-8EBC-5DB590348769} - System32\Tasks\{A0D2A674-A307-4641-950C-55F1306EC06B} => C:\Users\walter\Desktop\Cool Edit Pro 2.1\Cool Edit Pro 2.1.exe
Task: {FA42F638-5940-4E2F-9C8D-6C1EABCC414F} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-18] (Dropbox, Inc -> Dropbox, Inc.)
Task: {FE367E9D-87DF-4EBA-A032-0D5737F0983F} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\system32\Macromed\Flash\FlashUtil32_31_0_0_108_pepper.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\Windows\Tasks\DriverEasy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files\Dropbox\Update\DropboxUpdate.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 200.83.1.4 190.160.0.14 200.30.192.15
Tcpip\..\Interfaces\{3100BEF9-6842-40A2-AC20-26F7B775D9E3}: [DhcpNameServer] 200.83.1.4 190.160.0.14 200.30.192.15
Tcpip\..\Interfaces\{A1027262-0F84-4B8B-A726-084E896FEB10}: [DhcpNameServer] 200.83.1.4 190.160.0.14 200.30.192.15

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Start Page = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_192\bin\ssv.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_192\bin\jp2ssv.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368 [2019-05-24]
FF user.js: detected! => C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\user.js [2019-04-26]
FF Homepage: Mozilla\Firefox\Profiles\li04kydz.default-1490757013368 -> hxxps://www.google.cl/
FF Extension: (Custom Google Visited Link Color) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\[email protected] [2018-04-29]
FF Extension: (hotfix-update-xpi-intermediate) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\[email protected] [2019-05-14]
FF Extension: (Rotate and Zoom Image) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\[email protected] [2018-01-18]
FF Extension: (HTTP Directory Downloader) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\[email protected] [2019-04-09]
FF Extension: (S3.Translator) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\[email protected] [2018-11-18]
FF Extension: (Google Translator for Firefox) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\[email protected] [2018-12-02]
FF Extension: (Editor de documentos de Word) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\{51a33be5-1547-4a87-969e-dfea5ad04b7d}.xpi [2019-05-19]
FF Extension: (Flash Video Downloader) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\{a1be3447-d87d-409b-8721-d895935f65b8}.xpi [2019-05-17]
FF Extension: (Easy Video Downloader) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\Extensions\{cd04e15e-6b23-4648-860d-0057602a5c2a}.xpi [2019-05-17]
FF Extension: (Baidu Search Update) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\features\{85983bc9-7083-4aae-b58c-3af109c22fdf}\[email protected] [2019-05-04]
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\walter\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\walter\AppData\Roaming\IDM\idmmzcc5 [2019-01-08] [Legacy] [not signed]
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\walter\AppData\Roaming\IDM\idmmzcc5
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_31_0_0_122.dll [2019-05-18] (Adobe Systems Incorporated -> )
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-05-18] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-05-18] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-05-18] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2016-05-18] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-01-17] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-01-17] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-01-17] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2019-01-17] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.192.2 -> C:\Program Files\Java\jre1.8.0_192\bin\dtplugin\npDeployJava1.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.192.2 -> C:\Program Files\Java\jre1.8.0_192\bin\plugin2\npjp2.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-14] (Google Inc -> Google LLC)
FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
FF Plugin: @wolfram.com/Mathematica -> C:\Program Files\Common Files\Wolfram Research\Browser\10.4.1.5514075\npmathplugin.dll [2016-04-11] (Wolfram Research, Inc. -> Wolfram Research, Inc.)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems Incorporated -> Adobe Systems)

Chrome: 
=======
CHR DefaultSearchURL: Default -> hxxps://es.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://es.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default [2019-05-19]
CHR Extension: (Chameleon) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\acdpiemklcfaoglpjmidpjdbhkgdoede [2019-01-08]
CHR Extension: (Video Downloader professional) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeeajafchghccbnppaimjhhfpejabole [2019-01-08]
CHR Extension: (Yahoo Partner) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdbpcigaolookbahgdofnimidinicfid [2018-10-26]
CHR Extension: (GetThemAll) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhkjfciooifcflkailbnchdaihccdebf [2019-01-08]
CHR Extension: (Avast Online Security) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2019-05-05]
CHR Extension: (Video Downloader professional) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpaglkhbmbmhlnpnehlffkgaaapoicnk [2019-04-07]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-10-26]
CHR Extension: (Chrome Media Router) - C:\Users\walter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-05-12]
CHR HKLM\...\Chrome\Extension: [fdbpcigaolookbahgdofnimidinicfid] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - F:\Temp\~sfx00001228\IDMGCExt.crx <not found>

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AIPS; C:\Program Files\netcut\services\AIPS.exe [262144 2011-07-28] (Arcai.com) [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5398416 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [317280 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [466280 2019-04-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
S2 dbupdate; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-18] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-18] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [43856 2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
R2 DigitalWave.Update.Service; C:\Program Files\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-03-22] (Digital Wave Ltd -> Digital Wave Ltd.)
S3 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [370792 2010-01-21] (NVIDIA Corporation -> )
R2 FoxitPhantomService; C:\Program Files\Foxit Software\Foxit PhantomPDF\FoxitConnectedPDFService.exe [1647808 2016-06-21] (Foxit Software Incorporated -> Foxit Software Inc.)
S3 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [97824 2018-01-11] (INTERNET PROJECT LLC -> Freemake)
R2 HuaweiHiSuiteService.exe; C:\Program Files\HiSuite\HandSetService\HuaweiHiSuiteService.exe [154432 2018-12-12] (Huawei Technologies Co., Ltd. -> ) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [5247944 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [167528 2010-01-21] (NVIDIA Corporation -> )
R2 OS Selector; C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe [2139400 2010-05-25] (Acronis, Inc -> )
S3 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient.exe [3499576 2017-07-02] (SoftEther K.K. -> SoftEther VPN Project at University of Tsukuba, Japan.)
R2 STacSV; c:\program files\idt\v114_ecs_d_6207.2v7_6099.8xp_g2.0v_rc_sdc\wdm\STacSV.exe [217185 2009-06-11] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [11791704 2019-03-18] (TeamViewer GmbH -> TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S3 WsAppService; C:\Program Files\Wondershare\WAF\2.4.3.236\WsAppService.exe [495840 2018-01-26] (Wondershare Technology Co.,Ltd -> Wondershare)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AmUStor; C:\Windows\System32\drivers\AmUStor.SYS [75200 2018-03-24] (Alcorlink Corp. -> Alcorlink Corp.)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [34720 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [172424 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [220128 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [158240 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblog.sys [255360 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [51264 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [194680 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [40904 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [138480 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [101200 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [73008 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [783232 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [403408 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [165464 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [312464 2019-04-25] (AVAST Software s.r.o. -> AVAST Software)
R3 BlueletAudio; C:\Windows\System32\DRIVERS\blueletaudio.sys [29872 2012-12-19] (Ralink Technology Corporation -> IVT Corporation)
R3 BT; C:\Windows\System32\DRIVERS\btnetdrv.sys [10804 2005-04-30] (IVT Corporation) [File not signed]
S3 Btcsrusb; C:\Windows\System32\Drivers\btcusb.sys [23000 2005-05-31] (IVT Corporation) [File not signed]
S3 BTHidEnum; C:\Windows\System32\DRIVERS\vbtenum.sys [11860 2005-04-30] () [File not signed]
R0 BTHidMgr; C:\Windows\System32\Drivers\BTHidMgr.sys [28271 2005-04-30] (IVT Corporation) [File not signed]
R3 cbfs3; C:\Windows\System32\DRIVERS\cbfs3.sys [299024 2012-04-09] (EldoS Corporation -> EldoS Corporation)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2015-08-31] (Power Technology -> Windows (R) Win 7 DDK provider)
R3 DFX12; C:\Windows\System32\drivers\dfx12.sys [26104 2015-11-12] (Power Technology -> Windows (R) Win 7 DDK provider)
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [38400 2009-03-02] (Samsung Electronics Co., Ltd.) [File not signed]
R3 DLKRTE32; C:\Windows\System32\DRIVERS\DLKRTE32.sys [399360 2011-08-04] (Microsoft Windows Hardware Compatibility Publisher -> D-Link Corp. )
R1 ElRawDisk; C:\Windows\system32\drivers\rsdrv.sys [22312 2009-02-12] (EldoS Corporation -> EldoS Corporation)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [21496 2016-01-14] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [128552 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10208 2016-07-11] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R3 EuMusDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\vrtaucbl.sys [50728 2017-04-22] (NTONYX Ltd. -> Eugene V. Muzychenko)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [15360 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
S3 FETND62; C:\Windows\System32\DRIVERS\DLF62X86.SYS [45568 2009-11-23] (Microsoft Windows Hardware Compatibility Publisher -> D-Link )
S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-13] (Microsoft Windows -> VIA Technologies, Inc. )
R3 gHidPnp; C:\Windows\System32\Drivers\gHidPnp.Sys [20480 2018-09-06] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 gMouUsb; C:\Windows\System32\DRIVERS\gMouUsb.sys [11520 2018-08-15] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 GridinSoftInetSecurityDriver; C:\Windows\System32\DRIVERS\gsInetSecurity.sys [81160 2018-01-05] (GridinSoft, LLC -> GridinSoft LLC)
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [17472 2017-03-24] (Glarysoft Ltd -> Glarysoft Ltd)
R2 Hardlock; C:\Windows\system32\drivers\hardlock.sys [693760 2006-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Aladdin Knowledge Systems Ltd.)
R2 Haspnt; C:\Windows\system32\drivers\Haspnt.sys [47616 2018-01-04] (Aladdin Knowledge Systems) [File not signed]
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [38224 2018-11-04] (SurfRight B.V. -> )
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2016-11-12] (Martin Malik - REALiX -> REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R1 IMFCameraProtect; C:\Windows\system32\drivers\IMFCameraProtect.sys [25120 2017-03-17] (IObit Information Technology -> IObit.com)
S3 IMFDownProtect; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\IMFDownProtect.sys [20336 2017-03-08] (IObit Information Technology -> IObit.com)
S3 IMFFilter; C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\IMFFilter.sys [21392 2017-01-06] (IObit Information Technology -> IObit)
S3 IMFForceDelete; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\IMFForceDelete.sys [14168 2017-03-17] (IObit Information Technology -> IObit.com)
S3 ksapi; C:\Windows\system32\drivers\ksapi.sys [81768 2015-11-22] (Beijing Kingsoft Security software Co.,Ltd -> Kingsoft Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [173512 2019-05-23] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [107168 2019-05-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [64088 2019-05-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [241760 2019-05-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [87280 2019-05-24] (Malwarebytes Corporation -> Malwarebytes)
S3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0023.sys [26208 2017-07-02] (SoftEther K.K. -> SoftEther VPN Project at University of Tsukuba, Japan.)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [17160 2015-03-05] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\Windows\system32\pwdspio.sys [13064 2016-11-24] (MiniTool Solution Ltd -> )
S3 RegFilter; C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [32192 2016-12-15] (IObit Information Technology -> IObit.com)
S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [6528848 2019-01-01] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )
R3 Serenum; C:\Windows\System32\DRIVERS\nuvserenum.sys [17920 2013-11-25] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R3 Serial; C:\Windows\System32\DRIVERS\nuvserial.sys [76288 2013-11-25] (Microsoft Windows Hardware Compatibility Publisher -> Nuvoton Technology Corp.)
S3 snpstd; C:\Windows\System32\DRIVERS\snpstd.sys [390784 2006-05-03] () [File not signed]
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2011-02-08] (Samsung Electronics) [File not signed]
R3 STHDA; C:\Windows\System32\DRIVERS\stwrt.sys [407552 2009-06-11] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S3 tpg86win7; C:\Windows\System32\DRIVERS\tpg86win7.sys [491112 2012-02-22] (Realtek Semiconductor Corp -> TP-LINK TECHNOLOGIES CO., LTD)
S3 TrojanKillerDriver; C:\Windows\System32\DRIVERS\gtkdrv.sys [27408 2018-01-05] (GridinSoft, LLC -> Windows (R) Win 7 DDK provider)
U1 aswbdisk; no ImagePath
S3 catchme; \??\F:\Temp\catchme.sys [X]
S3 cpuz140; \??\F:\Temp\cpuz140\cpuz140_x32.sys [X]
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x32.sys [X]
S3 DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [X]
S1 dsbwncfk; \??\C:\Windows\System32\drivers\dsbwnck.sys [X]
U0 Partizan; no ImagePath

==================== NetSvcs (Whitelisted) ===================

Hola @WALLY

Una consulta:

Error: (05/24/2019 02:58:09 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: walter-PC) Description: Windows no encuentra el perfil local y está iniciando la sesión con un perfil temporal. Los cambios que se efectúen en este perfil se perderán cuando se cierre la sesión.

Tienes tu perfil de usuario en Windows? O es un perfil temporal como menciona el error.


1.- Desinstala con Revo Uninstaller en su Modo Avanzado:

Driver Booster, Iobit Malware Fighter, Office 2016 KMS Activator Ultimate v1.2 Final**

Manual de Revo Uninstaller.

2.- Luego sigue estos pasos:

Muy Importante >>> Realizar una copia de Seguridad de su Registro.

  • Descarga DelFix en el escritorio de Windows.
  • Clic Derecho, “Ejecutar como Administrador”.
  • En la ventana principal, marca solamente la casilla “Create Registry Backup”.
  • Clic en Run.

Al terminar se abrirá un reporte llamado DelFix.txt, guárdelo por si fuera necesario y cierre la herramienta…

3.- Desactiva Temporalmente tu antivirus.

4.- Abre un nuevo archivo Notepad y copia y pega este contenido:


Start
CloseProcesses:
CreateRestorePoint:(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2019-04-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {07784A53-AAF2-44B1-BECE-AECF6302DF9C} - \OperaUpdateService -> No File <==== ATTENTION
Task: {7B4E731E-0B25-4875-BCBD-4C8F64958A47} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1983376 2019-04-05] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {B5412D51-22AF-457A-858B-DF8DA15D4E93} - System32\Tasks\{249DCE56-AFA6-4686-BD3A-B8052881FB3D} => C:\Windows\system32\pcalua.exe -a J:\Setup.exe -d J:\
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Start Page = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_192\bin\ssv.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_192\bin\jp2ssv.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
FF Extension: (Baidu Search Update) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\features\{85983bc9-7083-4aae-b58c-3af109c22fdf}\[email protected] [2019-05-04]
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found
CHR DefaultSearchURL: Default -> hxxps://es.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://es.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR HKLM\...\Chrome\Extension: [fdbpcigaolookbahgdofnimidinicfid] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - F:\Temp\~sfx00001228\IDMGCExt.crx <not found>
S3 catchme; \??\F:\Temp\catchme.sys [X]
S3 cpuz140; \??\F:\Temp\cpuz140\cpuz140_x32.sys [X]
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x32.sys [X]
S3 DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [X]
S1 dsbwncfk; \??\C:\Windows\System32\drivers\dsbwnck.sys [X]
U0 Partizan; no ImagePath
2019-05-24 14:55 - 2018-01-04 00:05 - 008405015 _____ C:\Windows\hlktmp
2019-05-13 21:30 - 2019-05-13 21:32 - 000000000 ____D C:\Users\TEMP.walter-PC.002
2019-05-18 19:47 - 2018-11-04 18:39 - 000000000 ____D C:\Program Files\Avira
2019-05-18 19:45 - 2018-11-08 21:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2019-05-18 19:45 - 2018-11-04 18:39 - 000000000 ____D C:\ProgramData\Avira
2019-05-18 13:36 - 2016-07-14 02:00 - 000000000 ____D C:\Program Files\Microsoft Office
2019-04-26 20:20 - 2019-03-09 22:41 - 000000000 ____D C:\Users\TEMP.walter-PC.000
2019-03-17 16:07 - 2019-03-17 16:07 - 007895040 _____ () C:\Program Files\GUT1863.tmp
2018-07-07 00:09 - 2018-07-07 00:09 - 000000000 _____ () C:\Users\walter\AppData\Local\aGTBYvlZAHrDQlIH.exe.txt
2018-08-16 23:16 - 2018-08-16 23:16 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT10A.tmp
2019-03-17 16:16 - 2019-03-17 16:16 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT146B.tmp
2018-08-25 15:51 - 2018-08-25 15:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1506.tmp
2018-08-25 15:51 - 2018-08-25 15:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1583.tmp
2019-03-01 15:28 - 2019-03-01 15:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1610.tmp
2019-04-16 21:55 - 2019-04-16 21:55 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1AD0.tmp
2019-03-21 21:09 - 2019-03-21 21:09 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1C7A.tmp
2019-04-09 22:34 - 2019-04-09 22:34 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT2AF6.tmp
2017-07-02 21:28 - 2017-07-02 21:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT2D59.tmp
2019-04-07 09:02 - 2019-04-07 09:02 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT3DF9.tmp
2019-05-05 10:19 - 2019-05-05 10:19 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT4692.tmp
2018-01-30 09:12 - 2018-01-30 09:12 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT59.tmp
2019-05-16 19:51 - 2019-05-16 19:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT5ADB.tmp
2019-04-09 22:35 - 2019-04-09 22:35 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT6A57.tmp
2019-03-27 08:45 - 2019-03-27 08:45 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT7741.tmp
2018-08-16 23:15 - 2018-08-16 23:15 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT7AF9.tmp
2019-04-07 09:03 - 2019-04-07 09:03 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT7F3E.tmp
2018-12-28 12:30 - 2018-12-28 12:30 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT933.tmp
2017-07-02 20:58 - 2017-07-02 20:58 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT9404.tmp
2017-07-02 20:58 - 2017-07-02 20:58 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT950E.tmp
2019-05-16 19:51 - 2019-05-16 19:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT96B4.tmp
2019-05-05 10:18 - 2019-05-05 10:18 - 000000000 _____ () C:\Users\walter\AppData\Local\BITA063.tmp
2019-03-21 21:06 - 2019-03-21 21:06 - 000000000 _____ () C:\Users\walter\AppData\Local\BITA0FF.tmp
2018-12-23 17:01 - 2018-12-23 17:01 - 000000000 _____ () C:\Users\walter\AppData\Local\BITA4E6.tmp
2019-04-25 22:16 - 2019-04-25 22:16 - 000000000 _____ () C:\Users\walter\AppData\Local\BITB3C4.tmp
2019-03-21 21:07 - 2019-03-21 21:07 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDAB5.tmp
2019-03-24 18:48 - 2019-03-24 18:48 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDAD3.tmp
2019-03-17 16:15 - 2019-03-17 16:15 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDAF3.tmp
2019-03-01 15:28 - 2019-03-01 15:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDB7F.tmp
2019-03-21 21:09 - 2019-03-21 21:09 - 000000000 _____ () C:\Users\walter\AppData\Local\BITE0E0.tmp
2018-12-23 16:59 - 2018-12-23 16:59 - 000000000 _____ () C:\Users\walter\AppData\Local\BITF69D.tmp
2017-07-02 21:01 - 2017-07-02 21:01 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFA88.tmp
2017-07-02 21:01 - 2017-07-02 21:01 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFAD7.tmp
2018-12-28 12:30 - 2018-12-28 12:30 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFC9.tmp
2017-07-02 21:28 - 2017-07-02 21:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFE1C.tmp
Avira (HKLM\...\{2504137A-5E42-4340-8F34-2086B49FBD1A}) (Version: 1.2.133.21088 - Avira Operations GmbH & Co. KG) Hidden
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers3: [DLLRegSvr] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
AlternateDataStreams: C:\ProgramData\TEMP:EC2E1DEC [456]
FirewallRules: [{62F3A5E0-7654-40E5-B457-EA9D23D809E7}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DriverBooster.exe No File
FirewallRules: [{EE6C2C26-2810-4311-8B7D-763460A85F26}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DriverBooster.exe No File
FirewallRules: [{12DAB7A6-7D4E-4EBA-8F8B-E03F12B43DFA}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DBDownloader.exe No File
FirewallRules: [{DF93A177-ABEF-43A3-9468-513375022B6A}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DBDownloader.exe No File
FirewallRules: [{6E292B05-EC9A-4C80-A5EA-9247B049D6A8}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\AutoUpdate.exe No File
FirewallRules: [{10E06301-34CC-4819-BE89-1755D2A4E6C9}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\AutoUpdate.exe No File
CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
  • Lo guardas bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

Nota: Es necesario que el ejecutable Frst.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajara.

  • Ejecutas Frst.exe.
  • Presionas el botón Fix y aguardas a que termine.
  • La Herramienta guardara el reporte en tu escritorio (Fixlog.txt).
  • Lo pegas en tu próxima respuesta.

Luego de reiniciar, nos comentas si el problema persiste.

Salu2.

Con respecto a mi perfil , si es que lo entiendo bien , esta correcto pero ocurre que win cada ciertos momentos se traba desaparecen todos los iconos y vuelve. Esto aparece en usuarios

00

Fix result of Farbar Recovery Scan Tool (x86) Version: 19-05-2019
Ran by walter (24-05-2019 22:50:18) Run:1
Running from C:\Users\walter\Desktop
Loaded Profiles: walter & UpdatusUser & Invitado (Available Profiles: walter & UpdatusUser & Invitado)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe
(Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.Systray.exe
HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2019-04-12] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {07784A53-AAF2-44B1-BECE-AECF6302DF9C} - \OperaUpdateService -> No File <==== ATTENTION
Task: {7B4E731E-0B25-4875-BCBD-4C8F64958A47} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [1983376 2019-04-05] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {B5412D51-22AF-457A-858B-DF8DA15D4E93} - System32\Tasks\{249DCE56-AFA6-4686-BD3A-B8052881FB3D} => C:\Windows\system32\pcalua.exe -a J:\Setup.exe -d J:\
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main,Start Page = 
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Start Page = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = 
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_192\bin\ssv.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_192\bin\jp2ssv.dll [2019-05-18] (Oracle America, Inc. -> Oracle Corporation)
FF Extension: (Baidu Search Update) - C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\features\{85983bc9-7083-4aae-b58c-3af109c22fdf}\[email protected] [2019-05-04]
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found
CHR DefaultSearchURL: Default -> hxxps://es.search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://es.search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR HKLM\...\Chrome\Extension: [fdbpcigaolookbahgdofnimidinicfid] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - F:\Temp\~sfx00001228\IDMGCExt.crx <not found>
S3 catchme; \??\F:\Temp\catchme.sys [X]
S3 cpuz140; \??\F:\Temp\cpuz140\cpuz140_x32.sys [X]
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x32.sys [X]
S3 DrvAgent32; \??\C:\Windows\system32\Drivers\DrvAgent32.sys [X]
S1 dsbwncfk; \??\C:\Windows\System32\drivers\dsbwnck.sys [X]
U0 Partizan; no ImagePath
2019-05-24 14:55 - 2018-01-04 00:05 - 008405015 _____ C:\Windows\hlktmp
2019-05-13 21:30 - 2019-05-13 21:32 - 000000000 ____D C:\Users\TEMP.walter-PC.002
2019-05-18 19:47 - 2018-11-04 18:39 - 000000000 ____D C:\Program Files\Avira
2019-05-18 19:45 - 2018-11-08 21:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2019-05-18 19:45 - 2018-11-04 18:39 - 000000000 ____D C:\ProgramData\Avira
2019-05-18 13:36 - 2016-07-14 02:00 - 000000000 ____D C:\Program Files\Microsoft Office
2019-04-26 20:20 - 2019-03-09 22:41 - 000000000 ____D C:\Users\TEMP.walter-PC.000
2019-03-17 16:07 - 2019-03-17 16:07 - 007895040 _____ () C:\Program Files\GUT1863.tmp
2018-07-07 00:09 - 2018-07-07 00:09 - 000000000 _____ () C:\Users\walter\AppData\Local\aGTBYvlZAHrDQlIH.exe.txt
2018-08-16 23:16 - 2018-08-16 23:16 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT10A.tmp
2019-03-17 16:16 - 2019-03-17 16:16 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT146B.tmp
2018-08-25 15:51 - 2018-08-25 15:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1506.tmp
2018-08-25 15:51 - 2018-08-25 15:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1583.tmp
2019-03-01 15:28 - 2019-03-01 15:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1610.tmp
2019-04-16 21:55 - 2019-04-16 21:55 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1AD0.tmp
2019-03-21 21:09 - 2019-03-21 21:09 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT1C7A.tmp
2019-04-09 22:34 - 2019-04-09 22:34 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT2AF6.tmp
2017-07-02 21:28 - 2017-07-02 21:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT2D59.tmp
2019-04-07 09:02 - 2019-04-07 09:02 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT3DF9.tmp
2019-05-05 10:19 - 2019-05-05 10:19 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT4692.tmp
2018-01-30 09:12 - 2018-01-30 09:12 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT59.tmp
2019-05-16 19:51 - 2019-05-16 19:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT5ADB.tmp
2019-04-09 22:35 - 2019-04-09 22:35 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT6A57.tmp
2019-03-27 08:45 - 2019-03-27 08:45 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT7741.tmp
2018-08-16 23:15 - 2018-08-16 23:15 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT7AF9.tmp
2019-04-07 09:03 - 2019-04-07 09:03 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT7F3E.tmp
2018-12-28 12:30 - 2018-12-28 12:30 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT933.tmp
2017-07-02 20:58 - 2017-07-02 20:58 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT9404.tmp
2017-07-02 20:58 - 2017-07-02 20:58 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT950E.tmp
2019-05-16 19:51 - 2019-05-16 19:51 - 000000000 _____ () C:\Users\walter\AppData\Local\BIT96B4.tmp
2019-05-05 10:18 - 2019-05-05 10:18 - 000000000 _____ () C:\Users\walter\AppData\Local\BITA063.tmp
2019-03-21 21:06 - 2019-03-21 21:06 - 000000000 _____ () C:\Users\walter\AppData\Local\BITA0FF.tmp
2018-12-23 17:01 - 2018-12-23 17:01 - 000000000 _____ () C:\Users\walter\AppData\Local\BITA4E6.tmp
2019-04-25 22:16 - 2019-04-25 22:16 - 000000000 _____ () C:\Users\walter\AppData\Local\BITB3C4.tmp
2019-03-21 21:07 - 2019-03-21 21:07 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDAB5.tmp
2019-03-24 18:48 - 2019-03-24 18:48 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDAD3.tmp
2019-03-17 16:15 - 2019-03-17 16:15 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDAF3.tmp
2019-03-01 15:28 - 2019-03-01 15:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BITDB7F.tmp
2019-03-21 21:09 - 2019-03-21 21:09 - 000000000 _____ () C:\Users\walter\AppData\Local\BITE0E0.tmp
2018-12-23 16:59 - 2018-12-23 16:59 - 000000000 _____ () C:\Users\walter\AppData\Local\BITF69D.tmp
2017-07-02 21:01 - 2017-07-02 21:01 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFA88.tmp
2017-07-02 21:01 - 2017-07-02 21:01 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFAD7.tmp
2018-12-28 12:30 - 2018-12-28 12:30 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFC9.tmp
2017-07-02 21:28 - 2017-07-02 21:28 - 000000000 _____ () C:\Users\walter\AppData\Local\BITFE1C.tmp
Avira (HKLM\...\{2504137A-5E42-4340-8F34-2086B49FBD1A}) (Version: 1.2.133.21088 - Avira Operations GmbH & Co. KG) Hidden
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers3: [DLLRegSvr] -> {8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
AlternateDataStreams: C:\ProgramData\TEMP:EC2E1DEC [456]
FirewallRules: [{62F3A5E0-7654-40E5-B457-EA9D23D809E7}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DriverBooster.exe No File
FirewallRules: [{EE6C2C26-2810-4311-8B7D-763460A85F26}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DriverBooster.exe No File
FirewallRules: [{12DAB7A6-7D4E-4EBA-8F8B-E03F12B43DFA}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DBDownloader.exe No File
FirewallRules: [{DF93A177-ABEF-43A3-9468-513375022B6A}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\DBDownloader.exe No File
FirewallRules: [{6E292B05-EC9A-4C80-A5EA-9247B049D6A8}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\AutoUpdate.exe No File
FirewallRules: [{10E06301-34CC-4819-BE89-1755D2A4E6C9}] => (Allow) C:\Program Files\IObit\Driver Booster\5.3.0\AutoUpdate.exe No File
CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
*****************

Processes closed successfully.
Restore point was successfully created.
C:\Program Files\Avira\Launcher\Avira.Systray.exe => No running process found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Avira SystrayStartTrigger" => not found
"HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NolowDiskSpaceChecks" => removed successfully.
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Policies\Mozilla => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{07784A53-AAF2-44B1-BECE-AECF6302DF9C}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{07784A53-AAF2-44B1-BECE-AECF6302DF9C}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OperaUpdateService" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7B4E731E-0B25-4875-BCBD-4C8F64958A47}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B4E731E-0B25-4875-BCBD-4C8F64958A47}" => removed successfully.
C:\Windows\System32\Tasks\AVG\Overseer => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG\Overseer" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5412D51-22AF-457A-858B-DF8DA15D4E93}" => removed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5412D51-22AF-457A-858B-DF8DA15D4E93}" => removed successfully.
C:\Windows\System32\Tasks\{249DCE56-AFA6-4686-BD3A-B8052881FB3D} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{249DCE56-AFA6-4686-BD3A-B8052881FB3D}" => removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page" => removed successfully.
"HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Search Page" => removed successfully.
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch => Error: No automatic fix found for this entry.
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\Software\Microsoft\Internet Explorer\Main,Start Page = => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully.
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{87A6A1F2-3D80-47D5-8295-F35B7D64E501} => removed successfully.
HKLM\Software\Classes\CLSID\{87A6A1F2-3D80-47D5-8295-F35B7D64E501} => not found
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> DefaultScope {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = => Error: No automatic fix found for this entry.
SearchScopes: HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754 -> {87A6A1F2-3D80-47D5-8295-F35B7D64E501} URL = => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully.
HKLM\Software\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully.
HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully.
C:\Users\walter\AppData\Roaming\Mozilla\Firefox\Profiles\li04kydz.default-1490757013368\features\{85983bc9-7083-4aae-b58c-3af109c22fdf}\[email protected] => moved successfully
"HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Mozilla\Firefox\Extensions\\[email protected]" => removed successfully.
"HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\Software\Mozilla\SeaMonkey\Extensions\\[email protected]" => removed successfully.
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\Firefox\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc3.xpi => not found => Error: No automatic fix found for this entry.
FF HKU\S-1-5-21-3193159865-2815699795-1142240979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05242019145704754\...\SeaMonkey\Extensions: [[email protected]] - F:\Temp\~sfx00001228\idmmzcc2.xpi => not found => Error: No automatic fix found for this entry.
"Chrome DefaultSearchURL" => removed successfully.
"Chrome DefaultSearchKeyword" => removed successfully.
"Chrome DefaultSuggestURL" => removed successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\fdbpcigaolookbahgdofnimidinicfid => removed successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => removed successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully.
HKLM\System\CurrentControlSet\Services\catchme => removed successfully.
catchme => service removed successfully.
HKLM\System\CurrentControlSet\Services\cpuz140 => removed successfully.
cpuz140 => service removed successfully.
HKLM\System\CurrentControlSet\Services\cpuz143 => removed successfully.
cpuz143 => service removed successfully.
HKLM\System\CurrentControlSet\Services\DrvAgent32 => removed successfully.
DrvAgent32 => service removed successfully.
HKLM\System\CurrentControlSet\Services\dsbwncfk => removed successfully.
dsbwncfk => service removed successfully.
HKLM\System\CurrentControlSet\Services\Partizan => removed successfully.
Partizan => service removed successfully.
Could not move "C:\Windows\hlktmp" => Scheduled to move on reboot.
C:\Users\TEMP.walter-PC.002 => moved successfully
"C:\Program Files\Avira" => not found
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira" => not found
"C:\ProgramData\Avira" => not found
C:\Program Files\Microsoft Office => moved successfully

"C:\Users\TEMP.walter-PC.000" folder move:

Could not move "C:\Users\TEMP.walter-PC.000" => Scheduled to move on reboot.

C:\Program Files\GUT1863.tmp => moved successfully
C:\Users\walter\AppData\Local\aGTBYvlZAHrDQlIH.exe.txt => moved successfully
C:\Users\walter\AppData\Local\BIT10A.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT146B.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT1506.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT1583.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT1610.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT1AD0.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT1C7A.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT2AF6.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT2D59.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT3DF9.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT4692.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT59.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT5ADB.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT6A57.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT7741.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT7AF9.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT7F3E.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT933.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT9404.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT950E.tmp => moved successfully
C:\Users\walter\AppData\Local\BIT96B4.tmp => moved successfully
C:\Users\walter\AppData\Local\BITA063.tmp => moved successfully
C:\Users\walter\AppData\Local\BITA0FF.tmp => moved successfully
C:\Users\walter\AppData\Local\BITA4E6.tmp => moved successfully
C:\Users\walter\AppData\Local\BITB3C4.tmp => moved successfully
C:\Users\walter\AppData\Local\BITDAB5.tmp => moved successfully
C:\Users\walter\AppData\Local\BITDAD3.tmp => moved successfully
C:\Users\walter\AppData\Local\BITDAF3.tmp => moved successfully
C:\Users\walter\AppData\Local\BITDB7F.tmp => moved successfully
C:\Users\walter\AppData\Local\BITE0E0.tmp => moved successfully
C:\Users\walter\AppData\Local\BITF69D.tmp => moved successfully
C:\Users\walter\AppData\Local\BITFA88.tmp => moved successfully
C:\Users\walter\AppData\Local\BITFAD7.tmp => moved successfully
C:\Users\walter\AppData\Local\BITFC9.tmp => moved successfully
C:\Users\walter\AppData\Local\BITFE1C.tmp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2504137A-5E42-4340-8F34-2086B49FBD1A}\\SystemComponent" => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully.
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\DLLRegSvr => removed successfully.
HKLM\Software\Classes\CLSID\{8AB81E72-CB2F-11D3-8D3B-AC2F34F1FA3C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully.
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\7-Zip => removed successfully.
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
"CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"" => removed successfully.
"BVTFilter" => removed successfully.
"BVTConsumer" => removed successfully.
C:\ProgramData\TEMP => ":EC2E1DEC" ADS removed successfully.
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{62F3A5E0-7654-40E5-B457-EA9D23D809E7}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EE6C2C26-2810-4311-8B7D-763460A85F26}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{12DAB7A6-7D4E-4EBA-8F8B-E03F12B43DFA}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DF93A177-ABEF-43A3-9468-513375022B6A}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6E292B05-EC9A-4C80-A5EA-9247B049D6A8}" => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10E06301-34CC-4819-BE89-1755D2A4E6C9}" => not found

========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Conexi¢n de  rea local 4 mientras los medios
est‚n desconectados.

Adaptador de Ethernet Conexi¢n de  rea local 2:

   Sufijo DNS espec¡fico para la conexi¢n. . : 
   V¡nculo: direcci¢n IPv6 local. . . : fe80::24da:2865:57ab:c4d3%19
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.29
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.0.1

Adaptador de Ethernet Conexi¢n de  rea local 4:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel isatap.{3100BEF9-6842-40A2-AC20-26F7B775D9E3}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel isatap.{09E2B554-A267-4EF9-9D36-06A3CA8CFD8E}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= End of CMD: =========


========= netsh int ipv4 reset =========

Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= RemoveProxy: =========

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully.
HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully.
"HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\S-1-5-21-3193159865-2815699795-1142240979-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully.
"HKU\S-1-5-21-3193159865-2815699795-1142240979-501\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\S-1-5-21-3193159865-2815699795-1142240979-501\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully.


========= End of RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 3153931 B
Java, Flash, Steam htmlcache => 1171 B
Windows/system/drivers => 1525462 B
Edge => 0 B
Chrome => 259107 B
Firefox => 207579824 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 33186 B
LocalService => 33058 B
NetworkService => 0 B
walter => 792045 B
UpdatusUser => 0 B
Max Ram => 38633 B
TEMP.walter-PC.000 => 0 B
Invitado.walter-PC => 0 B

RecycleBin => 248186417 B
EmptyTemp: => 448.2 MB temporary data Removed.

================================

Hola @WALLY

Pues por lo que se ve en la imagen no del todo, te esta creando perfiles temporales de la cuenta Walter

Podrías perderla o que no arranque mas.

Para salvarla crea una nueva cuenta de Usuario con Derechos de Administrador., colocale un nombre que se diferencie.

Cuando la tengas vienes y lo comentas.


Que paso luego del Fix, sigue el problema error con la dll al iniciar.

Salu2.

Bueno he creado otro usuario con otro nombre , ¿pero todo lo que esta en el viejo como lo paso al nuevo , (debo instalar todo de nuevo)? Debo decirte que el pc anda mucho mejor pero el error persiste arranque un par de programas y salta , en concreto chrome , psiphon3VPN , no me deja instalar office sale lo mismo

Hola @WALLY

No, tranquilo que ya te daré lo pasos, mañana la seguimos que aquí es muuuuuy tarde.

:+1:

Te había escrito que no lo instales hasta que te lo diga.


Por el momento desinstala con Revo Uninstaller en su Modo Avanzado:

  • Chrome , Psiphon3VPN

Manual de Revo Uninstaller.

Y no los reinstales aun.NO.


Descarga, instala y/o actualiza:

Lo ejecutas:

CCleaner

Usando su opción Limpiador y luego Registro de acuerdo a su Manual:

  • Para borrar Cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos.

  • NO necesitamos este reporte


Nos comentas.

Salu2.

Listo , este Psiphon3VPN lo borre asi no mas era solo un ejecutable , debe haber sido un portable, pase el Ccleaner y …el problema sigue :frowning: Buenas Noches

Última hora murió Firefox , mismo error , te escribo del celular

Hola:

Una consulta recuerdas que hiciste antes de que empezará el problema?

Intentaste restaurar sistema a una fecha anterior a cuando empezó el error.

Nos comentas.

Salu2

Ayer realice lo que me pediste y funcionaba todo bien ,de repente apareció el problema ,lo malo que tengo favoritos que no puedo recuperar .Realice 2 cosas ,intenté arrancar en modo a prueba de fallos nada, luego intenté arrancar con una sección anterior …la mejor que funcionaba…según dice sin y nada…voy a intentar ir más atrás …qué raro este problema jamás había tenido uno así…como de seguro me vas a pedir que borre Firefox , como recupero las pestañas favoritas …gracias por tu tiempo

Hola aqui estamos de nuevo , recupere firefox , restaure al punto de donde me pediste que fijara(Frst.exe) , bueno respalde favoritos y todo eso , al parecer cuando me pediste que fijara , algo hay ahi que causo el problema , lo curioso que es el mismo error…

Hola @WALLY

Me parece que no nos estamos entendiendo.:sleepy:

Solo te pregunte si cuando te apareció el error ( de las dll) no habias probado restaurar sistema, y si recordabas que descargaste o ejecutaste antes que te apareciera el error.

Con ello, desiciste todo lo que habiamos hecho :expressionless:

No entiendo a que te refieres cuando dices que te pedí que fijaras? FRST crea un punto de restauración por que así esta indicado en los comandos del Fixlist.

Y Delfix que si te indique guarda una copia de tu registro por seguridad, no te pedi que restauraras a ese punto.

El error ya lo tenias, no es FRST el que causo el error, aun no pudimos resolver tu error.


Solo revisa si tienes un punto de restauración anterior a la fecha que comentas en tu primer post, cuando mencionaste:

Nos comentas.

Salu2