Hace unos días mi PC se puso terriblemente lenta

Fixlog Parte 2:

====== Final 1 Folder: ======

C:\WINDOWS\zwjvhcytwbc => movido correctamente
C:\WINDOWS\xibfo.dat => movido correctamente
C:\WINDOWS\uivgphjr => movido correctamente
C:\WINDOWS\tzhdw => movido correctamente
C:\WINDOWS\togl => movido correctamente
C:\WINDOWS\tnlcyha => movido correctamente
C:\WINDOWS\SysWOW64\zzmbkjttcv.ini => movido correctamente
C:\WINDOWS\SysWOW64\zyowns => movido correctamente
C:\WINDOWS\SysWOW64\zyadeizbstq.ini => movido correctamente
C:\WINDOWS\SysWOW64\zxykwvw => movido correctamente
C:\WINDOWS\SysWOW64\zxntsmpkns => movido correctamente
C:\WINDOWS\SysWOW64\zxlhpcxet => movido correctamente
C:\WINDOWS\SysWOW64\zvybg => movido correctamente
C:\WINDOWS\SysWOW64\zvxxfsps => movido correctamente
C:\WINDOWS\SysWOW64\zvxuplfqaiv.dat => movido correctamente
C:\WINDOWS\SysWOW64\zufsomdnqb => movido correctamente
C:\WINDOWS\SysWOW64\zprns => movido correctamente
C:\WINDOWS\SysWOW64\zph => movido correctamente
C:\WINDOWS\SysWOW64\znubd => movido correctamente
C:\WINDOWS\SysWOW64\zmulmsalvp.ini => movido correctamente
C:\WINDOWS\SysWOW64\zmpm.dat => movido correctamente
C:\WINDOWS\SysWOW64\zlvlgaoro.dat => movido correctamente
C:\WINDOWS\SysWOW64\zkvadtmlfi => movido correctamente
C:\WINDOWS\SysWOW64\zkgl => movido correctamente
C:\WINDOWS\SysWOW64\zhbezzk.ini => movido correctamente
C:\WINDOWS\SysWOW64\zgtn.dat => movido correctamente
C:\WINDOWS\SysWOW64\zgdzvuq => movido correctamente
C:\WINDOWS\SysWOW64\zfxbo => movido correctamente
C:\WINDOWS\SysWOW64\zerryde => movido correctamente
C:\WINDOWS\SysWOW64\zdo => movido correctamente
C:\WINDOWS\SysWOW64\zbu.ini => movido correctamente
C:\WINDOWS\SysWOW64\zayfbnltwb => movido correctamente
C:\WINDOWS\SysWOW64\yzvlitevcp => movido correctamente
C:\WINDOWS\SysWOW64\yztg.dat => movido correctamente
C:\WINDOWS\SysWOW64\ywjmsytb => movido correctamente
C:\WINDOWS\SysWOW64\ywcotf.ini => movido correctamente
C:\WINDOWS\SysWOW64\yueiza => movido correctamente
C:\WINDOWS\SysWOW64\yrvdebxgrzt => movido correctamente
C:\WINDOWS\SysWOW64\yruogei.ini => movido correctamente
C:\WINDOWS\SysWOW64\yqwnxmuqkr.ini => movido correctamente
C:\WINDOWS\SysWOW64\yqjwaqwjrgn => movido correctamente
C:\WINDOWS\SysWOW64\ypwgam => movido correctamente
C:\WINDOWS\SysWOW64\ypn => movido correctamente
C:\WINDOWS\SysWOW64\ypb => movido correctamente
C:\WINDOWS\SysWOW64\ynbpico.ini => movido correctamente
C:\WINDOWS\SysWOW64\yjbyky => movido correctamente
C:\WINDOWS\SysWOW64\yifbtom => movido correctamente
C:\WINDOWS\SysWOW64\yhvfljhx => movido correctamente
C:\WINDOWS\SysWOW64\yft.ini => movido correctamente
C:\WINDOWS\SysWOW64\yfguqg.dat => movido correctamente
C:\WINDOWS\SysWOW64\yfddtyco.ini => movido correctamente
C:\WINDOWS\SysWOW64\yeubbz => movido correctamente
C:\WINDOWS\SysWOW64\yeqc.ini => movido correctamente
C:\WINDOWS\SysWOW64\ybnso => movido correctamente
C:\WINDOWS\SysWOW64\ybcwdcj.ini => movido correctamente
C:\WINDOWS\SysWOW64\yajdu => movido correctamente
C:\WINDOWS\SysWOW64\yacxpunyz => movido correctamente
C:\WINDOWS\SysWOW64\xxfxt => movido correctamente
C:\WINDOWS\SysWOW64\xwolbkcl => movido correctamente
C:\WINDOWS\SysWOW64\xwfjdkdtixu => movido correctamente
C:\WINDOWS\SysWOW64\xuyoohmb => movido correctamente
C:\WINDOWS\SysWOW64\xsdi => movido correctamente
C:\WINDOWS\SysWOW64\xrjnqaxgslz => movido correctamente
C:\WINDOWS\SysWOW64\xrjmwls.ini => movido correctamente
C:\WINDOWS\SysWOW64\xratz.ini => movido correctamente
C:\WINDOWS\SysWOW64\xogeiasqdx => movido correctamente
C:\WINDOWS\SysWOW64\xnrwoffi.ini => movido correctamente
C:\WINDOWS\SysWOW64\xnaaiqyn => movido correctamente
C:\WINDOWS\SysWOW64\xlaoaq => movido correctamente
C:\WINDOWS\SysWOW64\xkiazoygsu.dat => movido correctamente
C:\WINDOWS\SysWOW64\xivldzk => movido correctamente
C:\WINDOWS\SysWOW64\xitroqxj.dat => movido correctamente
C:\WINDOWS\SysWOW64\xhxj.ini => movido correctamente
C:\WINDOWS\SysWOW64\xhliavnncf.ini => movido correctamente
C:\WINDOWS\SysWOW64\xhjvdk => movido correctamente
C:\WINDOWS\SysWOW64\xhi.dat => movido correctamente
C:\WINDOWS\SysWOW64\xhepiahgu.ini => movido correctamente
C:\WINDOWS\SysWOW64\xfor.dat => movido correctamente
C:\WINDOWS\SysWOW64\xei.ini => movido correctamente
C:\WINDOWS\SysWOW64\xdu.dat => movido correctamente
C:\WINDOWS\SysWOW64\xdnu => movido correctamente
C:\WINDOWS\SysWOW64\xbwudob.ini => movido correctamente
C:\WINDOWS\SysWOW64\xbeumyws.ini => movido correctamente
C:\WINDOWS\SysWOW64\xabxrnwognq.ini => movido correctamente
C:\WINDOWS\SysWOW64\wztapis.ini => movido correctamente
C:\WINDOWS\SysWOW64\wvpmojcpagc.ini => movido correctamente
C:\WINDOWS\SysWOW64\wvmaql.ini => movido correctamente
C:\WINDOWS\SysWOW64\wuienx.ini => movido correctamente
C:\WINDOWS\SysWOW64\wtkvqxla.ini => movido correctamente
C:\WINDOWS\SysWOW64\wriuwbh => movido correctamente
C:\WINDOWS\SysWOW64\wrfmrz => movido correctamente
C:\WINDOWS\SysWOW64\wqnbogohpa => movido correctamente
C:\WINDOWS\SysWOW64\wpushbesv => movido correctamente
C:\WINDOWS\SysWOW64\wpa => movido correctamente
C:\WINDOWS\SysWOW64\wooq => movido correctamente
C:\WINDOWS\SysWOW64\wnzrlwgymia => movido correctamente
C:\WINDOWS\SysWOW64\wnwpuad => movido correctamente
C:\WINDOWS\SysWOW64\wnwis => movido correctamente
C:\WINDOWS\SysWOW64\wmsxmgb => movido correctamente
C:\WINDOWS\SysWOW64\wmcwjfwebcg.dat => movido correctamente
C:\WINDOWS\SysWOW64\wmcbsqz => movido correctamente
C:\WINDOWS\SysWOW64\wmaeoulj.ini => movido correctamente
C:\WINDOWS\SysWOW64\wltgfaapaxg => movido correctamente
C:\WINDOWS\SysWOW64\wlagsxpfnjc => movido correctamente
C:\WINDOWS\SysWOW64\wkaig => movido correctamente
C:\WINDOWS\SysWOW64\wjjkwjxof.dat => movido correctamente
C:\WINDOWS\SysWOW64\wjd.ini => movido correctamente
C:\WINDOWS\SysWOW64\wio => movido correctamente
C:\WINDOWS\SysWOW64\winwis => movido correctamente
C:\WINDOWS\SysWOW64\wgjy => movido correctamente
C:\WINDOWS\SysWOW64\wgfzxqxc.dat => movido correctamente
C:\WINDOWS\SysWOW64\wgekhz => movido correctamente
C:\WINDOWS\SysWOW64\wchut => movido correctamente
C:\WINDOWS\SysWOW64\wbyqcoru => movido correctamente
C:\WINDOWS\SysWOW64\vylysjgigsp => movido correctamente
C:\WINDOWS\SysWOW64\vydky => movido correctamente
C:\WINDOWS\SysWOW64\vxamvnvecd => movido correctamente
C:\WINDOWS\SysWOW64\vwx.ini => movido correctamente
C:\WINDOWS\SysWOW64\vwvpxtf.dat => movido correctamente
C:\WINDOWS\SysWOW64\vuzy.ini => movido correctamente
C:\WINDOWS\SysWOW64\vutlo => movido correctamente
C:\WINDOWS\SysWOW64\vtccpjjxhbl.ini => movido correctamente
C:\WINDOWS\SysWOW64\vrt => movido correctamente
C:\WINDOWS\SysWOW64\vrb => movido correctamente
C:\WINDOWS\SysWOW64\vqzkhuu => movido correctamente
C:\WINDOWS\SysWOW64\vpymgh.ini => movido correctamente
C:\WINDOWS\SysWOW64\vlzenqzgwi => movido correctamente
C:\WINDOWS\SysWOW64\vlv => movido correctamente
C:\WINDOWS\SysWOW64\vltbvctcek => movido correctamente
C:\WINDOWS\SysWOW64\vlhw => movido correctamente
C:\WINDOWS\SysWOW64\vky.dat => movido correctamente
C:\WINDOWS\SysWOW64\vhuya => movido correctamente
C:\WINDOWS\SysWOW64\vhgdwwy.ini => movido correctamente
C:\WINDOWS\SysWOW64\vgkauki => movido correctamente
C:\WINDOWS\SysWOW64\vexcv.ini => movido correctamente
C:\WINDOWS\SysWOW64\vekhfmquvd.dat => movido correctamente
C:\WINDOWS\SysWOW64\vedcfvtun => movido correctamente
C:\WINDOWS\SysWOW64\vcwbqe => movido correctamente
C:\WINDOWS\SysWOW64\uykjvcews => movido correctamente
C:\WINDOWS\SysWOW64\uvhkeoo.dat => movido correctamente
C:\WINDOWS\SysWOW64\uuknvmo.ini => movido correctamente
C:\WINDOWS\SysWOW64\usbsjhq => movido correctamente
C:\WINDOWS\SysWOW64\urupvqobgah => movido correctamente
C:\WINDOWS\SysWOW64\urfoeuqrrvx => movido correctamente
C:\WINDOWS\SysWOW64\upwhfcfpq => movido correctamente
C:\WINDOWS\SysWOW64\upqsk.dat => movido correctamente
C:\WINDOWS\SysWOW64\umckcky => movido correctamente
C:\WINDOWS\SysWOW64\umblkiu => movido correctamente
C:\WINDOWS\SysWOW64\ukqsipcp => movido correctamente
C:\WINDOWS\SysWOW64\ujurc => movido correctamente
C:\WINDOWS\SysWOW64\ujupkolaxz.ini => movido correctamente
C:\WINDOWS\SysWOW64\ujmb => movido correctamente
C:\WINDOWS\SysWOW64\ujemlvpjgb => movido correctamente
C:\WINDOWS\SysWOW64\uilhoi.dat => movido correctamente
C:\WINDOWS\SysWOW64\uhgxcxne.ini => movido correctamente
C:\WINDOWS\SysWOW64\ugh.ini => movido correctamente
C:\WINDOWS\SysWOW64\udixx.ini => movido correctamente
C:\WINDOWS\SysWOW64\ubomomrwsdk.dat => movido correctamente
C:\WINDOWS\SysWOW64\uaqqwmjt.ini => movido correctamente
C:\WINDOWS\SysWOW64\txkpazbbtc => movido correctamente
C:\WINDOWS\SysWOW64\tvumtdvg => movido correctamente
C:\WINDOWS\SysWOW64\tviuuwtwvs => movido correctamente
C:\WINDOWS\SysWOW64\tubh.ini => movido correctamente
C:\WINDOWS\SysWOW64\tttpgilubhz.ini => movido correctamente
C:\WINDOWS\SysWOW64\trpcwzo => movido correctamente
C:\WINDOWS\SysWOW64\trjhziwhqax => movido correctamente
C:\WINDOWS\SysWOW64\tqkrkktdw => movido correctamente
C:\WINDOWS\SysWOW64\tplabizkfi => movido correctamente
C:\WINDOWS\SysWOW64\tparier => movido correctamente
C:\WINDOWS\SysWOW64\tmksiwyo.ini => movido correctamente
C:\WINDOWS\SysWOW64\tmiduq => movido correctamente
C:\WINDOWS\SysWOW64\tmhmpisgrjb => movido correctamente
C:\WINDOWS\SysWOW64\tjerrruiu.ini => movido correctamente
C:\WINDOWS\SysWOW64\tixbprzs.dat => movido correctamente
C:\WINDOWS\SysWOW64\tgysztaa.ini => movido correctamente
C:\WINDOWS\SysWOW64\tgp.dat => movido correctamente
C:\WINDOWS\SysWOW64\teatwcjgoq => movido correctamente
C:\WINDOWS\SysWOW64\tcu.ini => movido correctamente
C:\WINDOWS\SysWOW64\szanch.dat => movido correctamente
C:\WINDOWS\SysWOW64\sxngztzr => movido correctamente
C:\WINDOWS\SysWOW64\swucw => movido correctamente
C:\WINDOWS\SysWOW64\swrosmstc.ini => movido correctamente
C:\WINDOWS\SysWOW64\swmx.dat => movido correctamente
C:\WINDOWS\SysWOW64\svh.dat => movido correctamente
C:\WINDOWS\SysWOW64\surl.ini => movido correctamente
C:\WINDOWS\SysWOW64\strlohjio => movido correctamente
C:\WINDOWS\SysWOW64\sthnpbr.ini => movido correctamente
C:\WINDOWS\SysWOW64\srt.ini => movido correctamente
C:\WINDOWS\SysWOW64\srceeuuzog => movido correctamente
C:\WINDOWS\SysWOW64\sqrvkkbktxz.dat => movido correctamente
C:\WINDOWS\SysWOW64\sntlrnm.dat => movido correctamente
C:\WINDOWS\SysWOW64\slvwlpnaqo => movido correctamente
C:\WINDOWS\SysWOW64\slfzi.ini => movido correctamente
C:\WINDOWS\SysWOW64\skjqlknoa.ini => movido correctamente
C:\WINDOWS\SysWOW64\skcx.dat => movido correctamente
C:\WINDOWS\SysWOW64\sjzadmi.ini => movido correctamente
C:\WINDOWS\SysWOW64\sjfso => movido correctamente
C:\WINDOWS\SysWOW64\sghtkpu => movido correctamente
C:\WINDOWS\SysWOW64\sfxzlgg => movido correctamente
C:\WINDOWS\SysWOW64\sfsz.dat => movido correctamente
C:\WINDOWS\SysWOW64\sbm => movido correctamente
C:\WINDOWS\SysWOW64\sao => movido correctamente
C:\WINDOWS\SysWOW64\rzyxt => movido correctamente
C:\WINDOWS\SysWOW64\rzuc.ini => movido correctamente
C:\WINDOWS\SysWOW64\rybqxma => movido correctamente
C:\WINDOWS\SysWOW64\rxlxmq => movido correctamente
C:\WINDOWS\SysWOW64\rwwmb => movido correctamente
C:\WINDOWS\SysWOW64\rwumiig => movido correctamente
C:\WINDOWS\SysWOW64\rvitifkhda.ini => movido correctamente
C:\WINDOWS\SysWOW64\ruwy.dat => movido correctamente
C:\WINDOWS\SysWOW64\rumiqlhw.dat => movido correctamente
C:\WINDOWS\SysWOW64\rtssxvscl => movido correctamente
C:\WINDOWS\SysWOW64\rtsquze.dat => movido correctamente
C:\WINDOWS\SysWOW64\rrbddpfknf => movido correctamente
C:\WINDOWS\SysWOW64\rquw => movido correctamente
C:\WINDOWS\SysWOW64\rpz.ini => movido correctamente
C:\WINDOWS\SysWOW64\rnixg => movido correctamente
C:\WINDOWS\SysWOW64\rnaxcorvnpm.ini => movido correctamente
C:\WINDOWS\SysWOW64\rmkgnn.ini => movido correctamente
C:\WINDOWS\SysWOW64\rlxrf => movido correctamente
C:\WINDOWS\SysWOW64\rkdkyehqiv => movido correctamente
C:\WINDOWS\SysWOW64\rjzxhrd => movido correctamente
C:\WINDOWS\SysWOW64\rilkwzwyil.xml => movido correctamente
C:\WINDOWS\SysWOW64\riffaw.ini => movido correctamente
C:\WINDOWS\SysWOW64\rifbww.ini => movido correctamente
C:\WINDOWS\SysWOW64\rhw.dat => movido correctamente
C:\WINDOWS\SysWOW64\rhrrf => movido correctamente
C:\WINDOWS\SysWOW64\rfmfahwb => movido correctamente
C:\WINDOWS\SysWOW64\rfbddh.dat => movido correctamente
C:\WINDOWS\SysWOW64\rex.dat => movido correctamente
C:\WINDOWS\SysWOW64\rckntimj.dat => movido correctamente
C:\WINDOWS\SysWOW64\rbw => movido correctamente
C:\WINDOWS\SysWOW64\rbou.dat => movido correctamente
C:\WINDOWS\SysWOW64\rbc => movido correctamente
C:\WINDOWS\SysWOW64\qzegqoobxiy.ini => movido correctamente
C:\WINDOWS\SysWOW64\qxbus.dat => movido correctamente
C:\WINDOWS\SysWOW64\qwdspx => movido correctamente
C:\WINDOWS\SysWOW64\qvt => movido correctamente
C:\WINDOWS\SysWOW64\quqsl => movido correctamente
C:\WINDOWS\SysWOW64\qttwzyei.dat => movido correctamente
C:\WINDOWS\SysWOW64\qswzofzltsi => movido correctamente
C:\WINDOWS\SysWOW64\qsopsnklrnj.dat => movido correctamente
C:\WINDOWS\SysWOW64\qrpcq.dat => movido correctamente
C:\WINDOWS\SysWOW64\qqqt.ini => movido correctamente
C:\WINDOWS\SysWOW64\qqqewpfdl.ini => movido correctamente
C:\WINDOWS\SysWOW64\qqmnchoguw => movido correctamente
C:\WINDOWS\SysWOW64\qpghwlpi.ini => movido correctamente
C:\WINDOWS\SysWOW64\qogqdj => movido correctamente
C:\WINDOWS\SysWOW64\qnretzig.ini => movido correctamente
C:\WINDOWS\SysWOW64\qncintxhpbv => movido correctamente
C:\WINDOWS\SysWOW64\qmlr => movido correctamente
C:\WINDOWS\SysWOW64\qldlx => movido correctamente
C:\WINDOWS\SysWOW64\qjhrojfdm => movido correctamente
C:\WINDOWS\SysWOW64\qhyfrlwcpck => movido correctamente
C:\WINDOWS\SysWOW64\qheefqe.dat => movido correctamente
C:\WINDOWS\SysWOW64\qebywplco => movido correctamente
C:\WINDOWS\SysWOW64\qcyfwezkrw => movido correctamente
C:\WINDOWS\SysWOW64\qcw => movido correctamente
C:\WINDOWS\SysWOW64\qbvhrrhf => movido correctamente
C:\WINDOWS\SysWOW64\qbt => movido correctamente
C:\WINDOWS\SysWOW64\qbqeurlah => movido correctamente
C:\WINDOWS\SysWOW64\qbdvroefxtf.ini => movido correctamente
C:\WINDOWS\SysWOW64\qayekwvmsh => movido correctamente
C:\WINDOWS\SysWOW64\pwlwjlqf => movido correctamente
C:\WINDOWS\SysWOW64\pwalonerzam => movido correctamente
C:\WINDOWS\SysWOW64\pwa => movido correctamente
C:\WINDOWS\SysWOW64\pvsbacopgo.ini => movido correctamente
C:\WINDOWS\SysWOW64\puxozpwjj.dat => movido correctamente
C:\WINDOWS\SysWOW64\ptuhkoey => movido correctamente
C:\WINDOWS\SysWOW64\ptfcgaof.dat => movido correctamente
C:\WINDOWS\SysWOW64\ptcwmepfq.xml => movido correctamente
C:\WINDOWS\SysWOW64\psxulyb.ini => movido correctamente
C:\WINDOWS\SysWOW64\psuezqksw.dat => movido correctamente
C:\WINDOWS\SysWOW64\pqognjycvt.dat => movido correctamente
C:\WINDOWS\SysWOW64\pqjjgvrcrr.ini => movido correctamente
C:\WINDOWS\SysWOW64\ppmurgqnqi => movido correctamente
C:\WINDOWS\SysWOW64\pplmagu.ini => movido correctamente
C:\WINDOWS\SysWOW64\pjtdqi.ini => movido correctamente
C:\WINDOWS\SysWOW64\pjjipw => movido correctamente
C:\WINDOWS\SysWOW64\phcioojd.ini => movido correctamente
C:\WINDOWS\SysWOW64\pgsh => movido correctamente
C:\WINDOWS\SysWOW64\pgmxllhrgl => movido correctamente
C:\WINDOWS\SysWOW64\pffkxpns => movido correctamente
C:\WINDOWS\SysWOW64\pepxq => movido correctamente
C:\WINDOWS\SysWOW64\pefaimbebk.ini => movido correctamente
C:\WINDOWS\SysWOW64\pedcjlq.ini => movido correctamente
C:\WINDOWS\SysWOW64\pdqrcouep => movido correctamente
C:\WINDOWS\SysWOW64\pctk => movido correctamente
C:\WINDOWS\SysWOW64\pcpmvigyknw.dat => movido correctamente
C:\WINDOWS\SysWOW64\pcnbisr => movido correctamente
C:\WINDOWS\SysWOW64\pclkwlz.ini => movido correctamente
C:\WINDOWS\SysWOW64\pbzcnzjjax => movido correctamente
C:\WINDOWS\SysWOW64\pathdekgnl.dat => movido correctamente
C:\WINDOWS\SysWOW64\oylo => movido correctamente
C:\WINDOWS\SysWOW64\oybbndhpat => movido correctamente
C:\WINDOWS\SysWOW64\oxxpcqneqfk.dat => movido correctamente
C:\WINDOWS\SysWOW64\oxsta => movido correctamente
C:\WINDOWS\SysWOW64\ousspnt.ini => movido correctamente
C:\WINDOWS\SysWOW64\ourtunrnnc => movido correctamente
C:\WINDOWS\SysWOW64\otvbczqzr.dat => movido correctamente
C:\WINDOWS\SysWOW64\otorwgb.ini => movido correctamente
C:\WINDOWS\SysWOW64\otngpkqlgc => movido correctamente
C:\WINDOWS\SysWOW64\oqljnan => movido correctamente
C:\WINDOWS\SysWOW64\oqipw => movido correctamente
C:\WINDOWS\SysWOW64\opnaypiuh => movido correctamente
C:\WINDOWS\SysWOW64\opn => movido correctamente
C:\WINDOWS\SysWOW64\oofzxmm.dat => movido correctamente
C:\WINDOWS\SysWOW64\oofsbkfk.ini => movido correctamente
C:\WINDOWS\SysWOW64\oocihv => movido correctamente
C:\WINDOWS\SysWOW64\ooaomuyhvz.ini => movido correctamente
C:\WINDOWS\SysWOW64\onuhfaqdr.dat => movido correctamente
C:\WINDOWS\SysWOW64\omgkwcqmzh => movido correctamente
C:\WINDOWS\SysWOW64\olwz => movido correctamente
C:\WINDOWS\SysWOW64\olvkvxg => movido correctamente
C:\WINDOWS\SysWOW64\olhitsu => movido correctamente
C:\WINDOWS\SysWOW64\olhdsirhbjm.dat => movido correctamente
C:\WINDOWS\SysWOW64\olcfhmx.ini => movido correctamente
C:\WINDOWS\SysWOW64\okbzdweogsf.ini => movido correctamente
C:\WINDOWS\SysWOW64\ojlw => movido correctamente
C:\WINDOWS\SysWOW64\oicryjbsxhd.ini => movido correctamente
C:\WINDOWS\SysWOW64\ohfmfxmgnvd => movido correctamente
C:\WINDOWS\SysWOW64\ogn.ini => movido correctamente
C:\WINDOWS\SysWOW64\ogknbwh.ini => movido correctamente
C:\WINDOWS\SysWOW64\odpeuveeirg => movido correctamente
C:\WINDOWS\SysWOW64\odklrkid => movido correctamente
C:\WINDOWS\SysWOW64\odieozehykz => movido correctamente
C:\WINDOWS\SysWOW64\ocduhsoaeky.ini => movido correctamente
C:\WINDOWS\SysWOW64\obfbsckxiuv => movido correctamente
C:\WINDOWS\SysWOW64\nysjggwyrz => movido correctamente
C:\WINDOWS\SysWOW64\nybrohbe => movido correctamente
C:\WINDOWS\SysWOW64\nvolurg => movido correctamente
C:\WINDOWS\SysWOW64\nvdkhnrqwn => movido correctamente
C:\WINDOWS\SysWOW64\ntpp.ini => movido correctamente
C:\WINDOWS\SysWOW64\nreadmitf => movido correctamente
C:\WINDOWS\SysWOW64\nqxtrw => movido correctamente
C:\WINDOWS\SysWOW64\npx => movido correctamente
C:\WINDOWS\SysWOW64\npuailglpt.dat => movido correctamente
C:\WINDOWS\SysWOW64\noyqt => movido correctamente
C:\WINDOWS\SysWOW64\nnzey => movido correctamente
C:\WINDOWS\SysWOW64\nlzvfpgxhuw.xml => movido correctamente
C:\WINDOWS\SysWOW64\netcd.ini => movido correctamente
C:\WINDOWS\SysWOW64\ndpxrjvfik.dat => movido correctamente
C:\WINDOWS\SysWOW64\narceunvfsr.ini => movido correctamente
C:\WINDOWS\SysWOW64\mzquaye => movido correctamente
C:\WINDOWS\SysWOW64\mxdvmytw.ini => movido correctamente
C:\WINDOWS\SysWOW64\mwzhlh.ini => movido correctamente
C:\WINDOWS\SysWOW64\mwuwz.dat => movido correctamente
C:\WINDOWS\SysWOW64\mvxgdkyrjxt => movido correctamente
C:\WINDOWS\SysWOW64\mvhxlyyr.dat => movido correctamente
C:\WINDOWS\SysWOW64\mvfhxic => movido correctamente
C:\WINDOWS\SysWOW64\msbwl => movido correctamente
C:\WINDOWS\SysWOW64\mrprxeehpe => movido correctamente
C:\WINDOWS\SysWOW64\mpvauzxwdz => movido correctamente
C:\WINDOWS\SysWOW64\mpuqpwyjjoe.ini => movido correctamente
C:\WINDOWS\SysWOW64\mpr => movido correctamente
C:\WINDOWS\SysWOW64\mlfml.ini => movido correctamente
C:\WINDOWS\SysWOW64\mkyszmt => movido correctamente
C:\WINDOWS\SysWOW64\minowwpnhw.dat => movido correctamente
C:\WINDOWS\SysWOW64\mimsxzkfsba => movido correctamente
C:\WINDOWS\SysWOW64\mhymnl.ini => movido correctamente
C:\WINDOWS\SysWOW64\mhefcltipun.ini => movido correctamente
C:\WINDOWS\SysWOW64\mftkul => movido correctamente
C:\WINDOWS\SysWOW64\mfpfkyzrxe => movido correctamente
C:\WINDOWS\SysWOW64\mflohpswrxl.dat => movido correctamente
C:\WINDOWS\SysWOW64\mcrrrdylbyb.dat => movido correctamente
C:\WINDOWS\SysWOW64\mbufohzbd.dat => movido correctamente
C:\WINDOWS\SysWOW64\mbpbf.ini => movido correctamente
C:\WINDOWS\SysWOW64\mbcuyqp => movido correctamente
C:\WINDOWS\SysWOW64\maynwlp.ini => movido correctamente
C:\WINDOWS\SysWOW64\lzjqvgauzfs => movido correctamente
C:\WINDOWS\SysWOW64\lxjydaq.dat => movido correctamente
C:\WINDOWS\SysWOW64\lwohwwxa => movido correctamente
C:\WINDOWS\SysWOW64\lwcnbd.ini => movido correctamente
C:\WINDOWS\SysWOW64\lvzw.dat => movido correctamente
C:\WINDOWS\SysWOW64\lvjfqnrfy.dat => movido correctamente
C:\WINDOWS\SysWOW64\ltm => movido correctamente
C:\WINDOWS\SysWOW64\ltcbbxm => movido correctamente
C:\WINDOWS\SysWOW64\lrwldsbcq => movido correctamente
C:\WINDOWS\SysWOW64\lrotxpqhol => movido correctamente
C:\WINDOWS\SysWOW64\lqya.dat => movido correctamente
C:\WINDOWS\SysWOW64\lqpksm => movido correctamente
C:\WINDOWS\SysWOW64\lptdlhqltgj => movido correctamente
C:\WINDOWS\SysWOW64\lnuzijew => movido correctamente
C:\WINDOWS\SysWOW64\lnm.ini => movido correctamente
C:\WINDOWS\SysWOW64\lmti => movido correctamente
C:\WINDOWS\SysWOW64\lmkwvtfa.ini => movido correctamente
C:\WINDOWS\SysWOW64\lljl => movido correctamente
C:\WINDOWS\SysWOW64\lklnirnii => movido correctamente
C:\WINDOWS\SysWOW64\litvwn => movido correctamente
C:\WINDOWS\SysWOW64\liif.ini => movido correctamente
C:\WINDOWS\SysWOW64\lhlcj.ini => movido correctamente
C:\WINDOWS\SysWOW64\lffhqjpt.dat => movido correctamente
C:\WINDOWS\SysWOW64\lfdwrke => movido correctamente
C:\WINDOWS\SysWOW64\lex.dat => movido correctamente
C:\WINDOWS\SysWOW64\lervczxc => movido correctamente
C:\WINDOWS\SysWOW64\lepkgvz => movido correctamente
C:\WINDOWS\SysWOW64\ldypa => movido correctamente
C:\WINDOWS\SysWOW64\ldna.ini => movido correctamente
C:\WINDOWS\SysWOW64\lbial => movido correctamente
C:\WINDOWS\SysWOW64\kza => movido correctamente
C:\WINDOWS\SysWOW64\kykkyyjuomq => movido correctamente
C:\WINDOWS\SysWOW64\kxfziwiehxe => movido correctamente
C:\WINDOWS\SysWOW64\ktkvvqws.dat => movido correctamente
C:\WINDOWS\SysWOW64\kppamcnflm.dat => movido correctamente
C:\WINDOWS\SysWOW64\kokjkgnayl.dat => movido correctamente
C:\WINDOWS\SysWOW64\knkpjcuzkb => movido correctamente
C:\WINDOWS\SysWOW64\knk.ini => movido correctamente
C:\WINDOWS\SysWOW64\kmgbr => movido correctamente
C:\WINDOWS\SysWOW64\kkxlvn => movido correctamente
C:\WINDOWS\SysWOW64\kkrk.ini => movido correctamente
C:\WINDOWS\SysWOW64\kjvzwobzke.ini => movido correctamente
C:\WINDOWS\SysWOW64\kjvgkvsar => movido correctamente
C:\WINDOWS\SysWOW64\kjj => movido correctamente
C:\WINDOWS\SysWOW64\khzpcmbe => movido correctamente
C:\WINDOWS\SysWOW64\kgqeevfnt.dat => movido correctamente
C:\WINDOWS\SysWOW64\kfzlj => movido correctamente
C:\WINDOWS\SysWOW64\kfkegdfzsmf.dat => movido correctamente
C:\WINDOWS\SysWOW64\kffzqte => movido correctamente
C:\WINDOWS\SysWOW64\kdi => movido correctamente
C:\WINDOWS\SysWOW64\kcd => movido correctamente
C:\WINDOWS\SysWOW64\kblu.ini => movido correctamente
C:\WINDOWS\SysWOW64\kagoeryt => movido correctamente
C:\WINDOWS\SysWOW64\kaddzumq.ini => movido correctamente
C:\WINDOWS\SysWOW64\jxvemnjznu => movido correctamente
C:\WINDOWS\SysWOW64\jxqxva.ini => movido correctamente
C:\WINDOWS\SysWOW64\jvpytddxshm.ini => movido correctamente
C:\WINDOWS\SysWOW64\jvanbm.ini => movido correctamente
C:\WINDOWS\SysWOW64\junn => movido correctamente
C:\WINDOWS\SysWOW64\jtdznq => movido correctamente
C:\WINDOWS\SysWOW64\jsslx => movido correctamente
C:\WINDOWS\SysWOW64\jsgzsb => movido correctamente
C:\WINDOWS\SysWOW64\jscxtijpp.ini => movido correctamente
C:\WINDOWS\SysWOW64\jresfclof => movido correctamente
C:\WINDOWS\SysWOW64\jmpx => movido correctamente
C:\WINDOWS\SysWOW64\jkne => movido correctamente
C:\WINDOWS\SysWOW64\jhvyfmljeob => movido correctamente
C:\WINDOWS\SysWOW64\jfuwpyqkkiu => movido correctamente
C:\WINDOWS\SysWOW64\jfilvhux => movido correctamente
C:\WINDOWS\SysWOW64\jes => movido correctamente
C:\WINDOWS\SysWOW64\jeoc => movido correctamente
C:\WINDOWS\SysWOW64\jecbuzopv.ini => movido correctamente
C:\WINDOWS\SysWOW64\jdlshte => movido correctamente
C:\WINDOWS\SysWOW64\jclas => movido correctamente
C:\WINDOWS\SysWOW64\jazdltqdat.ini => movido correctamente
C:\WINDOWS\SysWOW64\iyao => movido correctamente
C:\WINDOWS\SysWOW64\ixrmyzmuf.ini => movido correctamente
C:\WINDOWS\SysWOW64\ivz.ini => movido correctamente
C:\WINDOWS\SysWOW64\iuzsgndntd => movido correctamente
C:\WINDOWS\SysWOW64\itshnv.ini => movido correctamente
C:\WINDOWS\SysWOW64\ithugwck.dat => movido correctamente
C:\WINDOWS\SysWOW64\isnvgwxvzx.ini => movido correctamente
C:\WINDOWS\SysWOW64\ipldozicq => movido correctamente
C:\WINDOWS\SysWOW64\ipdnxhip => movido correctamente
C:\WINDOWS\SysWOW64\iooy => movido correctamente
C:\WINDOWS\SysWOW64\iobspad => movido correctamente
C:\WINDOWS\SysWOW64\imisiwl.ini => movido correctamente
C:\WINDOWS\SysWOW64\ilppyukvb.ini => movido correctamente
C:\WINDOWS\SysWOW64\ikvd.ini => movido correctamente
C:\WINDOWS\SysWOW64\ikugogpknz => movido correctamente
C:\WINDOWS\SysWOW64\ikitzfwrlzd => movido correctamente
C:\WINDOWS\SysWOW64\ihxkhtew => movido correctamente
C:\WINDOWS\SysWOW64\igy => movido correctamente
C:\WINDOWS\SysWOW64\igwyc => movido correctamente
C:\WINDOWS\SysWOW64\ifwyys => movido correctamente
C:\WINDOWS\SysWOW64\ifvbafbi.dat => movido correctamente
C:\WINDOWS\SysWOW64\ifhfyantlzc => movido correctamente
C:\WINDOWS\SysWOW64\ifh => movido correctamente
C:\WINDOWS\SysWOW64\iecx => movido correctamente
C:\WINDOWS\SysWOW64\idzfxu => movido correctamente
C:\WINDOWS\SysWOW64\iduxw.ini => movido correctamente
C:\WINDOWS\SysWOW64\ict.ini => movido correctamente
C:\WINDOWS\SysWOW64\ibqvywo.ini => movido correctamente
C:\WINDOWS\SysWOW64\iarssnndg => movido correctamente
C:\WINDOWS\SysWOW64\hzooveshuhi => movido correctamente
C:\WINDOWS\SysWOW64\hznd => movido correctamente
C:\WINDOWS\SysWOW64\hxpuo.dat => movido correctamente
C:\WINDOWS\SysWOW64\hxokmtz.ini => movido correctamente
C:\WINDOWS\SysWOW64\hwsfdvw => movido correctamente
C:\WINDOWS\SysWOW64\hvbzrysf => movido correctamente
C:\WINDOWS\SysWOW64\hulemjbpzih.dat => movido correctamente
C:\WINDOWS\SysWOW64\huiqk => movido correctamente
C:\WINDOWS\SysWOW64\htzs.dat => movido correctamente
C:\WINDOWS\SysWOW64\htubwk.ini => movido correctamente
C:\WINDOWS\SysWOW64\htmhmor => movido correctamente
C:\WINDOWS\SysWOW64\hsxps => movido correctamente
C:\WINDOWS\SysWOW64\hrqwp => movido correctamente
C:\WINDOWS\SysWOW64\hrfumedgw.ini => movido correctamente
C:\WINDOWS\SysWOW64\hqwxnfwmq.ini => movido correctamente
C:\WINDOWS\SysWOW64\hqofa => movido correctamente
C:\WINDOWS\SysWOW64\hoboh.dat => movido correctamente
C:\WINDOWS\SysWOW64\hmzimwaq.dat => movido correctamente
C:\WINDOWS\SysWOW64\hiushfclfla.ini => movido correctamente
C:\WINDOWS\SysWOW64\higwf => movido correctamente
C:\WINDOWS\SysWOW64\hhxjfatux.dat => movido correctamente
C:\WINDOWS\SysWOW64\hgu.ini => movido correctamente
C:\WINDOWS\SysWOW64\hgdxppghmnp.dat => movido correctamente
C:\WINDOWS\SysWOW64\hfbtzuzg => movido correctamente
C:\WINDOWS\SysWOW64\hfaptb.dat => movido correctamente
C:\WINDOWS\SysWOW64\hbqnkzjqm.dat => movido correctamente
C:\WINDOWS\SysWOW64\hbduxvmv => movido correctamente
C:\WINDOWS\SysWOW64\gzswrdxw.ini => movido correctamente
C:\WINDOWS\SysWOW64\gxveh.dat => movido correctamente
C:\WINDOWS\SysWOW64\gxiglgpq.ini => movido correctamente
C:\WINDOWS\SysWOW64\gwyphivwam => movido correctamente
C:\WINDOWS\SysWOW64\gwegf.dat => movido correctamente
C:\WINDOWS\SysWOW64\gwcogj => movido correctamente
C:\WINDOWS\SysWOW64\gvsgjc => movido correctamente
C:\WINDOWS\SysWOW64\gtkrjpla => movido correctamente
C:\WINDOWS\SysWOW64\gsztiwpu => movido correctamente
C:\WINDOWS\SysWOW64\gswxesatox.ini => movido correctamente
C:\WINDOWS\SysWOW64\gswssvrjl => movido correctamente
C:\WINDOWS\SysWOW64\gqr => movido correctamente
C:\WINDOWS\SysWOW64\gksspjwk.dat => movido correctamente
C:\WINDOWS\SysWOW64\gjrxn.dat => movido correctamente
C:\WINDOWS\SysWOW64\gityrsbrb => movido correctamente
C:\WINDOWS\SysWOW64\giemuzl.ini => movido correctamente
C:\WINDOWS\SysWOW64\ghgeryzg => movido correctamente
C:\WINDOWS\SysWOW64\ghdvcccqxcv.ini => movido correctamente
C:\WINDOWS\SysWOW64\ggjxmqh.ini => movido correctamente
C:\WINDOWS\SysWOW64\gfgr => movido correctamente
C:\WINDOWS\SysWOW64\gecrm.ini => movido correctamente
C:\WINDOWS\SysWOW64\gdsbvd => movido correctamente
C:\WINDOWS\SysWOW64\gck => movido correctamente
C:\WINDOWS\SysWOW64\gcgii.ini => movido correctamente
C:\WINDOWS\SysWOW64\gbx.ini => movido correctamente
C:\WINDOWS\SysWOW64\gazeenlg => movido correctamente
C:\WINDOWS\SysWOW64\ganwg => movido correctamente
C:\WINDOWS\SysWOW64\fzzu.dat => movido correctamente
C:\WINDOWS\SysWOW64\fyvyvw.ini => movido correctamente
C:\WINDOWS\SysWOW64\fxwpiwys => movido correctamente
C:\WINDOWS\SysWOW64\fxhn => movido correctamente
C:\WINDOWS\SysWOW64\fsopbrrnag => movido correctamente
C:\WINDOWS\SysWOW64\fsjfcnvfjr => movido correctamente
C:\WINDOWS\SysWOW64\frznpwqgbxt => movido correctamente
C:\WINDOWS\SysWOW64\fqat.dat => movido correctamente
C:\WINDOWS\SysWOW64\fonbotjzdzr => movido correctamente
C:\WINDOWS\SysWOW64\fnyj.ini => movido correctamente
C:\WINDOWS\SysWOW64\fnxe.dat => movido correctamente
C:\WINDOWS\SysWOW64\fnwncbqssp.xml => movido correctamente
C:\WINDOWS\SysWOW64\fmlgoxxnn.ini => movido correctamente
C:\WINDOWS\SysWOW64\fkuuzbgv.dat => movido correctamente
C:\WINDOWS\SysWOW64\fjpkjgod => movido correctamente
C:\WINDOWS\SysWOW64\fhsongrcc => movido correctamente
C:\WINDOWS\SysWOW64\fhg => movido correctamente
C:\WINDOWS\SysWOW64\fhagevihj.dat => movido correctamente
C:\WINDOWS\SysWOW64\fcibhhrxsu => movido correctamente
C:\WINDOWS\SysWOW64\ezafudvoiyt.ini => movido correctamente
C:\WINDOWS\SysWOW64\evpk => movido correctamente
C:\WINDOWS\SysWOW64\eswjlbv => movido correctamente
C:\WINDOWS\SysWOW64\erauoi => movido correctamente
C:\WINDOWS\SysWOW64\eqartqwjeg => movido correctamente
C:\WINDOWS\SysWOW64\epvvbcvej => movido correctamente
C:\WINDOWS\SysWOW64\epuzw.ini => movido correctamente
C:\WINDOWS\SysWOW64\eng => movido correctamente
C:\WINDOWS\SysWOW64\eiwxqfsa => movido correctamente
C:\WINDOWS\SysWOW64\ehe.dat => movido correctamente
C:\WINDOWS\SysWOW64\egskehx.ini => movido correctamente
C:\WINDOWS\SysWOW64\egeegu => movido correctamente
C:\WINDOWS\SysWOW64\efwxeovrva => movido correctamente
C:\WINDOWS\SysWOW64\eesejbzog.ini => movido correctamente
C:\WINDOWS\SysWOW64\eebifxejokv => movido correctamente
C:\WINDOWS\SysWOW64\edsljcdivuy.ini => movido correctamente
C:\WINDOWS\SysWOW64\edovnmlhmu.xml => movido correctamente
C:\WINDOWS\SysWOW64\ecqooiby => movido correctamente
C:\WINDOWS\SysWOW64\ebwmf => movido correctamente
C:\WINDOWS\SysWOW64\ebeblkboibi => movido correctamente
C:\WINDOWS\SysWOW64\eafryqglx => movido correctamente
C:\WINDOWS\SysWOW64\dzna => movido correctamente
C:\WINDOWS\SysWOW64\dxrnzku.ini => movido correctamente
C:\WINDOWS\SysWOW64\dtxfol => movido correctamente
C:\WINDOWS\SysWOW64\dqeavzgp.xml => movido correctamente
C:\WINDOWS\SysWOW64\dqajfj.ini => movido correctamente
C:\WINDOWS\SysWOW64\dpfrqyaznoo => movido correctamente
C:\WINDOWS\SysWOW64\dows => movido correctamente
C:\WINDOWS\SysWOW64\dogequdlcho => movido correctamente
C:\WINDOWS\SysWOW64\dmuuqmc.ini => movido correctamente
C:\WINDOWS\SysWOW64\dmtlsnues.dat => movido correctamente
C:\WINDOWS\SysWOW64\dkfd.ini => movido correctamente
C:\WINDOWS\SysWOW64\djzobvavx.ini => movido correctamente
C:\WINDOWS\SysWOW64\dizbniz.xml => movido correctamente
C:\WINDOWS\SysWOW64\dgppwo.dat => movido correctamente
C:\WINDOWS\SysWOW64\dgckkqqq.ini => movido correctamente
C:\WINDOWS\SysWOW64\dfswulgomz.ini => movido correctamente
C:\WINDOWS\SysWOW64\dfol.ini => movido correctamente
C:\WINDOWS\SysWOW64\dfdenbmhi => movido correctamente
C:\WINDOWS\SysWOW64\detwvkklv.ini => movido correctamente
C:\WINDOWS\SysWOW64\defhdp.ini => movido correctamente
C:\WINDOWS\SysWOW64\dbsbm => movido correctamente
C:\WINDOWS\SysWOW64\daltzc => movido correctamente
C:\WINDOWS\SysWOW64\daflhn => movido correctamente
C:\WINDOWS\SysWOW64\cxoab => movido correctamente
C:\WINDOWS\SysWOW64\cwr => movido correctamente
C:\WINDOWS\SysWOW64\ctxnogspj.ini => movido correctamente
C:\WINDOWS\SysWOW64\ctsn => movido correctamente
C:\WINDOWS\SysWOW64\cqbt.ini => movido correctamente
C:\WINDOWS\SysWOW64\cprceg => movido correctamente
C:\WINDOWS\SysWOW64\cntaml.ini => movido correctamente
C:\WINDOWS\SysWOW64\cjsvjsn => movido correctamente
C:\WINDOWS\SysWOW64\cixpn => movido correctamente
C:\WINDOWS\SysWOW64\civwzqm.ini => movido correctamente
C:\WINDOWS\SysWOW64\cheng.ini => movido correctamente
C:\WINDOWS\SysWOW64\cguaohd => movido correctamente
C:\WINDOWS\SysWOW64\cfclssx.ini => movido correctamente
C:\WINDOWS\SysWOW64\cdntf.dat => movido correctamente
C:\WINDOWS\SysWOW64\cbqynozbpo.ini => movido correctamente
C:\WINDOWS\SysWOW64\cbgvboorrjj.dat => movido correctamente
C:\WINDOWS\SysWOW64\cakqt => movido correctamente
C:\WINDOWS\SysWOW64\bzyz.dat => movido correctamente
C:\WINDOWS\SysWOW64\bzkhikmncyf => movido correctamente
C:\WINDOWS\SysWOW64\byoqvakieh.ini => movido correctamente
C:\WINDOWS\SysWOW64\bycuny => movido correctamente
C:\WINDOWS\SysWOW64\bxqecmpfn.ini => movido correctamente
C:\WINDOWS\SysWOW64\bulcyfilrrd.dat => movido correctamente
C:\WINDOWS\SysWOW64\bsxkwl.dat => movido correctamente
C:\WINDOWS\SysWOW64\bsmobir.dat => movido correctamente
C:\WINDOWS\SysWOW64\bpajjydv => movido correctamente
C:\WINDOWS\SysWOW64\bmpedqmgmxo => movido correctamente
C:\WINDOWS\SysWOW64\blxcchdo.dat => movido correctamente
C:\WINDOWS\SysWOW64\bloulzqvnrd => movido correctamente
C:\WINDOWS\SysWOW64\bfsdlrscmiv => movido correctamente
C:\WINDOWS\SysWOW64\betjex.ini => movido correctamente
C:\WINDOWS\SysWOW64\bacdzugy => movido correctamente
C:\WINDOWS\SysWOW64\azuxhafgo.ini => movido correctamente
C:\WINDOWS\SysWOW64\azepwokxctz => movido correctamente
C:\WINDOWS\SysWOW64\ayyyufnvi.ini => movido correctamente
C:\WINDOWS\SysWOW64\axxvniyw => movido correctamente
C:\WINDOWS\SysWOW64\auqopa => movido correctamente
C:\WINDOWS\SysWOW64\auemdu.ini => movido correctamente
C:\WINDOWS\SysWOW64\aso.dat => movido correctamente
C:\WINDOWS\SysWOW64\arsimaqa => movido correctamente
C:\WINDOWS\SysWOW64\arembuqqlhl.ini => movido correctamente
C:\WINDOWS\SysWOW64\aqluxxpvzxz => movido correctamente
C:\WINDOWS\SysWOW64\apluecjxljh.ini => movido correctamente
C:\WINDOWS\SysWOW64\aotnjwxb.xml => movido correctamente
C:\WINDOWS\SysWOW64\alswcpnkwg => movido correctamente
C:\WINDOWS\SysWOW64\alpzadzk => movido correctamente
C:\WINDOWS\SysWOW64\akophcvl => movido correctamente
C:\WINDOWS\SysWOW64\akjgqsepny.ini => movido correctamente
C:\WINDOWS\SysWOW64\ajnzyssdz.dat => movido correctamente
C:\WINDOWS\SysWOW64\ajfm.ini => movido correctamente
C:\WINDOWS\SysWOW64\aihwg => movido correctamente
C:\WINDOWS\SysWOW64\ahlkupje => movido correctamente
C:\WINDOWS\SysWOW64\agd => movido correctamente
C:\WINDOWS\SysWOW64\afocvlmwd => movido correctamente
C:\WINDOWS\SysWOW64\aesvs.dat => movido correctamente
C:\WINDOWS\SysWOW64\adpgegoatcl => movido correctamente
C:\WINDOWS\SysWOW64\aclcvmx.ini => movido correctamente
C:\WINDOWS\SysWOW64\abqj => movido correctamente
C:\WINDOWS\SysWOW64\aaydghedumh => movido correctamente
C:\WINDOWS\rnni.ini => movido correctamente
C:\WINDOWS\refyhravcw.dat => movido correctamente
C:\WINDOWS\qgqkumwr.ini => movido correctamente
C:\WINDOWS\pxluctu.dat => movido correctamente
C:\WINDOWS\pnaphwmzlgp => movido correctamente
C:\WINDOWS\oaap => movido correctamente
C:\WINDOWS\nhs => movido correctamente
C:\WINDOWS\lzuovdq => movido correctamente
C:\WINDOWS\lyi => movido correctamente
C:\WINDOWS\lqrbl => movido correctamente
C:\WINDOWS\kragnbr.dat => movido correctamente
C:\WINDOWS\jnpltjziixr => movido correctamente
C:\WINDOWS\iurduaasebj => movido correctamente
C:\WINDOWS\hihw => movido correctamente
C:\WINDOWS\grgqrvb => movido correctamente
C:\WINDOWS\fas.ini => movido correctamente
C:\WINDOWS\err.ini => movido correctamente
C:\WINDOWS\ejxebk => movido correctamente
C:\WINDOWS\eewo.ini => movido correctamente
C:\WINDOWS\ecisfvuhpa.ini => movido correctamente
C:\WINDOWS\dwbwxg => movido correctamente
C:\WINDOWS\dehidfjtpt => movido correctamente
C:\WINDOWS\cpznhdhikek => movido correctamente
C:\WINDOWS\baxqskha.dat => movido correctamente
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => eliminado correctamente
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => eliminado correctamente
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => eliminado correctamente
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => eliminado correctamente
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WondershareVideoConverterFileOpreation => eliminado correctamente
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => eliminado correctamente
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => eliminado correctamente
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => eliminado correctamente
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => eliminado correctamente
C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Pro Clubs Head.lnk => Acceso directo argumento eliminado correctamente
C:\Windows\System32\Drivers\etc\hosts => movido correctamente
Hosts restaurado correctamente.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente


========= Final 1 RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= Final 1 CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Ethernet 3 mientras los medios
est‚n desconectados.
Error al renovar la interfaz Hamachi: no se puede establecer contacto con el
servidor DHCP. La solicitud super¢ el tiempo de espera.

========= Final 1 CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= Final 1 CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

Unable to connect to BITS - 0x80070422

========= Final 1 CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= Final 1 CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= Final 1 CMD: =========


========= netsh int ipv4 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final 1 CMD: =========


========= netsh int ipv6 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final 1 CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 59839489 B
Java, Flash, Steam htmlcache => 388043733 B
Windows/system/drivers => 13617742 B
Edge => 32256 B
Chrome => 591627494 B
Firefox => 23536321 B
Opera => 393559164 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 73334 B
NetworkService => 73334 B
ALVARO => 62552781 B
DefaultAppPool => 62552781 B

RecycleBin => 0 B
EmptyTemp: => 1.5 GB datos temporales eliminados.

================================


El sistema necesita reiniciarse.

==== Final 1 Fixlog 11:11:08 ====

Referente al problema, las letras se visualizan correctamente y en general está bien rápida la máquina, el único problema que he identificado es que el disco se pone a 100% en algunas ocasiones, a veces bastante seguidas y mientras está en 100% pues la computadora no responde, no sé si sea ya algo físico.

Hola

Descarga Malwarebytes Anti-Rootkit (Beta) y descomprimes el contenido en tu escritorio.

  • Abre la carpeta Mbar, haces doble clic en el archivo Mbar.exe
  • En la ventana que saldrá pulsas en "Next".
  • Pulsar en "Update", y cuando termine en "Next"
  • Ahora inicias el análisis pulsando en el botón "Scan"
  • Al terminar, si existe infección pulsamos en "CleanUp" y si no hay infección pulsamos en ""Exit"

Al terminar busca en la carpeta Mbar, y abres los archivos mbar-log.txt y system-log.txt, nos copias el contenido en la siguiente respuesta y comentas resultados.

Un saludo :bye:

1 me gusta

Hola:

Corrí el programa, adjunto los reportes:

mbar-log:

Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org

Database version:
  main:    v2020.08.30.02
  rootkit: v2020.08.30.02

Windows 10 x64 NTFS
Internet Explorer 11.450.19041.0
ALVARO :: DESKTOP-PR8LE57 [administrator]

30/08/2020 03:32:29
mbar-log-2020-08-30 (03-32-29).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 239742
Time elapsed: 47 minute(s), 21 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)

system-log:

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

Account is Administrative

Internet Explorer version: 11.450.19041.0

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, E:\ DRIVE_FIXED
CPU speed: 1.800000 GHz
Memory total: 8459489280, free: 3333173248

Downloaded database version: v2020.08.30.02
Downloaded database version: v2020.08.30.02
Downloaded database version: v2018.01.20.01
=======================================
Initializing...
Driver version: 4.3.0.15
------------ Kernel report ------------
     08/30/2020 03:32:21
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\System32\drivers\FLTMGR.SYS
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\ksecdd.sys
\SystemRoot\System32\drivers\clipsp.sys
\SystemRoot\System32\drivers\cmimcext.sys
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\ntosext.sys
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\cng.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\WppRecorder.sys
\SystemRoot\system32\drivers\SleepStudyHelper.sys
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\system32\drivers\mssecflt.sys
\SystemRoot\system32\drivers\SgrmAgent.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\tpm.sys
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\system32\drivers\WindowsTrustedRT.sys
\SystemRoot\System32\drivers\IntelTA.sys
\SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\system32\drivers\CEA.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\drivers\wfplwfs.sys
\SystemRoot\system32\DRIVERS\edevmon.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volume.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iorate.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\system32\drivers\filecrypt.sys
\SystemRoot\system32\drivers\tbs.sys
\SystemRoot\system32\DRIVERS\eamonm.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\ehdrv.sys
\??\C:\Program Files\ESET\ESET Security\Modules\em000k_64\1018\em000k_64.dll
\??\C:\Program Files\ESET\ESET Security\Modules\em018k_64\1675\em018k_64.dll
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_62ba5773ba05edee\BasicDisplay.sys
\SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_49a8589f00d970d9\BasicRender.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\CimFS.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afunix.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\epfwwfp.sys
\SystemRoot\system32\DRIVERS\VBoxNetLwf.sys
\SystemRoot\System32\drivers\vwififlt.sys
\SystemRoot\System32\drivers\pacer.sys
\SystemRoot\System32\drivers\ndiscap.sys
\SystemRoot\system32\drivers\netbios.sys
\SystemRoot\System32\drivers\Vid.sys
\SystemRoot\System32\drivers\winhvr.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\system32\DRIVERS\VBoxUSBMon.sys
\SystemRoot\system32\DRIVERS\VBoxDrv.sys
\SystemRoot\System32\Drivers\SCDEmu.SYS
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\gpuenergydrv.sys
\SystemRoot\System32\Drivers\ElbyCDIO.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\drivers\bam.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\System32\drivers\tap0901.sys
\SystemRoot\system32\DRIVERS\Hamdrv.sys
\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys
\SystemRoot\System32\drivers\kdnic.sys
\SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys
\SystemRoot\System32\drivers\CAD.sys
\SystemRoot\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6bb02522ea3fdb0d\igdkmd64.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\system32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\iaLPSS2i_I2C.sys
\SystemRoot\system32\drivers\SpbCx.sys
\SystemRoot\System32\drivers\TeeDriverW8x64.sys
\SystemRoot\System32\DriverStore\FileRepository\nvaci.inf_amd64_5fdb95a41accb3a1\nvlddmkm.sys
\SystemRoot\System32\drivers\RtsPer.sys
\SystemRoot\System32\drivers\rt640x64.sys
\SystemRoot\System32\drivers\Qcamain10x64.sys
\SystemRoot\system32\DRIVERS\wdiwifi.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\System32\drivers\i8042prt.sys
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\System32\drivers\CmBatt.sys
\SystemRoot\System32\drivers\BATTC.SYS
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\drivers\IntcAudioBus.sys
\SystemRoot\System32\drivers\portcls.sys
\SystemRoot\System32\drivers\drmk.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\System32\drivers\iaLPSS2i_GPIO2.sys
\SystemRoot\System32\Drivers\msgpioclx.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\System32\drivers\acpipagr.sys
\SystemRoot\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys
\SystemRoot\system32\drivers\nvvad64v.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\drivers\nvvhci.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys
\SystemRoot\System32\drivers\ScpVBus.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\System32\drivers\USBD.SYS
\SystemRoot\System32\drivers\IntcOED.sys
\SystemRoot\System32\drivers\btfilter.sys
\SystemRoot\System32\drivers\BTHUSB.sys
\SystemRoot\System32\drivers\BTHport.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\drivers\rfcomm.sys
\SystemRoot\System32\drivers\BthEnum.sys
\SystemRoot\System32\drivers\bthpan.sys
\SystemRoot\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\System32\drivers\IntcDAud.sys
\SystemRoot\System32\drivers\BthA2dp.sys
\SystemRoot\System32\drivers\btampm.sys
\SystemRoot\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys
\SystemRoot\System32\drivers\hidbth.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\win32kbase.sys
\SystemRoot\System32\win32kfull.sys
\SystemRoot\System32\drivers\dxgmms2.sys
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\drivers\WUDFRd.sys
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\wcifs.sys
\SystemRoot\system32\drivers\mmcss.sys
\SystemRoot\system32\drivers\msquic.sys
\SystemRoot\system32\drivers\cldflt.sys
\SystemRoot\system32\drivers\mslldp.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\drivers\storqosflt.sys
\SystemRoot\system32\drivers\bindflt.sys
\SystemRoot\system32\drivers\rspndr.sys
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\drivers\ndisuio.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\??\C:\Windows\system32\Drivers\SSPORT.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\drivers\rassstp.sys
\SystemRoot\System32\DRIVERS\NDProxy.sys
\SystemRoot\System32\drivers\AgileVpn.sys
\SystemRoot\System32\drivers\rasl2tp.sys
\SystemRoot\System32\drivers\raspptp.sys
\SystemRoot\System32\DRIVERS\raspppoe.sys
\SystemRoot\System32\DRIVERS\ndistapi.sys
\SystemRoot\System32\drivers\ndiswan.sys
\SystemRoot\System32\drivers\vwifimp.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\system32\drivers\qwavedrv.sys
\??\C:\Program Files\ESET\ESET Security\Modules\em006_64\1222\em006_64.dll
\SystemRoot\System32\drivers\WpdUpFltr.sys
\SystemRoot\System32\drivers\USBSTOR.SYS
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\3A704184.sys
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2020.08.30.02
  rootkit: v2020.08.30.02

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffff9885b1065060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffff9885adf4c940, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffff9885b1065060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xffff9885adeace10, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffff9885adead050, DeviceName: \Device\00000043\, DriverName: \Driver\storahci\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 0

GPT Protective MBR Partition information:

    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

GPT Partition information:

    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 4083428664
    GPT Header CurrentLba = 1 BackupLba 1953525167
    GPT Header FirstUsableLba 34  LastUsableLba 1953525134
    GPT Header Guid ced4cbae-25ba-4881-9ad-d695d1d291ab
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128

    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 4083428664
    Backup GPT header CurrentLba = 1953525167 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 1953525134
    Backup GPT header Guid ced4cbae-25ba-4881-9ad-d695d1d291ab
    Backup GPT header Contains 128 partition entries starting at LBA 1953525135
    Backup GPT header Partition entry size = 128

    Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 3f960ffd-f1c6-4b30-b5f6-43c6f4148def
    FirstLBA 2048  Last LBA 1023999
    Attributes 1
    Partition Name                 Basic data partition

    Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
    Partition ID e2786fe1-d2d8-4296-80ab-cb18d77e187
    FirstLBA 1024000  Last LBA 1228799
    Attributes 0
    Partition Name                 EFI system partition

    GPT Partition 1 is bootable
    Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID 5d9674a9-6be5-4c75-8a77-43a510e28f83
    FirstLBA 1228800  Last LBA 1261567
    Attributes 0
    Partition Name         Microsoft reserved partition

    Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID d9210910-55ec-454f-8df0-7f1cdfe4dbf6
    FirstLBA 1261568  Last LBA 1008617420
    Attributes 0
    Partition Name                 Basic data partition

    Partition 4 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID df48ad85-69c4-4a85-b57d-2cbb471b329
    FirstLBA 1008617472  Last LBA 1009803263
    Attributes 1
    Partition Name                                     

    Partition 5 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID 2062dc35-eb4a-48d7-98ba-9361b86d7886
    FirstLBA 1009805312  Last LBA 1953521663
    Attributes 0
    Partition Name                 Basic data partition

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xffff9885b69c3060, DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffff9885ba0176a0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffff9885b69c3060, DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\disk\
DevicePointer: 0xffff9885b7cedab0, DeviceName: \Device\000000c7\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR3\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 5B28D69F

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 1953519616
    Partition is not bootable
    Partition file system is NTFS

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 1000204883968 bytes
Sector size: 512 bytes

Done!
File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\user32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768)
File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768)
File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768)
File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\combase.dll" is sparse (flags = 32768)
File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768)
File "C:\Windows\System32\version.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768)
File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768)
File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768)
File "C:\Windows\System32\sfc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768)
File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768)
File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wldp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\schannel.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\COREMESSAGING.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768)
File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STATEREPOSITORYPS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768)
File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768)
File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768)
File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\smss.exe" is sparse (flags = 32768)
File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768)
File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768)
File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768)
File "C:\Windows\System32\services.exe" is sparse (flags = 32768)
File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768)
File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768)
File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768)
File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SGRMBROKER.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768)
File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768)
File "C:\Windows\System32\SensApi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msimg32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TEXTSHAPING.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DATAEXCHANGE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWSCODECS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MSSPELLCHECKINGFACILITY.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\UIAUTOMATIONCORE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\oleacc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\hid.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wer.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DWrite.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dxva2.dll" is sparse (flags = 32768)
File "C:\Windows\System32\d3d9.dll" is sparse (flags = 32768)
File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768)
File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768)
File "C:\Windows\System32\umpdc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINSQLITE3.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STORAGE.APPLICATIONDATA.DLL" is sparse (flags = 32768)
File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.450_none_4294d6e08a97344a\GdiPlus.dll" is sparse (flags = 32768)
File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\avrt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MMDevAPI.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rasapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rasman.dll" is sparse (flags = 32768)
File "C:\Windows\System32\daxexec.dll" is sparse (flags = 32768)
File "C:\Windows\System32\APPXDEPLOYMENTCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\fltLib.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CONTAINER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STATEREPOSITORYCORE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\twinapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nlaapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\mscms.dll" is sparse (flags = 32768)
File "C:\Windows\System32\COLORADAPTERCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.UI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWMANAGEMENTAPI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\INPUTHOST.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\EXECMODELCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.GLOBALIZATION.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BCP47mrm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\atlthunk.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DIRECTMANIPULATION.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wpnapps.dll" is sparse (flags = 32768)
File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768)
File "C:\Windows\System32\USERMGRCLI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mf.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mfplat.dll" is sparse (flags = 32768)
File "C:\Windows\System32\RTWorkQ.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MSMPEG2VDEC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DXCore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\COMPPKGSUP.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.MEDIA.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\gpapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wmiclnt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wlanapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\netprofm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\npmproxy.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.NETWORKING.CONNECTIVITY.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mfcore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ksuser.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.APPLICATIONMODEL.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MFCAPTUREENGINE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\devenum.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msdmo.dll" is sparse (flags = 32768)
File "C:\Windows\System32\atl.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MFSENSORGROUP.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\mfc42.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CAPABILITYACCESSMANAGERCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\USERMGRPROXY.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\FRAMESERVERCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\AudioSes.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MFREADWRITE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.MEDIA.DEVICES.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.DEVICES.ENUMERATION.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\STRUCTUREDQUERY.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\RESOURCEPOLICYCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.MEDIA.FACEANALYSIS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\RTMEDIAFRAME.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\perfos.dll" is sparse (flags = 32768)
File "C:\Windows\System32\perfdisk.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINSATAPI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wdmaud.drv" is sparse (flags = 32768)
File "C:\Windows\System32\msacm32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msftedit.dll" is sparse (flags = 32768)
File "C:\Windows\System32\netbios.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FIREWALLAPI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\fwbase.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FWPOLICYIOMGR.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dciman32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\quartz.dll" is sparse (flags = 32768)
File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768)
File "C:\Windows\explorer.exe" is sparse (flags = 32768)
File "C:\Windows\SYSTEMAPPS\SHELLEXPERIENCEHOST_CW5N1H2TXYEWY\SHELLEXPERIENCEHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\SYSTEMAPPS\MICROSOFT.WINDOWS.STARTMENUEXPERIENCEHOST_CW5N1H2TXYEWY\STARTMENUEXPERIENCEHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\SYSTEMAPPS\MICROSOFT.WINDOWS.SEARCH_CW5N1H2TXYEWY\SEARCHAPP.EXE" is sparse (flags = 32768)
File "C:\Windows\SYSTEMAPPS\MICROSOFTWINDOWS.CLIENT.CBS_CW5N1H2TXYEWY\InputApp\TEXTINPUTHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\THUMBCACHE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\slc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\cmdext.dll" is sparse (flags = 32768)
File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768)
File "C:\Windows\System32\credssp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768)
File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Acx01000.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768)
File "C:\Windows\System32\APPVCLIENT.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bindflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\scfilter.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bthenum.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HYPERVIDEO.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\portcfg.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BthMini.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bthport.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BTHUSB.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bttflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\CREDENTIALENROLLMENTMANAGER.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mssecflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbvideo.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBAUDIO.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768)
File "C:\Windows\MICROSOFT.NET\FRAMEWORK64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidbth.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidspi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768)
File "C:\Windows\MICROSOFT.NET\FRAMEWORK64\v3.0\Windows Communication Foundation\SMSVCHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MbbCx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\msquic.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768)
File "C:\Windows\System32\PERCEPTIONSIMULATION\PERCEPTIONSIMULATIONSERVICE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ramdisk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768)
File "C:\Windows\SERVICING\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tsusbhub.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\vds.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Vid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vwifimp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768)
File "C:\Windows\System32\NATURALAUTH.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\AarSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DISPBROKER.DESKTOP.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MICROSOFT.BLUETOOTH.USERSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WALLETSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\ASSIGNEDACCESSMANAGERSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\psmsrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\APPREADINESS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STATEREPOSITORY.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BCASTDVRUSERSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wevtsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CAPTURESERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\XBLAUTHMANAGER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\netman.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cscsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768)
File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CBDHSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768)
File "C:\Windows\System32\BTAGSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BTHAVCTPSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\vac.dll" is sparse (flags = 32768)
File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CAPABILITYACCESSMANAGER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\certprop.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CONSENTUXCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DEVICEACCESS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.DEVICES.PICKER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DiagSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MICROSOFT.GRAPHICS.DISPLAY.DISPLAYENHANCEMENTSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ENTERPRISEAPPMGMTSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768)
File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768)
File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\INSTALLSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\lpasvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768)
File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768)
File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\APHOSTSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\PHONESERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\icsvcext.dll" is sparse (flags = 32768)
File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\PRINTWORKFLOWSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\PUSHTOINSTALL.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768)
File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SCardSvr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\XBLGAMESAVE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\SCDEVICEENUM.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\SEMgrSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SENSORSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.SHAREDPC.ACCOUNTMANAGER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MITIGATIONCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWSUDK.SHELLCOMMON.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\USERDATASERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\usosvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\vaultsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768)
File "C:\Windows\System32\inetsrv\w3logsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WAASMEDICSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wbiosrvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.MANAGEMENT.SERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WPCDESKTOPMONSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768)
File "C:\Users\ALVARO\AppData\Local\Comms\UnistoreDB\store.vol" is sparse (flags = 32768)
File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished

Hola

Cuando realizaste el análisis con UsbFix conectaste un disco externo?

|G:|NTFS|(666GB/931GB)||

Realiza un nuevo análisis de EsetOnline y FRST con el disco externo conectado.

Trae los 3 reportes.

Un saludo

1 me gusta

Hola:

Si, normalmente tengo conectado 1 disco externo, pero tengo 2 y los voy variando dependiendo de qué vaya a utilizar. Solo tengo conectado 1 a la vez.

¿Corro los programas que mencionas con ambos discos conectados? ¿Uno por uno?

Gracias.

Hola

Si, con los dos a la vez.

Un saludo

1 me gusta

Hola:

Corrí ambos programas:

Adjunto los reportes, Eset online:

1/09/2020 03:13:35
Archivos explorados: 975168
Archivos detectados: 20
Archivos desinfectados: 20
Tiempo total de exploración 10:03:23
Estado de la exploración: Finalizado
E:\Desktop\Alvaro\AUDIO\Sound Forge Audio Studio 10.zip	una variante de Win32/Keygen.HU aplicación potencialmente no segura	contenía archivos infectados

E:\Desktop\Alvaro\DMM_v2.5.3.2.rar	una variante de Win32/HackTool.Patcher.CZ aplicación potencialmente no segura	eliminado

E:\Desktop\Alvaro - Disco\Trabajo\Indra\Todo Descargas\winamp5623_full_emusic-7plus_all.exe	Win32/OpenCandy aplicación potencialmente no segura	desinfectado por eliminación

E:\Desktop\Alvaro - Disco\Trabajo\Indra\USB\USB1\IDM.UltraEdit.v13.20.Plus.3.by.Skavenger\Keygen\keygen.exe	una variante de Win32/Keygen.IH aplicación potencialmente no segura	desinfectado por eliminación

E:\Desktop\Alvaro - Disco\Trabajo\Indra\USB\USB1\Todo Downloads\ccsetup322.exe	Win32/Bundled.Toolbar.Google.E aplicación potencialmente no segura	desinfectado por eliminación

E:\Disco Alvaro\Alvaro Escritorio\PDFCreator 0_9_6.rar	Win32/Toolbar.SearchBar.A aplicación potencialmente no deseada,una variante de Win32/Toolbar.Conduit.B aplicación potencialmente no deseada,Win32/Toolbar.Conduit.Y aplicación potencialmente no deseada,está correcto,Win32/Toolbar.Conduit.A aplicación potencialmente no deseada	eliminado

E:\Disco Alvaro\Vieja PC\Moche2\USB Negro\DFX WINAMP\DFX Audio 9.301.rar	una variante de Win32/Bundled.Toolbar.Ask.G aplicación potencialmente no segura,una variante de Win32/Bundled.Toolbar.Ask.A aplicación potencialmente no segura	eliminado

E:\Disco Alvaro\Vieja PC\Programas\Programas2\DFX Audio 9.301.rar	una variante de Win32/Bundled.Toolbar.Ask.G aplicación potencialmente no segura,una variante de Win32/Bundled.Toolbar.Ask.A aplicación potencialmente no segura	eliminado

E:\Disco Alvaro\Vieja PC\Programas\DFX Audio 9.301.rar	una variante de Win32/Bundled.Toolbar.Ask.G aplicación potencialmente no segura,una variante de Win32/Bundled.Toolbar.Ask.A aplicación potencialmente no segura	eliminado

E:\Disco C\Descargas\4nydvd7-programasfullmega.com\Crack\Patch.exe	una variante de Win32/HackTool.Patcher.CQ aplicación potencialmente no segura	desinfectado por eliminación

E:\Disco C\Descargas\hdd+regenerator+v161+repara+sectores+danados+fisicamente+de+tu+disco+duro_10924_i40494802_il345.exe\hdd regenerator v161 repara sectores danados fisicamente de tu disco duro_10924_i40494802_il345.exe.zip	una variante de Win32/Amonetize.DW aplicación potencialmente no deseada	eliminado

E:\Disco C\Descargas\MSSQLS1313-S\MSSQLS1313-S\MSProject Professional 2013 [32-64 bits][Español + Activador] 1 link\HEU_KMS_Activator_EN_v6.1\HEU_KMS_Activator_EN_v6.1.exe	una variante de Win32/HackKMS.AV aplicación potencialmente no segura	desinfectado por eliminación

E:\Disco C\Descargas\MSSQLS1313-S\MSSQLS1313-S.zip	una variante de Win32/HackKMS.AV aplicación potencialmente no segura	contenía archivos infectados

E:\Disco C\Descargas\hdd+regenerator+v161+repara+sectores+danados+fisicamente+de+tu+disco+duro_10924_i40494802_il345.exe.zip	una variante de Win32/Amonetize.DW aplicación potencialmente no deseada	eliminado

E:\Disco C\Descargas\poweiso.rar	Win32/Toolbar.Conduit.R aplicación potencialmente no deseada,una variante de Win32/OpenCandy.A aplicación potencialmente no segura,una variante de Win32/HackTool.Patcher.AD aplicación potencialmente no segura	eliminado

E:\PC Nokia\Guitar Pro 7.0.1 Full Cracked - softasm.com\Guitar Pro 7.0.1 Full Cracked - softasm.com\gp7_hosts_patch.cmd	BAT/HostsChanger.A aplicación potencialmente no segura	desinfectado por eliminación

E:\PC Nokia\USB\Guitar pro 6 Full\Guitar pro 6 Full\Crack\keygen.exe	una variante de Win32/Keygen.PD aplicación potencialmente no segura	desinfectado por eliminación

E:\PC Nokia\USB\HOPE\DVDFab.v9.1.9.6.Multilingual.Cracked-BRD\DVDFab.v9.1.9.6.Multilingual.Cracked-BRD\Patch\Patch.exe	una variante de Win32/HackTool.Patcher.AD aplicación potencialmente no segura	desinfectado por eliminación

E:\PC Nokia\USB\MSProject Professional 2013 [32-64 bits][Español + Activador] 1 link\HEU_KMS_Activator_EN_v6.1\HEU_KMS_Activator_EN_v6.1.exe	una variante de Win32/HackKMS.AV aplicación potencialmente no segura	desinfectado por eliminación

E:\PC Nokia\Guitar Pro 7.0.1 Full Cracked - softasm.com.rar	BAT/HostsChanger.A aplicación potencialmente no segura	eliminado

FRST:

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 29-08-2020
Ejecutado por ALVARO (administrador) sobre DESKTOP-PR8LE57 (Acer Aspire A515-51G) (01-09-2020 13:23:40)
Ejecutado desde C:\Users\ALVARO\Desktop
Perfiles cargados: ALVARO
Platform: Windows 10 Pro Versión 2004 19041.450 (X64) Idioma: Español (México)
Navegador predeterminado: Chrome
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <24>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Krzysztof Kowalczyk -> Krzysztof Kowalczyk) C:\Users\ALVARO\AppData\Local\SumatraPDF\SumatraPDF.exe
(MAGIX Software GmbH -> MAGIX Software GmbH) C:\Program Files (x86)\MAGIX\Music Maker Premium\2017\Online\DM\MxDownloadManager.exe
(MAGIX Software GmbH -> MAGIX Software GmbH) C:\Users\ALVARO\Documents\MAGIX Downloads\Installationsmanager\Vita_Church_Organ_INT_180611_08-11_2_4_0_96.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
(Notepad++ -> Don HO [email protected]) C:\Program Files (x86)\Notepad++\notepad++.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(SAP SE -> SAP, Walldorf) C:\Program Files (x86)\SAP\FrontEnd\SapGui\gneux.exe
Error al acceder al proceso -> MxDownloadManager.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [185648 2020-08-29] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] (Samsung Electronics CO., LTD. -> )
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302392 2020-05-20] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [456160 2018-11-22] (Power Software Limited -> Power Software Ltd)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [710264 2020-06-18] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
HKLM\...\RunOnce: [DEL_ST_CPL] => CMD /C del "C:\Program Files\Realtek\Audio\HDA\ST_CPL.XML" /F
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Run: [AnyDVD] => C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe [8760232 2014-12-23] (SlySoft, Inc. -> SlySoft, Inc.)
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [29271224 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe [5482544 2020-08-17] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Run: [Opera Browser Assistant] => C:\Users\ALVARO\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3126296 2020-08-31] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --no-startup-window /prefetch:5 --flag-switches-begin --flag-switches-end --enable-audio-service-sandbox --flag-switches-begin --flag-switc (la entrada de datos tiene 61 más caracteres).
HKLM\...\Windows x64\Print Processors\ssm4mPC: C:\Windows\System32\spool\prtprocs\x64\ssm4mpc.dll [43520 2014-10-30] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Codename Longhorn DDK provider)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.135\Installer\chrmstp.exe [2020-08-20] (Google LLC -> Google LLC)

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {058AA212-F250-4FCB-818F-89522FD705A3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-11] (Adobe Inc. -> Adobe)
Task: {0D79BD70-1025-4A3F-8BE4-F5050CEA33E9} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {10B7F397-9963-4E1C-8343-A9D462E4858B} - System32\Tasks\RtHDVBg_ASC => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {263F6B06-3DD6-4E00-98C6-95EB7FA9AF73} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {29683DF5-6818-4B3B-A20E-CF79224F93E6} - System32\Tasks\Opera scheduled Autoupdate 1592891224 => C:\Users\ALVARO\AppData\Local\Programs\Opera\launcher.exe [1529880 2020-08-11] (Opera Software AS -> Opera Software)
Task: {3D02EB03-E178-43CC-819C-90F55B0BA95F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24770744 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {4D0CB792-DA48-48E6-9D4A-9A6E11DE02BE} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F13A2A8-0AB7-4159-BE2E-A24CAD18E97B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-12] (Google Inc -> Google Inc.)
Task: {56330C81-3E1D-4694-9D7A-56937820F0FC} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-05] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {56B706DD-3E4B-4926-B23D-134B95F4429B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_414_pepper.exe [1471032 2020-08-11] (Adobe Inc. -> Adobe)
Task: {604F374D-6025-46F4-AB65-4F4A117561AA} - System32\Tasks\Connect => C:\Program Files (x86)\MAGIX\Connect\connect.exe [324680 2017-05-10] (MAGIX Software GmbH -> MAGIX Software GmbH)
Task: {75FCE372-2905-46D0-B80B-4D4BCAE2BB9B} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {782DC247-3E14-42D1-BEB6-FA738DE2AF1A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-08-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {7B8733DE-CA62-464D-BF0F-FD42E1AE379A} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {82E44BE8-DF2B-4FAB-9734-9A991BAEC7D0} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9A2759EA-3143-4B1C-AA42-85FE7689A774} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302880 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AC010295-FFE5-4B4E-881E-37028A54793D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {B5E9F576-B797-45AD-BC9B-07570353B1B6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [653848 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D0E28E6C-A2C5-48E7-865B-2D24525419FB} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {DE0DB8EA-1B4B-4D32-A99F-CAC44450F280} - System32\Tasks\Opera scheduled assistant Autoupdate 1592891242 => C:\Users\ALVARO\AppData\Local\Programs\Opera\launcher.exe [1529880 2020-08-11] (Opera Software AS -> Opera Software)
Task: {E9425140-8B1F-44F5-98B3-BBCB0840F2F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-12] (Google Inc -> Google Inc.)
Task: {ECC251F7-CABC-4E6A-9AA1-85BEF570D4BC} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {F2DC7DD6-649F-451E-80AB-B5DAD5AB3C9C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1336400 2020-07-08] (Adobe Inc. -> Adobe Inc.)
Task: {F76DE41E-36F9-46B1-ACE7-259C8FC790BE} - System32\Tasks\Agent Activation Runtime\S-1-5-21-2743258333-1936799210-4253938688-1001 => C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe [13312 2020-07-04] (Microsoft Windows -> )
Task: {FBEAB300-9F33-449B-AC33-EB77A65D0855} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [3617568 2020-03-06] (Realtek Semiconductor Corp. -> Realtek Semiconductor)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\WINDOWS\Tasks\Connect.job => C:\Program Files (x86)\MAGIX\Connect\connect.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Tcpip\..\Interfaces\{052e2aed-e38b-49cb-bcc4-4317366c9abb}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{4b417baf-8770-4328-ba49-b1329901b5e0}: [NameServer] 8.8.4.4,8.8.8.8
Tcpip\..\Interfaces\{85b86b09-bfbe-4b5e-b82b-34acd1f8167b}: [DhcpNameServer] 192.168.42.129

Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_261\bin\ssv.dll [2020-08-02] (Oracle America, Inc. -> Oracle Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_261\bin\jp2ssv.dll [2020-08-02] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\ssv.dll [2020-07-14] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\jp2ssv.dll [2020-07-14] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files (x86)\sap\frontend\sapgui\saphtmlp.dll [2016-06-22] (SAP SE -> SAP, Walldorf)
Handler-x32: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files (x86)\sap\frontend\sapgui\saphtmlp.dll [2016-06-22] (SAP SE -> SAP, Walldorf)

Edge: 
======
Edge Profile: C:\Users\ALVARO\AppData\Local\Microsoft\Edge\User Data\Default [2020-08-21]
Edge HomePage: Default -> hxxp://www.google.com.pe/

FireFox:
========
FF DefaultProfile: 83lk43z0.default
FF ProfilePath: C:\Users\ALVARO\AppData\Roaming\Mozilla\Firefox\Profiles\83lk43z0.default [2020-08-21]
FF NewTab: Mozilla\Firefox\Profiles\83lk43z0.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10440__200105
FF ProfilePath: C:\Users\ALVARO\AppData\Roaming\Mozilla\Firefox\Profiles\4z1dmuk3.default-release-1581371286710 [2020-08-21]
FF Plugin: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-08-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-08-02] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-01-10] (VideoLAN -> VideoLAN)
FF Plugin-x32: @java.com/DTPlugin,version=11.261.2 -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\dtplugin\npDeployJava1.dll [2020-07-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.261.2 -> C:\Program Files (x86)\Java\jre1.8.0_261\bin\plugin2\npjp2.dll [2020-07-14] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-08-17] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2743258333-1936799210-4253938688-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\ALVARO\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-12] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-2743258333-1936799210-4253938688-1001: SkypeForBusinessPlugin-16.2 -> C:\Users\ALVARO\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin HKU\S-1-5-21-2743258333-1936799210-4253938688-1001: SkypeForBusinessPlugin64-16.2 -> C:\Users\ALVARO\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\npGatewayNpapi-x64.dll [2019-08-03] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-08-17]

Chrome: 
=======
CHR Profile: C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default [2020-09-01]
CHR HomePage: Default -> hxxp://www.google.com.pe/
CHR Session Restore: Default -> está habilitado.
CHR Extension: (Documentos) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-02-12]
CHR Extension: (Google Meet Grid View) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjkegbgpfgpikgkfidhcihhiflbjgfic [2020-05-12]
CHR Extension: (Slinky Elegante) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmanlajnpdncmhfkiccmbgeocgbncfln [2020-05-15]
CHR Extension: (Adobe Acrobat) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-08-21]
CHR Extension: (Pro Clubs Head) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjkagndofdedillnafpbjekcjdmbejab [2020-08-31]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-08-14]
CHR Extension: (AdBlock: el mejor bloqueador de anuncios) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-08-14]
CHR Extension: (Dark theme suite) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikojddbdekpboemgplhbloojlncbpmdd [2020-05-15]
CHR Extension: (Cisco Webex Extension) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2020-06-15]
CHR Extension: (Hangouts de Google) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2019-05-31]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Chrome Media Router) - C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-08-13]
CHR Profile: C:\Users\ALVARO\AppData\Local\Google\Chrome\User Data\System Profile [2020-08-21]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]

Opera: 
=======
OPR Extension: (Google Cast for Education) - C:\Users\ALVARO\AppData\Roaming\Opera Software\Opera Stable\Extensions\bnmgbcehmiinmmlmepibeeflglhbhlea [2020-08-24]
OPR Extension: (Install Chrome Extensions) - C:\Users\ALVARO\AppData\Roaming\Opera Software\Opera Stable\Extensions\kipjbhgniklcnglfaldilecjomjaddfi [2020-06-23]

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

S4 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-08-11] (Adobe Inc. -> Adobe)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2371760 2020-08-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2371760 2020-08-29] (ESET, spol. s r.o. -> ESET)
S4 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6970968 2020-08-18] (Malwarebytes Inc -> Malwarebytes)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2332464 2019-07-24] (Electronic Arts, Inc. -> Electronic Arts)
S4 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3206448 2019-07-24] (Electronic Arts, Inc. -> Electronic Arts)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5097344 2020-08-11] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 VBoxSDS; C:\Program Files\Oracle\VirtualBox\VBoxSDS.exe [690424 2019-01-25] (Oracle Corporation -> Oracle Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2019-12-08] (Microsoft Windows Publisher -> Microsoft Corporation)

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

S3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc. -> SlySoft, Inc.)
S3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc. -> SlySoft, Inc.)
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [158512 2020-08-29] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [106640 2020-08-29] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15800 2019-06-05] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [195976 2020-08-29] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [116488 2020-08-29] (ESET, spol. s r.o. -> ESET)
R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
S3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [49272 2014-12-28] (ManyCam -> Visicom Media Inc.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-08-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-08-21] (Malwarebytes Inc -> Malwarebytes)
S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-28] (ManyCam -> Visicom Media Inc.)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [44976 2019-12-13] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)
S3 uvhid; C:\WINDOWS\System32\drivers\uvhid.sys [28128 2019-08-04] (Unified Intents AB -> Windows (R) Win 7 DDK provider)
S3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [235832 2019-01-28] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [247216 2019-01-28] (Oracle Corporation -> Oracle Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2019-12-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2019-12-08] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2019-12-08] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) ===================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-09-01 13:22 - 2020-09-01 13:23 - 002298880 _____ (Farbar) C:\Users\ALVARO\Desktop\FRST64.exe
2020-09-01 01:13 - 2020-09-01 01:13 - 000000000 ____D C:\Users\ALVARO\Documents\MAGIX Downloads
2020-09-01 01:12 - 2020-09-01 01:12 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Zynaptiq
2020-09-01 01:02 - 2020-09-01 01:13 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\MAGIX
2020-09-01 01:02 - 2020-09-01 01:02 - 000000000 ____D C:\Users\Public\Documents\MAGIX
2020-09-01 01:02 - 2020-09-01 01:02 - 000000000 ____D C:\Users\ALVARO\Documents\MAGIX_MusicEditor
2020-09-01 01:02 - 2020-09-01 01:02 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Xara
2020-09-01 01:02 - 2020-09-01 01:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2020-09-01 00:59 - 2020-09-01 01:12 - 000000000 ___RD C:\Users\ALVARO\Documents\MAGIX
2020-09-01 00:59 - 2020-09-01 01:02 - 000000000 ____D C:\ProgramData\Magix
2020-09-01 00:59 - 2020-09-01 01:00 - 000000000 ____D C:\Program Files (x86)\MAGIX
2020-09-01 00:59 - 2020-09-01 00:59 - 000002808 _____ C:\WINDOWS\system32\Tasks\Connect
2020-09-01 00:59 - 2020-09-01 00:59 - 000000378 _____ C:\WINDOWS\Tasks\Connect.job
2020-09-01 00:59 - 2020-09-01 00:59 - 000000000 ____D C:\ProgramData\simplitec
2020-09-01 00:58 - 2020-09-01 00:58 - 000000000 ____D C:\Program Files (x86)\MSXML 4.0
2020-09-01 00:50 - 2020-09-01 00:50 - 000000000 ____D C:\Users\ALVARO\Downloads\MMMSPKXG5119
2020-09-01 00:48 - 2020-09-01 00:48 - 922566878 _____ C:\Users\ALVARO\Downloads\MMMSPKXG5119.rar
2020-08-31 23:26 - 2020-09-01 00:26 - 922936776 _____ C:\Users\ALVARO\Downloads\MAGIX Music Maker 2017 Premium 24.1.5.119 2018 Tested by Bicfic.com.zip
2020-08-31 23:25 - 2020-08-31 23:25 - 006023320 _____ (MAGIX Software GmbH) C:\Users\ALVARO\Downloads\musicmaker--phS43gKQhUl2BPPmsK.exe
2020-08-31 23:14 - 2020-08-31 23:16 - 068422094 _____ C:\Users\ALVARO\Downloads\lmms-1.2.0-rc6.6933-win64.exe
2020-08-31 23:06 - 2020-08-31 23:06 - 000000000 ____D C:\Users\ALVARO\Downloads\magix-music-maker-29-0-0-13-crack-full-serial-number-late-1598933052
2020-08-31 23:04 - 2020-08-31 23:04 - 004077751 _____ C:\Users\ALVARO\Downloads\magix-music-maker-29-0-0-13-crack-full-serial-number-late-1598933052.zip
2020-08-31 23:04 - 2020-08-31 23:04 - 004077751 _____ C:\Users\ALVARO\Downloads\magix-music-maker-29-0-0-13-crack-full-serial-number-late-1598933035.zip
2020-08-31 22:38 - 2020-08-31 22:41 - 036829951 _____ C:\Users\ALVARO\Downloads\lmms-1-2-2.exe
2020-08-31 16:40 - 2020-08-31 16:40 - 014860896 _____ (ESET spol. s r.o.) C:\Users\ALVARO\Desktop\esetonlinescanner.exe
2020-08-30 03:32 - 2020-08-30 03:32 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3A704184.sys
2020-08-30 03:31 - 2020-08-30 08:32 - 000000000 ____D C:\Users\ALVARO\Desktop\mbar
2020-08-30 03:31 - 2020-08-30 08:32 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2020-08-30 03:29 - 2020-08-30 03:30 - 014178840 _____ (Malwarebytes Corp.) C:\Users\ALVARO\Desktop\mbar-1.10.3.1001.exe
2020-08-26 08:54 - 2020-08-26 08:54 - 000036260 _____ C:\Users\ALVARO\Downloads\Matrícula - Alvaro Villena 1.jpeg
2020-08-24 00:45 - 2020-08-24 00:45 - 000465399 _____ C:\Users\ALVARO\Downloads\Archivo Adjunto.pdf
2020-08-24 00:07 - 2020-08-24 00:07 - 000707102 _____ C:\Users\ALVARO\Downloads\abap101-exercises-beginner-abap-open-source.pdf
2020-08-22 03:09 - 2020-08-22 03:13 - 000000000 ____D C:\Users\ALVARO\Documents\Warcraft III
2020-08-22 02:53 - 2020-08-22 02:53 - 000000970 _____ C:\Users\Public\Desktop\Warcraft III.lnk
2020-08-22 02:53 - 2020-08-22 02:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Warcraft III
2020-08-21 11:04 - 2020-08-22 18:58 - 000000000 ____D C:\Users\ALVARO\AppData\LocalLow\IGDump
2020-08-21 11:00 - 2020-08-21 11:11 - 000105602 _____ C:\Users\ALVARO\Desktop\Fixlog.txt
2020-08-21 10:58 - 2020-08-21 10:58 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2020-08-21 10:57 - 2020-08-21 11:00 - 000247198 _____ C:\WINDOWS\ntbtlog.txt
2020-08-21 10:35 - 2020-08-21 10:35 - 000000036 _____ C:\Users\ALVARO\Desktop\Apagar Windows 8-Iniciar a prueba de fallos.bat
2020-08-21 10:33 - 2020-08-21 10:33 - 000000254 _____ C:\DelFix.txt
2020-08-21 10:33 - 2020-08-21 10:33 - 000000000 ____D C:\WINDOWS\ERUNT
2020-08-20 21:59 - 2020-08-20 21:59 - 000000000 ____D C:\ProgramData\Doctor Web
2020-08-20 21:58 - 2020-09-01 03:14 - 000000000 ____D C:\Users\ALVARO\Desktop\Foro
2020-08-20 21:58 - 2020-08-21 08:20 - 000000000 ____D C:\Users\ALVARO\Doctor Web
2020-08-20 20:56 - 2020-08-20 20:56 - 000000000 ____D C:\ProgramData\SosVirus
2020-08-20 17:37 - 2020-08-20 17:37 - 000002817 _____ C:\Users\ALVARO\Documents\Audio CD1.cue
2020-08-20 17:33 - 2020-08-20 17:37 - 817468176 _____ C:\Users\ALVARO\Documents\Audio CD1.bin
2020-08-20 16:37 - 2020-08-20 16:37 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Longman
2020-08-20 16:37 - 2020-08-20 16:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Longman
2020-08-20 16:36 - 2020-08-20 16:36 - 000000000 ____D C:\Program Files (x86)\Longman
2020-08-20 01:01 - 2020-08-20 01:01 - 000000000 ____D C:\KVRT_Data
2020-08-20 00:11 - 2020-08-20 00:11 - 000002700 _____ C:\Users\ALVARO\Documents\Online_Scanner_200820.txt
2020-08-19 16:41 - 2020-08-19 16:42 - 000002325 _____ C:\Users\ALVARO\Desktop\Google Chrome - Prueba.lnk
2020-08-19 16:28 - 2020-08-19 16:28 - 000006589 _____ C:\Users\ALVARO\Documents\ESTUDIO1.m3u8
2020-08-19 16:27 - 2020-08-31 15:21 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\foobar2000
2020-08-19 16:27 - 2020-08-19 16:27 - 000001186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
2020-08-19 16:27 - 2020-08-19 16:27 - 000000000 ____D C:\Program Files (x86)\foobar2000
2020-08-19 16:25 - 2020-08-19 16:26 - 000000000 ____D C:\Users\ALVARO\AppData\Local\SumatraPDF
2020-08-19 16:25 - 2020-08-19 16:25 - 000002122 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk
2020-08-19 16:25 - 2020-08-19 16:25 - 000002080 _____ C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk
2020-08-19 16:25 - 2020-08-19 16:25 - 000002072 _____ C:\Users\ALVARO\Desktop\SumatraPDF.lnk
2020-08-19 16:24 - 2020-08-19 16:25 - 009380520 _____ (Krzysztof Kowalczyk) C:\Users\ALVARO\Downloads\SumatraPDF-3.2-64-install.exe
2020-08-19 16:24 - 2020-08-19 16:24 - 004425110 _____ (foobar2000.org) C:\Users\ALVARO\Downloads\foobar2000_v1.5.5.exe
2020-08-19 16:24 - 2020-08-19 16:24 - 001447178 _____ (Igor Pavlov) C:\Users\ALVARO\Downloads\7z1900-x64.exe
2020-08-18 22:38 - 2020-08-18 22:38 - 000000112 ___SH C:\bootTel.dat
2020-08-18 16:47 - 2020-08-18 16:48 - 000000299 _____ C:\Users\ALVARO\Desktop\Chequear_ Disco_Windows.bat
2020-08-18 12:36 - 2020-08-18 12:36 - 001710608 _____ C:\Users\ALVARO\Downloads\epm_free_installer.exe
2020-08-18 11:32 - 2020-08-18 11:32 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-08-18 11:32 - 2020-08-18 11:32 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-08-18 11:31 - 2020-08-21 11:27 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-08-18 11:30 - 2020-08-18 11:29 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-08-18 11:30 - 2020-08-18 11:29 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-08-18 11:21 - 2020-08-30 03:32 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-08-18 11:18 - 2020-08-18 11:18 - 002040904 _____ (Malwarebytes) C:\Users\ALVARO\Downloads\MBSetup.exe
2020-08-18 02:12 - 2020-08-20 05:21 - 000051592 _____ C:\Users\ALVARO\Desktop\Addition.txt
2020-08-18 02:09 - 2020-09-01 13:41 - 000026409 _____ C:\Users\ALVARO\Desktop\FRST.txt
2020-08-18 02:08 - 2020-09-01 13:34 - 000000000 ____D C:\FRST
2020-08-18 01:08 - 2020-08-18 01:08 - 000001769 _____ C:\Users\ALVARO\Desktop\MWB.txt
2020-08-18 00:08 - 2020-08-31 16:41 - 000000773 _____ C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2020-08-18 00:08 - 2020-08-31 16:41 - 000000627 _____ C:\Users\ALVARO\Desktop\ESET Online Scanner.lnk
2020-08-18 00:07 - 2020-08-18 00:08 - 014860896 _____ (ESET spol. s r.o.) C:\Users\ALVARO\Downloads\esetonlinescanner.exe
2020-08-17 15:28 - 2020-08-17 15:28 - 000001412 _____ C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
2020-08-15 01:13 - 2020-08-18 01:02 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\ZHP
2020-08-15 01:13 - 2020-08-15 01:13 - 000000000 ____D C:\Users\ALVARO\AppData\Local\ZHP
2020-08-14 22:57 - 2020-08-14 23:15 - 000000000 ____D C:\AdwCleaner
2020-08-14 17:44 - 2020-08-14 17:44 - 000000000 ____D C:\Users\ALVARO\Documents\League of Legends
2020-08-14 17:37 - 2008-07-12 08:18 - 003851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2020-08-14 17:37 - 2008-07-12 08:18 - 001493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2020-08-14 17:37 - 2008-07-12 08:18 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2020-08-14 17:36 - 2020-08-14 17:43 - 000001681 _____ C:\Users\Public\Desktop\League of Legends.lnk
2020-08-14 17:36 - 2020-08-14 17:36 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games
2020-08-14 17:36 - 2020-08-14 17:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2020-08-14 17:35 - 2020-08-14 17:44 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Riot Games
2020-08-14 17:35 - 2020-08-14 17:37 - 000000000 ____D C:\ProgramData\Riot Games
2020-08-14 08:53 - 2020-08-14 08:53 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-08-13 13:58 - 2020-08-14 08:55 - 000000000 ____D C:\WINDOWS\Minidump
2020-08-13 12:43 - 2020-08-13 12:43 - 000000386 _____ C:\Users\ALVARO\advanced_ip_scanner_MAC.bin
2020-08-13 12:43 - 2020-08-13 12:43 - 000000015 _____ C:\Users\ALVARO\advanced_ip_scanner_Comments.bin
2020-08-13 12:43 - 2020-08-13 12:43 - 000000015 _____ C:\Users\ALVARO\advanced_ip_scanner_Aliases.bin
2020-08-13 09:13 - 2020-08-21 11:27 - 000000008 __RSH C:\ProgramData\ntuser.pol
2020-08-13 02:53 - 2020-08-13 02:53 - 000000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2020-08-12 22:31 - 2020-08-18 00:01 - 000000000 ____D C:\Users\ALVARO\AppData\Local\LogMeIn Hamachi
2020-08-12 22:31 - 2020-08-12 22:31 - 000000000 ____D C:\Users\ALVARO\AppData\Local\LogMeIn
2020-08-12 22:31 - 2020-08-12 22:31 - 000000000 ____D C:\ProgramData\LogMeIn
2020-08-12 22:17 - 2020-08-12 22:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2020-08-12 22:17 - 2020-08-12 22:17 - 000000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2020-08-11 22:13 - 2020-08-11 22:13 - 024264704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 018766848 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 004819968 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 004783328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 004307456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 004273664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 003661312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 003547280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 002523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2020-08-11 22:13 - 2020-08-11 22:13 - 002520056 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 002254544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2020-08-11 22:13 - 2020-08-11 22:13 - 002113032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001879488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001818568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001707008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001501000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001423360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001352248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001328936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001225640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001117328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 001014888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000913120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000759784 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2020-08-11 22:13 - 2020-08-11 22:13 - 000756224 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscsvc.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000665256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2020-08-11 22:13 - 2020-08-11 22:13 - 000530440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000441856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WalletService.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2020-08-11 22:13 - 2020-08-11 22:13 - 000423224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000362064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP4SDECD.DLL
2020-08-11 22:13 - 2020-08-11 22:13 - 000343408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP4SDECD.DLL
2020-08-11 22:13 - 2020-08-11 22:13 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\syncutil.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvsievaluator.exe
2020-08-11 22:13 - 2020-08-11 22:13 - 000162616 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvsigpext.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000137016 _____ C:\WINDOWS\system32\HvsiManagementApi.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000083768 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsdefenderapplicationguardcsp.dll
2020-08-11 22:13 - 2020-08-11 22:13 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-08-11 22:13 - 2020-08-11 22:13 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintBrmUi.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 019868160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 018071040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 008229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 007104000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 006406144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 005820416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 004362832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 003859968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-08-11 22:12 - 2020-08-11 22:12 - 002686464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 002422072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 002018632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001980744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001719096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 001506616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001332224 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmclient.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001314616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001264128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 001252864 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 001101312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagCpl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000986624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000945152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmclient.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000930304 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000892928 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000837120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000772608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000685568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000638976 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmscan.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000526848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2020-08-11 22:12 - 2020-08-11 22:12 - 000468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsregcmd.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000465408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srmscan.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServerClient.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000396288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncCenter.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000367416 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Vault.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000360024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000353256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsensorgroup.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000345600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FrameServerClient.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapisrv.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallControlPanel.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BioCredProv.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000271360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Vault.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxpTaskSync.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapisrv.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000247296 _____ (Microsoft Corporation) C:\WINDOWS\system32\tapi32.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000193536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tapi32.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000187904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autoplay.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000176128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercpl.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Dsui.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000146944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\recovery.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000042808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-08-11 22:12 - 2020-08-11 22:12 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2020-08-11 22:12 - 2020-08-11 22:12 - 000020280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 026271744 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 023434752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 008894656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 007754752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 007596032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 005990344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 004880896 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 003333632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-08-11 22:11 - 2020-08-11 22:11 - 001717760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 001557832 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 001309512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-08-11 22:11 - 2020-08-11 22:11 - 001255736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 001233408 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 001221632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 001090560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 001029632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000920904 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000801544 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdcpl.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000743320 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiaservc.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000675640 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2020-08-11 22:11 - 2020-08-11 22:11 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\IESettingSync.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000517976 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000500952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000471600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcIso.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000470528 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasgcw.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000403456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallControlPanel.dll

FRST-2:

2020-08-11 22:11 - 2020-08-11 22:11 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxpTaskSync.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000318464 _____ (Microsoft Corporation) C:\WINDOWS\system32\sti.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000303288 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.FileExplorer.Common.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000254464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000217912 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000215040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000212480 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercpl.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowslivelogin.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000180736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Dsui.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiapi.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpcsp.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdrsvc.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvsetup.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000107368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\compstui.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DafPrintProvider.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiarpc.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ndadmin.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidfdp.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\findnetprinters.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidnsp.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wiatrace.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msidcrl40.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000009281 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2020-08-11 22:11 - 2020-08-11 22:11 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll
2020-08-11 22:11 - 2020-08-11 22:11 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2020-08-11 22:11 - 2020-08-11 22:11 - 000006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 004523520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 003818472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 002744832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-08-11 22:10 - 2020-08-11 22:10 - 002265336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 001616576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 001596464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 001448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 001181200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 001041920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000759296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000722432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000707584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000696760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000675024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-08-11 22:10 - 2020-08-11 22:10 - 000671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000630088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000600376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000583608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000582656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000581576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000528360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000495840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000442680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000402944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-08-11 22:10 - 2020-08-11 22:10 - 000324424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accessibilitycpl.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-08-11 22:10 - 2020-08-11 22:10 - 000195128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000166288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000142008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000139952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000138928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mskeyprotcli.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcl.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenterCPL.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserAccountControlSettings.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcfgutils.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000092960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2020-08-11 22:10 - 2020-08-11 22:10 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unenrollhook.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcacli.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmlocalmanagement.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\acwow64.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCShellCommonProxyStub.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-08-11 22:10 - 2020-08-11 22:10 - 000004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2020-08-11 22:10 - 2020-08-11 22:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 014754816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 007628208 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 006362176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 005420648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 004746752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 004003384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 003913216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 002842112 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 002541056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 002433024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 002202112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001819648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001695216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001370112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001333248 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001314616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 001158656 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2020-08-11 22:09 - 2020-08-11 22:09 - 000971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000943416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000910336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontext.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000904192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000755664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000749960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000747864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000645120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntimewindows.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000630272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\agentactivationruntime.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000614912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.ConversationalAgent.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000611952 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000602184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000589824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000548544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxs.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UiaManager.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000508720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000440120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000387072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShellCommonCommonProxyStub.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000378880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000377856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.FileExplorer.Common.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HrtfApo.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AarSvc.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RADCUI.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000292664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000288152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000264704 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000264192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngctasks.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000248320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiapi.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000202568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatializerApo.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000152576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\control.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvsetup.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.HostName.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000123968 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DafPrintProvider.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcmapi.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000099640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ndadmin.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\findnetprinters.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000061752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GameInput.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardBi.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scfilter.sys
2020-08-11 22:09 - 2020-08-11 22:09 - 000042312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxstrace.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2020-08-11 22:09 - 2020-08-11 22:09 - 000012088 _____ (Microsoft Corporation) C:\WINDOWS\system32\6bea57fb-8dfb-4177-9ae8-42e8b3529933_RuntimeDeviceInstall.dll
2020-08-11 22:09 - 2020-08-11 22:09 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 010925880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 010336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 005056000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 004629312 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 003806720 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 003588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 002994504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 002918728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 002806160 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 002178040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 002023688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001868152 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001777152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001751432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001710080 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001641472 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001472824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 001255424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001044880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001009664 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000986976 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000976680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000912744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000887296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000881624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000876544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000867328 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000827704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 000825864 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000823280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000765408 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000760120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000711680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000706032 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000665600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000660584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxs.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000647992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 000639920 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000636416 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000634240 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasgcw.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMPushRouterCore.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000538440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000517432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000502600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-08-11 22:08 - 2020-08-11 22:08 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000419840 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000417376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000373560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000328704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000295936 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowslivelogin.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000253016 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000227640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000213352 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000195248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000180040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 000172496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000167896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000151864 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcl.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000134984 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserAccountControlSettings.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000118072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\MaintenanceUI.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcfgutils.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidfdp.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000094496 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidnsp.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000064824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmlocalmanagement.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdfLdr.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagnosticdataquery.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmpostprocessevaluator.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDriverRetrievalClient.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000039736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxstrace.exe
2020-08-11 22:08 - 2020-08-11 22:08 - 000033096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys
2020-08-11 22:08 - 2020-08-11 22:08 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000020480 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000017224 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msidcrl40.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-08-11 22:08 - 2020-08-11 22:08 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 006188544 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 003999744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 003867136 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 003843584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 003810816 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-08-11 22:07 - 2020-08-11 22:07 - 003380224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 002587464 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 002450944 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 001805744 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-08-11 22:07 - 2020-08-11 22:07 - 001765376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 001538664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 001504768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MoUsoCoreWorker.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 001496576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 001414144 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 001394552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-08-11 22:07 - 2020-08-11 22:07 - 001323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 001209624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 001197752 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 001095168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000994616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Facilitator.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000881152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-08-11 22:07 - 2020-08-11 22:07 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000524088 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000509248 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2020-08-11 22:07 - 2020-08-11 22:07 - 000405304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000364032 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioCredProv.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000348672 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000321024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\accessibilitycpl.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 000132744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcacli.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-08-11 22:07 - 2020-08-11 22:07 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCShellCommonProxyStub.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-08-11 22:07 - 2020-08-11 22:07 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 008004728 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 007972696 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 006709248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 006192640 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 005858136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 005771904 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 004726784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 003779400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-08-11 22:06 - 2020-08-11 22:06 - 003750400 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 003181056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 003062784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 002947584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-08-11 22:06 - 2020-08-11 22:06 - 002403328 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 002259968 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 002245632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 002242048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 002101248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsudk.shellcommon.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001930200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001766912 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001337168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001197568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001132544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001093432 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001089336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2020-08-11 22:06 - 2020-08-11 22:06 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001059328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001047040 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001024744 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 001019008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000900936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-08-11 22:06 - 2020-08-11 22:06 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000777728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000768512 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000752128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000725608 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000707024 _____ C:\WINDOWS\system32\TextShaping.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000637440 _____ (Microsoft Corporation) C:\WINDOWS\system32\UiaManager.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000609792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000454984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-08-11 22:06 - 2020-08-11 22:06 - 000448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000437760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000401720 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe
2020-08-11 22:06 - 2020-08-11 22:06 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RADCUI.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000381704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000359936 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000269624 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000249672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\XamlTileRender.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mskeyprotcli.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Clipc.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000153600 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-08-11 22:06 - 2020-08-11 22:06 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000116040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-08-11 22:06 - 2020-08-11 22:06 - 000088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000070968 _____ (Microsoft Corporation) C:\WINDOWS\system32\GameInput.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2020-08-11 22:06 - 2020-08-11 22:06 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-08-11 22:06 - 2020-08-11 22:06 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2020-08-11 22:05 - 2020-08-11 22:06 - 000827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.Schema.Shell.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 004582288 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2020-08-11 22:05 - 2020-08-11 22:05 - 003846144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 002103712 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001922048 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001903104 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001763640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001643008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001514496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001277440 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll

FRST-3:

2020-08-11 22:05 - 2020-08-11 22:05 - 001253376 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpasvc.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001184360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 001046528 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001030656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 001030656 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000994304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000938416 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000882176 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000843416 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000781312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000777728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShellCommonCommonProxyStub.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\HrtfApo.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000420464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2020-08-11 22:05 - 2020-08-11 22:05 - 000360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000293176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2020-08-11 22:05 - 2020-08-11 22:05 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApproveChildRequest.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\fcon.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000214840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\control.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmapi.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2020-08-11 22:05 - 2020-08-11 22:05 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssecuser.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000090416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\GPCSEWrapperCsp.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifidatacapabilityhandler.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll
2020-08-11 22:05 - 2020-08-11 22:05 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-08-11 22:05 - 2020-08-11 22:05 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-08-11 22:04 - 2020-08-11 22:04 - 001548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000808248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000678200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000639288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000602424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-08-11 22:04 - 2020-08-11 22:04 - 000472888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000418800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000314168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000215880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2020-08-11 22:04 - 2020-08-11 22:04 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2020-08-11 22:04 - 2020-08-11 22:04 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2020-08-11 22:04 - 2020-08-11 22:04 - 000026600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IntelTA.sys
2020-08-11 21:22 - 2020-07-17 21:22 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-08-11 21:22 - 2020-07-17 21:01 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-08-11 11:08 - 2020-08-11 11:08 - 000002029 _____ C:\Users\ALVARO\Desktop\Frozen Throne.lnk
2020-08-11 11:01 - 2020-08-12 20:24 - 000115155 _____ C:\WINDOWS\War3Unin.dat
2020-08-11 11:01 - 2020-08-11 11:16 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warcraft III
2020-08-11 11:01 - 2020-08-11 11:08 - 000139264 _____ (Blizzard Entertainment) C:\WINDOWS\War3Unin.exe
2020-08-11 11:01 - 2020-08-11 11:08 - 000002829 _____ C:\WINDOWS\War3Unin.pif
2020-08-11 11:00 - 2020-08-22 02:54 - 000000000 ____D C:\Program Files (x86)\Warcraft III
2020-08-11 10:40 - 2020-08-11 10:40 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2020-08-03 19:37 - 2020-08-03 19:37 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLovePDF
2020-08-03 19:36 - 2020-08-03 19:37 - 000544702 _____ C:\Users\ALVARO\Desktop\Conformidad 2do_entregable_DSaldarriaga.pdf
2020-08-03 02:05 - 2020-08-23 22:51 - 000000000 ____D C:\Users\ALVARO\eclipse-workspace
2020-08-03 02:05 - 2020-08-03 02:05 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Eclipse
2020-08-03 02:05 - 2020-08-03 02:05 - 000000000 ____D C:\Users\ALVARO\.tooling
2020-08-03 02:03 - 2020-08-03 02:03 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eclipse
2020-08-03 01:59 - 2020-08-03 01:59 - 000000000 ____D C:\Users\ALVARO\eclipse
2020-08-02 23:32 - 2020-08-23 22:51 - 000000000 ____D C:\Users\ALVARO\.p2
2020-08-02 23:32 - 2020-08-03 02:50 - 000000000 ____D C:\Users\ALVARO\.eclipse
2020-08-02 23:32 - 2020-08-02 23:31 - 000193704 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2020-08-02 22:49 - 2020-08-02 23:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2020-08-02 22:47 - 2020-08-02 23:30 - 000000000 ____D C:\Program Files\Java
2020-08-02 22:44 - 2020-08-02 22:44 - 000000000 ____D C:\Users\ALVARO\AppData\LocalLow\Oracle

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-09-01 13:17 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-09-01 13:10 - 2020-07-04 01:36 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-09-01 12:25 - 2019-02-12 17:54 - 000000000 ____D C:\ProgramData\NVIDIA
2020-09-01 02:05 - 2019-06-12 10:10 - 000000000 ____D C:\Users\ALVARO\AppData\Local\ElevatedDiagnostics
2020-09-01 02:04 - 2020-07-04 02:03 - 000003214 _____ C:\WINDOWS\system32\Tasks\RTKCPL
2020-09-01 02:04 - 2020-07-04 02:03 - 000003206 _____ C:\WINDOWS\system32\Tasks\RtHDVBg_ASC
2020-09-01 02:01 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2020-09-01 00:59 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Help
2020-08-31 23:19 - 2019-08-16 02:11 - 000001148 _____ C:\Users\ALVARO\.lmmsrc.xml
2020-08-31 23:19 - 2019-08-16 02:10 - 000000000 ____D C:\Users\ALVARO\Documents\lmms
2020-08-31 23:18 - 2019-08-16 02:03 - 000000000 ____D C:\Program Files\LMMS
2020-08-31 15:30 - 2019-02-13 01:22 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\vlc
2020-08-31 15:03 - 2020-07-04 02:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-08-31 15:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-08-31 15:02 - 2019-12-07 04:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-08-31 08:32 - 2020-07-04 02:03 - 000004470 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1592891242
2020-08-31 08:31 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-08-31 08:31 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-08-30 23:55 - 2020-03-31 20:01 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\discord
2020-08-30 10:28 - 2020-02-18 16:44 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\obs-studio
2020-08-29 03:56 - 2020-07-08 23:51 - 000106640 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2020-08-29 03:56 - 2018-04-12 16:26 - 000195976 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-08-29 03:56 - 2018-04-12 16:26 - 000158512 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-08-29 03:56 - 2018-04-12 16:26 - 000116488 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-08-29 03:31 - 2020-06-04 03:07 - 000002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-08-29 03:31 - 2020-06-04 03:07 - 000002261 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2020-08-27 21:24 - 2020-07-04 02:03 - 000003580 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-08-27 21:24 - 2020-07-04 02:03 - 000003456 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-08-24 21:05 - 2019-02-13 02:44 - 000000000 ____D C:\Users\ALVARO\AppData\Local\CrashDumps
2020-08-24 13:42 - 2019-02-12 17:38 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Packages
2020-08-23 22:34 - 2019-02-14 05:16 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Battle.net
2020-08-22 22:00 - 2020-04-07 13:45 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\WhatsApp
2020-08-22 14:54 - 2019-02-12 20:54 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-08-22 02:20 - 2019-04-02 18:19 - 000000000 ____D C:\Users\ALVARO\AppData\Local\D3DSCache
2020-08-21 20:15 - 2019-07-21 05:19 - 000000000 ____D C:\Program Files (x86)\Steam
2020-08-21 19:23 - 2019-02-14 05:18 - 000000000 ____D C:\Program Files (x86)\StarCraft
2020-08-21 18:53 - 2019-02-14 05:13 - 000000000 ____D C:\Program Files (x86)\Battle.net
2020-08-21 18:40 - 2019-02-12 17:51 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-08-21 18:39 - 2020-07-04 02:03 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-08-21 11:10 - 2019-11-29 16:18 - 000000000 ____D C:\Users\ALVARO\AppData\LocalLow\Temp
2020-08-21 11:00 - 2019-05-24 03:18 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome
2020-08-21 11:00 - 2018-04-11 18:38 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2020-08-21 10:55 - 2020-07-04 00:38 - 000000000 ____D C:\Users\ALVARO
2020-08-21 08:55 - 2020-04-01 10:05 - 000000000 ____D C:\Users\ALVARO\Documents\Zoom
2020-08-21 08:20 - 2020-04-14 18:01 - 000000000 ____D C:\Program Files (x86)\FreeCodecPack
2020-08-20 16:48 - 2019-02-12 20:59 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-08-20 02:17 - 2020-07-04 02:03 - 000003382 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2743258333-1936799210-4253938688-1001
2020-08-20 02:16 - 2020-07-04 00:38 - 000002370 _____ C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-08-20 02:16 - 2019-02-12 17:41 - 000000000 ___RD C:\Users\ALVARO\OneDrive
2020-08-19 19:59 - 2019-07-11 00:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conjunto de programas de NCH
2020-08-19 19:57 - 2019-02-23 02:28 - 000000000 ____D C:\Program Files (x86)\DVDFab 9
2020-08-18 14:27 - 2020-07-04 01:35 - 000008192 ___SH C:\DumpStack.log.tmp
2020-08-18 12:25 - 2019-02-12 20:50 - 000000000 ____D C:\Users\ALVARO\AppData\Local\NVIDIA Corporation
2020-08-18 11:27 - 2019-02-12 21:09 - 000000000 __SHD C:\Users\ALVARO\IntelGraphicsProfiles
2020-08-18 11:22 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-08-18 11:03 - 2019-09-17 00:08 - 000000000 ____D C:\Users\ALVARO\Downloads\PS2
2020-08-18 10:51 - 2020-04-13 20:44 - 000000000 ____D C:\Users\ALVARO\AppData\Local\jammr
2020-08-18 10:50 - 2020-03-20 00:59 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-08-18 10:50 - 2020-02-10 16:47 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-08-18 09:08 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-08-18 00:31 - 2019-03-27 22:19 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\uTorrent
2020-08-18 00:08 - 2019-02-13 01:40 - 000000000 ____D C:\Users\ALVARO\AppData\Local\ESET
2020-08-17 23:43 - 2020-07-04 01:48 - 002005642 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-08-17 23:43 - 2019-12-07 10:02 - 000859814 _____ C:\WINDOWS\system32\perfh00A.dat
2020-08-17 23:43 - 2019-12-07 10:02 - 000183238 _____ C:\WINDOWS\system32\perfc00A.dat
2020-08-17 23:41 - 2020-07-04 01:35 - 000462976 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-08-17 23:36 - 2019-09-15 14:32 - 000000000 ____D C:\Users\ALVARO\Downloads\Recalbox
2020-08-17 21:43 - 2019-12-29 19:11 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\DS4Windows
2020-08-17 17:50 - 2019-08-14 10:20 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\TeamViewer
2020-08-17 17:50 - 2019-08-14 10:20 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-08-17 17:49 - 2020-04-13 20:08 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2020-08-17 17:44 - 2020-01-31 11:30 - 000000000 ____D C:\Users\ALVARO\AppData\Local\EpicGamesLauncher
2020-08-17 17:22 - 2019-04-19 09:32 - 000000000 ____D C:\Users\ALVARO\Downloads\unecm_y_ff8patch
2020-08-17 15:29 - 2020-07-04 02:03 - 000004222 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1592891224
2020-08-15 11:50 - 2020-01-31 11:39 - 000000000 ____D C:\Program Files\Epic Games
2020-08-14 23:15 - 2020-01-04 20:58 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Lavasoft
2020-08-14 23:15 - 2020-01-04 20:58 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Lavasoft
2020-08-14 23:15 - 2020-01-04 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2020-08-14 23:15 - 2020-01-04 20:58 - 000000000 ____D C:\Program Files (x86)\Lavasoft
2020-08-14 23:15 - 2020-01-04 20:57 - 000000000 ____D C:\ProgramData\Lavasoft
2020-08-14 23:15 - 2019-02-14 09:24 - 000000000 ____D C:\Program Files (x86)\Samsung
2020-08-14 09:09 - 2020-01-02 17:17 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2020-08-14 09:08 - 2019-10-21 17:52 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Guitar Pro 6
2020-08-14 08:53 - 2020-07-04 02:03 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-08-13 02:53 - 2020-07-04 00:37 - 000000000 ____D C:\Users\DefaultAppPool
2020-08-13 02:09 - 2020-05-15 12:27 - 000000000 ____D C:\Users\ALVARO\.fontconfig
2020-08-12 22:45 - 2020-04-07 13:45 - 000000000 ____D C:\Users\ALVARO\AppData\Local\WhatsApp
2020-08-12 03:52 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2020-08-12 03:52 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-08-12 03:52 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2020-08-12 03:52 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-08-12 03:52 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-08-12 03:51 - 2019-12-07 10:05 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-08-12 03:51 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-08-11 22:26 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-08-11 10:31 - 2019-02-12 17:38 - 000000000 ____D C:\Users\ALVARO\AppData\Local\VirtualStore
2020-08-11 09:03 - 2020-07-04 02:03 - 000004628 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-08-11 09:03 - 2020-06-10 05:03 - 004510264 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2020-08-11 09:03 - 2019-12-07 04:18 - 000842296 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-08-11 09:03 - 2019-12-07 04:18 - 000175160 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-08-11 09:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-08-11 09:03 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-08-06 21:26 - 2020-03-31 20:01 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2020-08-06 21:26 - 2020-03-31 20:01 - 000000000 ____D C:\Users\ALVARO\AppData\Local\Discord
2020-08-04 14:34 - 2019-02-13 01:19 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\audacity
2020-08-03 19:38 - 2020-06-01 08:11 - 000000000 ____D C:\Users\ALVARO\AppData\Roaming\ILOVEPDF
2020-08-03 02:05 - 2020-01-06 21:54 - 000000000 ____D C:\Users\ALVARO\.config
2020-08-02 23:32 - 2019-05-26 03:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java

==================== Archivos en la raíz de algunos directorios ========

2019-03-29 12:51 - 2019-03-29 12:51 - 000000032 _____ () C:\Users\ALVARO\AppData\Roaming\CuotasMensuales.cca
2019-04-19 14:28 - 2019-04-19 14:28 - 000000600 _____ () C:\Users\ALVARO\AppData\Roaming\PUTTY.RND
2019-09-15 14:58 - 2019-09-15 14:58 - 000000600 _____ () C:\Users\ALVARO\AppData\Roaming\winscp.rnd
2019-04-19 09:21 - 2019-09-15 23:13 - 000000600 _____ () C:\Users\ALVARO\AppData\Local\PUTTY.RND
2020-03-27 00:36 - 2020-03-27 00:36 - 000000875 _____ () C:\Users\ALVARO\AppData\Local\recently-used.xbel
2019-09-17 00:39 - 2019-09-17 00:39 - 000007602 _____ () C:\Users\ALVARO\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)

==================== Final de FRST.txt ========================

Addition:

Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 29-08-2020
Ejecutado por ALVARO (01-09-2020 13:48:09)
Ejecutado desde C:\Users\ALVARO\Desktop
Windows 10 Pro Versión 2004 19041.450 (X64) (2020-07-04 07:04:46)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-2743258333-1936799210-4253938688-500 - Administrator - Disabled)
ALVARO (S-1-5-21-2743258333-1936799210-4253938688-1001 - Administrator - Enabled) => C:\Users\ALVARO
DefaultAccount (S-1-5-21-2743258333-1936799210-4253938688-503 - Limited - Disabled)
Invitado (S-1-5-21-2743258333-1936799210-4253938688-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2743258333-1936799210-4253938688-504 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Security (Enabled - Up to date) {885D845F-AF19-0124-FECE-FFF49D00F440}
AS: ESET Security (Enabled - Up to date) {333C65BB-8923-0EAA-C47E-C486E687BEFD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

µTorrent (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\uTorrent) (Version: 3.5.5.45704 - BitTorrent Inc.)
Actualización de NVIDIA 38.0.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 38.0.4.0 - NVIDIA Corporation) Hidden
Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 20.012.20043 - Adobe Systems Incorporated)
Adobe Flash Player 10 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 10.0.12.36 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.414 - Adobe)
Amazon Kindle (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Amazon Kindle) (Version: 1.28.0.57030 - Amazon)
Anaconda3 2019.10 (Python 3.7.4 64-bit) (HKLM\...\Anaconda3 2019.10 (Python 3.7.4 64-bit)) (Version: 2019.10 - Anaconda, Inc.)
AnthemScore (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\{0d3a8d8f-1c11-4b32-8dea-0dbcc4e9aef5}) (Version: 1.0.3 - Lunaverus)
AnyDVD (HKLM-x32\...\AnyDVD) (Version: 7.5.5.0 - SlySoft)
Apple Application Support (32 bits) (HKLM-x32\...\{11C4575B-4B32-44D2-A097-D59A00BA60DE}) (Version: 8.5 - Apple Inc.)
Apple Application Support (64 bits) (HKLM\...\{D39B163A-9E12-442C-95E9-33FA5746AB21}) (Version: 8.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C788AE25-3D4E-4D18-811B-3219F778487E}) (Version: 13.5.1.2 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
Arobas Music Guitar Pro 7 (HKLM\...\Guitar Pro 7_is1) (Version: 7.0.1 - Arobas Music)
Audacity 2.3.0 (HKLM-x32\...\Audacity_is1) (Version: 2.3.0 - Audacity Team)
Avidemux VC++ 64bits (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\{c0858d89-a637-42c3-9fdf-1d6ce0a5de90}) (Version: 2.7.3 - Mean)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BluFab 9.1.4.4 (05/06/2014) (HKLM-x32\...\BluFab 9_is1) (Version:  - BluFab Software)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.70 - Piriform)
Cheating-Death 4.33.4 (HKLM-x32\...\Cheating-Death) (Version:  - )
Cisco Packet Tracer 7.2.1 64Bit (HKLM\...\Cisco Packet Tracer 7.2.1 64Bit_is1) (Version:  - Cisco Systems, Inc.)
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
Connect (HKLM-x32\...\MAGIX_connector_is1) (Version: 2.5.1.84 - MAGIX Software GmbH)
Contenido adicional Vita 2 (HKLM\...\{946AF57B-74AA-4F40-AA9A-732438F81D0B}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Counter-Strike 1.6 (HKLM-x32\...\Counter-Strike 1.6_is1) (Version: Counter-Strike 1.6 No Steam - KingSOFT DVD)
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
Dia (sólo eliminar) (HKLM-x32\...\Dia) (Version:  - )
Diagnóstico de impresoras Samsung (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.1.6.02 - Samsung Electronics Co., Ltd.)
Discord (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Discord) (Version: 0.0.307 - Discord Inc.)
Driver Easy 5.6.14 (HKLM\...\DriverEasy_is1) (Version: 5.6.14 - Easeware)
DVDFab 9.1.9.6 (07/04/2015) (HKLM-x32\...\DVDFab 9_is1) (Version:  - Fengtao Software Inc.)
Eines de correcció del Microsoft Office 2016: català (HKLM\...\{90160000-001F-0403-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
ESET Security (HKLM\...\{BEFBE0CD-6723-4D98-8263-9A2C376BC6CD}) (Version: 13.2.18.0 - ESET, spol. s r.o.)
Express Scribe (HKLM-x32\...\Scribe) (Version: 5.63 - NCH Software)
Ferramentas de verificación de Microsoft Office 2016 - Galego (HKLM\...\{90160000-001F-0456-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
FFmpeg (Windows) for Audacity versión 2.2.2 (HKLM-x32\...\{9C7E31E3-017F-434C-AC40-24431A354A1E}_is1) (Version: 2.2.2 - )
FileZilla Client 3.44.2 (HKLM-x32\...\FileZilla Client) (Version: 3.44.2 - Tim Kosse)
foobar2000 v1.5.5 (HKLM-x32\...\foobar2000) (Version: 1.5.5 - Peter Pawlowski)
Free PDF Compressor (HKLM-x32\...\{BFA49A14-EC18-4071-BC13-B43043B09222}_is1) (Version:  - freepdfcompressor.com)
Free Screen Video Recorder (HKLM-x32\...\Free Screen Video Recorder_is1) (Version: 3.0.50.708 - Digital Wave Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 84.0.4147.135 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Herramientas de corrección de Microsoft Office 2016: español (HKLM\...\{90160000-001F-0C0A-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
HxD Hex Editor 2.3 (HKLM\...\HxD_is1) (Version: 2.3 - Maël Hörz)
iLovePDF (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\{51e6afad-9617-499b-8116-04b6fc472cbf}) (Version: - - ILOVEPDF S.L.)
Injected Anti-cheat (HKLM-x32\...\Injected Anti-cheat) (Version: 17.2.0.0 - Alejandro Cortés)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.5018 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{00000070-0210-1034-84C8-B8D95FA3C8C3}) (Version: 21.70.0.3 - Intel Corporation)
iTunes (HKLM\...\{A6D5EE3D-95FC-4CED-8F43-3C9B95D7165F}) (Version: 12.10.7.3 - Apple Inc.)
Java 8 Update 261 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180261F0}) (Version: 8.0.2610.12 - Oracle Corporation)
Java 8 Update 261 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180261F0}) (Version: 8.0.2610.12 - Oracle Corporation)
Java SE Development Kit 8 Update 261 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180261}) (Version: 8.0.2610.12 - Oracle Corporation)
Jubler subtitle editor (HKLM\...\Jubler) (Version:  - www.jubler.org)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
LINE (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\LINE) (Version: 5.19.0.2020 - LINE Corporation)
LMMS 1.2.2 (HKLM-x32\...\LMMS) (Version: 1.2.2 - LMMS Developers)
LogMeIn Hamachi (HKLM-x32\...\{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}) (Version: 2.2.0.633 - LogMeIn, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.633 - LogMeIn, Inc.)
MAGIX Contenido y Soundpools (HKLM-x32\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX Software GmbH)
MAGIX Music Maker Live add-on Soundpools (HKLM\...\{33FC9737-6C22-4900-8B6D-D4B58F3602A1}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Music Maker Live Pads (HKLM\...\{562592A6-D397-452B-A97C-EA3D653F9014}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Music Maker Premium (HKLM\...\{7C0E97DB-B7FF-4248-BA47-4718D1D104A6}) (Version: 24.1.5.119 - MAGIX Software GmbH) Hidden
MAGIX Music Maker Premium (HKLM-x32\...\MX.{7C0E97DB-B7FF-4248-BA47-4718D1D104A6}) (Version: 24.1.5.119 - MAGIX Software GmbH)
MAGIX Music Maker Premium (Synthesizer and effects) (HKLM\...\{36ACE6D3-26DB-41B3-AE7E-33E8573DEEAF}) (Version: 24.0.1.0 - MAGIX Software GmbH) Hidden
MAGIX Music Maker Premium (Synthesizer and effects) (HKLM-x32\...\MX.{36ACE6D3-26DB-41B3-AE7E-33E8573DEEAF}) (Version: 24.0.1.0 - MAGIX Software GmbH)
MAGIX Music Maker Premium (Visuals) (HKLM\...\{1864BD0D-717B-4B1E-891C-124361319786}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Music Maker Premium (Visuals) (HKLM-x32\...\MX.{1864BD0D-717B-4B1E-891C-124361319786}) (Version: 24.0.0.0 - MAGIX Software GmbH)
MAGIX Music Maker Premium add-on Soundpools (HKLM\...\{96A90A53-7A38-459B-9F86-6612D260E066}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Music Maker Standard Soundpools (HKLM\...\{607A869D-A22B-4D50-B50E-E8539075AE4F}) (Version: 24.0.0.0 - MAGIX Software GmbH) Hidden
MAGIX Speed burnR (HKLM\...\{D4FB5477-8465-4E62-ADDA-0C37189E1EE2}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden
MAGIX Speed burnR (HKLM-x32\...\MX.{D4FB5477-8465-4E62-ADDA-0C37189E1EE2}) (Version: 7.0.1.27 - MAGIX Software GmbH)
Malwarebytes version 4.1.2.73 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.2.73 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 85.0.564.41 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.135.29 - )
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\OneDriveSetup.exe) (Version: 20.134.0705.0008 - Microsoft Corporation)
Microsoft Project Professional 2016 (HKLM\...\Office16.PRJPRO) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft redistributable runtime DLLs VS2005 SP1(x86) (HKLM-x32\...\{CEC7A786-A9C8-4EF7-BB59-6518E3B3C878}) (Version: 8.0.50727.4053 - SAP)
Microsoft redistributable runtime DLLs VS2010 SP1 (x86) (HKLM-x32\...\{2385C070-EC26-4AB9-8718-E605C977C0ED}) (Version: 10.0.40219.1 - SAP)
Microsoft Visio Professional 2016 (HKLM\...\Office16.VISPRO) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.25.28508 (HKLM-x32\...\{6913e92a-b64e-41c9-a5e6-cef39207fe89}) (Version: 14.25.28508.3 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
Movavi Video Converter 20 Premium (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Movavi Video Converter 20 Premium) (Version: 20.1.2 - Movavi)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.8.5 - Notepad++ Team)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden
NVIDIA Controlador de gráficos 442.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 442.50 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.20.2.34 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.2.34 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 24.0.3 - OBS Project)
OpenBoard (1.5.4.240) (HKLM-x32\...\{8CCA6AC7-BBF9-4DD2-8E70-A907E0FCA38F}}_is1) (Version: 1.5.4.240 - Open Education Foundation)
Opera Stable 70.0.3728.106 (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Opera 70.0.3728.106) (Version: 70.0.3728.106 - Opera Software)
Oracle VM VirtualBox 6.0.4 (HKLM\...\{79366295-CD6A-4467-9901-4A7DFCF90F40}) (Version: 6.0.4 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.43.28287 - Electronic Arts, Inc.)
Panel de control de NVIDIA 442.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 442.50 - NVIDIA Corporation) Hidden
PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version:  - )
PowerISO (HKLM-x32\...\PowerISO) (Version: 7.3 - Power Software Ltd)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8907.1 - Realtek Semiconductor Corp.)
REAPER (x64) (HKLM\...\REAPER) (Version:  - )
Revisores de Texto do Microsoft Office 2016 – Português (Brasil) (HKLM\...\{90160000-001F-0416-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.05.66.00(30/10/2014) - Samsung Electronics Co., Ltd.)
Samsung M2070 Series (HKLM-x32\...\Samsung M2070 Series) (Version: 1.20 (16/12/2014) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Samsung Scan Process Machine (HKLM-x32\...\Samsung Scan Process Machine) (Version: 1.03.05.18 - Samsung Electronics Co., Ltd.) Hidden
SAP GUI for Windows 7.40  (Patch 9) (HKLM-x32\...\SAPGUI) (Version: 7.40 Compilation 3 - SAP SE)
SAPscript Legacy Text Editor (HKLM-x32\...\SAPScriptEditorControls) (Version:  - SAP SE)
Skype Meetings App (HKLM-x32\...\{BC1D9E47-8927-4AA1-A891-7763BC2475B7}) (Version: 16.2.0.511 - Microsoft Corporation)
Spotify (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Spotify) (Version: 1.1.35.458.g891674f3 - Spotify AB)
StarCraft (HKLM-x32\...\StarCraft) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SumatraPDF (HKLM\...\SumatraPDF) (Version: 3.2 - Krzysztof Kowalczyk)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
Text-To-Speech-Runtime (HKLM-x32\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
The Sims 4 Digital Deluxe Edition MULTi17 - ElAmigos versión 1.47.49 (HKLM-x32\...\{27B947C0-320C-4997-9681-1E7010A15896}_is1) (Version: 1.47.49 - EA Games)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
UpdateAssistant (HKLM\...\{F339C545-24DC-4870-AA32-6EB6B0500B95}) (Version: 1.24.0.0 - Microsoft Corporation) Hidden
Ver el Manual de Usuario (HKLM-x32\...\View User Guide) (Version: 3.60.43.0 - )
Vita 2 (HKLM\...\{40161542-D9DF-4601-AA60-E969B017FB48}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita 2 common (HKLM\...\{C7B5259E-11DC-4B21-BBDD-DDAAA88C1F36}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Choir (HKLM\...\{9098B857-4CC8-4399-AF6A-0A0A59352487}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Church Organ (HKLM\...\{ED854B8E-17E3-4A38-80C5-F4DF85C1F540}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Cinematic Soundscapes (HKLM\...\{8DDAE083-BECC-4675-AB3E-D9BC3BF16F38}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Concert Grand (HKLM\...\{29691FB3-299F-4675-B899-851183C4BF92}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Concert Grand LE (HKLM\...\{4FF1C203-F4AE-4B8C-8D74-871911A4BC4E}) (Version: 2.4.0.95 - MAGIX Software GmbH) Hidden
Vita Drum Engine (HKLM\...\{46038AEE-DD50-49FC-A69F-F9D64D83D6FA}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Jazz Drums (HKLM\...\{8E867DF7-58FE-48B9-83AD-43FA9D982A01}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Lead Synth (HKLM\...\{61DE70FD-A4A9-4ACB-8B50-C79D30F31F09}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
Vita Pop Drums (HKLM\...\{5109B03D-84D7-4D22-B9E1-56C025EE61B9}) (Version: 2.4.0.96 - MAGIX Software GmbH) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.6 - VideoLAN)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0-3) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Warcraft III (HKLM-x32\...\Warcraft III) (Version:  - Blizzard Entertainment)
Warcraft III: All Products (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\Warcraft III) (Version:  - )
WhatsApp (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\WhatsApp) (Version: 2.2033.7 - WhatsApp)
WIDI Recognition System Pro 4.5 (remove only) (HKLM-x32\...\WIDI Recognition System Pro 4.5) (Version:  - )
Win32DiskImager version 1.0.0 (HKLM-x32\...\{3DFFA293-DF2C-4B23-92E5-3433BDC310E1}}_is1) (Version: 1.0.0 - ImageWriter Developers)
Winamp (HKLM-x32\...\Winamp) (Version: 5.8  - Winamp SA)
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
WinSCP 5.15.3 (HKLM-x32\...\winscp3_is1) (Version: 5.15.3 - Martin Prikryl)
Wondershare Filmora9(Build 9.4.5) (HKLM\...\Wondershare Filmora9_is1) (Version:  - Wondershare Software)
Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare)
Zoom (HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)

Packages:
=========
Ajedrez V+ -> C:\Program Files\WindowsApps\ZingMagicLimited.ChessV_1.1.30.0_x64__ekfg0vgp37mkp [2020-07-01] (ZingMagic Limited)
Damas V+ -> C:\Program Files\WindowsApps\ZingMagicLimited.CheckersV_1.1.27.0_x64__ekfg0vgp37mkp [2020-08-29] (ZingMagic Limited)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.4.255.0_x64__rz1tebttyb220 [2020-08-31] (Dolby Laboratories)
Fitbit Coach -> C:\Program Files\WindowsApps\Fitbit.FitbitCoach_4.4.133.0_x64__6mqt6hf9g46tw [2019-02-12] (Fitbit)
LINE -> C:\Program Files\WindowsApps\NAVER.LINEwin8_6.2.2.0_x86__8ptj331gd3tyt [2020-08-24] (LINE Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-20] (Microsoft Studios) [MS Ad]
MSN El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.97.752.0_x64__mcm4njqhnhss8 [2020-07-16] (Netflix, Inc.)
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_3.21.1.0_x64__nfy108tqq3p12 [2020-08-26] (Thumbmunkeys Ltd)
Reader Notification Client -> C:\Program Files\WindowsApps\ReaderNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2020-05-31] (Adobe Systems Incorporated)
Samsung Printer Experience -> C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g [2019-02-13] (Samsung Electronics Co. Ltd.)
Scratch Desktop -> C:\Program Files\WindowsApps\ScratchFoundation.ScratchDesktop_3.6.0.0_x86__wmbdy4q6dbx4t [2020-07-11] (Scratch Foundation)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

CustomCLSID: HKU\S-1-5-21-2743258333-1936799210-4253938688-1001_Classes\CLSID\{3E3AD4BD-346A-460A-80E8-90699B75C00B}\InprocServer32 -> C:\Users\ALVARO\AppData\Local\Microsoft\SkypeForBusinessPlugin\16.2.0.511\GatewayActiveX-x64.dll (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> Ningún archivo
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2019-05-19] (Notepad++ -> )
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> Ningún archivo
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-08-29] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2018-11-22] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-08-29] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-08-18] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> Ningún archivo
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> Ningún archivo
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2018-11-22] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_6bb02522ea3fdb0d\igfxDTCM.dll [2018-05-23] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-02-24] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> Ningún archivo
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2020-08-29] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-08-18] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2018-11-22] (Power Software Limited -> Power Software Ltd)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-11] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [vidc.VP60] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2018-11-15] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.VP61] => C:\WINDOWS\SysWOW64\vp6vfw.dll [447752 2018-11-15] (Electronic Arts -> On2.com)

==================== Accesos directos & WMI ========================

(Las entradas pueden ser listadas para ser restauradas o eliminadas.)

Shortcut: C:\Users\ALVARO\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.htm
ShortcutWithArgument: C:\Users\ALVARO\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Hangouts de Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=knipolnnllmklapflnccelgolnpehhpl

==================== Módulos cargados (Lista blanca) =============

2020-08-19 16:25 - 2020-08-19 16:25 - 011137536 _____ (Artifex Software et al.) [Archivo no firmado] C:\Users\ALVARO\AppData\Local\SumatraPDF\libmupdf.dll
2020-06-15 23:17 - 2013-09-10 08:48 - 001030144 _____ (Microsoft Corporation) [Archivo no firmado] C:\Program Files (x86)\SAP\FrontEnd\SapGui\dbghelp.dll

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

(Si una entrada es incluida en el fixlist, será eliminada del registro.)

IE trusted site: HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\localhost -> localhost

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2018-04-11 18:38 - 2020-08-21 11:00 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1       localhost

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ALVARO\Pictures\beatles2.jpg
DNS Servers: 8.8.4.4 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Firewall de Windows está habilitado.

Network Binding:
=============
Hamachi: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) 
Ethernet: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) 
Ethernet 3: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) 
Wi-Fi: VirtualBox NDIS6 Bridged Networking Driver -> oracle_VBoxNetLwf (enabled) 

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: AtherosSvc => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: cplspcon => 2
MSCONFIG\Services: DigitalWave.Update.Service => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: Hamachi2Svc => 2
MSCONFIG\Services: igfxCUIService2.0.0.0 => 2
MSCONFIG\Services: IntelAudioService => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: LMIGuardianSvc => 2
MSCONFIG\Services: NvContainerLocalSystem => 2
MSCONFIG\Services: NvContainerNetworkService => 3
MSCONFIG\Services: NVDisplay.ContainerLocalSystem => 2
MSCONFIG\Services: Origin Client Service => 3
MSCONFIG\Services: Origin Web Helper Service => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: VBoxSDS => 3
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run: => "CDAServer"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\StartupApproved\Run: => "AnyDVD"
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\StartupApproved\Run: => "Adobe Reader Synchronizer"
HKU\S-1-5-21-2743258333-1936799210-4253938688-1001\...\StartupApproved\Run: => "Opera Browser Assistant"

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [TCP Query User{D80EA4D1-4E63-4575-8C3D-C8522BB0EE49}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{C6A7A339-F8B9-412C-BEE1-98981DDD7D1C}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{4CC06181-659B-42AC-8977-363567D9DA72}C:\program files (x86)\warcraft iii\war3.exe] => (Allow) C:\program files (x86)\warcraft iii\war3.exe (Blizzard Entertainment) [Archivo no firmado]
FirewallRules: [UDP Query User{E99E3E7F-43F0-4A2B-B19D-87900E5778EF}C:\program files (x86)\warcraft iii\war3.exe] => (Allow) C:\program files (x86)\warcraft iii\war3.exe (Blizzard Entertainment) [Archivo no firmado]
FirewallRules: [{F895DBF3-8861-4977-A255-6F776014E0D5}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{97C6D47C-0447-4DB1-A2FB-7753F0B9BF8C}] => (Allow) C:\Program Files (x86)\Steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{EFADF761-2E8D-4604-A30B-1F0D94D1A7FB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{0F67D5FA-88E7-4606-856D-58EA29300134}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{DB59354C-9467-4B99-AD43-626E63CF1923}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe (Valve -> )
FirewallRules: [{E1A8DA9B-2C73-4305-A681-B36B61D2FD55}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe (Valve -> )
FirewallRules: [{FC1AC00A-78B1-4A35-9840-011B42F1051C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RISK Global Domination\RISK.exe () [Archivo no firmado]
FirewallRules: [{23797403-6D80-4D26-9CEF-CED0CD968DDA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\RISK Global Domination\RISK.exe () [Archivo no firmado]
FirewallRules: [{5F5AE7D4-49BD-46D6-B7CC-BED12631246E}] => (Allow) D:\SteamLibrary\steamapps\common\Portal 2\portal2.exe () [Archivo no firmado]
FirewallRules: [{7BF110F6-3B6A-4F09-8972-C3B186B69363}] => (Allow) D:\SteamLibrary\steamapps\common\Portal 2\portal2.exe () [Archivo no firmado]
FirewallRules: [{9F55E829-DA64-4088-97C1-4B97559EB4B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{00807B41-B324-42D3-8133-B396B8E75BEE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{75A1BB66-F185-4136-9A02-FC2FF87C5DDE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Catan Universe\CatanUniverse.exe () [Archivo no firmado]
FirewallRules: [{C10054E5-28D4-4FD0-92F6-D6AC4C80E405}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Catan Universe\CatanUniverse.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{FCAA7377-D24A-4856-B0C3-A3FCAEB89EC4}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{0A94888E-11E5-4089-92CD-3B72D3ED8708}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{07F13548-AA9A-4C8B-AA44-D73C4FAE0AF7}C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe] => (Allow) C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc)
FirewallRules: [UDP Query User{4D547A03-CBB5-4E69-AFDE-924733981309}C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe] => (Allow) C:\program files (x86)\warcraft iii\_retail_\x86_64\warcraft iii.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment, Inc)
FirewallRules: [TCP Query User{324AB0DE-0039-46E8-9539-3272D99E4221}C:\program files\windowsapps\microsoft.skypeapp_15.63.76.0_x86__kzf8qxf38zg5c\skype\skype.exe] => (Allow) C:\program files\windowsapps\microsoft.skypeapp_15.63.76.0_x86__kzf8qxf38zg5c\skype\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [UDP Query User{854FE1AB-EC73-4D8F-95EF-4F5F0E44AFE4}C:\program files\windowsapps\microsoft.skypeapp_15.63.76.0_x86__kzf8qxf38zg5c\skype\skype.exe] => (Allow) C:\program files\windowsapps\microsoft.skypeapp_15.63.76.0_x86__kzf8qxf38zg5c\skype\skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{407D14F6-C150-4350-AB97-27471FE99314}] => (Allow) C:\Program Files (x86)\MAGIX\Music Maker Premium\2017\MusicMaker.exe (MAGIX Software GmbH -> MAGIX Software GmbH) [Archivo no firmado]

==================== Puntos de Restauración =========================

18-08-2020 03:38:12 Punto de control programado
27-08-2020 03:12:02 Punto de control programado

==================== Dispositivos defectuosos en el Administrador de dispositivos ============


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (08/31/2020 08:32:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa SystemSettings.exe (versión 10.0.19041.423) dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible sobre el problema, comprueba el historial de problemas en el panel de control de seguridad y mantenimiento.

Id. de proceso: 910

Hora de Inicio: 01d67fff93e86cb3

Hora de finalización: 4294967295

Ruta de la aplicación: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

Id. de informe: f23bd8c4-6dc0-44ce-a3a8-eb770be2c65a

Nombre completo del paquete con errores: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy

Id. de la aplicación relativa al paquete con errores: microsoft.windows.immersivecontrolpanel

Tipo de bloqueo: Cross-thread

Error: (08/27/2020 06:01:23 PM) (Source: .NET Runtime) (EventID: 1025) (User: )
Description: Application: wmiprvse.exe
Framework Version: v4.0.30319
Description: The application requested process termination through System.Environment.FailFast(string message).
Message: El proveedor ha iniciado una excepción inesperada:
 System.IO.FileLoadException: 
File name: 'Microsoft.AppV.AppvClientComConsumer, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35'
   at Microsoft.AppV.AppvPublishingServerWMI.AppvPublishingServer.EnumeratePublishingServers()


Stack:
   at System.Environment.FailFast(System.String)
   at WmiNative.WbemProvider.WmiNative.IWbemServices.CreateInstanceEnumAsync(System.String, Int32, WmiNative.IWbemContext, WmiNative.IWbemObjectSink)

Error: (08/27/2020 05:59:46 PM) (Source: Microsoft Security Client) (EventID: 3002) (User: )
Description: Event-ID 3002

Error: (08/27/2020 05:59:46 PM) (Source: Microsoft Security Client) (EventID: 3002) (User: )
Description: Event-ID 3002

Error: (08/27/2020 05:59:46 PM) (Source: Microsoft Security Client) (EventID: 2002) (User: )
Description: Event-ID 2002

Error: (08/27/2020 05:59:46 PM) (Source: Microsoft Security Client) (EventID: 2002) (User: )
Description: Event-ID 2002

Error: (08/27/2020 05:59:46 PM) (Source: Microsoft Security Client) (EventID: 2003) (User: )
Description: Event-ID 2003

Error: (08/27/2020 05:59:46 PM) (Source: Microsoft Security Client) (EventID: 2003) (User: )
Description: Event-ID 2003


Errores del sistema:
=============
Error: (09/01/2020 01:53:52 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:51 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:51 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:50 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:50 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:49 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:49 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.

Error: (09/01/2020 01:53:48 PM) (Source: disk) (EventID: 7) (User: )
Description: El dispositivo, \Device\Harddisk0\DR0, tiene un bloque defectuoso.


Windows Defender:
===================================
Date: 2020-08-22 18:54:51.4700000Z
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {7FBC48B0-42C1-46B1-B841-387FDAA865EF}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-08-22 18:49:52.2990000Z
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {C6296FCC-3C0B-4D2D-99AC-E0F4CE203536}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-08-22 18:42:55.9560000Z
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {641E9A95-09EA-427A-8BE5-7D55734FC077}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

CodeIntegrity:
===================================

Date: 2020-09-01 09:04:01.1900000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:04:01.1870000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:04:01.1810000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:04:01.1780000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:04:01.1700000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:03:57.0800000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:03:57.0770000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2020-09-01 09:03:57.0710000Z
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\ESET\ESET Security\eamsi.dll because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Información de la memoria =========================== 

BIOS: Insyde Corp. V1.15 01/08/2018
Placa base: KBL Charmander_KL
Procesador: Intel(R) Core(TM) i5-8250U CPU @ 1.60GHz
Porcentaje de memoria en uso: 74%
RAM física total: 8067.6 MB
RAM física disponible: 2032.45 MB
Virtual total: 8067.6 MB
Virtual disponible: 1994.58 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:480.34 GB) (Free:173.01 GB) NTFS
Drive d: (Disco datos) (Fixed) (Total:450 GB) (Free:237.14 GB) NTFS
Drive e: (TOSHIBA EXT) (Fixed) (Total:931.51 GB) (Free:102.64 GB) NTFS
Drive g: (HardDrive01) (Fixed) (Total:931.48 GB) (Free:665.68 GB) NTFS

\\?\Volume{3f960ffd-f1c6-4b30-b5f6-43c6f4148def}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.47 GB) NTFS
\\?\Volume{df48ad85-69c4-4a85-b57d-02cbb471b329}\ () (Fixed) (Total:0.57 GB) (Free:0.04 GB) NTFS
\\?\Volume{e2786fe1-d2d8-4296-80ab-cb18d77e0187}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 398757D9)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 5B28D69F)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== Final de Addition.txt =======================

Hola:

He estado usando la PC y después de correr el Malwarebytes Anti-Rootkit, he notado que el disco ya no llega al 100% o lo hace poquísimo y no lo he notado.

Pero en general la PC está peor, nuevamente cuando cambio de pantalla o doy clic en cualquier lugar, la PC se queda colgada, aparecen mensajes de “No responde”, ni siquiera va bien al dar play a un vídeo de Youtube. Luego de un rato, como se quitara lo que tapaba, todo corre a la vez y de golpe, todos los clics. Esto ya no estaba pasando, solo era lo del disco que llegaba al 100%.

Saludos, muchas gracias por su ayuda.

Hola:

La PC está mucho peor, el disco no llega a 100%, pero está completamente clavado en 50%, no sube ni baja y todo demora, ahora que escribo también demoran en aparecer las letras y cada ventana da mensaje de “No responde” a cada rato.

Seguro tiene varios casos, pero si por favor pudiera darle prioridad al mío… justo he vuelto a empezar clases y no puedo hacer nada… se congela la pantalla a cada rato.

Gracias.

Hola

Has estado descargando programas durante estos días y no deberías descargar nada mientras revisamos tu equipo, lo que adelantamos por un lado lo atrasamos por el otro, damos un paso adelante y dos para atrás.

Realiza los siguientes pasos:

1.- Desinstala Eset con su herramienta.

2.- Descarga Hard Disk Sentinel * Selecciona la versión portable. - Descomprime el zip a una carpeta o ubicación de fácil acceso (como por ejemplo el escritorio) y ejecútalo. - Adjunta en tu próxima respuesta una captura de pantalla, donde se aprecie la pantalla principal de este programa, es decir, abre el programa y captura la primera pantalla que te dé. No des clic en ninguna opción dentro de él.

Un saludo

Hola:

Ok, no instalaré absolutamente nada. Disculpa la equivocación.

Esta es la captura:

Hola

Tienes el disco duro en muy mal estado, está muy dañado, deberías sacar tdos los datos importantes y cambiarlo, en cualquier momento te fallará.

Falta el reporte de EsetOnline.

Un saludo

1 me gusta

Hola:

Disculpa la demora, estaba haciendo el cambio de disco, ya puse otro y bueno… he estado instalando algunos programas que tenía. Ahora no sé si debo seguir haciendo algunas pruebas o asumir que está todo bien porque el disco es nuevo, es de estado sólido. Gracias.

Hola

Que tal es el funcionamiento del PC al poner el disco nuevo?

Si no has descargado e instalado nada nuevo, debería estar limpio, pero si quieres puedes realizar los pasos que te indiqué aquí:

Un saludo