Go.Mail.ru

Buenas noches, esta tarde mi portátil se ha infectado con Go.Mail.ru. Una vez infectado no me permitía el acceso a las webs de antivirus para poder descargarme uno. He ido siguiendo pasos básicos que he leído en el foro y en otras webs para eliminarlo. Finalmente parece que lo conseguí ya que el Malwarebytes ya no me detecta nada, el antivirus tampoco y puedo acceder ya a las webs de cualquier antivirus. De todas formas me gustaría, si es posible, que alguien me indique algún programa de análisis para pegar un reporte aquí y que algún compañero del foro puede ojearlo.

Muchas gracias y enhorabuena por el foro

Buenas @borjaar

Por favor, realiza estos pasos :

:one: Desactiva temporalmente el Antivirus :arrow_forward: Cómo deshabilitar temporalmente su Antivirus, mientras estemos realizando TODOS los pasos.

Descargar en TU ESCRITORIO(y NO en otro lugar :face_with_monocle:)

:two: Farbar Recovery Scan Tool.-

  • Ejecuta FRST.exe.

  • En el mensaje de la ventana del Disclaimer, pulsamos Yes

  • En la ventana principal pulsamos en el botón Scan y esperamos a que concluya el proceso.

  • Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

:three: Poner los dos informes en tu próxima respuesta.

Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(mas de 50.000 caracteres aprox.).

Saludos, Javier.

Gracias por contestar tan rápido!


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 3-07-2019
Ran by borja (administrator) on LAPTOP-FLU41M84 (LENOVO 81DE) (08-07-2019 23:43:14)
Running from C:\Users\borja\Desktop
Loaded Profiles: borja (Available Profiles: borja)
Platform: Windows 10 Home Version 1803 17134.829 (X64) Language: Español (España, internacional)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19041.16510.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Adaware Software -> ) C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.1005.11662\AdAwareTray.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe
(Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrl.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDCtrlHelper.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDService.exe
(ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.) C:\Windows\System32\ETDTouch.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0a3294d3216a4a83\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch_comp.inf_amd64_deecec7d232ced2b\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\cui_dch_comp.inf_amd64_deecec7d232ced2b\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch_base.inf_amd64_4965439bad64e97e\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\iigd_dch_base.inf_amd64_4965439bad64e97e\IntelCpHeciSvc.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.0.52.0_x64__5grkq8ppsgwt4\VFS\ProgramFilesX64\Lenovo\LenovoUtility\utility.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\borja\AppData\Local\Microsoft\OneDrive\19.103.0527.0003\FileCoAuth.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\borja\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1906.3-0\NisSrv.exe
(Paito Anderson) [File not signed] C:\Users\borja\Downloads\Wallcat.exe
(Qualcomm Atheros -> Qualcomm Technologies Inc.) C:\Windows\System32\drivers\QcomWlanSrvx64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdAwareTray] => C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.1005.11662\AdAwareTray.exe [4742616 2019-02-13] (Adaware Software -> )
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22695280 2019-06-18] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --notification-launch-id=1|0|2|Default|0|chrome-extension://cfhdojbkjhnklbpkdaibdccddilifddb/|cfhdojbkjhnklbpkdaibdccddilifddb-e7b98bd0-509c-49d3-8564-983422ffca3b --flag-switches-begin --flag-switches-end --restore-last-session
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-21] (Google LLC -> Google LLC)
Startup: C:\Users\borja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wallcat.lnk [2019-02-12]
ShortcutTarget: Wallcat.lnk -> C:\Users\borja\Downloads\Wallcat.exe (Paito Anderson) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {06C92064-F67B-4388-9F07-298B8E4DE53A} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => %windir%\system32\sc.exe START ImControllerService
Task: {0868E948-640F-4986-89C8-0CBC70701D3F} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [152104 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {20295852-200D-4944-89BE-E74B2F634CFD} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler  /v start /t reg_dword /d 1 /f /reg:32
Task: {22964C23-C992-4A16-8F01-A25DC41BE3B6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-03-11] (Google Inc -> Google Inc.)
Task: {24C1C5B8-EF8B-4716-977C-572F9886054D} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\da0848ec-2584-4139-a628-cdc9c28eefa6 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {2AAFE484-90B5-4C76-9825-3C36737FE09B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {2E3FEEAD-E478-43EC-A228-4CF58116FB46} - System32\Tasks\RtHDVBg_LENOVO_DOLBYDRAGON => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1503584 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
Task: {2F96CCA3-8424-4448-9F0C-618C1C0ED937} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-03-11] (Google Inc -> Google Inc.)
Task: {54C6213B-6896-43A2-AE95-04E30EA3CEA3} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2208400 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {6340E932-B1EB-43B1-A1E4-9C1571B40C19} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-06-18] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {663FAA8B-6583-428A-8DE9-F6C4890EA7A8} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2314008 2019-06-04] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {6FF23AA3-EA2E-464F-8074-42570ECE08F2} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2248736 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {7977CF9E-621D-45D9-99FB-05D7FAAD4A76} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [152104 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {8A6197C6-9AC1-4BCE-B86B-BA0B2C88EA8F} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\31c2ea03-7d70-444d-b036-b93fde977795 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {97BBC3AD-E43F-499F-83AB-CC8C490AF2F1} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\2ed651c1-fcb1-48d5-bb3c-c39dac92dba3 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {9884E863-5A4F-4992-8EAB-5E5B52C67B91} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2208400 2019-07-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {9FD28BDA-C634-4E9E-ABF6-172D34944F79} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1503584 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
Task: {A5D4DD23-65FC-4360-A2C5-A248BE127491} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16667424 2019-06-18] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {B25B2BFA-D064-4516-8632-C4C99ADD6D20} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
Task: {B8652F02-4012-4A70-82F7-6D1C03257B79} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [26804232 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {B925A3CB-6C75-4D31-A7DF-0D6E7EBCC040} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\Windows\system32\ImController.InfInstaller.exe [54440 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {CDDD2452-B251-4DD4-A800-FB2DEAAE3FB0} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1503584 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}: [NameServer] 45.86.180.227,185.162.93.213,116.203.6.218,185.130.104.222
Tcpip\..\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}: [DhcpNameServer] 150.201.1.2
Tcpip\..\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}: [NameServer] 8.8.8.8,8.8.4.4,116.203.6.218,185.130.104.222
Tcpip\..\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
SearchScopes: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = 
SearchScopes: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001 -> {639673F9-AD4B-41E6-80A2-AB8CBF9E29F4} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-06-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-06-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-06-15] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-06-15] (Microsoft Corporation -> Microsoft Corporation)

Edge: 
======
Edge HomeButtonPage: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001 -> hxxps://www.google.es/
Edge Extension: (Traductor para Microsoft Edge) -> MicrosoftTranslate_MicrosoftTranslatorforMicrosoftEdge_8wekyb3d8bbwe => C:\Program Files\WindowsApps\Microsoft.TranslatorforMicrosoftEdge_0.91.51.0_neutral__8wekyb3d8bbwe [2019-03-13]

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.es/
CHR StartupUrls: Default -> "hxxps://www.google.es/"
CHR Profile: C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default [2019-07-08]
CHR Extension: (Presentaciones) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-03-11]
CHR Extension: (Documentos) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-03-11]
CHR Extension: (Google Drive) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-03-11]
CHR Extension: (YouTube) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-03-11]
CHR Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-06-18]
CHR Extension: (Alexa Traffic Rank) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel [2019-07-08]
CHR Extension: (Spotify - Music for every moment) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2019-06-18]
CHR Extension: (MozBar) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\eakacpaijcpapndcfffdgphdiccmpknp [2019-06-22]
CHR Extension: (Hojas de cálculo) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-03-11]
CHR Extension: (Edición de Office) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2019-06-18]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-06-18]
CHR Extension: (Keywords Everywhere - Keyword Tool) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbapdpeemoojbophdfndmlgdhppljgmp [2019-06-18]
CHR Extension: (SimilarWeb - Traffic Rank & Website Analysis) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoklmmgfnpapgjgcpechhaamimifchmp [2019-06-18]
CHR Extension: (Google Play Music) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2019-06-18]
CHR Extension: (Dropbox) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2019-06-18]
CHR Extension: (Evernote Web) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2019-06-18]
CHR Extension: (Yosemite) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldcmfdcmbmemodgapljjjceihmaljeii [2019-06-18]
CHR Extension: (TalentLMS) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpfainkhcagedicmgclllagojcminpkm [2019-06-18]
CHR Extension: (Google Play Books) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2019-06-18]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-03-11]
CHR Extension: (Outlook.com) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2019-06-18]
CHR Extension: (Gmail) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-18]
CHR Extension: (Chrome Media Router) - C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-18]
CHR Profile: C:\Users\borja\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-08]
CHR Profile: C:\Users\borja\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-08]
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 adawareantivirusservice; C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.1005.11662\AdAwareService.exe [587832 2019-02-13] (Adaware Software -> )
R2 AtherosSvc; C:\Windows\system32\DRIVERS\AdminService.exe [409176 2018-09-26] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11413600 2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
R2 Dolby DAX2 API Service; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [197120 2017-07-13] (Dolby Laboratories, Inc. -> Dolby Laboratories, Inc.)
R2 ETDService; C:\Windows\System32\ETDService.exe [249496 2019-01-31] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Windows\System32\Intel\iCLS Client\lib\SocketHeciServer.exe [780600 2018-10-02] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Windows\System32\Intel\iCLS Client\lib\TPMProvisioningService.exe [718656 2018-10-02] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_0a3294d3216a4a83\jhi_service.exe [578752 2018-11-13] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R2 QcomWlanSrv; C:\Windows\System32\drivers\QcomWlanSrvx64.exe [191440 2018-09-26] (Qualcomm Atheros -> Qualcomm Technologies Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [266080 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\NisSrv.exe [2455544 2019-07-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MsMpEng.exe [110104 2019-07-05] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\Windows\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\Windows\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 atc; C:\Windows\System32\DRIVERS\atc.sys [1380880 2018-11-17] (Bitdefender SRL -> BitDefender S.R.L. Bucharest, ROMANIA)
R1 bdfwfpf; C:\Program Files\adaware\adaware antivirus\AdAwareProxyEngine\1.0.0.8\bdfwfpf.sys [127312 2016-06-16] (Bitdefender SRL -> BitDefender LLC)
R3 ETDHCF; C:\Windows\System32\drivers\ETDHCF.sys [30360 2019-01-31] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.)
S3 ETD_Keyboard; C:\Windows\System32\drivers\ETD.sys [744088 2019-01-31] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronics Corp.)
R3 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [187688 2018-05-02] (Bitdefender SRL -> BitDefender LLC)
S3 iaLPSS2_GPIO2; C:\Windows\System32\drivers\iaLPSS2_GPIO2.sys [98864 2018-06-11] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R0 iaStorAC; C:\Windows\System32\drivers\iaStorAC.sys [1016288 2019-01-07] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R0 Ignis; C:\Windows\System32\drivers\ignis.sys [304448 2017-08-29] (Bitdefender SRL -> Bitdefender)
R3 IntcAzAudAddService; C:\Windows\system32\drivers\RTKVHD64.sys [6314848 2018-07-13] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Semiconductor Corp.)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 Qcamain10x64; C:\Windows\System32\drivers\Qcamain10x64.sys [2358736 2018-09-26] (Qualcomm Atheros -> Qualcomm Atheros, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [1024392 2018-05-21] (Realtek Semiconductor Corp. -> Realtek )
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [421312 2017-10-18] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
U5 rtsuvc; C:\Windows\System32\Drivers\rtsuvc.sys [3236320 2017-11-26] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)
S3 tapprotonvpn; C:\Windows\System32\drivers\tapprotonvpn.sys [44976 2018-06-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [442848 2018-05-02] (Bitdefender SRL -> BitDefender S.R.L.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [47704 2019-07-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [367032 2019-07-05] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [54200 2019-07-05] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-07-08 23:43 - 2019-07-08 23:44 - 000028966 _____ C:\Users\borja\Desktop\FRST.txt
2019-07-08 23:42 - 2019-07-08 23:43 - 000000000 ____D C:\FRST
2019-07-08 23:38 - 2019-07-08 23:38 - 002420224 _____ (Farbar) C:\Users\borja\Desktop\FRST64.exe
2019-07-08 22:27 - 2019-07-08 22:27 - 000000000 ___HD C:\OneDriveTemp
2019-07-08 22:21 - 2019-07-08 22:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\adaware
2019-07-08 22:14 - 2019-07-08 22:14 - 000000000 ____D C:\Users\borja\AppData\Local\ElevatedDiagnostics
2019-07-08 21:24 - 2019-07-08 21:24 - 000000000 ____D C:\Program Files\Common Files\adaware
2019-07-08 21:11 - 2019-07-08 21:11 - 000000000 ____D C:\Users\borja\AppData\Roaming\adaware
2019-07-08 21:07 - 2019-07-08 21:07 - 000000000 ____D C:\Program Files\adaware
2019-07-08 21:05 - 2019-07-08 21:05 - 000000000 ____D C:\ProgramData\adaware
2019-07-08 21:04 - 2019-07-08 21:04 - 002709464 _____ C:\Users\borja\Downloads\Adaware_Installer.exe
2019-07-08 20:47 - 2019-07-08 20:48 - 000000000 ____D C:\AdwCleaner
2019-07-08 20:46 - 2019-07-08 20:46 - 007025360 _____ (Malwarebytes) C:\Users\borja\Downloads\adwcleaner_7.3.exe
2019-07-08 20:22 - 2019-07-08 20:27 - 000000000 ____D C:\FSTool
2019-07-08 19:48 - 2019-07-08 19:48 - 000130614 _____ C:\Users\borja\Documents\cc_20190708_194800.reg
2019-07-08 19:48 - 2019-07-08 19:48 - 000001536 _____ C:\Users\borja\Documents\cc_20190708_194822-2.reg
2019-07-08 19:31 - 2019-07-08 21:34 - 000004210 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-07-08 19:31 - 2019-07-08 19:31 - 000002888 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2019-07-08 19:31 - 2019-07-08 19:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-07-08 19:31 - 2019-07-08 19:31 - 000000000 ____D C:\Program Files\CCleaner
2019-07-08 19:30 - 2019-07-08 19:30 - 020650160 _____ (Piriform Software Ltd) C:\Users\borja\Downloads\ccsetup559.exe
2019-07-08 19:26 - 2019-07-08 19:26 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-07-08 18:37 - 2019-07-08 18:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-07-08 18:37 - 2019-07-08 18:37 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-08 18:37 - 2019-07-08 18:37 - 000000000 ____D C:\Program Files\Malwarebytes
2019-07-08 18:37 - 2019-02-01 12:20 - 000020936 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamElam.sys
2019-07-08 18:37 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2019-07-08 18:33 - 2019-07-08 18:36 - 063194536 _____ (Malwarebytes ) C:\Users\borja\Downloads\mb3-setup-consumer-3.7.1.2839-1.0.586-1.0.10374.exe
2019-07-08 18:14 - 2019-07-08 18:14 - 000000000 ____D C:\Users\borja\AppData\Local\AdAwareDesktop
2019-07-08 18:10 - 2019-07-08 18:10 - 000000000 ____D C:\Users\borja\AppData\Local\AdAwareUpdater
2019-07-08 17:50 - 2019-07-08 18:01 - 000000000 ____D C:\Users\borja\AppData\Local\Mail.Ru
2019-07-08 17:50 - 2019-07-08 17:50 - 000000000 ____D C:\Users\borja\AppData\Roaming\Python
2019-07-08 17:50 - 2019-07-08 17:50 - 000000000 ____D C:\Users\borja\AppData\Roaming\prunld3227
2019-07-08 17:50 - 2019-07-08 17:50 - 000000000 ____D C:\ProgramData\Padur
2019-07-08 17:49 - 2019-07-08 17:50 - 000000000 ____D C:\ProgramData\Mail.Ru
2019-07-08 17:33 - 2019-07-08 17:33 - 000000000 ____D C:\Users\borja\AppData\LocalLow\Adobe
2019-07-08 17:25 - 2019-07-08 17:51 - 000000000 ____D C:\Users\borja\AppData\LocalLow\uTorrent
2019-07-08 17:17 - 2019-07-08 17:17 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2019-07-08 17:16 - 2019-07-08 17:21 - 000000000 ____D C:\Program Files\Adobe
2019-07-08 17:16 - 2019-07-08 17:16 - 000001127 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk
2019-07-08 17:16 - 2019-07-08 17:16 - 000001089 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
2019-07-08 17:14 - 2019-07-08 17:21 - 000000000 ____D C:\Program Files (x86)\Adobe
2019-07-08 17:14 - 2019-07-08 17:14 - 000001607 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
2019-07-08 17:14 - 2019-07-08 17:14 - 000001437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
2019-07-08 17:12 - 2019-07-08 17:16 - 000000000 ____D C:\Program Files\Common Files\Adobe
2019-07-08 17:09 - 2019-07-08 17:17 - 000000000 ____D C:\ProgramData\Adobe
2019-07-08 17:08 - 2019-07-08 18:23 - 000000000 ____D C:\Users\borja\AppData\Local\Adobe
2019-07-08 16:09 - 2019-07-08 17:25 - 000000000 ____D C:\Users\borja\AppData\Local\BitTorrentHelper
2019-07-03 14:09 - 2019-07-03 14:11 - 000000000 ____D C:\Users\borja\Documents\Borja
2019-06-27 08:32 - 2019-06-27 08:32 - 000000000 ____D C:\Users\borja\Downloads\pen amarillo
2019-06-24 18:33 - 2019-01-07 13:03 - 001016288 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorAC.sys
2019-06-19 11:39 - 2019-06-19 11:39 - 000000000 ____D C:\Program Files\UNP
2019-06-18 18:59 - 2019-07-08 10:24 - 000000000 ____D C:\Users\borja\Documents\#TIENDA ONLINE#
2019-06-18 17:05 - 2019-06-18 17:05 - 000000000 ____D C:\Users\borja\AppData\Roaming\Google
2019-06-17 19:02 - 2019-06-17 19:02 - 000217995 _____ C:\Users\borja\Desktop\190531_FacT0109964[1034].pdf
2019-06-17 16:47 - 2019-06-17 16:47 - 000230397 _____ C:\Users\borja\Desktop\GlosarioSEO.pdf
2019-06-11 23:16 - 2019-06-07 13:04 - 021388752 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2019-06-11 23:16 - 2019-06-07 13:04 - 001633136 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2019-06-11 23:16 - 2019-06-07 12:45 - 012756480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-06-11 23:16 - 2019-06-07 12:42 - 003613696 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2019-06-11 23:16 - 2019-06-07 12:41 - 004055552 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-06-11 23:16 - 2019-06-07 12:40 - 001663488 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2019-06-11 23:16 - 2019-06-07 12:40 - 001364992 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvruserservice.dll
2019-06-11 23:16 - 2019-06-07 12:23 - 001453920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2019-06-11 23:16 - 2019-06-07 12:19 - 020383832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2019-06-11 23:16 - 2019-06-07 12:07 - 011942400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-06-11 23:16 - 2019-06-07 12:04 - 004056064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2019-06-11 23:16 - 2019-06-07 12:04 - 002881536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2019-06-11 23:16 - 2019-06-07 12:04 - 001471488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2019-06-11 23:16 - 2019-06-07 08:07 - 000707384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2019-06-11 23:16 - 2019-06-07 08:01 - 001035040 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe
2019-06-11 23:16 - 2019-06-07 07:58 - 001220112 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2019-06-11 23:16 - 2019-06-07 07:58 - 001027384 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2019-06-11 23:16 - 2019-06-07 07:58 - 000568320 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe
2019-06-11 23:16 - 2019-06-07 07:57 - 007519896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2019-06-11 23:16 - 2019-06-07 07:57 - 007436536 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2019-06-11 23:16 - 2019-06-07 07:57 - 002811192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2019-06-11 23:16 - 2019-06-07 07:57 - 002719032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2019-06-11 23:16 - 2019-06-07 07:57 - 001934808 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2019-06-11 23:16 - 2019-06-07 07:57 - 001209696 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2019-06-11 23:16 - 2019-06-07 07:57 - 000792888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2019-06-11 23:16 - 2019-06-07 07:57 - 000709728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2019-06-11 23:16 - 2019-06-07 07:57 - 000594024 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2019-06-11 23:16 - 2019-06-07 07:57 - 000435000 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-06-11 23:16 - 2019-06-07 07:57 - 000383504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2019-06-11 23:16 - 2019-06-07 07:56 - 009084216 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-06-11 23:16 - 2019-06-07 07:47 - 000380432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-06-11 23:16 - 2019-06-07 07:46 - 006569344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-06-11 23:16 - 2019-06-07 07:46 - 006043496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2019-06-11 23:16 - 2019-06-07 07:46 - 001805656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2019-06-11 23:16 - 2019-06-07 07:46 - 001011872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2019-06-11 23:16 - 2019-06-07 07:46 - 000581048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVideoDSP.dll
2019-06-11 23:16 - 2019-06-07 07:38 - 025857536 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2019-06-11 23:16 - 2019-06-07 07:37 - 022019584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2019-06-11 23:16 - 2019-06-07 07:31 - 019372544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-06-11 23:16 - 2019-06-07 07:27 - 022718976 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-06-11 23:16 - 2019-06-07 07:24 - 005784064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2019-06-11 23:16 - 2019-06-07 07:24 - 003400704 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2019-06-11 23:16 - 2019-06-07 07:23 - 000608768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2019-06-11 23:16 - 2019-06-07 07:23 - 000561152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-06-11 23:16 - 2019-06-07 07:22 - 005307392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2019-06-11 23:16 - 2019-06-07 07:22 - 003710976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-06-11 23:16 - 2019-06-07 07:21 - 007588864 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2019-06-11 23:16 - 2019-06-07 07:21 - 004866048 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-06-11 23:16 - 2019-06-07 07:21 - 001778688 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2019-06-11 23:16 - 2019-06-07 07:21 - 000808448 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2019-06-11 23:16 - 2019-06-07 07:21 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-06-11 23:16 - 2019-06-07 07:20 - 002610688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2019-06-11 23:16 - 2019-06-07 07:20 - 000894464 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2019-06-11 23:16 - 2019-06-07 07:19 - 003212288 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2019-06-11 23:16 - 2019-06-07 07:19 - 002175488 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2019-06-11 23:16 - 2019-06-07 07:19 - 001560576 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2019-06-11 23:16 - 2019-06-07 07:19 - 001549824 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-06-11 23:16 - 2019-06-07 07:19 - 000778240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-06-11 23:16 - 2019-06-07 07:18 - 002166784 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2019-06-11 23:16 - 2019-06-07 07:18 - 000686592 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2019-06-11 23:16 - 2019-06-07 07:18 - 000531968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-06-11 23:16 - 2019-06-07 07:17 - 001920000 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2019-06-11 23:16 - 2019-06-07 07:17 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2019-06-11 23:16 - 2019-06-07 07:17 - 000889344 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2019-06-11 23:16 - 2019-06-07 07:16 - 001102336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2019-06-11 23:16 - 2019-06-07 07:16 - 000900096 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-06-11 23:16 - 2019-06-07 07:16 - 000544768 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-06-11 23:16 - 2019-06-07 07:16 - 000478720 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2019-06-11 23:16 - 2019-05-19 00:12 - 000353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-06-11 23:16 - 2019-05-17 14:44 - 000348160 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe
2019-06-11 23:16 - 2019-05-17 14:40 - 002394960 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2019-06-11 23:16 - 2019-05-17 14:27 - 006586880 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2019-06-11 23:16 - 2019-05-17 14:26 - 004393984 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2019-06-11 23:16 - 2019-05-17 14:25 - 004718080 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2019-06-11 23:16 - 2019-05-17 14:25 - 004491264 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2019-06-11 23:16 - 2019-05-17 14:22 - 000182784 _____ (Microsoft Corporation) C:\Windows\system32\LanguageComponentsInstaller.dll
2019-06-11 23:16 - 2019-05-17 14:21 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2019-06-11 23:16 - 2019-05-17 14:21 - 000878592 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2019-06-11 23:16 - 2019-05-17 14:19 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-06-11 23:16 - 2019-05-17 14:00 - 005658112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2019-06-11 23:16 - 2019-05-17 13:58 - 003397632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2019-06-11 23:16 - 2019-05-17 13:55 - 000704000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2019-06-11 23:16 - 2019-05-17 08:44 - 000829960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2019-06-11 23:16 - 2019-05-17 08:44 - 000550520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 005625160 _____ (Microsoft Corporation) C:\Windows\system32\StartTileData.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 004789944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 002256560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 001989552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 001980256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 001620264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 001380096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2019-06-11 23:16 - 2019-05-17 08:42 - 001130568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2019-06-11 23:16 - 2019-05-17 08:30 - 013878784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2019-06-11 23:16 - 2019-05-17 08:26 - 002969600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2019-06-11 23:16 - 2019-05-17 08:21 - 000333824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2019-06-11 23:16 - 2019-05-17 08:19 - 004515840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-06-11 23:16 - 2019-05-17 08:19 - 001630720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-06-11 23:16 - 2019-05-17 08:19 - 001110528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallService.dll
2019-06-11 23:16 - 2019-05-17 08:19 - 000835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2019-06-11 23:16 - 2019-05-17 08:18 - 002796032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll
2019-06-11 23:16 - 2019-05-17 08:18 - 001006592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2019-06-11 23:16 - 2019-05-17 08:08 - 001063224 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2019-06-11 23:16 - 2019-05-17 08:08 - 000723432 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2019-06-11 23:16 - 2019-05-17 08:08 - 000491200 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 004404720 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 002768960 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 002571640 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 002467320 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 001459120 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-06-11 23:16 - 2019-05-17 08:07 - 001288712 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 001260272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2019-06-11 23:16 - 2019-05-17 08:07 - 000930616 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2019-06-11 23:16 - 2019-05-17 08:07 - 000275768 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2019-06-11 23:16 - 2019-05-17 08:07 - 000260800 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2019-06-11 23:16 - 2019-05-17 08:06 - 001943136 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-06-11 23:16 - 2019-05-17 08:06 - 001784696 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2019-06-11 23:16 - 2019-05-17 08:06 - 001140992 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-06-11 23:16 - 2019-05-17 08:06 - 001098056 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2019-06-11 23:16 - 2019-05-17 08:06 - 000983424 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2019-06-11 23:16 - 2019-05-17 08:04 - 001826816 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll
2019-06-11 23:16 - 2019-05-17 07:44 - 016597504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2019-06-11 23:16 - 2019-05-17 07:38 - 004709376 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2019-06-11 23:16 - 2019-05-17 07:37 - 004385280 _____ (Microsoft Corporation) C:\Windows\system32\EdgeContent.dll
2019-06-11 23:16 - 2019-05-17 07:35 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2019-06-11 23:16 - 2019-05-17 07:35 - 000322560 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2019-06-11 23:16 - 2019-05-17 07:34 - 001804288 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2019-06-11 23:16 - 2019-05-17 07:34 - 000916480 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2019-06-11 23:16 - 2019-05-17 07:34 - 000671744 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2019-06-11 23:16 - 2019-05-17 07:33 - 003091456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2019-06-11 23:16 - 2019-05-17 07:33 - 002912256 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2019-06-11 23:16 - 2019-05-17 07:33 - 002370560 _____ (Microsoft Corporation) C:\Windows\system32\WebRuntimeManager.dll
2019-06-11 23:16 - 2019-05-17 07:33 - 001487360 _____ (Microsoft Corporation) C:\Windows\system32\InstallService.dll
2019-06-11 23:16 - 2019-05-17 07:33 - 000787968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2019-06-11 23:16 - 2019-05-17 07:32 - 001070080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2019-06-11 23:16 - 2019-05-17 07:32 - 000815104 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 004937216 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 003376640 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 003293184 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 001854976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 001805312 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 001383424 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 001215488 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 001027584 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2019-06-11 23:16 - 2019-05-17 07:31 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2019-06-11 23:16 - 2019-05-17 07:30 - 000917504 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2019-06-11 23:16 - 2019-05-17 07:30 - 000507392 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2019-06-11 23:16 - 2019-05-17 07:30 - 000276992 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-06-11 23:15 - 2019-06-07 12:48 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\iemigplugin.dll
2019-06-11 23:15 - 2019-06-07 12:47 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-06-11 23:15 - 2019-06-07 12:10 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2019-06-11 23:15 - 2019-06-07 07:58 - 000422416 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2019-06-11 23:15 - 2019-06-07 07:58 - 000135176 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2019-06-11 23:15 - 2019-06-07 07:58 - 000076304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys
2019-06-11 23:15 - 2019-06-07 07:57 - 000494304 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2019-06-11 23:15 - 2019-06-07 07:57 - 000413720 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2019-06-11 23:15 - 2019-06-07 07:57 - 000412984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2019-06-11 23:15 - 2019-06-07 07:57 - 000170296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-06-11 23:15 - 2019-06-07 07:57 - 000148280 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2019-06-11 23:15 - 2019-06-07 07:57 - 000137448 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-06-11 23:15 - 2019-06-07 07:56 - 000713272 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2019-06-11 23:15 - 2019-06-07 07:47 - 000097272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-06-11 23:15 - 2019-06-07 07:46 - 000357072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2019-06-11 23:15 - 2019-06-07 07:46 - 000128792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\userenv.dll
2019-06-11 23:15 - 2019-06-07 07:24 - 001361408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSPhotography.dll
2019-06-11 23:15 - 2019-06-07 07:23 - 000209408 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2019-06-11 23:15 - 2019-06-07 07:22 - 000578560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2019-06-11 23:15 - 2019-06-07 07:22 - 000233984 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2019-06-11 23:15 - 2019-06-07 07:22 - 000216064 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-06-11 23:15 - 2019-06-07 07:21 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2019-06-11 23:15 - 2019-06-07 07:20 - 001708544 _____ (Microsoft Corporation) C:\Windows\system32\MSPhotography.dll
2019-06-11 23:15 - 2019-06-07 07:20 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-06-11 23:15 - 2019-06-07 07:19 - 000369664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2019-06-11 23:15 - 2019-06-07 06:00 - 000001308 _____ C:\Windows\system32\tcbres.wim
2019-06-11 23:15 - 2019-05-19 00:12 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-06-11 23:15 - 2019-05-19 00:12 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2019-06-11 23:15 - 2019-05-19 00:12 - 000241152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2019-06-11 23:15 - 2019-05-17 14:40 - 000280888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2019-06-11 23:15 - 2019-05-17 14:25 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\WindowsUpdateElevatedInstaller.exe
2019-06-11 23:15 - 2019-05-17 14:24 - 000122368 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2019-06-11 23:15 - 2019-05-17 14:23 - 000110080 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2019-06-11 23:15 - 2019-05-17 14:22 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-06-11 23:15 - 2019-05-17 14:21 - 001121792 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2019-06-11 23:15 - 2019-05-17 14:21 - 000274944 _____ (Microsoft Corporation) C:\Windows\system32\dot3gpui.dll
2019-06-11 23:15 - 2019-05-17 14:21 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-06-11 23:15 - 2019-05-17 14:20 - 002084864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-06-11 23:15 - 2019-05-17 14:07 - 002206424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVCORE.DLL
2019-06-11 23:15 - 2019-05-17 13:56 - 000344576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-06-11 23:15 - 2019-05-17 13:56 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dot3gpui.dll
2019-06-11 23:15 - 2019-05-17 13:55 - 000668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-06-11 23:15 - 2019-05-17 13:55 - 000470528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcSpecfc.dll
2019-06-11 23:15 - 2019-05-17 13:54 - 002016768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-06-11 23:15 - 2019-05-17 13:54 - 000908288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2019-06-11 23:15 - 2019-05-17 11:33 - 001008640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MixedRealityCapture.dll
2019-06-11 23:15 - 2019-05-17 10:52 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-06-11 23:15 - 2019-05-17 09:07 - 000105272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2019-06-11 23:15 - 2019-05-17 08:43 - 000297688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtapi.dll
2019-06-11 23:15 - 2019-05-17 08:42 - 000129088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2019-06-11 23:15 - 2019-05-17 08:42 - 000125504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KerbClientShared.dll
2019-06-11 23:15 - 2019-05-17 08:23 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dtdump.exe
2019-06-11 23:15 - 2019-05-17 08:23 - 000068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
2019-06-11 23:15 - 2019-05-17 08:23 - 000002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2019-06-11 23:15 - 2019-05-17 08:22 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallServiceTasks.dll
2019-06-11 23:15 - 2019-05-17 08:22 - 000031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2019-06-11 23:15 - 2019-05-17 08:21 - 000326144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\esentutl.exe
2019-06-11 23:15 - 2019-05-17 08:21 - 000224768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2019-06-11 23:15 - 2019-05-17 08:20 - 000366080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2019-06-11 23:15 - 2019-05-17 08:20 - 000118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2019-06-11 23:15 - 2019-05-17 08:19 - 001073664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2019-06-11 23:15 - 2019-05-17 08:19 - 000873472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2019-06-11 23:15 - 2019-05-17 08:18 - 000251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2019-06-11 23:15 - 2019-05-17 08:08 - 000401328 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll
2019-06-11 23:15 - 2019-05-17 08:06 - 001307648 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2019-06-11 23:15 - 2019-05-17 08:06 - 000151888 _____ (Microsoft Corporation) C:\Windows\system32\KerbClientShared.dll
2019-06-11 23:15 - 2019-05-17 08:00 - 001295360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2019-06-11 23:15 - 2019-05-17 07:37 - 000185344 _____ (Microsoft Corporation) C:\Windows\system32\InstallServiceTasks.dll
2019-06-11 23:15 - 2019-05-17 07:37 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\DuCsps.dll
2019-06-11 23:15 - 2019-05-17 07:36 - 000228864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys
2019-06-11 23:15 - 2019-05-17 07:36 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\updatecsp.dll
2019-06-11 23:15 - 2019-05-17 07:36 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
2019-06-11 23:15 - 2019-05-17 07:36 - 000067584 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2019-06-11 23:15 - 2019-05-17 07:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\UsoClient.exe
2019-06-11 23:15 - 2019-05-17 07:36 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2019-06-11 23:15 - 2019-05-17 07:36 - 000002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2019-06-11 23:15 - 2019-05-17 07:35 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\esentutl.exe
2019-06-11 23:15 - 2019-05-17 07:34 - 000275456 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe
2019-06-11 23:15 - 2019-05-17 07:34 - 000270336 _____ (Microsoft Corporation) C:\Windows\system32\credprovhost.dll
2019-06-11 23:15 - 2019-05-17 07:34 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2019-06-11 23:15 - 2019-05-17 07:34 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2019-06-11 23:15 - 2019-05-17 07:34 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-06-11 23:15 - 2019-05-17 07:33 - 001214464 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2019-06-11 23:15 - 2019-05-17 07:33 - 000270336 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2019-06-11 23:15 - 2019-05-17 07:31 - 000466432 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2019-06-11 22:56 - 2019-02-13 07:47 - 001909560 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-07-08 23:12 - 2019-02-08 12:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-08 22:27 - 2019-02-08 19:57 - 000000000 ___RD C:\Users\borja\OneDrive
2019-07-08 22:25 - 2019-02-08 19:53 - 000000000 __SHD C:\Users\borja\IntelGraphicsProfiles
2019-07-08 22:25 - 2019-02-08 17:33 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-07-08 22:24 - 2019-02-08 12:23 - 000786432 _____ C:\Windows\system32\config\BBI
2019-07-08 22:14 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\system32\NDF
2019-07-08 20:48 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\system32\Tasks_Migrated
2019-07-08 19:45 - 2019-03-11 23:21 - 000000000 ____D C:\Users\borja\AppData\Local\CrashDumps
2019-07-08 19:45 - 2019-03-10 21:20 - 000000000 ____D C:\Users\borja\AppData\Roaming\uTorrent
2019-07-08 19:45 - 2019-02-08 12:56 - 000000000 ____D C:\Windows\Panther
2019-07-08 19:45 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\LiveKernelReports
2019-07-08 19:45 - 2019-02-08 12:36 - 000000000 ____D C:\Windows\INF
2019-07-08 19:11 - 2019-02-08 17:11 - 005066656 _____ C:\Windows\system32\FNTCACHE.DAT
2019-07-08 19:11 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\AppReadiness
2019-07-08 19:06 - 2019-04-05 14:12 - 000000000 ____D C:\ProgramData\Bitdefender
2019-07-08 18:37 - 2019-02-08 12:38 - 000000000 ___HD C:\Windows\ELAMBKUP
2019-07-08 17:50 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\SysWOW64\GroupPolicy
2019-07-08 17:50 - 2017-09-29 15:46 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2019-07-08 17:23 - 2019-02-08 12:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-08 17:22 - 2019-02-08 19:53 - 000000000 ____D C:\Users\borja\AppData\Roaming\Adobe
2019-07-08 17:13 - 2019-02-08 12:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-07-08 15:26 - 2019-02-08 17:11 - 000000000 ____D C:\Windows\system32\SleepStudy
2019-07-08 14:09 - 2019-02-06 14:04 - 000000000 ____D C:\Users\borja\Documents\AltoArredo
2019-07-06 17:02 - 2019-02-08 19:59 - 000003380 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4246120014-1606218229-2831048643-1001
2019-07-06 17:02 - 2019-02-08 19:50 - 000002408 _____ C:\Users\borja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-07-05 13:22 - 2019-02-08 17:33 - 000000000 ____D C:\Windows\system32\Drivers\wd
2019-07-01 18:37 - 2019-02-08 20:00 - 000000000 ____D C:\Program Files\Microsoft Office
2019-06-26 16:26 - 2019-02-12 18:39 - 000000000 ____D C:\Users\borja\Downloads\Telegram Desktop
2019-06-21 16:24 - 2019-02-09 17:54 - 000000000 ____D C:\Program Files\rempl
2019-06-21 10:54 - 2019-03-11 18:45 - 000002306 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-06-20 17:00 - 2019-02-08 12:28 - 000000000 ____D C:\Windows\CbsTemp
2019-06-19 07:12 - 2019-02-08 19:53 - 000000000 ____D C:\Users\borja\AppData\Local\Packages
2019-06-18 17:18 - 2019-03-11 18:45 - 000000000 ____D C:\Users\borja\AppData\Local\Google
2019-06-16 18:48 - 2019-03-21 18:41 - 000053614 _____ C:\Users\borja\Documents\V de Vendetta.xlsx


2019-06-12 01:24 - 2019-02-08 17:36 - 001679422 _____ C:\Windows\system32\PerfStringBackup.INI
2019-06-12 01:24 - 2019-02-08 12:48 - 000751674 _____ C:\Windows\system32\perfh00A.dat
2019-06-12 01:24 - 2019-02-08 12:48 - 000147560 _____ C:\Windows\system32\perfc00A.dat
2019-06-12 01:20 - 2019-02-08 19:53 - 000000000 ___RD C:\Users\borja\3D Objects
2019-06-12 01:20 - 2017-10-03 18:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-06-12 01:16 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\TextInput
2019-06-12 01:16 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\ShellExperiences
2019-06-12 01:16 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\Provisioning
2019-06-12 01:16 - 2019-02-08 12:38 - 000000000 ____D C:\Windows\bcastdvr
2019-06-11 23:15 - 2019-02-09 17:59 - 000000000 ____D C:\Windows\system32\MRT
2019-06-11 22:59 - 2019-02-09 17:59 - 135349160 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 3-07-2019
Ran by borja (08-07-2019 23:45:35)
Running from C:\Users\borja\Desktop
Windows 10 Home Version 1803 17134.829 (X64) (2019-02-08 15:35:21)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-4246120014-1606218229-2831048643-500 - Administrator - Disabled)
borja (S-1-5-21-4246120014-1606218229-2831048643-1001 - Administrator - Enabled) => C:\Users\borja
DefaultAccount (S-1-5-21-4246120014-1606218229-2831048643-503 - Limited - Disabled)
Invitado (S-1-5-21-4246120014-1606218229-2831048643-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-4246120014-1606218229-2831048643-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: adaware antivirus (Disabled - Up to date) {3AF56CA3-CA5A-215C-108D-CECA729D293A}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: adaware antivirus (Disabled - Up to date) {81948D47-EC60-2ED2-2A3D-F5B8091A6387}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: adaware firewall (Disabled) {02CEED86-8035-2004-3BD2-67FF8C4E6E41}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\uTorrent) (Version: 3.5.5.45271 - BitTorrent Inc.)
adaware antivirus (HKLM\...\{5FFF7119-74E8-442E-970E-50BAD81D5371}_AdAwareUpdater) (Version: 12.6.1005.11662 - adaware)
AdAwareInstaller (HKLM\...\{44DE19DF-AA86-497A-9CCA-4F52D0BFF9A8}) (Version: 12.6.1005.11662 - adaware) Hidden
AdAwareProxyEngine (HKLM\...\{7F7C8AE0-961B-4AED-B99A-D9BE29C0F24C}) (Version: 1.0.0.8 - adaware) Hidden
AdAwareUpdater (HKLM\...\{5FFF7119-74E8-442E-970E-50BAD81D5371}) (Version: 12.6.1005.11662 - adaware) Hidden
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
AntimalwareEngine (HKLM\...\{5C7A5F94-02E9-4C5D-A594-B1F10865965A}) (Version: 3.0.160.0 - adaware) Hidden
AntispamEngine (HKLM\...\{7DE129E5-BB4A-4517-A6CD-C69EEB346781}) (Version: 2.5.337.0 - adaware) Hidden
AvcEngine (HKLM\...\{700C79E1-C8E3-454E-B760-CAFFE9F2A6AA}) (Version: 3.22.183.0 - adaware) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.59 - Piriform)
CONTASOL (HKLM-x32\...\{85C468DA-F5E3-46A5-9B33-115FE49F0317}) (Version: 1.04.00009 - Software del Sol, S.A.)
Dolby Audio X2 Windows API SDK (HKLM\...\{F994125B-7BF5-4A38-A569-82833CEB24DC}) (Version: 0.8.4.83 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows APP (HKLM\...\{4A02DCED-C2B0-4DD3-87BD-7D8E68D6AF3C}) (Version: 0.8.6.75 - Dolby Laboratories, Inc.)
FACTUSOL (HKLM-x32\...\{1D100E38-FA60-4729-9F7D-4F1F5644DC9D}) (Version: 1.04.000010 - Software del Sol, S.A.)
FirewallEngine (HKLM\...\{232046DA-BB57-4114-9A0D-1119F00C4398}) (Version: 3.0.0.21 - adaware) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1052 - Intel Corporation)
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Malwarebytes versión 3.7.1.2839 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.7.1.2839 - Malwarebytes)
MEGAsync (HKLM-x32\...\MEGAsync) (Version:  - Mega Limited)
Microsoft Access database engine 2010 (Spanish) (HKLM\...\{90140000-00D1-0C0A-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office 365 Business - es-es (HKLM\...\O365BusinessRetail - es-es) (Version: 16.0.11727.20230 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\OneDriveSetup.exe) (Version: 19.103.0527.0003 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\Teams) (Version: 1.1.00.29068 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0C0A-1000-0000000FF1CE}) (Version: 16.0.11727.20230 - Microsoft Corporation) Hidden
OnlineThreatsEngine (HKLM\...\{26F31E12-3722-45FD-903B-49012286BB4C}) (Version: 3.0.1.23 - adaware) Hidden
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
SketchUp 2018 (HKLM\...\{C702DD60-EBF4-4961-8B7D-F209B361F985}) (Version: 18.0.16975 - Trimble, Inc.)
Software para dispositivos de chipset Intel® (HKLM-x32\...\{44ded3eb-1686-46a6-9770-fd79096c29f7}) (Version: 10.1.1.45 - Intel(R) Corporation) Hidden
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.1.0.29068 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden

Packages:
=========
Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20174.0_x64__8wekyb3d8bbwe [2019-05-30] (Microsoft Corporation) [MS Ad]
Deezer Music -> C:\Program Files\WindowsApps\Deezer.62021768415AF_4.10.2.0_x86__q7m17pa7q8kj0 [2019-06-27] (Deezer SA)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.520.0_x64__rz1tebttyb220 [2019-03-09] (Dolby Laboratories)
Earth View - Map 3D -> C:\Program Files\WindowsApps\22785wolfSYS.EarthView_10.17763.132.0_x64__pqnwjbykz6t3m [2019-06-02] (wolfSYS) [MS Ad]
Extensión de vídeo MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2019-02-09] (Microsoft Corporation)
Fitbit Coach -> C:\Program Files\WindowsApps\Fitbit.FitbitCoach_4.4.133.0_x64__6mqt6hf9g46tw [2019-02-09] (Fitbit)
Instagram -> C:\Program Files\WindowsApps\Facebook.InstagramBeta_41.1788.50991.0_x86__8xx8rvfyw5nnt [2019-02-12] (Instagram)
Intel® Graphics Control Panel -> C:\Program Files\WindowsApps\AppUp.IntelGraphicsControlPanel_3.2.0.0_x64__8j3eq9eme6ctt [2019-06-18] (INTEL CORP)
iTunes -> C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa [2019-05-28] (Apple Inc.)
La Caixa -> C:\Program Files\WindowsApps\8F25708A.LaCaixa_1.4.0.15_x64__e26djcgrw58de [2019-02-10] (CaixaBank S.A.)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_4.27.32.0_x86__k1h2ywk1493x8 [2019-03-26] (LENOVO INC.)
LenovoUtility -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.0.52.0_x64__5grkq8ppsgwt4 [2019-04-17] (LENOVO INC)
LinkedIn -> C:\Program Files\WindowsApps\7EE7776C.LinkedInforWindows_2.1.7098.0_neutral__w1wdnht996qgy [2019-02-09] (LinkedIn)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-08] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-08] (Microsoft Corporation) [MS Ad]
Microsoft News: Noticias destacadas en español -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11723.0_x64__8wekyb3d8bbwe [2019-06-27] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.6132.0_x64__8wekyb3d8bbwe [2019-06-17] (Microsoft Studios) [MS Ad]
MSN El Tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
Music Maker Jam -> C:\Program Files\WindowsApps\MAGIX.MusicMakerJam_2.3.1055.0_x64__a2t3txkz9j1jw [2019-02-09] (MAGIX)
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.93.478.0_x64__mcm4njqhnhss8 [2019-06-27] (Netflix, Inc.)
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_2.2.9.0_x64__nfy108tqq3p12 [2019-02-09] (Thumbmunkeys Ltd) [MS Ad]
Telegram Desktop -> C:\Program Files\WindowsApps\TelegramMessengerLLP.TelegramDesktop_1.7.14.0_x64__t4vj0pshhgkwm [2019-07-08] (Telegram Messenger LLP)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-02-19] (Twitter Inc.)
WhatsApp Desktop -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.3328.0_x64__cv1g1gvanyjgm [2019-06-02] (WhatsApp Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} -> [OneDrive - Personal] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}0
CustomCLSID: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\borja\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.18288.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\borja\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.18288.4\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers2: [AdAwareContextMenu] -> {5B64240D-5B36-4B9F-A75F-4925B6A53D5B} => C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.1005.11662\AdAwareShellExtension.dll [2019-02-13] (Adaware Software -> )
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers3: [AdAwareContextMenu] -> {5B64240D-5B36-4B9F-A75F-4925B6A53D5B} => C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.1005.11662\AdAwareShellExtension.dll [2019-02-13] (Adaware Software -> )
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\borja\AppData\Local\MEGAsync\ShellExtX64.dll [2019-02-08] (Mega Limited -> )
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-02-01] (Malwarebytes Corporation -> Malwarebytes)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2019-02-12 11:50 - 2019-02-12 11:50 - 000052736 _____ (Paito Anderson) [File not signed] C:\Users\borja\Downloads\Wallcat.exe
2019-03-15 17:11 - 2018-08-12 21:29 - 001255424 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\adawareantivirusservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\adawareantivirusservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\sharepoint.com -> hxxps://altoarredo-files.sharepoint.com

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 15:46 - 2019-05-17 13:08 - 000001151 _____ C:\Windows\system32\drivers\etc\hosts

0.0.0.0 adclick.g.doublecklick.net
0.0.0.0 googleads.g.doubleclick.net
0.0.0.0 http://www.googleadservices.com
0.0.0.0 pubads.g.doubleclick.net
0.0.0.0 securepubads.g.doubleclick.net
0.0.0.0 pagead2.googlesyndication.com
0.0.0.0 spclient.wg.spotify.com
0.0.0.0 audio2.spotify.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\borja\AppData\Roaming\Microsoft\Windows\Themes\WallcatWallpaper.tmp
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{6801C867-F551-465C-8D6D-8AEBDCA322AF}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{DA378D2A-A019-40CB-B1F0-8161A5C5E541}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F1DEFA2E-7AAB-4A1C-B4E2-99006CC2EB19}] => (Allow) C:\Users\borja\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{49FE6EAB-B47B-41C2-8BAA-FE3B263E6796}] => (Allow) C:\Users\borja\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{5E3D28DE-725A-4345-80E1-4D03E64C6174}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F5158975-04EF-447F-BBE8-51EBE4A520DD}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{603BEF7D-618E-42AB-A6C4-2DB18AD79DD3}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FC3A9892-A7AA-470D-98EB-66EC998BA0CB}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A1DBD46A-CE62-419C-A0E8-454BEA293280}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{5526872C-506F-4CAC-8EE7-36BF7F6FF3B4}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{651AD46A-8FF9-4DF5-B0C0-E9C2ED2597E4}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{92B44985-8168-4B53-BF5D-A5F364C3D30F}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{6C18F171-B355-4D66-B00C-52BC291F9A3E}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{D3E85EAF-DB63-473E-85FF-26A25FE353D8}] => (Allow) C:\Program Files\WindowsApps\AppleInc.iTunes_12095.7.41059.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{30952606-44F0-48FD-95F6-F83D3C1A3D99}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{ACD09CFB-497A-4AEC-8FE9-44B6E8C3EFAD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

19-06-2019 17:42:19 Punto de control programado
27-06-2019 02:07:21 Punto de control programado
04-07-2019 11:21:39 Punto de control programado
08-07-2019 18:09:04 AA11

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/08/2019 07:45:23 PM) (Source: ESENT) (EventID: 489) (User: )
Description: taskhostw (5796,G,0) Al intentar abrir el archivo "C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" para acceso de sólo lectura se produjo el error de sistema 32 (0x00000020): "El proceso no tiene acceso al archivo porque está siendo utilizado por otro proceso. ". La operación para abrir el archivo se cerrará con el error -1032 (0xfffffbf8).

Error: (07/08/2019 07:44:14 PM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) al abrir un archivo de registro C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log.

Error: (07/08/2019 07:44:14 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Al intentar abrir el archivo "C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log" para acceso de lectura y escritura se produjo el error de sistema 32 (0x00000020): "El proceso no tiene acceso al archivo porque está siendo utilizado por otro proceso. ". La operación para abrir el archivo se cerrará con el error -1032 (0xfffffbf8).

Error: (07/08/2019 07:44:04 PM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) al abrir un archivo de registro C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log.

Error: (07/08/2019 07:44:04 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Al intentar abrir el archivo "C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log" para acceso de lectura y escritura se produjo el error de sistema 32 (0x00000020): "El proceso no tiene acceso al archivo porque está siendo utilizado por otro proceso. ". La operación para abrir el archivo se cerrará con el error -1032 (0xfffffbf8).

Error: (07/08/2019 07:43:54 PM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) al abrir un archivo de registro C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log.

Error: (07/08/2019 07:43:54 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Al intentar abrir el archivo "C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log" para acceso de lectura y escritura se produjo el error de sistema 32 (0x00000020): "El proceso no tiene acceso al archivo porque está siendo utilizado por otro proceso. ". La operación para abrir el archivo se cerrará con el error -1032 (0xfffffbf8).

Error: (07/08/2019 07:43:44 PM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhostw (5796,R,98) WebCacheLocal: Error -1032 (0xfffffbf8) al abrir un archivo de registro C:\Users\borja\AppData\Local\Microsoft\Windows\WebCache\V01.log.


System errors:
=============
Error: (07/08/2019 10:56:12 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-FLU41M84)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario LAPTOP-FLU41M84\borja con SID (S-1-5-21-4246120014-1606218229-2831048643-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (07/08/2019 10:44:02 PM) (Source: DCOM) (EventID: 10010) (User: LAPTOP-FLU41M84)
Description: El servidor microsoft.windowscommunicationsapps_16005.11629.20174.0_x64__8wekyb3d8bbwe!microsoft.windowslive.mail no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/08/2019 10:30:59 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (07/08/2019 10:30:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio atc no pudo iniciarse debido al siguiente error: 
Windows no puede comprobar la firma digital en este archivo. Un cambio reciente en el hardware o en el software podría haber instalado un archivo con una firma incorrecta o dañada, o podría también tratarse de un software malintencionado proveniente de un origen desconocido.

Error: (07/08/2019 10:29:20 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Optimización de entrega no respondió después de iniciar.

Error: (07/08/2019 10:27:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio atc no pudo iniciarse debido al siguiente error: 
Windows no puede comprobar la firma digital en este archivo. Un cambio reciente en el hardware o en el software podría haber instalado un archivo con una firma incorrecta o dañada, o podría también tratarse de un software malintencionado proveniente de un origen desconocido.

Error: (07/08/2019 10:26:58 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID 
Windows.SecurityCenter.WscBrokerManager
 y APPID 
No disponible
 al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (07/08/2019 10:22:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio atc no pudo iniciarse debido al siguiente error: 
Windows no puede comprobar la firma digital en este archivo. Un cambio reciente en el hardware o en el software podría haber instalado un archivo con una firma incorrecta o dañada, o podría también tratarse de un software malintencionado proveniente de un origen desconocido.


Windows Defender:
===================================
Date: 2019-07-08 21:11:41.954
Description: 
El acceso controlado a carpetas impidió que C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.997.11652\AdAwareService.exe realizara cambios en la memoria.
Tiempo de detección: 2019-07-08T19:11:41.952Z
Usuario: NT AUTHORITY\SYSTEM
Ruta de acceso: \Device\Harddisk0\DR0
Nombre del proceso: C:\Program Files\adaware\adaware antivirus\adaware antivirus\12.6.997.11652\AdAwareService.exe
Versión de la firma: 1.297.664.0
Versión del motor: 1.1.16100.4
Versión del producto: 4.18.1906.3

Date: 2019-07-08 20:32:14.776
Description: 
El acceso controlado a carpetas bloqueó C:\Users\borja\Downloads\iExplore64-32369.exe para que no pueda modificar %desktopdirectory%\.
Hora de detección: 2019-07-08T18:32:14.776Z
Usuario: LAPTOP-FLU41M84\borja
Ruta de acceso: %desktopdirectory%\
Nombre del proceso: C:\Users\borja\Downloads\iExplore64-32369.exe
Versión de la firma: 1.297.664.0
Versión del motor: 1.1.16100.4
Versión del producto: 4.18.1906.3

Date: 2019-07-08 20:32:00.009
Description: 
El acceso controlado a carpetas bloqueó C:\Users\borja\Downloads\iExplore64.exe para que no pueda modificar %desktopdirectory%\.
Hora de detección: 2019-07-08T18:31:59.964Z
Usuario: LAPTOP-FLU41M84\borja
Ruta de acceso: %desktopdirectory%\
Nombre del proceso: C:\Users\borja\Downloads\iExplore64.exe
Versión de la firma: 1.297.664.0
Versión del motor: 1.1.16100.4
Versión del producto: 4.18.1906.3

Date: 2019-07-08 20:28:08.446
Description: 
El acceso controlado a carpetas bloqueó C:\Users\borja\Downloads\iExplore64.exe para que no pueda modificar %desktopdirectory%\.
Hora de detección: 2019-07-08T18:28:08.446Z
Usuario: LAPTOP-FLU41M84\borja
Ruta de acceso: %desktopdirectory%\
Nombre del proceso: C:\Users\borja\Downloads\iExplore64.exe
Versión de la firma: 1.297.664.0
Versión del motor: 1.1.16100.4
Versión del producto: 4.18.1906.3

Date: 2019-07-08 20:24:48.096
Description: 
El acceso controlado a carpetas impidió que C:\FSTool\DF.exe realizara cambios en la memoria.
Tiempo de detección: 2019-07-08T18:24:48.086Z
Usuario: LAPTOP-FLU41M84\borja
Ruta de acceso: \Device\HarddiskVolume1
Nombre del proceso: C:\FSTool\DF.exe
Versión de la firma: 1.297.664.0
Versión del motor: 1.1.16100.4
Versión del producto: 4.18.1906.3

Date: 2019-07-08 23:45:22.231
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.297.664.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16100.4
Código de error: 0x8024402c
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2019-07-08 21:35:44.849
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.297.664.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16100.4
Código de error: 0x80240438
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2019-07-08 20:59:41.899
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.297.664.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16100.4
Código de error: 0x80240438
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2019-07-08 20:40:09.046
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.297.664.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16100.4
Código de error: 0x80240438
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2019-07-08 20:00:30.802
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.297.664.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16100.4
Código de error: 0x80240438
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

CodeIntegrity:
===================================

Date: 2019-07-08 22:30:10.455
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atc.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-07-08 22:27:23.713
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atc.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-07-08 22:22:28.227
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atc.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-07-08 22:19:18.673
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atc.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-07-08 19:14:30.978
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atc.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-07-08 19:09:12.231
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atc.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2019-05-17 12:42:53.958
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\FlightSettings.dll because the set of per-page image hashes could not be found on the system.

Date: 2019-05-17 12:42:53.946
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\FlightSettings.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info =========================== 

BIOS: LENOVO 8TCN51WW 12/08/2018
Motherboard: LENOVO LNVNB161216
Processor: Intel(R) Core(TM) i7-8550U CPU @ 1.80GHz
Percentage of memory in use: 48%
Total physical RAM: 8101.22 MB
Available physical RAM: 4205.39 MB
Total Virtual: 12453.22 MB
Available Virtual: 9188 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:905.27 GB) (Free:825.11 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:24.87 GB) NTFS

\\?\Volume{a55ae722-be8e-4c87-ae9e-a53616e88c50}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.58 GB) NTFS
\\?\Volume{6a7eefc7-42a1-45f3-8c1d-4b796a681bad}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 8EB25DD5)

Partition: GPT.

==================== End of Addition.txt ============================

Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0]
HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\Run: [AdobeBridge] => [X]
Startup: C:\Users\borja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wallcat.lnk [2019-02-12]
ShortcutTarget: Wallcat.lnk -> C:\Users\borja\Downloads\Wallcat.exe (Paito Anderson) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Task: {663FAA8B-6583-428A-8DE9-F6C4890EA7A8} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2314008 2019-06-04] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}: [NameServer] 45.86.180.227,185.162.93.213,116.203.6.218,185.130.104.222
Tcpip\..\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}: [DhcpNameServer] 150.201.1.2
Tcpip\..\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}: [NameServer] 8.8.8.8,8.8.4.4,116.203.6.218,185.130.104.222
Tcpip\..\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}: [DhcpNameServer] 192.168.1.1 192.168.1.1
2019-07-08 17:50 - 2019-07-08 18:01 - 000000000 ____D C:\Users\borja\AppData\Local\Mail.Ru
2019-07-08 17:49 - 2019-07-08 17:50 - 000000000 ____D C:\ProgramData\Mail.Ru
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.

Buenos días! @JavierHF
Te pego el reporte del paso que me has recomendado hacer.


Fix result of Farbar Recovery Scan Tool (x64) Version: 3-07-2019
Ran by borja (09-07-2019 08:22:26) Run:1
Running from C:\Users\borja\Desktop
Loaded Profiles: borja (Available Profiles: borja)
Boot Mode: Safe Mode (minimal)
==============================================

fixlist content:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxlctlfudivq`qsp`29hfm [0]
HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\...\Run: [AdobeBridge] => [X]
Startup: C:\Users\borja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wallcat.lnk [2019-02-12]
ShortcutTarget: Wallcat.lnk -> C:\Users\borja\Downloads\Wallcat.exe (Paito Anderson) [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
Task: {663FAA8B-6583-428A-8DE9-F6C4890EA7A8} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2314008 2019-06-04] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}: [NameServer] 45.86.180.227,185.162.93.213,116.203.6.218,185.130.104.222
Tcpip\..\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}: [DhcpNameServer] 150.201.1.2
Tcpip\..\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}: [NameServer] 8.8.8.8,8.8.4.4,116.203.6.218,185.130.104.222
Tcpip\..\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}: [DhcpNameServer] 192.168.1.1 192.168.1.1
2019-07-08 17:50 - 2019-07-08 18:01 - 000000000 ____D C:\Users\borja\AppData\Local\Mail.Ru
2019-07-08 17:49 - 2019-07-08 17:50 - 000000000 ____D C:\ProgramData\Mail.Ru
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: Restore point can only be created in normal mode.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
C:\ProgramData\Reprise => ":wupeogjxlctlfudivq`qsp`29hfm" ADS removed successfully
"HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => removed successfully
C:\Users\borja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wallcat.lnk => moved successfully
C:\Users\borja\Downloads\Wallcat.exe => moved successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\Windows\system32\GroupPolicy\User => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{663FAA8B-6583-428A-8DE9-F6C4890EA7A8}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{663FAA8B-6583-428A-8DE9-F6C4890EA7A8}" => removed successfully
C:\Windows\System32\Tasks\AVG\Overseer => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG\Overseer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46465537-f35f-4e3e-9e02-dd38061f4e4a}\\DhcpNameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}\\NameServer" => removed successfully
"HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5ef31440-899f-4537-a8da-5cc8233eb0b3}\\DhcpNameServer" => removed successfully
C:\Users\borja\AppData\Local\Mail.Ru => moved successfully
C:\ProgramData\Mail.Ru => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-4246120014-1606218229-2831048643-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

No se puede vaciar la cach‚ de resoluci¢n de DNS: Error de una funci¢n durante la ejecuci¢n.


========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

Unable to connect to BITS - 0x8007043c
El servicio no puede iniciarse en modo a prueba de errores



========= End of CMD: =========


========= netsh advfirewall reset =========


Error al intentar ponerse en contacto con el servicio Firewall de Windows Defender. Aseg£rate de que el servicio se est  ejecutando e intenta la solicitud de nuevo.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========


Error al intentar ponerse en contacto con el servicio Firewall de Windows Defender. Aseg£rate de que el servicio se est  ejecutando e intenta la solicitud de nuevo.


========= End of CMD: =========


========= netsh int ipv4 reset =========

No hay valores configurados por el usuario para restablecer.


========= End of CMD: =========


========= netsh int ipv6 reset =========

No hay valores configurados por el usuario para restablecer.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 127948554 B
Java, Flash, Steam htmlcache => 524 B
Windows/system/drivers => 1384411 B
Edge => 85718523 B
Chrome => 382336438 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 186404 B
systemprofile32 => 0 B
LocalService => 8276 B
LocalService => 0 B
NetworkService => 10918 B
NetworkService => 0 B
borja => 38000809 B

RecycleBin => 0 B
EmptyTemp: => 614.9 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 08:23:15 ====

Perfecto y ahora para asegurarnos que NO queda nada “escondido” en tu equipo sigue estos pasos, en el orden indicado y leyendo todo lo explicado. :+1:

:one: Desactiva temporalmente el Antivirus :arrow_forward: Cómo deshabilitar temporalmente su Antivirus, mientras estemos realizando TODOS los pasos.

Vamos a descargar en TU ESCRITORIO(y NO en otro lugar :face_with_monocle:) todas las herramientas que vamos a utilizar en este procedimiento (pero no las ejecutes todavía) :


:two: Ejecutas las herramientas de una en una y en el orden indicado :



CCleaner.-

  • Instalas y Ejecutas CCleaner siguiendo los pasos indicados en el manual.

  • Úsalo primero en su opción de Limpiador para borrar cookies, temporales de Internet y todos los archivos que te muestre como obsoletos.

  • Después usa su opción de Registro para limpiar todo el registro de Windows(haciendo copia de seguridad).

Malwarebytes.-

  • Instalas y Ejecutas MBAM siguiendo los pasos indicados en el manual.

  • Realiza un Análisis Completo. :white_check_mark:

  • Seleccionando TODOS a Cuarentena para enviarlo a la cuarentena y Reinicias el sistema.

  • En el apartado del manual :arrow_forward:Historial :arrow_backward: encontrarás el informe del MBAM, que debes copiar y pegar en tu próxima respuesta, para analizarlo.

AdwCleaner.-

  • Ejecuta Adwcleaner.exe.

  • Pulsamos en el botón Analizar ahora, y espera a que se realice el proceso, inmediatamente pulsa siempre sobre el botón Iniciar Reparación.

  • Espera a que se complete y sigue las instrucciones, si te pidiera Reiniciar el sistema Aceptas.

  • El log/informe lo encontramos en la pestaña “Informes”, volviendo a abrir el programa si fuese necesario, para poder copiarlo y pegarlo en tu próxima respuesta.

  • El informe también se puede encontrar en C:\AdwCleaner\Logs\AdwCleaner[C00].txt

Junkware Removal Tool.-

  • Ejecuta JRT.exe.

  • Y pulsar cualquier tecla para continuar, esperar pacientemente a que termine el proceso.

  • Si en algún momento te pide Reiniciar hazlo.

  • Al finalizar, un registro/informe (JRT.txt) se guardara en el escritorio y se abrirá automáticamente.

  • Copia y pega el contenido de JRT.txt en tu próxima respuesta.

:three: Poner los informes en tu próxima respuesta de :

  • Malwarebytes, AdwCleaner + JRT, y en ese orden. :+1:

Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(mas de 50.000 caracteres aprox.).

Y nos cuentas como funciona tu equipo en relación al problema planteado. :face_with_monocle:

Saludos.

Buenas @JavierHF

Vamos a ello, a ver qué tal ha quedado…

Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 9/7/19
Hora del análisis: 14:30
Archivo de registro: 5a486016-a245-11e9-9216-8c164565a209.json

-Información del software-
Versión: 3.8.3.2965
Versión de los componentes: 1.0.613
Versión del paquete de actualización: 1.0.11450
Licencia: Prueba

-Información del sistema-
SO: Windows 10 (Build 17134.829)
CPU: x64
Sistema de archivos: NTFS
Usuario: LAPTOP-FLU41M84\borja

-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 273249
Amenazas detectadas: 0
Amenazas en cuarentena: 0
Tiempo transcurrido: 1 min, 43 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 0
(No hay elementos maliciosos detectados)

Valor del registro: 0
(No hay elementos maliciosos detectados)
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build:    04-04-2019
# Database: 2019-04-03.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    07-09-2019
# Duration: 00:00:12
# OS:       Windows 10 Home
# Scanned:  27198
# Detected: 1


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Legacy             Alexa Traffic Rank

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.


AdwCleaner[S00].txt - [1949 octets] - [08/07/2019 20:47:46]
AdwCleaner[C00].txt - [1945 octets] - [08/07/2019 20:48:14]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S01].txt ##########
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build:    04-04-2019
# Database: 2019-04-03.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    07-09-2019
# Duration: 00:00:01
# OS:       Windows 10 Home
# Cleaned:  1
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

Deleted       Alexa Traffic Rank
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64 
Ran by borja (Administrator) on 09/07/2019 at 14:41:10,61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2 

Successfully deleted: C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel (Folder) 
Successfully deleted: C:\Users\borja\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol (Folder) 



Registry: 1 

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{639673F9-AD4B-41E6-80A2-AB8CBF9E29F4} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09/07/2019 at 14:47:39,49
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

El equipo aparentemente va perfecto. La única pega es que ahora me aparece así el SmartScreen.

Pero no sé si está relacionado o es por otro tema.

A qué te refieres a que antes te aparecia esa ventana de otra manera o que NO aparecia ese tipo de ventana…??

Me refiero a que nunca me había aparecido ese tipo de ventana.

El filtro Smartscreen de Windows viene preactivado por defecto, y SI no te habia salido anteriormente seria porque se desactivo en algún momento.

Revisa este enlace para que veas como puedes desactivarlo :

Cuando lo hayas verificado nos comentas como sigue tu problema inicial para que te podamos dar los pasos finales.

Saludos.

Buenos días @JavierHF

Gracias por el enlace sobre SmartScreen.

Con respecto al problema inicial comentarte que el ordenador parece que funciona bien pero esta mañana el Malwarebytes me ha detectado esto al encender el portátil.

 Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 10/7/19
Hora del análisis: 2:07
Archivo de registro: b387acde-a2a6-11e9-91b0-8c164565a209.json

-Información del software-
Versión: 3.8.3.2965
Versión de los componentes: 1.0.613
Versión del paquete de actualización: 1.0.11474
Licencia: Prueba

-Información del sistema-
SO: Windows 10 (Build 17134.829)
CPU: x64
Sistema de archivos: NTFS
Usuario: System

-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Programador de tareas
Resultado: Completado
Objetos analizados: 273272
Amenazas detectadas: 3
Amenazas en cuarentena: 3
Tiempo transcurrido: 5 min, 16 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 2
Adware.ExtenBro, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\36509B8F624CE280E0C797F42F4A8F552A280313, En cuarentena, [2068], [706129],1.0.11474
Adware.ExtenBro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\36509B8F624CE280E0C797F42F4A8F552A280313, En cuarentena, [2068], [706129],1.0.11474

Valor del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Secuencia de datos: 0
(No hay elementos maliciosos detectados)

Carpeta: 0
(No hay elementos maliciosos detectados)

Archivo: 1
Adware.DNSChanger, C:\USERS\BORJA\APPDATA\ROAMING\PRUNLD3227\HE67832.EXE, En cuarentena, [695], [706144],1.0.11474

Sector físico: 0
(No hay elementos maliciosos detectados)

WMI: 0
(No hay elementos maliciosos detectados)


(end)

Comentar además que ayer me di cuenta que se había hecho un pago mediante Paypal de 70€ a http://www.twitch.tv sin que yo lo efectuase. Paypal ya me ha devuelto el dinero y por supuesto he cambiado todas mis contraseñas.

Hola.

Que raro… :thinking: instalaste algun programa/software o complemento de algún navegador…??

Perfecto… efectivamente en caso de encontrarte con ese tipo de problemas, lo primero siempre es cambiar las contraseñas. :+1:

Y ahora vas a realizar una desinfección con :arrow_right: Manual Dr Web Curelt!

Al terminar nos pones el informe que se indica en el manual y comentas los resultados.

Saludos.

Pues des instalé una extensión de chrome, Lastpass, cuando cambié todas las contraseñas. Es la única modificación que hice en el navegador. Y en el PC no he instalado nada salvo los programas que me has ido comentando.

Total 90112117002 bytes in 303861 files scanned (429699 objects)
Total 303556 files (429220 objects) are clean
Total 3 files are infected
Total 1 file are suspicious
Total 473 files are raised error condition
Scan time is 01:29:14.352

-----------------------------------------------------------------------------
Start curing
-----------------------------------------------------------------------------

\Registry\Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit - cured
C:\Users\borja\Downloads\Programas\Adaware_Installer.exe - quarantined
C:\Windows\Installer\{44DE19DF-AA86-497A-9CCA-4F52D0BFF9A8}\NewShortcut6_46B5678CC4A24F4AA166FBA0D99B16EE.exe - quarantined
C:\Windows\Installer\{D13B7904-0E4D-4375-B4C7-C86C7C15D995}\NewShortcut6_46B5678CC4A24F4AA166FBA0D99B16EE.exe - quarantined

Total 90112117002 bytes in 303861 files scanned (429699 objects)
Total 303556 files (429220 objects) are clean
Total 3 files are infected
Total 1 file are suspicious
Total 4 files are neutralized
Total 473 files are raised error condition
Scan time is 01:29:14.352

Perfecto. :clap:

REALIZA un APAGADO total del equipo y luego enciendes la máquina y vuelves a usar Malwarebytes y después AdwCleaner.

Nos pones los dos informes de las herramientas.

Saludos.

Ahí va

Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 11/7/19
Hora del análisis: 9:20
Archivo de registro: 54c62bf7-a3ac-11e9-ac02-8c164565a209.json

-Información del software-
Versión: 3.8.3.2965
Versión de los componentes: 1.0.613
Versión del paquete de actualización: 1.0.11492
Licencia: Prueba

-Información del sistema-
SO: Windows 10 (Build 17134.885)
CPU: x64
Sistema de archivos: NTFS
Usuario: System

-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Programador de tareas
Resultado: Completado
Objetos analizados: 273189
Amenazas detectadas: 0
Amenazas en cuarentena: 0
Tiempo transcurrido: 6 min, 43 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 0
(No hay elementos maliciosos detectados)

Valor del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Secuencia de datos: 0
(No hay elementos maliciosos detectados)

Carpeta: 0
(No hay elementos maliciosos detectados)

Archivo: 0
(No hay elementos maliciosos detectados)

Sector físico: 0
(No hay elementos maliciosos detectados)

WMI: 0
(No hay elementos maliciosos detectados)


(end)
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build:    04-04-2019
# Database: 2019-04-03.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    07-11-2019
# Duration: 00:00:14
# OS:       Windows 10 Home
# Scanned:  27198
# Detected: 1


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Legacy             Alexa Traffic Rank

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.


AdwCleaner[S00].txt - [1949 octets] - [08/07/2019 20:47:46]
AdwCleaner[C00].txt - [1945 octets] - [08/07/2019 20:48:14]
AdwCleaner[S01].txt - [1386 octets] - [09/07/2019 14:34:14]
AdwCleaner[C01].txt - [1552 octets] - [09/07/2019 14:34:31]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########
# -------------------------------
# Malwarebytes AdwCleaner 7.3.0.0
# -------------------------------
# Build:    04-04-2019
# Database: 2019-04-03.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    07-11-2019
# Duration: 00:00:02
# OS:       Windows 10 Home
# Cleaned:  1
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

Deleted       Alexa Traffic Rank

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1949 octets] - [08/07/2019 20:47:46]
AdwCleaner[C00].txt - [1945 octets] - [08/07/2019 20:48:14]
AdwCleaner[S01].txt - [1386 octets] - [09/07/2019 14:34:14]
AdwCleaner[C01].txt - [1552 octets] - [09/07/2019 14:34:31]
AdwCleaner[S02].txt - [1508 octets] - [11/07/2019 09:27:31]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########