Google en arabe


#1

Muy buenas amigos,en la antigua web me ayudaron a instalar google de nuevo ya que me salia todo en arabe,no se el motivo,la cuestión es que un compañero me dio un link para descargar y me funciono a la perfeccion,ahora se me volvio a poner como antes,todas las paginas me salen en arabe,pueden darme nuevamente el link,muchas gracias de antemano…saludos¡¡¡


#2

Hola @kapy.

Cuando hicisteis los anteriores procesos que indicas, antes de hacer la reinstalación NO hicisteis ningún otro proceso de verificación de tu equipo.??


#3

Muy buenas javier,no,tan solo desinstale y instale el nuevo google que me mandaron.


#4

Y en la anterior ocasión… tenias Google en tu idioma y de pronto se paso al otro idioma.??


#5

buena tarde javi,perdona la tardanza,si se cambio todo solo…


#6

Bien… pues lo primero que vas a realizar es una revisión de tu máquina, sigue estos pasos, en el orden indicado y leyendo todo lo explicado. :+1:

:one: Desactiva temporalmente el Antivirus :arrow_forward: Cómo deshabilitar temporalmente su Antivirus, mientras estemos realizando TODOS los pasos.

Vamos a descargar en TU ESCRITORIO(y NO en otro lugar :face_with_monocle:) todas las herramientas que vamos a utilizar en este procedimiento (pero no las ejecutes todavía) :


:two: Ejecutas las herramientas de una en una y en el orden indicado :


CCleaner.-

  • Instalas y Ejecutas CCleaner siguiendo los pasos indicados en el manual.

  • Úsalo primero en su opción de Limpiador para borrar cookies, temporales de Internet y todos los archivos que te muestre como obsoletos.

  • Después usa su opción de Registro para limpiar todo el registro de Windows(haciendo copia de seguridad).

Malwarebytes.-

  • Instalas y Ejecutas MBAM siguiendo los pasos indicados en el manual.

  • Realiza un Análisis Completo. :white_check_mark:

  • Seleccionando TODOS a Cuarentena para enviarlo a la cuarentena y Reinicias el sistema.

  • En el apartado del manual :arrow_forward:Historial :arrow_backward: encontrarás el informe del MBAM, que debes copiar y pegar en tu próxima respuesta, para analizarlo.

AdwCleaner.-

  • Ejecuta Adwcleaner.exe.

  • Pulsamos en el botón Analizar ahora, y espera a que se realice el proceso, inmediatamente pulsa siempre sobre el botón Iniciar Reparación.

  • Espera a que se complete y sigue las instrucciones, si te pidiera Reiniciar el sistema Aceptas.

  • El log/informe lo encontramos en la pestaña “Informes”, volviendo a abrir el programa si fuese necesario, para poder copiarlo y pegarlo en tu próxima respuesta.

  • El informe también se puede encontrar en C:\AdwCleaner\Logs\AdwCleaner[C00].txt

Junkware Removal Tool.-

  • Ejecuta JRT.exe.

  • Y pulsar cualquier tecla para continuar, esperar pacientemente a que termine el proceso.

  • Si en algún momento te pide Reiniciar hazlo.

  • Al finalizar, un registro/informe (JRT.txt) se guardara en el escritorio y se abrirá automáticamente.

  • Copia y pega el contenido de JRT.txt en tu próxima respuesta.

Farbar Recovery Scan Tool.-

  • Ejecuta FRST.exe.

  • En el mensaje de la ventana del Disclaimer, pulsamos Yes

  • En la ventana principal pulsamos en el botón Scan y esperamos a que concluya el proceso.

  • Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

:three: Poner los informes en tu próxima respuesta de :

  • Malwarebytes, AdwCleaner, JRT, FRST + Addition.txt, y en ese orden. :+1:

Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(mas de 50.000 caracteres aprox.).

Y nos cuentas como funciona tu equipo en relacion al problema planteado. :face_with_monocle:

Saludos, Javier.


#7

gracias javi,cuando tenga un ratin(por el trabajo) lo realizo y te digo,un abrazo compañero¡¡


#8

Perfecto :+1: @kapy.

En cuanto lo hayas realizado pones los informes.

Saludos.


#9

muy buena compañerp,realize lo que me dijiste …paso a paso y na de na…google sigue en arabe…de todas formas gracias por tu voluntad¡¡ saludos¡¡


#10

Pero debes poner los informes, :thinking: para que podamos analizarlos.


#11

buena tarde javi,haber si ahora esta bien.

# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build:    09-25-2018
# Database: 2018-09-21.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    10-22-2018
# Duration: 00:00:08
# OS:       Windows 8.1
# Scanned:  42056
# Detected: 0


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.


AdwCleaner[S00].txt - [1976 octets] - [19/10/2018 10:56:02]
AdwCleaner[C00].txt - [2034 octets] - [19/10/2018 10:56:50]
AdwCleaner[S01].txt - [1368 octets] - [21/10/2018 21:00:48]
AdwCleaner[C01].txt - [1554 octets] - [21/10/2018 21:01:04]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S02].txt ##########

#12
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 8.1 x64 
Ran by Esteban-Kapy (Administrator) on 22/10/2018 at 18:01:12,25
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0 




Registry: 0 





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/10/2018 at 18:02:50,59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

#13
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.10.2018
Ran by Esteban-Kapy (administrator) on DJKAPY (22-10-2018 18:03:20)
Running from C:\Users\Esteban-Kapy\Desktop\LIMPIADORES
Loaded Profiles: Esteban-Kapy (Available Profiles: Esteban-Kapy)
Platform: Windows 8.1 (Update) (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(GEAR Software) C:\Windows\SysWOW64\gearsec.exe
() C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [18594760 2018-09-19] (Piriform Ltd)
HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [11776 2014-11-21] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 212.231.6.7 8.8.8.8
Tcpip\..\Interfaces\{8BF5BAEE-BA19-4C94-8D1E-62355571F0E0}: [DhcpNameServer] 212.231.6.7 8.8.8.8

Internet Explorer:
==================
HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/es-es/?ocid=iehp

FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-09-20] (Adobe Systems Inc.)

Chrome: 
=======
CHR DefaultProfile: Profile 1
CHR HomePage: Profile 1 -> hxxp://www.google.com
CHR StartupUrls: Profile 1 -> "hxxp://www.gmail.com/","hxxp://www.facebook.com/","hxxp://www.tunein.com/","hxxp://www.youtube.com/","hxxp://www.google.com/"
CHR Profile: C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-10-22]
CHR Extension: (Presentaciones) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-09-19]
CHR Extension: (Documentos) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2018-09-19]
CHR Extension: (Google Drive) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-09-28]
CHR Extension: (YouTube) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-09-19]
CHR Extension: (Lumin PDF - Beautiful PDF Editor) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dbkidnlfklnjanneifjjojofckpcogcl [2018-09-19]
CHR Extension: (Mixcloud) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdcenekolminfbkcbchinlcgfhpmggpk [2018-09-19]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-19]
CHR Extension: (Guardar en Google Drive) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2018-09-19]
CHR Extension: (Mixcloud Tracklist & Downloads) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lglkomjmpemepahcicfhkpbcmfncpefi [2018-09-19]
CHR Extension: (Extensión de Google Keep para Chrome) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2018-10-19]
CHR Extension: (Alarma de Lluvia) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\meaikaglpfemjncbioflellmppndgmok [2018-09-19]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-09-19]
CHR Extension: (Gmail) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-09-19]
CHR Extension: (Chrome Media Router) - C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-19]
CHR Profile: C:\Users\Esteban-Kapy\AppData\Local\Google\Chrome\User Data\System Profile [2018-10-22]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 gearsec; C:\WINDOWS\SysWOW64\gearsec.exe [53248 2003-12-02] (GEAR Software) [File not signed]
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 NMSAccess; C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2018-03-27] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2018-03-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 GEARAspiWDM; C:\Windows\SysWOW64\DRIVERS\GEARAspiWDM.sys [13872 2004-06-11] (GEAR Software Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [260384 2018-10-21] (Malwarebytes)
S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [5504 2009-11-12] () [File not signed]
S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [7168 2009-11-12] () [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [46600 2018-03-27] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [274776 2018-03-27] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [117592 2018-03-27] (Microsoft Corporation)
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\WINDOWS\System32\drivers\zamguard64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-10-22 18:02 - 2018-10-22 18:02 - 000000550 _____ C:\Users\Esteban-Kapy\Desktop\JRT.txt
2018-10-22 17:55 - 2018-10-22 17:55 - 000001530 _____ C:\Users\Esteban-Kapy\Desktop\informe malware.txt
2018-10-22 17:47 - 2018-10-22 17:47 - 000000000 _____ C:\Users\Esteban-Kapy\Desktop\informes.txt
2018-10-22 17:42 - 2018-10-22 17:42 - 000000000 ____D C:\Users\Esteban-Kapy\Desktop\FRST-OlderVersion
2018-10-21 21:10 - 2018-10-15 23:48 - 000559880 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-10-21 21:04 - 2018-10-22 18:03 - 000000000 ____D C:\Users\Esteban-Kapy\Desktop\LIMPIADORES
2018-10-21 21:02 - 2018-10-21 21:02 - 000260384 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-10-21 20:58 - 2018-10-21 20:58 - 000000000 ____D C:\Users\Esteban-Kapy\AppData\Local\mbamtray
2018-10-21 20:58 - 2018-10-21 20:58 - 000000000 ____D C:\Users\Esteban-Kapy\AppData\Local\mbam
2018-10-21 20:58 - 2018-10-21 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-10-21 20:58 - 2018-10-21 20:58 - 000000000 ____D C:\Program Files\Malwarebytes
2018-10-21 20:58 - 2018-09-11 13:18 - 000152688 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-10-21 20:56 - 2018-10-21 20:56 - 000004128 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-10-21 20:56 - 2018-10-21 20:56 - 000002800 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-10-21 20:56 - 2018-10-21 20:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-10-21 20:56 - 2018-10-21 20:56 - 000000000 ____D C:\Program Files\CCleaner
2018-10-11 15:56 - 2018-09-18 07:52 - 025735168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-10-11 15:56 - 2018-09-18 07:25 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-10-11 15:56 - 2018-09-18 07:14 - 005779456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-10-11 15:56 - 2018-09-18 07:14 - 000794624 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-10-11 15:56 - 2018-09-18 06:49 - 001033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-10-11 15:56 - 2018-09-18 06:42 - 000809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-10-11 15:56 - 2018-09-18 06:39 - 015283712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-10-11 15:56 - 2018-09-18 06:35 - 004510720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-10-11 15:56 - 2018-09-18 06:33 - 020278784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-10-11 15:56 - 2018-09-18 06:23 - 001555968 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-10-11 15:56 - 2018-09-18 06:21 - 000497664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-10-11 15:56 - 2018-09-18 06:13 - 000662016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-10-11 15:56 - 2018-09-18 06:10 - 000800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-10-11 15:56 - 2018-09-18 05:57 - 004494848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-10-11 15:56 - 2018-09-18 05:55 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-10-11 15:56 - 2018-09-18 05:53 - 013679616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-10-11 15:56 - 2018-09-18 05:51 - 000696320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-10-11 15:56 - 2018-09-18 05:37 - 004037632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-10-11 15:56 - 2018-09-18 05:34 - 001330176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-10-11 15:56 - 2018-09-18 05:31 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-10-11 15:56 - 2018-09-18 02:26 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2018-10-11 15:56 - 2018-09-11 18:38 - 004168704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2018-10-11 15:56 - 2018-09-08 22:53 - 002532552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-10-11 15:56 - 2018-09-08 20:40 - 007372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-10-11 15:56 - 2018-09-08 20:40 - 002014136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-10-11 15:56 - 2018-09-08 20:33 - 001368776 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2018-10-11 15:56 - 2018-09-08 20:22 - 001737696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-10-11 15:56 - 2018-09-08 20:22 - 001676152 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-10-11 15:56 - 2018-09-08 20:22 - 001536216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-10-11 15:56 - 2018-09-08 20:22 - 001500528 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-10-11 15:56 - 2018-09-08 20:22 - 001371448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-10-11 15:56 - 2018-09-08 19:58 - 001902936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-10-11 15:56 - 2018-09-08 17:43 - 001085440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2018-10-11 15:56 - 2018-09-08 04:12 - 001549040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-10-11 15:56 - 2018-09-08 04:12 - 000388336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-10-11 15:56 - 2018-09-07 19:39 - 002902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2018-10-11 15:56 - 2018-09-07 18:51 - 002849280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2018-10-11 15:56 - 2018-09-01 18:43 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-10-11 15:56 - 2018-08-29 15:51 - 002451800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-10-11 15:56 - 2018-08-26 06:07 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2018-10-11 15:56 - 2018-08-26 06:07 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2018-10-11 15:56 - 2018-08-26 05:13 - 015441920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-10-11 15:56 - 2018-08-26 05:08 - 013321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-10-11 15:56 - 2018-08-14 21:04 - 004171264 _____ (Gracenote, Inc.) C:\WINDOWS\SysWOW64\gnsdk_fp.dll
2018-10-11 15:56 - 2018-08-12 22:25 - 000149632 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-10-11 15:56 - 2018-08-12 19:07 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-10-11 15:56 - 2018-08-12 18:32 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-10-11 15:56 - 2018-08-12 16:21 - 001633008 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-10-11 15:56 - 2018-08-09 15:16 - 004876800 _____ (Gracenote, Inc.) C:\WINDOWS\system32\gnsdk_fp.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-10-22 18:03 - 2018-04-08 19:30 - 000000000 ___DC C:\FRST
2018-10-22 17:49 - 2018-08-13 20:08 - 000000000 ____D C:\Users\Esteban-Kapy\AppData\Local\CrashDumps
2018-10-22 16:06 - 2012-07-26 09:59 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-10-21 22:51 - 2018-03-25 12:39 - 000003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2366818653-3867854855-1377537276-1001
2018-10-21 21:32 - 2018-03-27 10:18 - 000000000 ____D C:\Users\Esteban-Kapy\OneDrive
2018-10-21 21:32 - 2018-03-25 13:19 - 000009421 _____ C:\Users\Esteban-Kapy\Documents\poesia.txt
2018-10-21 21:10 - 2013-08-22 15:25 - 000262144 ___SH C:\WINDOWS\system32\config\ELAM
2018-10-21 21:02 - 2018-03-25 12:56 - 000000000 __SHD C:\Users\Esteban-Kapy\IntelGraphicsProfiles
2018-10-21 21:01 - 2013-08-22 16:45 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-10-21 21:01 - 2013-08-22 15:25 - 000262144 ___SH C:\WINDOWS\system32\config\BBI
2018-10-21 20:58 - 2018-07-26 11:11 - 000024064 ___SH C:\Users\Esteban-Kapy\Desktop\Thumbs.db
2018-10-21 20:58 - 2018-03-25 13:11 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-10-21 20:57 - 2018-06-04 18:13 - 000000000 ____D C:\Users\Esteban-Kapy\AppData\Roaming\PhotoScape
2018-10-21 20:57 - 2018-03-27 10:48 - 000000000 ___DC C:\WINDOWS\Panther
2018-10-21 20:57 - 2013-08-22 15:36 - 000000000 ____D C:\WINDOWS\Inf
2018-10-21 20:52 - 2018-03-25 12:39 - 000000000 ____D C:\ProgramData\AVAST Software
2018-10-19 10:56 - 2018-03-13 08:25 - 000000000 ___DC C:\AdwCleaner
2018-10-17 08:34 - 2018-03-25 13:19 - 000000000 ____D C:\Users\Esteban-Kapy\Documents\MI EXCEL
2018-10-12 16:07 - 2013-08-22 17:36 - 000000000 ____D C:\WINDOWS\rescache
2018-10-11 19:48 - 2013-08-22 16:44 - 000362832 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-10-11 16:35 - 2018-03-27 00:10 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-10-11 16:31 - 2018-03-27 00:10 - 136745976 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-10-10 16:57 - 2018-06-27 07:26 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-10-07 13:13 - 2018-07-08 20:05 - 001586688 ___SH C:\Users\Esteban-Kapy\Downloads\Thumbs.db
2018-10-02 19:59 - 2018-09-14 15:00 - 000835152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-10-02 19:59 - 2018-09-14 15:00 - 000179792 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-09-22 19:01 - 2018-06-27 07:26 - 000004476 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-10-15 09:45

==================== End of FRST.txt ============================

#14
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.10.2018
Ran by Esteban-Kapy (22-10-2018 18:04:05)
Running from C:\Users\Esteban-Kapy\Desktop\LIMPIADORES
Windows 8.1 (Update) (X64) (2018-03-27 08:16:28)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-2366818653-3867854855-1377537276-500 - Administrator - Disabled)
Esteban-Kapy (S-1-5-21-2366818653-3867854855-1377537276-1001 - Administrator - Enabled) => C:\Users\Esteban-Kapy
HomeGroupUser$ (S-1-5-21-2366818653-3867854855-1377537276-1005 - Limited - Enabled)
Invitado (S-1-5-21-2366818653-3867854855-1377537276-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 19.008.20074 - Adobe Systems Incorporated)
CCleaner (HKLM\...\CCleaner) (Version: 5.47 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.3.2.2140 - CDBurnerXP)
Free Mp3 Wma Converter V 1.9 (HKLM-x32\...\Free Mp3 Wma Converter_is1) (Version: 1.9.0.1 - Koyote Soft)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 69.0.3497.100 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Malwarebytes versión 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MixMeister Pro 6 (HKLM-x32\...\{6FF6CE46-2F27-4A4B-916F-AB1C678C8F5E}) (Version: 6.0.3.0 - MixMeister Technology LLC)
OpenOffice 4.1.5 (HKLM-x32\...\{A93E0F8F-B3C1-4784-916D-15865808017B}) (Version: 4.15.9789 - Apache Software Foundation)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Revo Uninstaller 2.0.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.5 - VS Revo Group, Ltd.)
Songr (HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\...\Songr) (Version: 2.1 - Xamasoft)
WinRAR 5.50 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-2366818653-3867854855-1377537276-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2015-08-27] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02972180-D0DF-44C7-984C-06F18CF78237} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-19] (Piriform Ltd)
Task: {2C0C1EF3-7A01-4426-B5F8-9C93AF5FB99B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated)
Task: {5AEE5FE6-574C-4800-8FC5-28B17F14D997} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-19] (Piriform Ltd)
Task: {5DEBD1B2-F50B-40AF-B25F-2F041C159619} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {73DC501C-09D0-4BE1-94C1-359AF06874C7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-01] (Google Inc.)
Task: {A0EC9227-0C4C-4273-8786-17F1B3197090} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-01] (Google Inc.)
Task: {C66CFCD9-E3C3-46A9-9421-14AA72BBF2F4} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-10-06] (AVAST Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-04-20 10:39 - 2010-03-04 23:38 - 000071096 _____ () C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
2018-10-21 20:58 - 2018-09-12 11:35 - 002701064 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-09-19 10:13 - 2018-09-19 10:13 - 000095168 _____ () C:\Program Files\CCleaner\lang\lang-1034.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Esteban-Kapy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{2830B3D4-3908-4826-87FD-EFE1144203C7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{86E2F304-FEA6-4DEF-AB7A-CE830C1EFFBB}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{3CEE9FD6-CDB5-4CD8-AB9C-853D9A2551E0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe

==================== Restore Points =========================

07-10-2018 10:39:26 Revo Uninstaller's restore point - Ration Mix 2013 versión rev 3
11-10-2018 16:27:17 Windows Update
21-10-2018 15:55:05 Punto de control programado
21-10-2018 20:42:16 Revo Uninstaller's restore point - Malwarebytes versión 3.5.1.2522
21-10-2018 20:45:19 Revo Uninstaller's restore point - Avast Free Antivirus
21-10-2018 21:03:13 JRT Pre-Junkware Removal
22-10-2018 18:01:12 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/22/2018 05:49:01 PM) (Source: ESENT) (EventID: 454) (User: )
Description: DllHost (5224) WebCacheLocal: Error inesperado al recuperar o restaurar la base de datos -1032.

Error: (10/22/2018 05:49:01 PM) (Source: ESENT) (EventID: 490) (User: )
Description: DllHost (5224) WebCacheLocal: Al intentar abrir el archivo "C:\Users\Esteban-Kapy\AppData\Local\Microsoft\Windows\WebCache\V01.log" para acceso de lectura y escritura se produjo el error de sistema 32 (0x00000020): "El proceso no tiene acceso al archivo porque está siendo utilizado por otro proceso. ". La operación para abrir el archivo se cerrará con el error -1032 (0xfffffbf8).

Error: (10/22/2018 05:48:51 PM) (Source: ESENT) (EventID: 490) (User: )
Description: DllHost (5224) WebCacheLocal: Al intentar abrir el archivo "C:\Users\Esteban-Kapy\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" para acceso de lectura y escritura se produjo el error de sistema 32 (0x00000020): "El proceso no tiene acceso al archivo porque está siendo utilizado por otro proceso. ". La operación para abrir el archivo se cerrará con el error -1032 (0xfffffbf8).

Error: (10/21/2018 09:25:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: mbam.exe, versión: 3.1.0.1614, marca de tiempo: 0x5b9bcc2b
Nombre del módulo con errores: Qt5Core.dll, versión: 5.11.1.0, marca de tiempo: 0x5b9bc256
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0019d749
Identificador del proceso con errores: 0x10ac
Hora de inicio de la aplicación con errores: 0x01d46973cd50be41
Ruta de acceso de la aplicación con errores: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Ruta de acceso del módulo con errores: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
Identificador del informe: 0c1a31fb-d567-11e8-be96-902b34bc8a3b
Nombre completo del paquete con errores: 
Identificador de aplicación relativa del paquete con errores:

Error: (10/21/2018 08:42:14 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al consultar la interfaz IVssWriterCallback. HR = 0x80070005, Acceso denegado.
.
A menudo ocurre por una configuración de seguridad incorrecta en el proceso de escritura o de solicitud.


Operación:
   Recopilando datos del escritor

Contexto:
   Id. de clase del escritor: {e8132975-6f93-4464-a53e-1050253ae220}
   Nombre del escritor: System Writer
   Id. de instancia del escritor: {438f3ae8-e1a6-4e26-bad7-c676d18ec6c5}

Error: (10/07/2018 10:39:25 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al consultar la interfaz IVssWriterCallback. HR = 0x80070005, Acceso denegado.
.
A menudo ocurre por una configuración de seguridad incorrecta en el proceso de escritura o de solicitud.


Operación:
   Recopilando datos del escritor

Contexto:
   Id. de clase del escritor: {e8132975-6f93-4464-a53e-1050253ae220}
   Nombre del escritor: System Writer
   Id. de instancia del escritor: {a332beb4-fdf0-40c7-bfc6-6cac2efb82b8}

Error: (10/07/2018 10:33:09 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa mbam.exe, versión 3.1.0.1594, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: d24

Hora de inicio: 01d45e17f9b4097d

Hora de finalización: 5

Ruta de acceso de la aplicación: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe

Identificador de informe: 8dca922d-ca0b-11e8-be92-902b34bc8a3b

Nombre completo de paquete con errores: 

Identificador de aplicación relativa del paquete con errores:

Error: (10/04/2018 02:53:55 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa LiveComm.exe, versión 17.5.9600.22013, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: a0

Hora de inicio: 01d45b0617706deb

Hora de finalización: 4294967295

Ruta de acceso de la aplicación: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe\LiveComm.exe

Identificador de informe: f2e9c9d1-c76f-11e8-be91-902b34bc8a3b

Nombre completo de paquete con errores: microsoft.windowscommunicationsapps_17.5.9600.22013_x64__8wekyb3d8bbwe

Identificador de aplicación relativa del paquete con errores: ppleae38af2e007f4358a809ac99a64a67c1


System errors:
=============
Error: (10/22/2018 06:02:06 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/22/2018 06:02:05 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/22/2018 02:56:59 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/22/2018 02:56:57 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/22/2018 02:48:44 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/22/2018 02:48:42 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/21/2018 09:04:54 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (10/21/2018 09:04:52 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.


Windows Defender:
===================================
Date: 2018-10-21 21:22:59.200
Description: 
Windows Defender detectó un comportamiento sospechoso.
Nombre: Informational:Behavior/ModifiedKernel
Id.: 2301077074
Gravedad: Baja
Categoría: Comportamiento sospechoso
Ruta de acceso encontrada: process:_0
Origen de detección: Desconocido
Tipo de detección: Sospechoso
Fuente de detección: Protección en tiempo real
Estado: Ejecutando
Usuario: Unknown\Unknown
Nombre de proceso: Unknown
Id. de firma: 717259538435
Versión de firma: AV: 1.279.236.0, AS: 1.279.236.0
Versión de motor: 1.1.15400.4
Etiqueta de fidelidad:  Bajo
Nombre de archivo de destino:  

Date: 2018-10-21 20:49:43.935
Description: 
Windows Defender encontró un error al intentar cargar firmas e intentará revertirlas a un conjunto de firmas conocidas.
Firmas intentadas: Actual
Código de error: 0x80073aba
Descripción del error: El recurso es demasiado antiguo para ser compatible. 
Versión de firma: 1.155.266.0;1.155.266.0
Versión de motor: 1.1.9700.0

CodeIntegrity:
===================================

Date: 2018-08-29 03:50:31.042
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.917
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.777
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.652
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.527
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.407
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.283
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

Date: 2018-08-29 03:50:30.163
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wow64.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 30%
Total physical RAM: 3987.84 MB
Available physical RAM: 2789.36 MB
Total Virtual: 5971.84 MB
Available Virtual: 4665.7 MB

==================== Drives ================================

Drive c: (DJ KAPY) (Fixed) (Total:464.98 GB) (Free:427.55 GB) NTFS
Drive i: (DJKAPY) (Removable) (Total:14.4 GB) (Free:14.09 GB) FAT32

\\?\Volume{69d6522f-3016-11e8-be66-806e6f6e6963}\ (Reservado para el sistema) (Fixed) (Total:0.34 GB) (Free:0.04 GB) NTFS
\\?\Volume{69d65231-3016-11e8-be66-806e6f6e6963}\ () (Fixed) (Total:0.44 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 14.4 GB) (Disk ID: 5D30CA24)
Partition 1: (Not Active) - (Size=14.4 GB) - (Type=0C)

==================== End of Addition.txt ============================

#15

perdona ,pero en estos temas no ando muy puesto,gracias por el interes,saludos¡¡¡


#16

Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\...\ChromeHTML: -> <==== ATTENTION
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {5DEBD1B2-F50B-40AF-B25F-2F041C159619} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {73DC501C-09D0-4BE1-94C1-359AF06874C7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-01] (Google Inc.)
Task: {A0EC9227-0C4C-4273-8786-17F1B3197090} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-01] (Google Inc.)
Task: {C66CFCD9-E3C3-46A9-9421-14AA72BBF2F4} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-10-06] (AVAST Software)
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\WINDOWS\System32\drivers\zamguard64.sys [X]
2018-10-21 20:52 - 2018-03-25 12:39 - 000000000 ____D C:\ProgramData\AVAST Software
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.


#17

gracias,encuanto tenga libre lo hago y te comento,nuevamente gracias¡¡¡


#18

Muy buenas javi,realize todo lo que me citaste y na de nada compañero,te adjunto el informe ,gracias de todos modos,un saludo.

-Fix result of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
Ran by Esteban-Kapy (26-10-2018 18:47:40) Run:1
Running from C:\Users\Esteban-Kapy\Desktop
Loaded Profiles: Esteban-Kapy (Available Profiles: Esteban-Kapy)
Boot Mode: Normal
==============================================

fixlist content:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\...\ChromeHTML: -> <==== ATTENTION
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {5DEBD1B2-F50B-40AF-B25F-2F041C159619} - \Microsoft\Windows\Setup\EOSNotify -> No File <==== ATTENTION
Task: {73DC501C-09D0-4BE1-94C1-359AF06874C7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-01] (Google Inc.)
Task: {A0EC9227-0C4C-4273-8786-17F1B3197090} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-04-01] (Google Inc.)
Task: {C66CFCD9-E3C3-46A9-9421-14AA72BBF2F4} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-10-06] (AVAST Software)
S1 ZAM; \??\C:\WINDOWS\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\WINDOWS\System32\drivers\zamguard64.sys [X]
2018-10-21 20:52 - 2018-03-25 12:39 - 000000000 ____D C:\ProgramData\AVAST Software
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Restore point was successfully created.
Processes closed successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent" => removed successfully
HKU\S-1-5-21-2366818653-3867854855-1377537276-1001_Classes\ChromeHTML => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5DEBD1B2-F50B-40AF-B25F-2F041C159619}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5DEBD1B2-F50B-40AF-B25F-2F041C159619}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\EOSNotify" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{73DC501C-09D0-4BE1-94C1-359AF06874C7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73DC501C-09D0-4BE1-94C1-359AF06874C7}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A0EC9227-0C4C-4273-8786-17F1B3197090}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0EC9227-0C4C-4273-8786-17F1B3197090}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C66CFCD9-E3C3-46A9-9421-14AA72BBF2F4}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C66CFCD9-E3C3-46A9-9421-14AA72BBF2F4}" => removed successfully
C:\WINDOWS\System32\Tasks\Avast Software\Overseer => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => removed successfully
HKLM\System\CurrentControlSet\Services\ZAM => removed successfully
ZAM => service removed successfully
HKLM\System\CurrentControlSet\Services\ZAM_Guard => removed successfully
ZAM_Guard => service removed successfully
C:\ProgramData\AVAST Software => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-2366818653-3867854855-1377537276-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


Adaptador de Ethernet Ethernet:

   Sufijo DNS espec¡fico para la conexi¢n. . : Home
   V¡nculo: direcci¢n IPv6 local. . . : fe80::f573:592e:b07f:b1e%3
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.1.128
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.1.1

Adaptador de t£nel isatap.Home:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : Home

========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.7.9600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= End of CMD: =========


========= netsh int ipv4 reset =========

Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Interfaz se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 21313586 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 3338107 B
Edge => 0 B
Chrome => 638463054 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 24182 B
Esteban-Kapy => 14043325 B

RecycleBin => 2500170 B
EmptyTemp: => 656.2 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:52:37 ====

#19

Hola.

Perdona el retraso, se me paso la notificación de este tema. :roll_eyes:

Ahora vas a descargar desde este enlace la versión de Chrome en castellano :arrow_right: https://www.google.com/intl/es/chrome/?standalone=1

Una vez lo tengas instalado REINICIAS el equipo y nos comentas resultados.

Saludos.


#20

Muy buenas javi,arreglado…gracias por tu ayuda ,tiempo y paciencia,un abrazo bro¡¡¡