Estos es normal en windows 10?

Hola @SanMar

Desde que me di cuenta de este envió de datos. Bloquee todo lo referente a conexiones compartidas.

No.

.

. Si no me equivoco son esas dentro del recuadro rojo. No puedo terminar la conexión y si mato el proceso creo que windows crashea

Es como hablar con la pared (Literal). Voy a intentar a ver que me dicen.

Hola @jrac

Si son las marcadas en Rojo y apuntan a tu proveedor, tienes algún equipo de un amigo o familar, que no sea en tu red para que lo chequees, dado tu país, que no sea algo común de tu proveedor?

También revisa si puedes ubicar en el Administrador de Tareas, a que proceso le corresponde el PID 4

Salu2

Hola @SanMar

Conecte una laptop al wifi del vecino (Proveedor Cantv)… tiene Windows 7 (“Pirata”). No hay ninguna conexión que mande datos. Utilice TCPView.

No se de nadie que tenga Windows 10 y tenga de proveedor Cantv.

Estoy pesando en conectar mi pc al wifi del vecino a través de la laptop a ver si sigue enviando datos (Mi pc no cuenta con tarjeta de red wifi) o colocar un router en mi conexión ya que este cuenta con salidas Ethernet (RJ45).

Voy a intentar la dos opciones que mencione… Cualquier cosa actualizo la publicación.

Intente la primera opción y hasta los momentos no esta enviando datos. Desde las 6:50 pm. Son 7:25 pm al momento de publicar. La voy a dejar así conectada hasta mañana.

1 me gusta

Hola @jrac

Vale, espero tus comentarios.

Salu2

1 me gusta

Hola @SanMar

Asi esta desde ayer. No ha enviado nada y no han aparecido las ip.

Lo malo es que no tengo una tarjeta de red inalámbrica para probar directamente a la red wifi. Son 10:00PM. A las 12:00 m. pruebo otra ves con mi red.

Voy a conectar la laptop directamente a mi red para ver si esta empieza a enviar datos…

No se si tienen alguna otra sugerencia.

Saludos.

Hola @jrac

Perfecto, vuelve a tu equipo y tu red, ya sabemos que no pasa en otra red.

1.- Desinstala con su herramienta especifica tu antivirus Eset:

No queremos que nos este bloqueando alguno de los pasos.

2.- Luego de reiniciar, vuelve a ejecutar FRST tal como lo hiciste la primera vez y nos pegas reportes frescos.

Salu2

Hola @SanMar

Listo ya elimine ESET con la herremienta manual. El proceso System no esta enviando nada hasta el momento. Viendo las conexiones con TCPView.


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-11-2019
Ran by A.C (administrator) on DESKTOP-DGTGDVM (langchao 12345) (22-11-2019 16:40:38)
Running from C:\Users\A.C\Desktop
Loaded Profiles: A.C (Available Profiles: A.C)
Platform: Microsoft Windows 10 Home Version 1909 18363.476 (X86) Language: Español (España, internacional)
Default browser: "C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" -- "%1"
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> Brave Software, Inc.) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
(Brave Software, Inc. -> BraveSoftware Inc.) C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(Genesys Logic, Inc. -> Genesys Logic) C:\Windows\System32\DriverStore\FileRepository\genestor.inf_x86_72d3ca414e5dcd4d\GLCRIconSvc.exe
(Google Inc -> Google LLC) C:\Program Files\Google\Update\1.3.35.342\GoogleCrashHandler.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1908.0.0_x86__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12228.20206.0_x86__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12228.20206.0_x86__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MpCmdRun.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1908.7-0\MsMpEng.exe
(Telegram FZ-LLC -> Telegram FZ-LLC) C:\Users\A.C\AppData\Roaming\Telegram Desktop\Telegram.exe
(Valve -> Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve -> Valve Corporation) C:\Program Files\Steam\Steam.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [16553472 2017-06-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCEPServiceManager] => C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\Run: [uTorrent] => C:\Users\A.C\AppData\Roaming\uTorrent\uTorrent.exe [2005224 2019-11-03] (BitTorrent Inc -> BitTorrent Inc.)
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\Run: [GUDelayStartup] => C:\Program Files\Glary Utilities 5\StartupManager.exe [44024 2019-09-01] (Glarysoft LTD -> Glarysoft Ltd)
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\Run: [Voobly] => C:\Program Files\Voobly\voobly.exe [172032 2019-05-14] (Voobly) [File not signed]
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [3288016 2019-11-19] (Valve -> Valve Corporation)
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\RunOnce: [Application Restart #0] => C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe [1856144 2019-11-19] (Brave Software, Inc. -> Brave Software, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{43F137B0-8F4D-463B-AB83-ADEAD4F15096}] -> C:\Program Files\Microsoft\Edge Beta\Application\79.0.309.25\Installer\setup.exe [2019-11-22] (Microsoft Corporation -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\78.0.3904.108\Installer\chrmstp.exe [2019-11-20] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}] -> C:\Program Files\BraveSoftware\Brave-Browser\Application\78.1.0.1\Installer\chrmstp.exe [2019-11-19] (Brave Software, Inc.) [File not signed]
Startup: C:\Users\A.C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2019-09-07]
ShortcutTarget: MEGAsync.lnk -> C:\Users\A.C\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2019-09-04]
ShortcutTarget: Telegram.lnk -> C:\Users\A.C\AppData\Roaming\Telegram Desktop\Telegram.exe (Telegram FZ-LLC -> Telegram FZ-LLC)
Startup: C:\Users\A.C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2019-09-07]
ShortcutTarget: MEGAsync.lnk -> C:\Users\A.C\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {26D01975-F3A6-434C-84BF-C6F740D35DCF} - System32\Tasks\BraveSoftwareUpdateTaskMachineCore => C:\Program Files\BraveSoftware\Update\BraveUpdate.exe [159368 2019-09-04] (Brave Software, Inc. -> BraveSoftware Inc.)
Task: {2E1DEF93-E803-494F-BC1D-7125D06091B9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [403816 2019-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2F4E51CD-0834-4AB3-BE99-4BE10A89E06C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [403816 2019-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {33550B1D-A7C4-429F-88F4-12305AE01A0C} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA => C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223336 2019-11-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {5F1E5B6A-B5A6-482E-96D4-4F347BD81AB0} - System32\Tasks\klcp_update => C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1724928 2019-10-03] () [File not signed]
Task: {6B2FA4A2-2DAB-4D95-A598-0BA7F763CE45} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore => C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223336 2019-11-22] (Microsoft Corporation -> Microsoft Corporation)
Task: {8597787F-877F-4076-B416-EC4E50BD6593} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [403816 2019-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B72154F9-17D3-4889-8C18-B0456CE86E3A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [154920 2019-09-04] (Google Inc -> Google LLC)
Task: {C8839541-E5A3-4224-88E7-ED297FB39061} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [154920 2019-09-04] (Google Inc -> Google LLC)
Task: {D4B24485-E161-4BF4-9035-E0AA90783DC3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MpCmdRun.exe [403816 2019-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 200.109.78.12 200.44.32.12
Tcpip\..\Interfaces\{0b9129b6-3f1e-48d0-aa29-31aca8314401}: [DhcpNameServer] 200.109.78.12 200.44.32.12
Tcpip\..\Interfaces\{f0b26f8f-7e2a-430b-8208-eaec92f258b7}: [NameServer] 8.8.8.8,8.8.4.4

Internet Explorer:
==================

FireFox:
========
FF DefaultProfile: 90157zhq.default
FF ProfilePath: C:\Users\A.C\AppData\Roaming\Mozilla\Firefox\Profiles\90157zhq.default [2019-11-18]
FF ProfilePath: C:\Users\A.C\AppData\Roaming\Mozilla\Firefox\Profiles\4nah6wq3.default-release [2019-11-22]
FF Plugin: @tools.brave.com/BraveSoftware Update;version=3 -> C:\Program Files\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-09-04] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin: @tools.brave.com/BraveSoftware Update;version=9 -> C:\Program Files\BraveSoftware\Update\1.3.99.0\npBraveUpdate3.dll [2019-09-04] (Brave Software, Inc. -> BraveSoftware Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-04] (Google Inc -> Google LLC)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-04] (Google Inc -> Google LLC)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2013-03-21] (Adobe Systems Incorporated -> Adobe Systems)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.co.ve/
CHR StartupUrls: Default -> "chrome://newtab/"
CHR Notifications: Default -> hxxps://tops-easyviaja.os.tc
CHR Profile: C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default [2019-11-21]
CHR Extension: (Presentaciones) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-09-04]
CHR Extension: (Documentos) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-09-04]
CHR Extension: (Google Drive) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-09-04]
CHR Extension: (Glow) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\bekmjjakgojplnhahcilegeiklenjbgb [2019-09-04]
CHR Extension: (WOT: Web of Trust, valoraciones de reputación de sitios web) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2019-09-04]
CHR Extension: (YouTube) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-09-04]
CHR Extension: (Hojas de cálculo) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-09-04]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-09-04]
CHR Extension: (AdBlock) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-11-20]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-09-04]
CHR Extension: (Chrome Media Router) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-10-30]
CHR Extension: (Audio Only Youtube) - C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkocpiliahoaohbolmkelakpiphnllog [2019-09-04]
CHR Profile: C:\Users\A.C\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-11-18]
CHR Profile: C:\Users\A.C\AppData\Local\Google\Chrome\User Data\System Profile [2019-11-18]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 brave; C:\Program Files\BraveSoftware\Update\BraveUpdate.exe [159368 2019-09-04] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 bravem; C:\Program Files\BraveSoftware\Update\BraveUpdate.exe [159368 2019-09-04] (Brave Software, Inc. -> BraveSoftware Inc.)
S3 chromoting; C:\Program Files\Google\Chrome Remote Desktop\79.0.3945.10\remoting_host.exe [74392 2019-10-24] (Google LLC -> Google Inc.)
S2 edgeupdate; C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223336 2019-11-22] (Microsoft Corporation -> Microsoft Corporation)
S3 edgeupdatem; C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [223336 2019-11-22] (Microsoft Corporation -> Microsoft Corporation)
R2 GeneStorSvc; C:\Windows\System32\DriverStore\FileRepository\genestor.inf_x86_72d3ca414e5dcd4d\GLCRIconSvc.exe [149592 2019-09-04] (Genesys Logic, Inc. -> Genesys Logic)
S3 MicrosoftEdgeBetaElevationService; C:\Program Files\Microsoft\Edge Beta\Application\79.0.309.25\elevation_service.exe [720256 2019-11-18] (Microsoft Corporation -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\NisSrv.exe [2662920 2019-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1908.7-0\MsMpEng.exe [85032 2019-10-01] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 ekrnEpfw; "C:\Program Files\ESET\ESET Security\ekrn.exe" [X]

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [112688 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [155016 2019-09-04] (Genesys Logic, Inc. -> Genesys Logic)
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [25864 2019-09-05] (Glarysoft LTD -> Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2019-09-04] (Martin Malik - REALiX -> REALiX(tm))
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [243800 2019-11-13] (Malwarebytes Inc -> Malwarebytes)
S3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial.sys [35840 2012-12-10] (Microsoft Windows Hardware Compatibility Publisher -> Research in Motion Ltd)
R3 rt640x86; C:\Windows\System32\drivers\rt640x86.sys [975648 2019-09-04] (Realtek Semiconductor Corp. -> Realtek )
S3 Secdrv; C:\Windows\system32\drivers\SECDRV.SYS [11616 2001-08-30] () [File not signed]
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [148536 2019-07-09] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [38280 2019-10-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [271072 2019-10-01] (Microsoft Windows -> Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [119952 2016-07-15] (NGO -> MBB)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [38624 2019-10-01] (Microsoft Windows -> Microsoft Corporation)
S3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [207360 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
S3 xhunter1; C:\Windows\xhunter1.sys [61760 2019-11-09] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-11-22 16:40 - 2019-11-22 16:42 - 000018871 _____ C:\Users\A.C\Desktop\FRST.txt
2019-11-22 16:36 - 2019-11-22 16:36 - 001990144 _____ (Farbar) C:\Users\A.C\Desktop\FRST.exe
2019-11-22 16:01 - 2019-11-22 16:01 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2019-11-22 16:00 - 2019-11-22 16:01 - 000115496 _____ C:\Windows\ntbtlog.txt
2019-11-22 15:50 - 2019-11-22 15:50 - 000002592 _____ C:\NetworkSettings.txt
2019-11-22 15:45 - 2019-11-22 15:46 - 000002592 _____ C:\Windows\system32\NetworkSettings.txt
2019-11-22 15:36 - 2019-11-22 15:37 - 000000112 _____ C:\Users\A.C\Desktop\Nuevo documento de texto (2).txt
2019-11-22 15:28 - 2019-11-22 15:29 - 001090168 _____ (ESET) C:\Users\A.C\Desktop\ESETUninstaller.exe
2019-11-22 11:58 - 2019-11-22 11:58 - 000002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge Beta.lnk
2019-11-22 11:37 - 2019-11-22 11:37 - 000003640 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2019-11-22 11:37 - 2019-11-22 11:37 - 000003516 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2019-11-21 12:22 - 2019-11-22 12:36 - 000000000 ____D C:\Users\A.C\Desktop\Nueva carpeta (2)
2019-11-20 09:08 - 2019-11-21 12:19 - 000000000 ____D C:\Users\A.C\AppData\LocalLow\uTorrent
2019-11-18 13:39 - 2019-11-18 13:39 - 000016896 ___SH C:\Users\Public\Thumbs.db
2019-11-18 10:34 - 2019-11-18 10:34 - 000083600 _____ C:\Users\A.C\Downloads\transferencia_otros_bancos(1).pdf
2019-11-18 08:30 - 2019-11-18 08:31 - 000000245 _____ C:\DelFix.txt
2019-11-18 08:30 - 2019-11-18 08:30 - 000000000 ____D C:\Windows\ERUNT
2019-11-17 08:49 - 2019-11-22 16:41 - 000000000 ____D C:\FRST
2019-11-14 20:07 - 2019-11-14 20:07 - 000000079 _____ C:\Windows\wininit.ini
2019-11-13 12:00 - 2019-11-13 12:00 - 000243800 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-11-13 11:55 - 2019-11-13 11:58 - 000000000 ____D C:\AdwCleaner
2019-11-13 11:54 - 2019-11-13 11:54 - 000129056 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae.sys
2019-11-13 11:54 - 2019-11-13 11:54 - 000000000 ____D C:\Users\A.C\AppData\Local\mbamtray
2019-11-13 11:54 - 2019-11-13 11:54 - 000000000 ____D C:\Users\A.C\AppData\Local\mbam
2019-11-13 11:54 - 2019-11-13 11:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-11-13 11:54 - 2019-11-13 11:54 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-11-13 11:48 - 2019-11-13 11:48 - 000000000 ____D C:\Program Files\Malwarebytes
2019-11-13 10:50 - 2019-11-13 10:50 - 009711616 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 004307968 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 001866272 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 000249856 _____ (Gracenote, Inc.) C:\Windows\system32\gnsdk_fp.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 000005632 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2019-11-13 10:50 - 2019-11-13 10:50 - 000005632 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2019-11-13 10:50 - 2019-11-13 10:50 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2019-11-13 10:49 - 2019-11-13 10:49 - 019849216 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 018020352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 007015936 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 006232576 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 005914112 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 005763848 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 003487232 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 002864640 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 002399232 _____ (Microsoft Corporation) C:\Windows\system32\AcGenral.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 001312256 _____ (Microsoft Corporation) C:\Windows\system32\msjet40.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 001156608 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000954368 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2019-11-13 10:49 - 2019-11-13 10:49 - 000772608 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000706048 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000701440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Mirage.Internal.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000689664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000532480 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000487424 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.FileExplorer.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000429568 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000380928 _____ (Microsoft Corporation) C:\Windows\system32\AcLayers.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000327680 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000186880 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE
2019-11-13 10:49 - 2019-11-13 10:49 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000164864 _____ (Microsoft Corporation) C:\Windows\system32\wscinterop.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\DiagSvc.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000117760 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2019-11-13 10:49 - 2019-11-13 10:49 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\AcXtrnal.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000067584 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2019-11-13 10:49 - 2019-11-13 10:49 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000059392 _____ (Microsoft Corporation) C:\Windows\system32\reg.exe
2019-11-13 10:49 - 2019-11-13 10:49 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000035328 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe
2019-11-13 10:49 - 2019-11-13 10:49 - 000026624 _____ (Microsoft Corporation) C:\Windows\system32\posetup.dll
2019-11-13 10:49 - 2019-11-13 10:49 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 007067960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 006521768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 006082808 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 004755456 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 003560960 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 003129856 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 003037184 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002995712 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002800640 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 002791424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002712080 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 002586816 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002576384 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002562048 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002440704 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002373120 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002305536 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002258848 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002235912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 002204176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 002073200 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 002059264 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 001909248 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001793024 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001691648 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001613312 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001539672 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001473848 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001429096 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001401856 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001394776 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-11-13 10:48 - 2019-11-13 10:48 - 001133056 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 001077424 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 001066496 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 001017680 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000892696 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000822072 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000787672 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000779776 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000768528 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000684544 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000679152 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000673664 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000669696 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000669352 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000627000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000608256 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000607544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000540472 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000526136 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000481792 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000477184 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000472576 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000469504 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000453632 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000452920 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000421888 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000415768 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000415544 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000413184 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000411648 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000404904 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000398864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000391480 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000382976 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000380944 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000374800 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000354816 _____ (Microsoft Corporation) C:\Windows\system32\Magnify.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000351232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cldflt.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000347136 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000336384 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000332288 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000331064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2019-11-13 10:48 - 2019-11-13 10:48 - 000327680 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000307712 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.th.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000299520 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000283136 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000271872 _____ (Microsoft Corporation) C:\Windows\system32\AppLockerCSP.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000265744 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000251904 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000247296 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SpeechPrivacy.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000199480 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000193800 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000193552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000189440 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000177152 _____ (Microsoft Corporation) C:\Windows\system32\wersvc.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000162856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000162816 _____ (Microsoft Corporation) C:\Windows\system32\wincredui.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000162304 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000160768 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000150528 _____ (Microsoft Corporation) C:\Windows\system32\dmvdsitf.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000144896 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000138552 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000136536 _____ (Microsoft Corporation) C:\Windows\system32\omadmapi.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\srpapi.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\fwbase.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000105592 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000099328 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\Utilman.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\EaseOfAccessDialog.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000086056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000085008 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000079360 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000066048 _____ (Microsoft Corporation) C:\Windows\system32\AtBroker.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000061240 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\CustomInstallExec.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000049152 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000042792 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000039936 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000031032 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000028344 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000020992 _____ (Microsoft Corporation) C:\Windows\system32\appidtel.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000020352 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\KBDJPN.DLL
2019-11-13 10:48 - 2019-11-13 10:48 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\applockerfltr.sys
2019-11-13 10:48 - 2019-11-13 10:48 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\KBDKOR.DLL
2019-11-13 10:48 - 2019-11-13 10:48 - 000011776 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\pacjsworker.exe
2019-11-13 10:48 - 2019-11-13 10:48 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tier2punctuations.dll
2019-11-13 10:48 - 2019-11-13 10:48 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 014816256 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 005943296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 005112320 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 004867608 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 004572224 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 004150272 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AI.MachineLearning.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 003967920 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 003742544 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 002763576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 001916984 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 001533952 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 001497600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 001451520 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 001348096 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 001154656 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 001091584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000896616 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000784384 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000741136 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000700416 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000689976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000586240 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000523776 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000506232 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000504848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000492032 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntime.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000487936 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000483328 _____ (Microsoft Corporation) C:\Windows\system32\agentactivationruntimewindows.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000466944 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000375720 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000363008 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Bluetooth.UserService.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000350208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000344376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000340480 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000274432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\MbbCx.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000264440 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000251512 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000239928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000202240 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000196096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000195072 _____ (Microsoft Corporation) C:\Windows\system32\WpcTok.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_CapabilityAccess.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000162320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spacedump.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000143872 _____ (Microsoft Corporation) C:\Windows\system32\SpatialAudioLicenseSrv.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\AarSvc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\dssvc.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000113152 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\UtcDecoderHost.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\ApplicationControlCSP.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000092672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthenum.sys
2019-11-13 10:47 - 2019-11-13 10:47 - 000082944 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000079872 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000073024 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BTHUSB.SYS
2019-11-13 10:47 - 2019-11-13 10:47 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\ApiSetHost.AppExecutionAlias.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000045392 _____ (Microsoft Corporation) C:\Windows\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\audioresourceregistrar.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000033280 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthMini.SYS
2019-11-13 10:47 - 2019-11-13 10:47 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\autopilotdiag.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\wscisvif.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\iscsilog.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\wscproxystub.dll
2019-11-13 10:47 - 2019-11-13 10:47 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\dstokenclean.exe
2019-11-13 10:47 - 2019-11-13 10:47 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\wscadminui.exe
2019-11-13 10:20 - 2019-10-17 02:01 - 000390656 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2019-11-08 13:10 - 2019-11-08 14:43 - 000000000 ____D C:\Users\A.C\AppData\Local\Research In Motion
2019-11-08 13:08 - 2019-11-08 13:08 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_RimSerial_01007.Wdf
2019-11-08 13:08 - 2012-12-10 15:48 - 000035840 _____ (Research in Motion Ltd) C:\Windows\system32\Drivers\RimSerial.sys
2019-11-08 13:05 - 2019-11-08 14:43 - 000000000 ____D C:\Program Files\Common Files\XCPCSync.OEM
2019-11-08 13:05 - 2019-11-08 14:43 - 000000000 ____D C:\Program Files\Common Files\Research In Motion
2019-11-08 12:32 - 2019-11-08 12:32 - 000000000 ____D C:\ProgramData\SP_FT_Logs
2019-11-04 11:23 - 2019-11-04 11:23 - 000094966 _____ C:\Users\A.C\Desktop\Banco Caroní, Sistema de Banca por Internet.pdf
2019-11-01 11:59 - 2019-11-04 06:00 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-10-24 22:28 - 2019-11-09 15:23 - 000061760 _____ (Wellbia.com Co., Ltd.) C:\Windows\xhunter1.sys
2019-10-24 22:03 - 2019-10-24 22:03 - 000000000 ____D C:\Game
2019-10-24 20:20 - 2019-10-24 20:20 - 000000000 ____D C:\Users\A.C\Desktop\Nueva carpeta
2019-10-24 17:51 - 2019-10-24 17:51 - 000000000 ____D C:\Users\A.C\AppData\Local\ElevatedDiagnostics
2019-10-23 22:34 - 2019-10-23 22:34 - 000000000 ____D C:\Users\A.C\AppData\Local\VS Revo Group
2019-10-23 22:34 - 2019-10-23 22:34 - 000000000 ____D C:\ProgramData\VS Revo Group
2019-10-23 22:34 - 2019-10-23 22:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2019-10-23 22:34 - 2016-12-16 08:53 - 000036376 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2019-10-23 22:33 - 2019-10-23 22:33 - 000000000 ____D C:\Program Files\VS Revo Group
2019-10-23 21:45 - 2019-10-23 21:45 - 000000212 _____ C:\Users\A.C\Desktop\Counter-Strike.url

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-11-22 16:38 - 2019-09-05 10:07 - 000000000 ____D C:\Users\A.C\AppData\LocalLow\Mozilla
2019-11-22 16:21 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\AppReadiness
2019-11-22 16:21 - 2019-03-18 22:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-11-22 16:07 - 2019-10-10 10:56 - 000000000 ____D C:\Program Files\Steam
2019-11-22 16:07 - 2019-10-10 10:56 - 000000000 ____D C:\Program Files\Common Files\Steam
2019-11-22 16:06 - 2019-09-04 18:49 - 000000000 ____D C:\Users\A.C\AppData\Roaming\Telegram Desktop
2019-11-22 16:06 - 2019-09-04 15:31 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-11-22 16:05 - 2019-03-18 22:35 - 000524288 _____ C:\Windows\system32\config\BBI
2019-11-22 15:37 - 2019-09-04 18:47 - 000001168 _____ C:\Users\A.C\Desktop\Nuevo documento de texto.txt
2019-11-22 13:40 - 2019-09-04 15:30 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-11-22 12:35 - 2019-09-14 15:17 - 000000000 ____D C:\Users\A.C\AppData\Roaming\AIMP
2019-11-21 20:03 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\system32\NDF
2019-11-21 18:37 - 2019-09-05 19:54 - 000000514 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2019-11-21 12:19 - 2019-09-05 09:55 - 000000000 ____D C:\Users\A.C\AppData\Roaming\uTorrent
2019-11-21 11:44 - 2019-03-18 22:46 - 000000000 ___HD C:\Program Files\WindowsApps
2019-11-21 11:35 - 2019-09-05 09:56 - 000000000 ____D C:\Users\A.C\AppData\Local\BitTorrentHelper
2019-11-20 23:23 - 2019-09-04 16:19 - 000000000 ____D C:\Users\A.C
2019-11-20 17:32 - 2019-09-04 17:09 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-11-19 14:50 - 2019-09-04 16:43 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-11-19 13:50 - 2019-09-08 19:29 - 000000000 ____D C:\Users\A.C\AppData\Local\JDownloader 2.0
2019-11-19 13:41 - 2019-09-04 23:20 - 000002362 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brave.lnk
2019-11-18 08:41 - 2019-09-16 13:28 - 000000008 __RSH C:\ProgramData\ntuser.pol
2019-11-18 08:36 - 2019-03-18 22:46 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-11-17 23:19 - 2019-09-05 16:42 - 000000216 _____ C:\Users\A.C\AppData\Local\Lockdir6
2019-11-17 14:52 - 2019-03-18 22:44 - 000000000 ____D C:\Windows\INF
2019-11-15 12:45 - 2019-09-04 17:02 - 000000000 ____D C:\Users\A.C\AppData\Local\PlaceholderTileLogoFolder
2019-11-14 15:34 - 2019-03-18 22:35 - 000032768 _____ C:\Windows\system32\config\ELAM
2019-11-14 10:11 - 2019-09-06 17:14 - 000000000 ____D C:\Users\A.C\AppData\Local\ESET
2019-11-14 00:08 - 2019-03-18 22:35 - 000000000 ____D C:\Windows\CbsTemp
2019-11-13 22:12 - 2019-03-18 22:46 - 000000000 ___HD C:\Windows\ELAMBKUP
2019-11-13 11:38 - 2019-09-04 15:43 - 000005810 _____ C:\Windows\system32\PerfStringBackup.INI
2019-11-13 11:38 - 2019-03-19 03:13 - 001039328 _____ C:\Windows\system32\perfh00A.dat
2019-11-13 11:38 - 2019-03-19 03:13 - 000228408 _____ C:\Windows\system32\perfc00A.dat
2019-11-13 11:26 - 2019-09-04 16:43 - 000000000 ___RD C:\Users\A.C\3D Objects
2019-11-13 11:21 - 2019-09-04 15:30 - 003926776 _____ C:\Windows\system32\FNTCACHE.DAT
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ___RD C:\Windows\PrintDialog
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\SystemResources
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\system32\appraiser
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\ShellExperiences
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\ShellComponents
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\PolicyDefinitions
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\DiagTrack
2019-11-13 11:16 - 2019-03-18 22:46 - 000000000 ____D C:\Windows\bcastdvr
2019-11-13 11:12 - 2019-09-05 18:08 - 000000000 ____D C:\Windows\system32\MRT
2019-11-13 11:04 - 2019-09-05 18:07 - 125283176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-11-11 22:43 - 2019-09-04 21:03 - 000000000 ____D C:\Users\A.C\AppData\Roaming\MPC-HC
2019-11-11 19:13 - 2019-09-05 16:28 - 000000000 ____D C:\Program Files\Glary Utilities 5
2019-11-11 16:53 - 2019-09-04 16:43 - 000000000 ____D C:\Users\A.C\AppData\Local\Packages
2019-11-08 14:44 - 2019-09-05 08:59 - 000000000 ___HD C:\Program Files\InstallShield Installation Information
2019-11-07 23:08 - 2019-09-04 22:11 - 000000000 ____D C:\Users\A.C\Downloads\Telegram Desktop
2019-11-04 21:24 - 2019-09-04 17:05 - 000003610 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2019-11-04 21:24 - 2019-09-04 17:05 - 000003486 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2019-11-04 21:23 - 2019-09-04 17:05 - 000000000 ____D C:\Program Files\Google
2019-11-04 06:00 - 2019-09-05 10:06 - 000000000 ____D C:\Program Files\Mozilla Maintenance Service
2019-11-02 18:12 - 2019-09-04 17:01 - 000000000 ____D C:\ProgramData\Packages
2019-11-02 06:16 - 2019-09-04 16:48 - 000003376 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4250646496-1170587832-3190748366-1001
2019-11-02 06:16 - 2019-09-04 16:48 - 000000000 ___RD C:\Users\A.C\OneDrive
2019-11-02 06:16 - 2019-09-04 16:19 - 000002395 _____ C:\Users\A.C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-11-01 14:56 - 2019-09-05 10:06 - 000001190 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-10-23 21:45 - 2019-10-10 11:18 - 000000000 ____D C:\Users\A.C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam

==================== Files in the root of some directories ========

2019-11-08 13:10 - 2019-11-08 13:33 - 000000077 _____ () C:\Users\A.C\AppData\Roaming\Rim.Desktop.Exception.log
2019-11-08 13:07 - 2019-11-08 14:42 - 000001925 _____ () C:\Users\A.C\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2019-11-08 13:10 - 2019-11-08 13:33 - 000000077 _____ () C:\Users\A.C\AppData\Roaming\Rim.DesktopHelper.Exception.log
2019-10-04 09:53 - 2019-10-04 09:53 - 000000001 _____ () C:\Users\A.C\AppData\Local\llftool.4.40.agreement
2019-09-05 16:42 - 2019-11-17 23:19 - 000000216 _____ () C:\Users\A.C\AppData\Local\Lockdir6

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-11-2019
Ran by A.C (22-11-2019 16:43:36)
Running from C:\Users\A.C\Desktop
Microsoft Windows 10 Home Version 1909 18363.476 (X86) (2019-09-04 19:42:11)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

A.C (S-1-5-21-4250646496-1170587832-3190748366-1001 - Administrator - Enabled) => C:\Users\A.C
Administrador (S-1-5-21-4250646496-1170587832-3190748366-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4250646496-1170587832-3190748366-503 - Limited - Disabled)
Invitado (S-1-5-21-4250646496-1170587832-3190748366-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4250646496-1170587832-3190748366-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: ESET Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}
FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\uTorrent) (Version: 3.5.5.45395 - BitTorrent Inc.)
Adobe Photoshop CC (HKLM\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
AIMP (HKLM\...\AIMP) (Version: v4.60.2146, 28.08.2019 - AIMP DevTeam)
Brave (HKLM\...\BraveSoftware Brave-Browser) (Version: 78.1.0.1 - Brave Software Inc)
Chrome Remote Desktop Host (HKLM\...\{738276A2-92E7-4313-9E4D-D090F7DA98EC}) (Version: 79.0.3945.10 - Google Inc.)
FormatFactory 4.6.1.0 (HKLM\...\FormatFactory) (Version: 4.6.1.0 - Free Time)
Glary Utilities 5.127 (HKLM\...\Glary Utilities 5) (Version: 5.127.0.152 - Glarysoft Ltd)
Google Chrome (HKLM\...\Google Chrome) (Version: 78.0.3904.108 - Google LLC)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.341 - Google LLC) Hidden
Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2413 - Intel Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
K-Lite Codec Pack 15.2.0 Full (32-bit) (HKLM\...\KLiteCodecPack_is1) (Version: 15.2.0 - KLCP)
LibreOffice 6.3.1.2 (HKLM\...\{953D746F-FA08-462B-A66E-7A7FFF322580}) (Version: 6.3.1.2 - The Document Foundation)
MEGAsync (HKLM\...\MEGAsync) (Version:  - Mega Limited)
Microsoft Edge Beta (HKLM\...\Microsoft Edge Beta) (Version: 79.0.309.25 - Microsoft Corporation)
Microsoft Edge Update (HKLM\...\Microsoft Edge Update) (Version: 1.3.117.13 - )
Microsoft OneDrive (HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\OneDriveSetup.exe) (Version: 19.174.0902.0013 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Mozilla Firefox 70.0.1 (x86 es-ES) (HKLM\...\Mozilla Firefox 70.0.1 (x86 es-ES)) (Version: 70.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 70.0.1.7242 - Mozilla)
Paquete de controladores de Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (01/27/2014 9.0.0000.00000) (HKLM\...\9CA77E2A8332A0824C54DA611BBE4CA24AB1F750) (Version: 01/27/2014 9.0.0000.00000 - Google, Inc.)
PDF Settings CC (HKLM\...\{1FBAE18D-4DE4-47AA-83EC-D1B046F262DC}) (Version: 12.0 - Adobe Systems Incorporated) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8186 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.8 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.8 - VS Revo Group, Ltd.)
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Telegram Desktop version 1.8.15 (HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.8.15 - Telegram FZ-LLC)
Voobly Game Data (HKLM\...\Voobly_is1) (Version: Voobly Game Datas - Voobly)
WinRAR 5.71 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)

Packages:
=========
Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12228.20206.0_x86__8wekyb3d8bbwe [2019-11-20] (Microsoft Corporation) [MS Ad]
HP Scan and Capture -> C:\Program Files\WindowsApps\AD2F1837.HPScanandCapture_40.0.245.0_x86__v10z8vjag6ke6 [2019-09-19] (Hewlett-Packard Company)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_105.1.623.0_x86__v10z8vjag6ke6 [2019-11-15] (HP Inc.)
Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_41.1788.50991.0_x86__8xx8rvfyw5nnt [2019-09-18] (Instagram)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-09-05] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.11052.0_x86__8wekyb3d8bbwe [2019-11-08] (Microsoft Studios) [MS Ad]
MSN El Tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.33.13094.0_x86__8wekyb3d8bbwe [2019-11-20] (Microsoft Corporation) [MS Ad]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu32.dll [2019-09-14] (Artem Izmaylov -> AIMP DevTeam)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers1: [FormatFactoryShell] -> {A3888923-CFD3-4A6B-89BF-08E6B95716E8} => C:\Program Files\FormatFactory\ShellEx_105.dll [2019-04-22] (Free Time) [File not signed]
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files\Glary Utilities 5\ContextHandler.dll [2019-03-10] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files\Glary Utilities 5\ContextHandler.dll [2019-03-10] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-11-13] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files\AIMP\System\aimp_menu32.dll [2019-09-14] (Artem Izmaylov -> AIMP DevTeam)
ContextMenuHandlers4: [FormatFactoryShell] -> {A3888923-CFD3-4A6B-89BF-08E6B95716E8} => C:\Program Files\FormatFactory\ShellEx_105.dll [2019-04-22] (Free Time) [File not signed]
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\A.C\AppData\Local\MEGAsync\ShellExtX32.dll [2019-09-17] (Mega Limited -> )
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-06-03] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files\Glary Utilities 5\ContextHandler.dll [2019-03-10] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-11-13] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2016-12-15] (VS Revo Group -> VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.IV41] => C:\Windows\system32\IR41_32.AX [9216 2019-03-18] (Microsoft Windows -> Microsoft Corporation)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\A.C\AppData\Local\Microsoft\Edge Beta\User Data\Default\Microsoft Edge Beta.lnk -> C:\Program Files\Microsoft\Edge Beta\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default
ShortcutWithArgument: C:\Users\A.C\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Edge Beta.lnk -> C:\Program Files\Microsoft\Edge Beta\Application\msedge.exe (Microsoft Corporation) -> --profile-directory=Default

==================== Loaded Modules (Whitelisted) =============

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-03-18 22:43 - 2019-11-18 08:36 - 000000027 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1       localhost

2019-09-05 19:54 - 2019-11-21 18:37 - 000000514 _____ C:\Windows\system32\drivers\etc\hosts.ics

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\Control Panel\Desktop\\Wallpaper -> D:\Documentos\Jose\Fondos\beautiful_beach_waves-wallpaper-1440x900.jpg
DNS Servers: 200.109.78.12 - 200.44.32.12
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "AdobeCEPServiceManager"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\StartupApproved\Run: => "GUDelayStartup"
HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\...\StartupApproved\Run: => "Voobly"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{91676BF4-5961-4454-B652-EFD72DE554D0}] => (Allow) C:\Program Files\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{E9F202F8-3E16-4309-BF0F-A36815767939}] => (Allow) C:\Program Files\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{6CC23CFE-746D-47C5-941C-EE3A91B12060}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{77E69DE0-E56F-427D-B9C5-446B3246D695}] => (Allow) C:\Program Files\Steam\bin\cef\cef.win7\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{5AEBF3BE-D6B8-4069-BF2F-1C3F2A2C5F91}] => (Allow) C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe (Brave Software, Inc. -> Brave Software, Inc.)
FirewallRules: [{DA0E7B0A-B91D-4954-9A3D-8C52723BC221}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{E937AB38-93F3-4067-A9A7-B24E7C90A933}] => (Allow) %systemroot%\system32\alg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{54AB38B5-33E2-4BF5-BC57-FE3FB5110D17}] => (Allow) C:\Program Files\Microsoft\Edge Beta\Application\msedge.exe (Microsoft Corporation -> Microsoft Corporation)

==================== Restore Points =========================

06-11-2019 16:44:51 Windows Update
08-11-2019 12:28:32 Installed BLU Phone Drivers
08-11-2019 12:29:52 Installed BLU Phone Drivers
08-11-2019 13:04:23 Installed BlackBerry Desktop Software.
08-11-2019 13:34:40 Installed BlackBerry 9000.
08-11-2019 14:43:53 Removed BLU Phone Drivers
13-11-2019 10:19:03 Windows Update
14-11-2019 00:07:45 Instalador de Módulos de Windows

==================== Faulty Device Manager Devices ============

Name: Realtek PCI GbE Family Controller
Description: Realtek PCI GbE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: rt640x86
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: ========================

Application errors:
==================
Error: (11/21/2019 01:43:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: GLCRIconSvc.exe, versión: 1.0.0.0, marca de tiempo: 0x5a25299e
Nombre del módulo con errores: CFGMGR32.dll, versión: 10.0.18362.387, marca de tiempo: 0xe4afe536
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0000b79d
Identificador del proceso con errores: 0x8ac
Hora de inicio de la aplicación con errores: 0x01d5a06d6e255698
Ruta de acceso de la aplicación con errores: C:\Windows\System32\DriverStore\FileRepository\genestor.inf_x86_72d3ca414e5dcd4d\GLCRIconSvc.exe
Ruta de acceso del módulo con errores: C:\Windows\System32\CFGMGR32.dll
Identificador del informe: a896c876-62e8-4128-bcf0-d3346f43e155
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (11/21/2019 09:11:56 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al llamar a la rutina CoCreateInstance. HR = 0x8007045b, Se está cerrando el sistema.
.

Error: (11/21/2019 09:11:56 AM) (Source: VSS) (EventID: 13) (User: )
Description: Información del Servicio de instantáneas de volumen: el servidor COM con CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} y el nombre CEventSystem no puede iniciarse. [0x8007045b, Se está cerrando el sistema.
]

Error: (11/20/2019 01:43:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: GLCRIconSvc.exe, versión: 1.0.0.0, marca de tiempo: 0x5a25299e
Nombre del módulo con errores: CFGMGR32.dll, versión: 10.0.18362.387, marca de tiempo: 0xe4afe536
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0000b79d
Identificador del proceso con errores: 0x890
Hora de inicio de la aplicación con errores: 0x01d59fc7e690b3ec
Ruta de acceso de la aplicación con errores: C:\Windows\System32\DriverStore\FileRepository\genestor.inf_x86_72d3ca414e5dcd4d\GLCRIconSvc.exe
Ruta de acceso del módulo con errores: C:\Windows\System32\CFGMGR32.dll
Identificador del informe: 1a0bfcee-6437-44e4-82c0-2ca6de4567c3
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (11/20/2019 01:26:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: svchost.exe, versión: 10.0.18362.1, marca de tiempo: 0x68f17365
Nombre del módulo con errores: wpnuserservice.dll, versión: 10.0.18362.1, marca de tiempo: 0x679bdb1b
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x00008771
Identificador del proceso con errores: 0xd88
Hora de inicio de la aplicación con errores: 0x01d59f95c880286a
Ruta de acceso de la aplicación con errores: C:\Windows\system32\svchost.exe
Ruta de acceso del módulo con errores: c:\windows\system32\wpnuserservice.dll
Identificador del informe: cad642cd-3305-454a-9efb-2030d4a2543c
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (11/20/2019 10:55:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: GLCRIconSvc.exe, versión: 1.0.0.0, marca de tiempo: 0x5a25299e
Nombre del módulo con errores: CFGMGR32.dll, versión: 10.0.18362.387, marca de tiempo: 0xe4afe536
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0000b79d
Identificador del proceso con errores: 0x8a0
Hora de inicio de la aplicación con errores: 0x01d59f2af5948646
Ruta de acceso de la aplicación con errores: C:\Windows\System32\DriverStore\FileRepository\genestor.inf_x86_72d3ca414e5dcd4d\GLCRIconSvc.exe
Ruta de acceso del módulo con errores: C:\Windows\System32\CFGMGR32.dll
Identificador del informe: bf1922f2-c192-4007-bb17-57584ff42d46
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (11/19/2019 06:43:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: svchost.exe_WpnUserService, versión: 10.0.18362.1, marca de tiempo: 0x68f17365
Nombre del módulo con errores: wpnuserservice.dll, versión: 10.0.18362.1, marca de tiempo: 0x679bdb1b
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x00008771
Identificador del proceso con errores: 0x1fd0
Hora de inicio de la aplicación con errores: 0x01d59ef5db0d7405
Ruta de acceso de la aplicación con errores: C:\Windows\system32\svchost.exe
Ruta de acceso del módulo con errores: c:\windows\system32\wpnuserservice.dll
Identificador del informe: 86a15376-cb1b-4dc3-bb1c-813f34b216e4
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (11/19/2019 12:39:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: GLCRIconSvc.exe, versión: 1.0.0.0, marca de tiempo: 0x5a25299e
Nombre del módulo con errores: CFGMGR32.dll, versión: 10.0.18362.387, marca de tiempo: 0xe4afe536
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0000b79d
Identificador del proceso con errores: 0x87c
Hora de inicio de la aplicación con errores: 0x01d59e162ccd7fd5
Ruta de acceso de la aplicación con errores: C:\Windows\System32\DriverStore\FileRepository\genestor.inf_x86_72d3ca414e5dcd4d\GLCRIconSvc.exe
Ruta de acceso del módulo con errores: C:\Windows\System32\CFGMGR32.dll
Identificador del informe: 2b70dab5-7088-4982-9468-e35abb9f302c
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:


System errors:
=============
Error: (11/22/2019 04:05:31 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-DGTGDVM)
Description: El servidor {F9717507-6651-4EDB-BFF7-AE615179BCCF} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (11/22/2019 04:05:25 PM) (Source: DCOM) (EventID: 10005) (User: DESKTOP-DGTGDVM)
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "No disponible" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}


Windows Defender:
===================================
Date: 2019-11-22 16:36:32.719
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
Nombre: Trojan:Win32/Occamy.C
Id.: 2147726780
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: file:_C:\Users\A.C\AppData\Local\BraveSoftware\Brave-Browser\User Data\Default\Cache\f_0039be
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Sistema
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: Unknown
Versión de inteligencia de seguridad: AV: 1.303.617.0, AS: 1.303.617.0, NIS: 1.303.617.0
Versión de motor: AM: 1.1.16400.2, NIS: 1.1.16400.2

Date: 2019-09-06 09:27:23.648
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {7C6B3881-CDBA-4F77-94AD-4A066E6257F1}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2019-09-06 09:15:22.373
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {0BF65512-CBCB-4127-9944-3BE1335AEE48}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2019-09-06 09:02:15.464
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {F9309218-2F95-4DCB-8703-6C307EDA4242}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2019-09-06 08:27:27.102
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {AEA536B6-297C-403F-91BC-2717B2C546F8}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2019-09-06 13:03:48.158
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.301.623.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor: 
Versión anterior del motor: 1.1.16300.1
Código de error: 0x80070643
Descripción del error: Error irrecuperable durante la instalación. 

CodeIntegrity:
===================================

Date: 2019-11-22 13:32:04.633
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 13:32:04.611
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 13:32:04.360
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 03:13:42.356
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 03:13:42.343
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 03:13:42.261
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 03:13:42.252
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

Date: 2019-11-22 03:13:42.001
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume3\Program Files\ESET\ESET Security\eamsi.dll that did not meet the Windows signing level requirements.

==================== Memory info =========================== 

BIOS: American Megatrends Inc. 080015 02/16/2011
Motherboard: langchao IPM41-D3
Processor: Pentium(R) Dual-Core CPU E5800 @ 3.20GHz
Percentage of memory in use: 91%
Total physical RAM: 1917.24 MB
Available physical RAM: 162.59 MB
Total Virtual: 3917.24 MB
Available Virtual: 959.24 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:297.52 GB) (Free:237.52 GB) NTFS
Drive d: () (Fixed) (Total:298.09 GB) (Free:198.29 GB) NTFS
Drive e: (Archivos) (Fixed) (Total:465.76 GB) (Free:306.74 GB) NTFS

\\?\Volume{000df857-0000-0000-0000-100000000000}\ (Reservado para el sistema) (Fixed) (Total:0.57 GB) (Free:0.21 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 66192377)
Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 0007C321)
Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)

==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 000DF857)
Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=297.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

Hola @jrac

Mientras analizo los reportes, cada tanto revisa las conexiones con TCPView.

Mas tarde te dejo los pasos a seguir.

Salu2

1 me gusta

Hola @jrac

Ahora si, consulta utilizas el Edge Beta?


Como aun quedaron muchos restos de Eset realizas lo siguiente:

1.- Muy Importante >>> Realizar una copia de Seguridad de su Registro.

  • Descarga DelFix en el escritorio de Windows.
  • Clic Derecho, “Ejecutar como Administrador”.
  • En la ventana principal, marca solamente la casilla “Create Registry Backup”.
  • Clic en Run.

Al terminar se abrirá un reporte llamado DelFix.txt, guárdelo por si fuera necesario y cierre la herramienta…

2.- Desactiva Temporalmente tu antivirus. en tu caso el Windows Defender que se activa al desinstalar Eset.

3.- Abre un nuevo archivo Notepad/Bloc de Notas y copia y pega este contenido:

Start
CloseProcesses:
CreateRestorePoint:
S3 ekrnEpfw; "C:\Program Files\ESET\ESET Security\ekrn.exe" [X]
C:\Program Files\ESET
019-11-22 15:28 - 2019-11-22 15:29 - 001090168 _____ (ESET) C:\Users\A.C\Desktop\ESETUninstaller.exe
2019-11-14 10:11 - 2019-09-06 17:14 - 000000000 ____D C:\Users\A.C\AppData\Local\ESET
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: ESET Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}
FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
  • Lo guardas bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

Nota: Es necesario que el ejecutable Frst.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajara.

  • Ejecutas Frst.exe.
  • Presionas el botón Fix y aguardas a que termine.
  • La Herramienta guardara el reporte en tu escritorio (Fixlog.txt).
  • Lo pegas en tu próxima respuesta.

Al reiniciar, vigilas tu conexión como ya sabes, y nos comentas si persiste el problema, así ya con el ordenador sin bloqueos posibles buscaremos la manera de bloquear tus puertos.

Salu2.

Hola @SanMar

Lo instale ayer para probar. (Es Chrome con los servicios de Microsoft).

Disculpa la demora… Mi proveedor de Internet tuvo una falla y casi medio país se quedo sin Internet por 13 Horas. “Excelente Servicio” :rage:


Fix result of Farbar Recovery Scan Tool (x86) Version: 23-11-2019
Ran by A.C (23-11-2019 19:40:07) Run:2
Running from C:\Users\A.C\Desktop
Loaded Profiles: A.C (Available Profiles: A.C)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
S3 ekrnEpfw; "C:\Program Files\ESET\ESET Security\ekrn.exe" [X]
C:\Program Files\ESET
019-11-22 15:28 - 2019-11-22 15:29 - 001090168 _____ (ESET) C:\Users\A.C\Desktop\ESETUninstaller.exe
2019-11-14 10:11 - 2019-09-06 17:14 - 000000000 ____D C:\Users\A.C\AppData\Local\ESET
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AV: ESET Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}
FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
*****************

Processes closed successfully.
Restore point was successfully created.
ekrnEpfw => service not found.
"C:\Program Files\ESET" => not found
019-11-22 15:28 - 2019-11-22 15:29 - 001090168 _____ (ESET) C:\Users\A.C\Desktop\ESETUninstaller.exe => Error: No automatic fix found for this entry.
C:\Users\A.C\AppData\Local\ESET => moved successfully
"AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}" => removed successfully.
"AV: ESET Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}" => removed successfully.
"FW: ESET Firewall (Enabled) {B066057A-E576-007C-D591-56C163D3B33B}" => removed successfully.
"FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}" => removed successfully.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ESET Security Shell => removed successfully.
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\ESET Security Shell => removed successfully.
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\ESET Security Shell => removed successfully.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully.

========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


Adaptador de Ethernet Ethernet:

   Sufijo DNS espec¡fico para la conexi¢n. . : cantv.net
   V¡nculo: direcci¢n IPv6 local. . . : fe80::24f6:5f88:5f94:764e%3
   Direcci¢n IPv4. . . . . . . . . . . . . . : 186.89.248.194
   M scara de subred . . . . . . . . . . . . : 255.255.224.0
   Puerta de enlace predeterminada . . . . . : 186.89.224.1

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

{80272EFD-A11D-49D1-BAF5-84AA3243A56F} canceled.
{B7F2BD35-3A5F-48F3-BFAE-F89B793EEA06} canceled.
{433C686A-8A65-4553-9FFF-3C1188BF9BB2} canceled.
3 out of 3 jobs canceled.

========= End of CMD: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= End of CMD: =========


========= netsh int ipv4 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\S-1-5-21-4250646496-1170587832-3190748366-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully.


========= End of RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10772480 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 103808264 B
Java, Flash, Steam htmlcache => 23205217 B
Windows/system/drivers => 92319 B
Edge => 69102 B
Chrome => 842948 B
Firefox => 28840631 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
LocalService => 37548 B
NetworkService => 70302 B
A.C => 13255581 B

RecycleBin => 5978 B
EmptyTemp: => 172.6 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:42:39 ====

Hola @jrac

Ya se eliminaron los restos.

Pero no has comentado nada de tu conexión, sigue enviando paquetes por el puerto 445???

Salu2

Hola @SanMar

Disculpa. Desde que se elimino Eset dejo de enviar paquetes.

Cada cierto tiempo estoy revisando la conexiones con TCPView y viendo el proceso System con el Administrador de Tareas. No veo nada fuera de lo común.

El problema era el ESET??

Saludos.

Hola @jrac

Pues parece que si, por ello te pregunte si era original y de donde lo habas descargado…:thinking:

Por el momento ya sabes como revisar tu equipo con TCPView (es muy útil para estos casos) y con los comandos de Netstat que usamos puedes ver los ejecutables asociados.

Así que por lo pronto si estas de acuerdo damos por resuelto el tema, cualquier problema sobre este mismo inconveniente, me mandas en MP y lo re-abriremos.


Para eliminar las herramientas utilizadas:

Descargas/Ejecutas >> Delfix, desde tu escritorio.

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7 /8 /10,presiona clic derecho y selecciona >> “Ejecutar como Administrador”)
  • Marca las casilla Remove disinfection tools y Purgue Sistem Restore
  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

Nos comentas.

Salu2.

1 me gusta

Hola @SanMar

Desde la web de Eset y la Licencia de prueba. No usaba programas ni nada para activarlo.

Si… Gracias por la herramienta no la conocía.

Ok excelente. Mil gracias de verdad :bowing_man: :star_struck:. Sin tu ayuda creo que hubiese formateado mi pc :smile:

.

No pediste el reporte pero igual lo dejo por si acaso.


# DelFix v1.013 - Logfile created 24/11/2019 at 23:46:28
# Updated 17/04/2016 by Xplode
# Username : A.C - DESKTOP-DGTGDVM
# Operating System : Windows 10 Home  (32 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\A.C\Desktop\FRST-OlderVersion
Deleted : C:\Users\A.C\Desktop\Addition.txt
Deleted : C:\Users\A.C\Desktop\Fixlog.txt
Deleted : C:\Users\A.C\Desktop\FRST.exe
Deleted : C:\Users\A.C\Desktop\FRST.txt

~ Cleaning system restore ...

Deleted : RP #33 [Punto de control programado | 11/22/2019 22:17:10]

New restore point created !

########## - EOF - ##########

Hola @jrac

Perfecto se eliminaron las herramientas correctamente…:+1:

Y si le colocabas Eset vuelta a el lio, no no mejor es siempre descubrir el problema cuando se puede obvio.:smiley:

Para otros problemas, ya sabes donde encontrarnos. :wink:

Tema Solucionado

Salu2.

1 me gusta