HackTool:Win32/AutoKMS!rfn - Trojan:Win32/Dynamer!dtc


#1

Hola a todos:

Llevo varios días con un problema que me está desquiciando.

Cada 2x3, el antivirus y el windows defender, saca pantallas, de que ha eliminado malware, cada uno con nombres distintos, similar al título. Los elimina, pero vuelven a aparecer. Todos los archivos infectados, se crean en la carpeta tmp de windows, con extensiones similares a tmp00000224.

He pasado todo tipo de programas antimalware, pero en los análisis no detectan nada.

He visto un post parecido, en el que dais unas instrucciones para resolverlo, pero como indica que la solución es solo valida para ese usuario, no he tocado nada.

¿Me podrías ayudar para resolver este problema?

Un saludo


#2

Hola fjpuerto bienvenido al nuevo foro

AutoKMS es un activador para Windows u Office, tienes alguno de ellos ilegal?

Realiza los siguientes pasos, aunque hayas hecho alguno, sin cambiar el orden:

1) Descarga, actualiza y ejecuta Malwarebytes’ Anti-Malware, revisa en detalle el manual, para que sepas usarlo y configurarlo.

  • Realiza un Análisis de amenazas, actualizando si te lo pide.
  • Pulsar en “Cuarentena seleccionado” para enviarlo a la cuarentena y Reinicias el sistema.
  • En el apartado del manual Informes :arrow_forward: Informe de análisis encontrarás el reporte de MBAM, clic en Exportar :arrow_forward: Copiar al portapapeles.

2) Descarga AdwCleaner | InfoSpyware en el escritorio.

  • Desactiva temporalmente el Antivirus :arrow_forward: Cómo deshabilitar temporalmente su Antivirus.
  • Cierra también todos los programas que tengas abiertos.
  • Ejecuta Adwcleaner.exe (Si usas Windows Vista/7 u 8 presiona clic derecho y selecciona "Ejecutar como Administrador".)
  • Pulsar en el botón Escanear, y espera a que se realice el proceso, inmediatamente pulsa sobre el botón Limpiar.
  • Espera a que se complete y sigue las instrucciones, si te pidiera Reiniciar el sistema Aceptas.
  • Guardas el reporte que te aparecerá, para copiarlo y pegarlo en tu próxima respuesta.
  • El informe también se puede encontrar en C:\AdwCleaner\AdwCleaner[C1].txt

3) Descarga CCleaner

  • Instala Ccleaner
  • Abres Ccleaner en la pestaña limpiador dejas como esta configurada predeterminadamente, haces clic en analizar esperas que termine :arrow_forward: clic en ejecutar limpiador
  • Clic en la pestaña Registro :arrow_forward: clic en buscar problemas esperas que termine :arrow_forward: clic en Reparar Seleccionadas y haces una copia de seguridad
  • Vuelves a darle clic en buscar problemas hasta que no encuentre ninguno.

Pega los reportes de Malwarebytes y AdwCleaner y comentas como va el problema.

Un saludo


#3

Gracias Por la respuesta.

Esta tarde realizaré todo lo que indicas.

Quiero recalcar, que el Windows que utilizo, es original comprado, y que no tengo instalado el office.

He puesto 2 de los nombres que aparecen en el windows defender, pero en el AVG, salen otros nombres Win32:Evo-gen [Susp] Win32:Malware-gen …

Ahora mismo estoy haciendo un escaneo completo con el esetonlinescanner

Ya pasare los reportes.

Un saludo.


#4

Hola

De acuerdo, cuando puedas nos pones los reportes y nos comentas como sigue el problema. :+1:

Un saludo


#5

Hola:

Finalmente he podido realizar todo lo que indicas antes del medio día. El AdwCleaner si que ha detectado cosas, y el cccleaner ha hecho la limpieza. El malwarebytes no ha encontrado nada. Ahora tengo que dejar el ordenador. Esta tarde continuaré a ver que pasa. Te pego los resultados

# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build:    01-30-2019
# Database: 2019-02-06.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    02-08-2019
# Duration: 00:00:03
# OS:       Windows 10 Pro
# Cleaned:  16
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Users\comercio\AppData\LocalLow\avg web tuneup
Deleted       C:\Users\comercio\AppData\Roaming\.acestream
Deleted       C:\Users\comercio\AppData\Local\Packages\windows_ie_ac_001\AC\AVG Web TuneUp
Deleted       C:\Users\FrancsicoJosé\AppData\Local\Packages\windows_ie_ac_001\AC\AVG Web TuneUp

***** [ Files ] *****

Deleted       C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\diuu9rjb.default\searchplugins\avg-secure-search.xml

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\RegisteredApplications|AceStream
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{F2AFB469-2A0F-40E8-9DCC-68E44D4A00CC}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\program.plexus\acestream\ace_engine.exe
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{F5C9EA9D-AC41-4C44-BF14-AD7A99B268BE}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\program.plexus\acestream\ace_engine.exe
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{2A3705B7-5AB3-42F6-8815-AD18320893CB}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\program.plexus\acestream\ace_engine.exe
Deleted       HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{40468BD7-3B7B-4007-897F-62D75538CAD9}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\program.plexus\acestream\ace_engine.exe
Deleted       HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
Deleted       HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ak.staticimgfarm.com
Deleted       HKCU\Software\PRODUCTSETUP
Deleted       HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
Deleted       HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G
Deleted       HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\thebrighttag.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3506 octets] - [08/02/2019 13:03:10]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 8/2/19
Hora del análisis: 12:37
Archivo de registro: df7a98ac-2b95-11e9-b934-0a0027000009.json

-Información del software-
Versión: 3.7.1.2839
Versión de los componentes: 1.0.538
Versión del paquete de actualización: 1.0.9172
Licencia: Premium

-Información del sistema-
SO: Windows 10 (Build 17763.292)
CPU: x64
Sistema de archivos: NTFS
Usuario: AMDFX8120\FranciscoJos\u00c3\u00a9

-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 477151
Amenazas detectadas: 0
Amenazas en cuarentena: 0
Tiempo transcurrido: 15 min, 16 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 0
(No hay elementos maliciosos detectados)

Valor del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Secuencia de datos: 0
(No hay elementos maliciosos detectados)

Carpeta: 0
(No hay elementos maliciosos detectados)

Archivo: 0
(No hay elementos maliciosos detectados)

Sector físico: 0
(No hay elementos maliciosos detectados)

WMI: 0
(No hay elementos maliciosos detectados)


(end)

#6

Esta tarde, después de hacer todo lo que comentas, sigue igual. No hay manera de encontrar el ejecutable que es el que crea los archivos temporales, que después los antivirus neutralizan.

La verdad es que es un incordio, y ya no se que hacer. Formatear de momento no es la opción.

Espero me puedas aconsejar algo más .

Un saludo


#7

Hola

Descarga Farbar Recovery Scan Tool.en el escritorio, seleccionando la versión adecuada para la arquitectura(32 o 64bits) de tu equipo. :arrow_forward: ¿Cómo saber si mi Windows es de 32 o 64 bits.?

  • Ejecuta FRST.exe.
  • En el mensaje de la ventana del Disclaimer, pulsamos Yes
  • En la ventana principal pulsamos en el botón Scan y esperamos a que concluya el proceso.
  • Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

Pon los dos reportes generados.

Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(mas de 50.000 caracteres aprox.).

Un saludo


#8

Hola: Te pego los resultados. Espero puedas ayudarme. Gracias.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10.02.2019 01
Ran by FranciscoJosé (administrator) on AMDFX8120 (11-02-2019 11:14:45)
Running from J:\Mis documentos C\Descargas
Loaded Profiles: FranciscoJosé (Available Profiles: FranciscoJosé & lourdes & comercio)
Platform: Windows 10 Pro Version 1809 17763.292 (X64) Language: Español (España, internacional)
Default browser: FF
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\AsRoutineController.exe
() G:\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\Remote GO!\AssistTools\WiFi GO! Server.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\afwServ.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.19\AsusFanControlService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
() C:\Program Files (x86)\QNAP\QVR\QVRService.exe
() C:\Windows\SysWOW64\SecUPDUtilSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
() C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe
(Plex, Inc.) G:\Plex\Plex Media Server\Plex Update Service.exe
(QNAP) G:\QNAP\QVHelper\QVHelper.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\aswEngSrv.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.38.138.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\AI Suite II.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\aswidsagent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() G:\No-IP\DUC40.exe
(Intel® Corporation) C:\Program Files\Intel\ConnectCenter\bin\CCFManager.exe
() C:\Program Files (x86)\Eye-Fi\EyeFiX2Receiver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
() C:\Program Files\Siber Systems\GoodSync\GoodSync-v10.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(ASUSTeK Computer Inc.) G:\ASUS\AI Suite II\Remote GO!\AsDLNAServerReal.exe
(Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(IO3O LLC) G:\Who Is On My Wifi\mywifi.exe
(Telegram Messenger LLP) G:\Telegram Desktop\Telegram.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(QNAP Systems, Inc.) C:\Program Files (x86)\QNAP\Qsync\Qsync.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon-x64.exe
() C:\Program Files\Siber Systems\GoodSync\gs-server.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe
(LG Electronisc Inc) C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OSCApplicationManager.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe
(TODO: <Company name>) C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\ScreenSplitterHook64App.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Firetrust) C:\Program Files (x86)\Firetrust\MailWasher\MailWasherPro.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\fsIPcam.exe
(Microsoft Corporation) C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(IncrediMail Ltd.) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
(IncrediMail Ltd.) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
(Lifehacker) G:\Belvedere\Belvedere.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
(Mozilla Corporation) G:\Mozilla Thunderbird\thunderbird.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\CNext\CCCSlim\MOM.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\CNext\CCCSlim\CCC.exe
(WhatsApp) C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\WhatsApp.exe
(WhatsApp) C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\WhatsApp.exe
(WhatsApp) C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\WhatsApp.exe
(WhatsApp) C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\WhatsApp.exe
(Sage) \\LOURDES-PC\GrupoSP\SPPanel\SPPG.EXE
(Sage SP) \\LOURDES-PC\GrupoSP\GES2012\EXE\GESTION.EXE
(Plex, Inc.) G:\Plex\Plex Media Server\Plex Media Server.exe
(Python Software Foundation) G:\Plex\Plex Media Server\PlexScriptHost.exe
(Plex, Inc.) G:\Plex\Plex Media Server\Plex DLNA Server.exe
(Plex) G:\Plex\Plex Media Server\Plex Tuner Service.exe
(Sage) \\LOURDES-PC\GrupoSP\GES2012\EXE\DashboardFrame.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\QtWebEngineProcess.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(The Qt Company Ltd.) C:\Program Files (x86)\Dropbox\Client\QtWebEngineProcess.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Xolido Systems, S.A.) C:\Program Files\XolidoSystems\XolidoSign\XolidoSign.exe
(Samsung Electronics) C:\Windows\System32\spool\drivers\x64\3\us013sm.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [682840 2014-02-15] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
HKLM\...\Run: [StartupDelayer] => G:\Startup Delayer\Startup Launcher.exe [1254400 2015-12-18] (r2 Studios) [File not signed]
HKLM\...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel® Corporation) [File not signed]
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [307632 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Emsisoft Anti-Malware] => C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [9604024 2019-02-01] (Emsisoft Ltd -> Emsisoft Ltd)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1075296 2013-04-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Qsync] => C:\Program Files (x86)\QNAP\Qsync\Qsync.exe [73444152 2018-12-14] (QNAP Systems, Inc. -> QNAP Systems, Inc.)
HKLM-x32\...\Run: [OnScreen Control] => C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreenStartUpApp.exe [1786808 2018-03-14] (LG Electronics Inc. -> TODO: <Company name>)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [307632 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [4190016 2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION
HKLM Group Policy restriction on software: ** <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION
HKLM-x32\...\Winlogon: [Userinit] C:\WINDOWS\system32\userinit.exe, [27648 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [Google Update] => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\1.3.33.23\GoogleUpdateCore.exe [605992 2018-12-20] (Google Inc -> Google Inc.)
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [NOIPDUCV4] => G:\No-IP\DUC40.exe [346624 2014-05-02] ()
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [Eye-FiX2] => C:\Program Files (x86)\Eye-Fi\EyeFiX2Receiver.exe [5064992 2016-09-08] (Eye-Fi, Inc -> )
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [Plex Media Server] => G:\Plex\Plex Media Server\Plex Media Server.exe [18429416 2018-07-23] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [GoodSync] => C:\Program Files\Siber Systems\GoodSync\GoodSync-v10.exe [14365920 2018-02-03] (Siber Systems -> )
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46504696 2018-12-07] (Google Inc -> )
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [145704 2018-12-13] (Siber Systems -> Siber Systems)
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKNE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [9001904 2019-01-28] (Support.com, Inc. -> SUPERAntiSpyware)
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19645800 2019-01-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKNE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
HKLM\...\Drivers32: [VIDC.FPS1] => C:\WINDOWS\system32\frapsv64.dll [71680 2013-02-26] (Beepa P/L)
HKLM\...\Drivers32-x32: [VIDC.MPG4] => C:\Windows\SysWOW64\mpg4c32.dll [420240 2001-05-11] (Microsoft Corporation)
HKLM\...\Drivers32-x32: [VIDC.MP42] => C:\Windows\SysWOW64\mpg4c32.dll [420240 2001-05-11] (Microsoft Corporation)
HKLM\...\Drivers32-x32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [65536 2013-02-26] (Beepa P/L)
HKLM\Software\...\AppCompatFlags\Custom\Acrobat.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\Acrobat.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\AcroRd32.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\AcroRd32.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\EXCEL.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\EXCEL.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\iexplore.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\iexplore.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\INFOPATH.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\INFOPATH.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\java.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\java.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\javaw.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\javaw.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\javaws.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\javaws.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\LYNC.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\LYNC.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\MSACCESS.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\MSACCESS.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\MSPUB.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\MSPUB.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\OIS.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\OIS.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\OUTLOOK.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\OUTLOOK.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\POWERPNT.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\POWERPNT.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\PPTVIEW.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\PPTVIEW.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\VISIO.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\VISIO.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\VPREVIEW.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\VPREVIEW.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\WINWORD.EXE: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\WINWORD.EXE: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\wordpad.exe: [{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\Custom\wordpad.exe: [{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb] -> EMET_Database
HKLM\Software\...\AppCompatFlags\InstalledSDB\{e1c810aa-f7cc-4aaf-ada1-181863075f9b}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{e1c810aa-f7cc-4aaf-ada1-181863075f9b}.sdb [2016-05-18]
HKLM\Software\...\AppCompatFlags\InstalledSDB\{f8c4cc07-6dc4-418f-b72b-304fcdb64052}: [DatabasePath] -> C:\WINDOWS\AppPatch\CustomSDB\{f8c4cc07-6dc4-418f-b72b-304fcdb64052}.sdb [2016-05-18]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.96\Installer\chrmstp.exe [2019-02-08] (Google LLC -> Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Who Is On My Wifi.lnk [2018-09-03]
ShortcutTarget: Who Is On My Wifi.lnk -> G:\Who Is On My Wifi\mywifi.exe (IO3O LLC)
Startup: C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2018-11-20]
ShortcutTarget: Telegram.lnk -> G:\Telegram Desktop\Telegram.exe (Telegram Messenger LLP)
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{1ab6435e-977f-47f1-9d74-3c7523c6debd}: [DhcpNameServer] 172.18.12.1
Tcpip\..\Interfaces\{4aa105bf-44b8-44aa-9254-4189b620d2fb}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{4aa105bf-44b8-44aa-9254-4189b620d2fb}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> DefaultScope {10D2EC5B-A816-4BB0-A0D2-E02A14461539} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> {10D2EC5B-A816-4BB0-A0D2-E02A14461539} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2014-11-07] (Shenzhen Wondershare Information Technology Co., Ltd. -> Wondershare)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-01-29] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Foxit PhantomPDF Create PDF ToolBar Helper -> {A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A} -> G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2017-06-29] (Foxit Software Incorporated -> )
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-01-29] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Foxit PhantomPDF Create PDF ToolBar - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2017-06-29] (Foxit Software Incorporated -> )
Toolbar: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> No Name - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} -  No File
DPF: HKLM-x32 {2DAB6EF1-66C3-427C-87CD-8DC448C47EAE} hxxps://www5.aeat.es/es13/h/tgvicab.cab
DPF: HKLM-x32 {947B00D2-962D-4A35-9E48-98EE6A442B41} hxxps://www1.agenciatributaria.gob.es/ADUA/internet/aded1503.cab
DPF: HKLM-x32 {B785FA3C-1DE9-4D20-8396-613C486FE95E} hxxps://www1.agenciatributaria.gob.es/es13/h/cactivex.cab
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File

Edge: 
======
Edge Extension: (RoboForm) -> EdgeExtension_SiberSystemsIncRoboFormEdge_7kk3kr9e0p1np => C:\Program Files\WindowsApps\SiberSystemsInc.RoboFormEdge_8.5.5.0_x86__7kk3kr9e0p1np [2018-12-07]

FireFox:
========
FF DefaultProfile: ml89f1kh.pcpacodefault
FF ProfilePath: C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault [2019-02-11]
FF Homepage: Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault -> hxxps://www.google.com/?bcutc=sp-118-756
FF NewTab: Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault -> about:newtab
FF Extension: (Bookmarks Organizer) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\[email protected] [2019-02-06]
FF Extension: (Spanish (Spain) Dictionary) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\[email protected] [2019-02-04]
FF Extension: (RoboForm Password Manager) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\[email protected] [2018-12-24]
FF Extension: (uBlock Origin) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\[email protected] [2019-02-06]
FF Extension: (Netcraft Extension) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\{0e10f3d7-07f6-4f12-97b9-9b27e07139a5}.xpi [2019-01-22]
FF Extension: (Complemento inhabilitación Google Analytics) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi [2017-03-31]
FF Extension: (NoScript) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-12-24]
FF Extension: (Open in Tor Browser) - C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\Extensions\{9d3b260b-886d-4263-b9d6-81d756ee4929}.xpi [2018-06-11]
FF SearchPlugin: C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault\searchplugins\google-avg.xml [2018-11-29]
FF ProfilePath: C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\vrbqafih.Dani [2019-02-08]
FF Homepage: Mozilla\Firefox\Profiles\vrbqafih.Dani -> hxxps://www.google.com/?bcutc=sp-118-756
FF NewTab: Mozilla\Firefox\Profiles\vrbqafih.Dani -> about:newtab
FF SearchPlugin: C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\Firefox\Profiles\vrbqafih.Dani\searchplugins\google-avg.xml [2018-11-29]
FF HKLM\...\Firefox\Extensions: [[email protected]] - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF Extension: (Foxit PDF Creator) - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2017-05-23] [Legacy]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected]
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected] [2015-01-30] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-02-09] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - G:\Video Converter Ultimate\SVRFirefoxExt => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-09] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> G:\PDF-XChange\PDF Viewer\npPDFXCviewNPPlugin.dll [2018-07-03] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-09] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> G:\PDF-XChange\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2018-07-03] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> G:\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2017-06-29] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> G:\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2017-06-29] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> G:\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2017-06-29] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> G:\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2017-06-29] (Foxit Corporation)
FF Plugin-x32: @IPCWebComponents -> C:\Program Files (x86)\IPCWebComponents\npIPCReg.dll [2014-11-21] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-01-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-01-29] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> g:\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> g:\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> g:\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> g:\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> g:\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-390596928-2417218115-2686252066-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> G:\PDF-XChange\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2018-07-03] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-390596928-2417218115-2686252066-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-390596928-2417218115-2686252066-1001: @talk.google.com/O1DPlugin -> C:\Users\FrancsicoJosé\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-390596928-2417218115-2686252066-1001: @tools.google.com/Google Update;version=3 -> C:\Users\FrancsicoJosé\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc.)
FF Plugin HKU\S-1-5-21-390596928-2417218115-2686252066-1001: @tools.google.com/Google Update;version=9 -> C:\Users\FrancsicoJosé\AppData\Local\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-20] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\FrancsicoJosé\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\FrancsicoJosé\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\user.js [2012-12-20]

Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default [2019-02-11]
CHR Extension: (Easy Auto Refresh) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2017-10-13]
CHR Extension: (Documentos) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-12-09]
CHR Extension: (Google Drive) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (Foxit PDF Creator) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci [2017-09-12]
CHR Extension: (uBlock Origin) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-02-04]
CHR Extension: (Búsqueda de Google) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-16]
CHR Extension: (Dropbox para Gmail) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2018-04-26]
CHR Extension: (Adobe Acrobat) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-04]
CHR Extension: (Google Calendar) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2018-02-14]
CHR Extension: (Play to Kodi) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\fncjhcjfnnooidlkijollckpakkebden [2018-03-28]
CHR Extension: (EditThisCookie) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2018-12-07]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22]
CHR Extension: (ScriptBlock) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcdjknjpbnhdoabbngpmfekaecnpajba [2018-06-14]
CHR Extension: (Tag Assistant (by Google)) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2018-11-20]
CHR Extension: (Hangouts de Google) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2019-01-14]
CHR Extension: (Real-Debrid Extension) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhbijccmpenbpkblhmeeneeaangebej [2016-09-05]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-02-20]
CHR Extension: (Clean Google Calendar) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\magodclodecbbnbdfpmoehfdddkhlfmm [2018-02-14]
CHR Extension: (Ace Script) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2018-12-13]
CHR Extension: (Hangouts de Google) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2019-01-04]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (NotScripts) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\odjhifogjcknibkahlpidmdajjpkkcfn [2014-02-13]
CHR Extension: (Tor) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohielanlcdleofjibfmjbbkaajdcpoil [2015-08-25]
CHR Extension: (Gmail) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR Extension: (Chrome Media Router) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-01-04]
CHR Extension: (RoboForm Password Manager) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2019-01-31]
CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2017-05-23]
CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-09-05]
CHR HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2017-05-23]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-09-05]

#9
==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [9574424 2019-02-01] (Emsisoft Ltd -> Emsisoft Ltd)
S3 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [44736 2014-03-11] (ArcSoft, Inc. -> ArcSoft, Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [560544 2017-10-13] (Advanced Micro Devices, Inc. -> AMD)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2013-09-17] (ASUSTeK Computer Inc. -> )
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2013-09-17] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.19\AsusFanControlService.exe [408960 2012-10-15] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [357360 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 AVG Firewall; C:\Program Files (x86)\AVG\Antivirus\afwServ.exe [369312 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\aswidsagent.exe [6807360 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S3 AvgWscReporter; C:\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe [110048 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-10-25] (Dropbox, Inc -> Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-10-25] (Dropbox, Inc -> Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
S3 FoxitPhantomService; G:\Foxit Software\Foxit PhantomPDF\FoxitConnectedPDFService.exe [1658944 2017-06-29] (Foxit Software Incorporated -> Foxit Software Inc.)
R2 GsServer; C:\Program Files\Siber Systems\GoodSync\gs-server.exe [8086240 2018-02-03] (Siber Systems -> )
R2 HsfXAudioService; C:\WINDOWS\SysWOW64\XAudio64.dll [436736 2009-04-29] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R2 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2011-06-20] (Hewlett-Packard Company) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
R2 PlexUpdateService; G:\Plex\Plex Media Server\Plex Update Service.exe [2233832 2018-07-23] (Plex, Inc -> Plex, Inc.)
R2 QVHelper; G:\QNAP\QVHelper\QVHelper.exe [192512 2018-01-25] (QNAP) [File not signed]
R2 QVRService; C:\Program Files (x86)\QNAP\QVR\QVRService.exe [73728 2018-02-14] () [File not signed]
S3 Samsung UPD Service2; C:\WINDOWS\System32\SUPDSvc2.exe [165456 2014-01-15] (Samsung Electronics CO., LTD. -> Samsung Electronics)
R2 SamsungUPDUtilSvc; C:\WINDOWS\SysWoW64\SecUPDUtilSvc.exe [143664 2018-10-18] (Samsung Electronics CO., LTD. -> )
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5381128 2019-01-28] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 sopcastp2p; g:\SopCast\srvany.exe [8192 2016-10-31] () [File not signed]
S2 STCServ; C:\Program Files\Intel\STCServ\STCServ.exe [8095456 2015-03-16] (Intel(R) iCDG WINS WSS CCF -> Intel Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10803440 2018-09-28] (TeamViewer GmbH -> TeamViewer GmbH)
R2 TunnelBearMaintenance; C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe [117120 2018-05-07] (TunnelBear, Inc. -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\NisSrv.exe [3880120 2019-01-28] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MsMpEng.exe [114208 2019-01-28] (Microsoft Corporation -> Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe [495720 2018-07-04] (Wondershare Technology Co.,Ltd -> Wondershare)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [23240 2016-03-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0318486.inf_amd64_11ba0b4b7cc81d52\atikmdag.sys [38774688 2017-10-13] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0318486.inf_amd64_11ba0b4b7cc81d52\atikmpag.sys [549792 2017-10-13] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-12-18] (ChengDu AoMei Tech Co., Ltd -> ) [File not signed]
S3 ampa; C:\Windows\SysWOW64\ampa.sys [17008 2013-12-18] (ChengDu AoMei Tech Co., Ltd -> ) [File not signed]
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R2 AODDriver4.3.0; G:\OverDrive\amd64\AODDriver2.sys [59624 2014-01-08] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R1 ArcCtrl; C:\WINDOWS\System32\drivers\ArcCtrl.sys [3315392 2013-11-20] (ArcSoft, Inc. -> )
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-02-20] (ASUSTeK Computer Inc. -> )
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2013-01-15] (ASUSTeK Computer Inc. -> )
S3 ASUSstpt; C:\WINDOWS\System32\drivers\ASUSstpt.sys [27392 2013-03-28] (MCCI Corporation -> MCCI Corporation)
S3 ASUSumsc; C:\WINDOWS\System32\drivers\ASUSumsc.sys [151808 2013-03-28] (MCCI Corporation -> MCCI Corporation)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102400 2016-03-21] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [205656 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdriver.sys [226448 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsh.sys [196848 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\System32\drivers\avgblog.sys [320960 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniv.sys [58008 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgElam; C:\WINDOWS\System32\drivers\avgElam.sys [15280 2019-01-07] (Microsoft Windows Early Launch Anti-malware Publisher -> AVG Technologies CZ, s.r.o.)
R1 avgKbd; C:\WINDOWS\System32\drivers\avgKbd.sys [42552 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [167560 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgNetSec; C:\WINDOWS\System32\drivers\avgNetSec.sys [519944 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [112568 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [88208 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [1034184 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [474712 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [217040 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S3 avgTap; C:\WINDOWS\System32\drivers\avgTap.sys [54888 2017-12-05] (AVG Technologies CZ, s.r.o. -> The OpenVPN Project)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [380208 2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
R3 CAXHWBS2; C:\WINDOWS\system32\DRIVERS\CAXHWBS2.sys [411136 2009-06-30] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
S3 dbx; C:\WINDOWS\System32\DRIVERS\dbx.sys [45640 2017-07-06] (Microsoft Windows Hardware Compatibility Publisher -> Dropbox, Inc.)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [17480 2013-03-07] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 epmntdrv; C:\WINDOWS\SysWOW64\epmntdrv.sys [14920 2013-03-07] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R1 epp; C:\Program Files\Emsisoft Anti-Malware\epp.sys [167816 2019-01-31] (Emsisoft Ltd -> Emsisoft Ltd)
R0 eppdisk; C:\WINDOWS\System32\drivers\eppdisk.sys [37064 2018-04-02] (Emsisoft Ltd -> Emsisoft Ltd)
R1 eppwfp; C:\Program Files\Emsisoft Anti-Malware\eppwfp.sys [131952 2019-01-02] (Emsisoft Ltd -> Emsisoft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
S3 etdrv; C:\Windows\etdrv.sys [25640 2014-04-23] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [9800 2013-03-07] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EuGdiDrv; C:\WINDOWS\SysWOW64\EuGdiDrv.sys [9160 2013-03-07] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [296736 2015-02-07] (Acronis International GmbH -> Acronis International GmbH)
S3 gdrv; C:\Windows\gdrv.sys [25640 2017-03-11] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
S3 ggsomc; C:\WINDOWS\System32\drivers\ggsomc.sys [30424 2016-07-19] (Sony Mobile Communications AB -> Sony Mobile Communications)
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-04-23] (GIGA-BYTE TECHNOLOGY CO., LTD -> )
R3 HSF_DPV; C:\WINDOWS\system32\DRIVERS\CAX_DPV.sys [1486848 2009-06-30] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [198512 2019-02-08] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [127136 2019-02-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [72864 2019-02-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [274416 2019-02-11] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [114040 2019-02-11] (Malwarebytes Corporation -> Malwarebytes)
R2 mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [17024 2006-06-19] (Microsoft Windows Hardware Compatibility Publisher -> Conexant)
R3 MODEMCSA; C:\WINDOWS\system32\drivers\MODEMCSA.sys [28160 2018-09-15] (Microsoft Windows -> Microsoft Corporation)
R1 ndisrd; C:\WINDOWS\system32\DRIVERS\ndisrd.sys [32840 2013-02-21] (Realtek Semiconductor Corp -> NT Kernel Resources)
R3 S3XXx64; C:\WINDOWS\system32\DRIVERS\S3XXx64.sys [73856 2015-02-17] (Microsoft Windows Hardware Compatibility Publisher -> Identiv)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 speedfan; C:\Windows\SysWow64\speedfan.sys [29592 2011-03-18] (Sokno S.R.L. -> Almico Software)
R3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2018-01-31] (TunnelBear, Inc. -> The OpenVPN Project)
R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R2 tib; C:\WINDOWS\system32\DRIVERS\tib.sys [1058632 2015-09-29] (Acronis International GmbH -> Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [248648 2015-09-29] (Acronis International GmbH -> Acronis International GmbH)
S1 UsbCharger; C:\WINDOWS\System32\DRIVERS\UsbCharger.sys [21584 2013-05-06] (Giga-Byte Technology -> )
R3 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [212552 2018-04-27] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [222848 2018-04-27] (Oracle Corporation -> Oracle Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46680 2019-01-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [330936 2019-01-28] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62136 2019-01-28] (Microsoft Windows -> Microsoft Corporation)
R3 winachsf; C:\WINDOWS\system32\DRIVERS\CAX_CNXT.sys [740864 2009-06-30] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)
R2 XAudio; C:\WINDOWS\system32\DRIVERS\XAudio64.sys [10240 2009-04-29] (Microsoft Windows Hardware Compatibility Publisher -> Conexant Systems, Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-02-11 11:14 - 2019-02-11 11:14 - 000000000 ____D C:\FRST
2019-02-11 09:42 - 2019-02-11 09:42 - 000002307 _____ C:\Users\FrancsicoJosé\Desktop\WhatsApp.lnk
2019-02-11 09:42 - 2019-02-11 09:42 - 000000000 ____N C:\Users\FrancsicoJosé\AppData\Local\slc5E77.tmp
2019-02-11 09:41 - 2019-02-11 09:42 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\WhatsApp
2019-02-11 09:32 - 2019-02-11 09:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2019-02-11 09:29 - 2019-02-11 09:29 - 000000000 ___HD C:\OneDriveTemp
2019-02-11 09:27 - 2019-02-11 09:27 - 000274416 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-02-11 09:27 - 2019-02-11 09:27 - 000127136 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2019-02-11 09:27 - 2019-02-11 09:27 - 000114040 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2019-02-11 09:27 - 2019-02-11 09:27 - 000072864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2019-02-08 20:20 - 2019-02-08 20:20 - 000000000 ____N C:\Users\FrancsicoJosé\AppData\Local\slc6DF0.tmp
2019-02-08 19:39 - 2019-02-08 19:39 - 000003410 _____ C:\Users\FrancsicoJosé\Desktop\Rkill.txt
2019-02-08 13:26 - 2019-02-08 16:54 - 000000546 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084.job
2019-02-08 13:10 - 2019-02-08 13:10 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-02-08 13:10 - 2019-02-08 13:10 - 000002892 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2019-02-08 13:09 - 2019-02-08 16:54 - 000000000 ____D C:\Program Files\CCleaner
2019-02-08 13:09 - 2019-02-08 13:09 - 000000871 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-02-08 13:09 - 2019-02-08 13:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-02-08 13:06 - 2019-02-08 13:06 - 000198512 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2019-02-08 09:41 - 2019-02-08 09:41 - 000003380 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-390596928-2417218115-2686252066-1001
2019-02-08 09:41 - 2019-02-08 09:41 - 000002427 _____ C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-02-07 18:31 - 2019-02-07 18:31 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\ESET
2019-02-06 20:25 - 2019-02-06 20:25 - 000000000 ____D C:\Users\FrancsicoJosé\Desktop\ShellBags Backups day=6 hour=20 min=25 s=51
2019-02-06 20:21 - 2019-02-08 13:26 - 000003698 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084
2019-02-06 20:21 - 2019-02-07 09:31 - 000000546 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 845e393e-1f26-419c-a61c-ff12915eb8f7.job
2019-02-06 20:21 - 2019-02-06 20:21 - 000003708 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task 845e393e-1f26-419c-a61c-ff12915eb8f7
2019-02-06 20:21 - 2019-02-06 20:21 - 000001871 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
2019-02-06 20:21 - 2019-02-06 20:21 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\SUPERAntiSpyware.com
2019-02-06 20:21 - 2019-02-06 20:21 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2019-02-06 20:21 - 2019-02-06 20:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2019-02-06 20:21 - 2019-02-06 20:21 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2019-02-06 18:54 - 2019-02-06 18:54 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2019-02-06 18:20 - 2019-02-06 18:20 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\mbam
2019-02-06 17:57 - 2019-02-06 17:57 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\mbamtray
2019-02-06 17:55 - 2019-02-06 17:55 - 000001926 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-02-06 17:55 - 2019-02-06 17:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-02-06 17:55 - 2019-02-01 11:20 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-02-06 17:55 - 2019-01-08 15:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-02-06 17:54 - 2019-02-06 17:54 - 000000000 ____D C:\Program Files\Malwarebytes
2019-02-06 13:34 - 2019-02-06 13:34 - 001034184 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000519944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgNetSec.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000474712 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000380208 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000362928 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2019-02-06 13:34 - 2019-02-06 13:34 - 000320960 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgblog.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000226448 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdriver.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000217040 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000205656 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000196848 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsh.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000167560 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000112568 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000088208 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000058008 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniv.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000042552 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgKbd.sys
2019-02-06 13:34 - 2019-02-06 13:34 - 000004004 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2019-02-06 13:34 - 2019-01-07 09:33 - 000015280 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgElam.sys
2019-02-06 10:44 - 2019-02-06 10:44 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2019-02-06 10:44 - 2019-02-06 10:44 - 000047800 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2019-02-06 10:44 - 2019-02-06 10:44 - 000047800 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2019-02-06 10:44 - 2019-02-06 10:44 - 000047800 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2019-02-02 12:21 - 2019-02-05 09:28 - 000000939 _____ C:\WINDOWS\Tasks\EPSON WF-5690 Series Update {B7BA0920-412D-44E8-9642-EFBD23A801AF}.job
2019-02-02 12:21 - 2019-02-05 09:28 - 000000753 _____ C:\WINDOWS\Tasks\EPSON WF-5690 Series Invitation {B7BA0920-412D-44E8-9642-EFBD23A801AF}.job
2019-02-02 12:21 - 2019-02-04 20:28 - 000003492 _____ C:\WINDOWS\System32\Tasks\EPSON WF-5690 Series Update {B7BA0920-412D-44E8-9642-EFBD23A801AF}
2019-02-02 12:21 - 2019-02-04 20:28 - 000003314 _____ C:\WINDOWS\System32\Tasks\EPSON WF-5690 Series Invitation {B7BA0920-412D-44E8-9642-EFBD23A801AF}
2019-01-31 10:52 - 2019-01-31 10:52 - 000000944 _____ C:\Users\FrancsicoJosé\Desktop\xampp-control.exe - Acceso directo.lnk
2019-01-29 11:30 - 2019-01-29 11:28 - 000099192 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2019-01-29 10:31 - 2019-01-31 16:58 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\AvgSetupLog
2019-01-29 09:29 - 2019-01-29 09:29 - 000000424 __RSH C:\ProgramData\ntuser.pol
2019-01-29 09:29 - 2019-01-28 17:48 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-01-29 09:29 - 2019-01-28 17:48 - 000179600 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-01-28 20:18 - 2019-01-28 20:18 - 000000020 ___SH C:\Users\comercio\ntuser.ini
2019-01-28 17:43 - 2019-01-28 17:43 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2019-01-28 17:39 - 2019-02-11 09:33 - 000004220 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{06281D45-2150-4FA3-B17D-B8C025E3F57C}
2019-01-28 17:39 - 2019-02-11 09:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-01-28 17:39 - 2019-02-08 09:25 - 000004086 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2019-01-28 17:39 - 2019-02-08 09:25 - 000003854 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2019-01-28 17:39 - 2019-02-04 20:28 - 000003836 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001UA
2019-01-28 17:39 - 2019-02-04 20:28 - 000003824 _____ C:\WINDOWS\System32\Tasks\Open URL by RoboForm
2019-01-28 17:39 - 2019-02-04 20:28 - 000003780 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-01-28 17:39 - 2019-02-04 20:28 - 000003768 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001UA1d24afb388b31ab
2019-01-28 17:39 - 2019-02-04 20:28 - 000003568 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001Core
2019-01-28 17:39 - 2019-02-04 20:28 - 000003548 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2019-01-28 17:39 - 2019-02-04 20:28 - 000003500 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001Core1d24afb38840a5c
2019-01-28 17:39 - 2019-02-04 20:28 - 000003492 _____ C:\WINDOWS\System32\Tasks\EPSON WF-5690 Series Update {6A80B607-4BF1-41F0-965D-526FFB89733D}
2019-01-28 17:39 - 2019-02-04 20:28 - 000003492 _____ C:\WINDOWS\System32\Tasks\EPSON WF-5690 Series Update {4AA1307B-C9C4-4154-BB5C-738F17DA99B9}
2019-01-28 17:39 - 2019-02-04 20:28 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-01-28 17:39 - 2019-02-04 20:28 - 000003346 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{28E09A97-ECF9-4B02-A67D-8103FD1803F6}
2019-01-28 17:39 - 2019-02-04 20:28 - 000003324 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2019-01-28 17:39 - 2019-02-04 20:28 - 000003314 _____ C:\WINDOWS\System32\Tasks\EPSON WF-5690 Series Invitation {6A80B607-4BF1-41F0-965D-526FFB89733D}
2019-01-28 17:39 - 2019-02-04 20:28 - 000003314 _____ C:\WINDOWS\System32\Tasks\EPSON WF-5690 Series Invitation {4AA1307B-C9C4-4154-BB5C-738F17DA99B9}
2019-01-28 17:39 - 2019-02-04 20:28 - 000003300 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CB7B5A32-1A41-422A-BB40-D118EC1F03B5}
2019-01-28 17:39 - 2019-02-04 20:28 - 000003286 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-01-28 17:39 - 2019-02-04 20:28 - 000003200 _____ C:\WINDOWS\System32\Tasks\Run RoboForm TaskBar Icon
2019-01-28 17:39 - 2019-02-04 20:28 - 000003166 _____ C:\WINDOWS\System32\Tasks\Google Updater and Installer
2019-01-28 17:39 - 2019-02-04 20:28 - 000003110 _____ C:\WINDOWS\System32\Tasks\Java Update Scheduler
2019-01-28 17:39 - 2019-02-04 20:28 - 000003100 _____ C:\WINDOWS\System32\Tasks\Programa de actualización online de Adobe
2019-01-28 17:39 - 2019-02-04 20:28 - 000002878 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-390596928-2417218115-2686252066-1003
2019-01-28 17:39 - 2019-02-04 20:28 - 000002846 _____ C:\WINDOWS\System32\Tasks\[email protected]il.com
2019-01-28 17:39 - 2019-02-04 20:28 - 000002842 _____ C:\WINDOWS\System32\Tasks\TrackerAutoUpdate
2019-01-28 17:39 - 2019-02-04 20:28 - 000002764 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-AMDFX8120-FranciscoJosé
2019-01-28 17:39 - 2019-02-04 20:28 - 000002636 _____ C:\WINDOWS\System32\Tasks\IntelBootstrapCCDashExe
2019-01-28 17:39 - 2019-02-04 20:28 - 000002624 _____ C:\WINDOWS\System32\Tasks\Run RoboForm Process
2019-01-28 17:39 - 2019-02-04 20:28 - 000002596 _____ C:\WINDOWS\System32\Tasks\[email protected]
2019-01-28 17:39 - 2019-02-04 20:28 - 000002326 _____ C:\WINDOWS\System32\Tasks\{B6059D5D-E6A7-41D7-9398-17773B1CE5EC}
2019-01-28 17:39 - 2019-02-04 20:28 - 000002288 _____ C:\WINDOWS\System32\Tasks\{D692D5C7-4088-4D47-B4CA-C115F3EBB7E9}
2019-01-28 17:39 - 2019-02-04 20:28 - 000002146 _____ C:\WINDOWS\System32\Tasks\StartCN
2019-01-28 17:39 - 2019-02-04 20:28 - 000002116 _____ C:\WINDOWS\System32\Tasks\{A3C2207C-CAFC-403B-A0D4-ED1AA0FB6038}
2019-01-28 17:39 - 2019-01-28 17:39 - 000002938 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-390596928-2417218115-2686252066-1001
2019-01-28 17:39 - 2019-01-28 17:39 - 000002526 _____ C:\WINDOWS\System32\Tasks\SamsungMagician
2019-01-28 17:39 - 2019-01-28 17:39 - 000000020 ___SH C:\Users\FrancsicoJosé\ntuser.ini
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 _SHDL C:\Documents and Settings
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 _SHDL C:\Archivos de programa
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\Western Digital
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-390596928-2417218115-2686252066-1001
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\DeskShare
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\AVG
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2019-01-28 17:39 - 2019-01-28 17:39 - 000000000 ____D C:\WINDOWS\System32\Tasks\ASUS
2019-01-28 17:37 - 2019-01-28 17:39 - 000015243 _____ C:\WINDOWS\diagwrn.xml
2019-01-28 17:37 - 2019-01-28 17:39 - 000015243 _____ C:\WINDOWS\diagerr.xml
2019-01-28 17:26 - 2019-02-11 09:33 - 001773362 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-01-28 17:18 - 2019-01-28 17:18 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2019-01-28 17:16 - 2019-01-28 17:16 - 000000000 ____D C:\ProgramData\USOShared
2019-01-28 17:15 - 2019-02-05 13:02 - 000000000 ____D C:\Users\FrancsicoJosé
2019-01-28 17:15 - 2019-01-28 20:18 - 000000000 ____D C:\Users\comercio
2019-01-28 17:15 - 2019-01-28 17:23 - 000000000 ____D C:\Users\lourdes
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Reciente
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Plantillas
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Mis documentos
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Menú Inicio
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Impresoras
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Entorno de red
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Datos de programa
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\Configuración local
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\AppData\Local\Historial
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\AppData\Local\Datos de programa
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\lourdes\AppData\Local\Archivos temporales de Internet
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Reciente
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Plantillas
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Mis documentos
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Menú Inicio
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Impresoras
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Entorno de red
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Datos de programa
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\Configuración local
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\AppData\Local\Historial
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\AppData\Local\Datos de programa
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\FrancsicoJosé\AppData\Local\Archivos temporales de Internet
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Reciente
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Plantillas
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Mis documentos
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Menú Inicio
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Impresoras
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Entorno de red
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Datos de programa
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\Configuración local
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\AppData\Local\Historial
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\AppData\Local\Datos de programa
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 _SHDL C:\Users\comercio\AppData\Local\Archivos temporales de Internet
2019-01-28 17:15 - 2019-01-28 17:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2019-01-28 17:15 - 2018-09-15 08:29 - 000001105 _____ C:\Users\lourdes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-01-28 17:15 - 2018-09-15 08:29 - 000001105 _____ C:\Users\comercio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-01-28 17:14 - 2018-09-15 08:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2019-01-28 17:13 - 2019-02-06 14:22 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-01-28 17:13 - 2019-01-29 16:53 - 005336568 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-01-28 17:11 - 2019-01-28 11:21 - 000408074 __RSH C:\bootmgr
2019-01-28 17:11 - 2019-01-28 11:21 - 000000001 ___SH C:\BOOTNXT
2019-01-28 11:01 - 2019-01-28 17:13 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2019-01-28 10:58 - 2019-01-28 11:01 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2019-01-28 10:54 - 2019-01-28 10:54 - 011724288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 007724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 005440008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 005112792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 004918784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 003601920 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 003566080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 003550384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 002469648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 002429752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2019-01-28 10:54 - 2019-01-28 10:54 - 002323904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 002278448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 002160160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2019-01-28 10:54 - 2019-01-28 10:54 - 001294864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 001289192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 001282640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 001259024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-01-28 10:54 - 2019-01-28 10:54 - 001200920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 001073448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 001057976 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000854784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000762272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2019-01-28 10:54 - 2019-01-28 10:54 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000427520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
2019-01-28 10:54 - 2019-01-28 10:54 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-01-28 10:54 - 2019-01-28 10:54 - 000301096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000263360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000241680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2019-01-28 10:54 - 2019-01-28 10:54 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 026806784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 024617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 023439360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 022111856 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 020811776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 019284480 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 019024384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 015224832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 012858368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 012151808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 009684000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 008875520 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 007897088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 007857152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 006925824 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 006549232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 006306152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 006057984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 005764608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 005584864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 005565952 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 005527552 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 005205464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 005088256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 004886016 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 004702704 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 004630016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 004588544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 004526080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 004298752 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 004019200 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003982848 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003952952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003744256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003730352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 003662336 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 003656192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003504640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003427328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003379000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003108864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 003092480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002986352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002942464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002927112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002879488 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002776920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002702528 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002689024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002626568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 002488320 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 002437552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002392576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002346496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002298880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002275888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002072728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001969704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 001903616 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001863168 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001830912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001749504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001696936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-01-28 10:53 - 2019-01-28 10:53 - 001688576 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001675712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001674480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001671864 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001641400 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001590288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001483264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001467552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001467384 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 001456736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001446400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001415680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001395248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001391096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 001387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001360696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 001341584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-01-28 10:53 - 2019-01-28 10:53 - 001314304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001309184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001294848 _____ (Microsoft Corporation) 

#10
C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001279024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 001271608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001254912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001249792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001221528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2019-01-28 10:53 - 2019-01-28 10:53 - 001180760 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001178344 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 001168384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2019-01-28 10:53 - 2019-01-28 10:53 - 001162280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001098136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 001056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001047552 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001026992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000964976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000927232 _____ (Microsoft Corporation) C:\WINDOWS\system32\assignedaccessmanagersvc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000901632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000887808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprddm.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000863752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000836096 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000820736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000794112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000782968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000762368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprddm.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceControl.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000726208 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000652320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000649272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000622592 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessManager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000615936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000609792 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000588304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000566584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000547840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000522312 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000514112 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000496872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000474936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-01-28 10:53 - 2019-01-28 10:53 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000454160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000430904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000383288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000373768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasppp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\discan.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasppp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000277536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000262672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000252536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000201216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasman.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000175096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPTaskScheduler.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\spopk.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasman.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000151872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastingShellExt.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowService.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpaceAgent.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CastingShellExt.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spopk.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000121872 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcln.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000114344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcln.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000094224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fileinfo.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlahc.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\PktMon.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000091424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\nslookup.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nslookup.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WindowsTrustedRT.sys
2019-01-28 10:53 - 2019-01-28 10:53 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpkinstall.exe
2019-01-28 10:53 - 2019-01-28 10:53 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnsruprov.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfts.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfts.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2019-01-28 10:52 - 2019-01-28 10:53 - 001797128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 017520640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 007685016 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 007645600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 006132736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 005561856 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 005312512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 005130752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 004991096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 004245280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 003556352 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 003386368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 003338328 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002992640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002929152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002766136 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002721792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 002654208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002630656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002618880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002594872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002187264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002185728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002149368 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002085376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 002021584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001842600 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001824768 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001751560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001700880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001616384 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001612808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001604096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001533440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001520208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001496064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001401864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001387496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001331744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001315840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001287776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001258512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 001255944 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 001221120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 001212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001209360 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001199104 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001054200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 001051960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 001051152 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000970256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\drvstore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000918304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000897848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000865784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000864056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000850968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000828936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000822448 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000818832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000806560 _____ C:\WINDOWS\SysWOW64\locale.nls
2019-01-28 10:52 - 2019-01-28 10:52 - 000806560 _____ C:\WINDOWS\system32\locale.nls
2019-01-28 10:52 - 2019-01-28 10:52 - 000799568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000756640 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000752136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000743432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000741888 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000667152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000651792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000651304 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000649736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000629576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000612368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000604552 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000582240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000580024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000527872 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000495624 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000473616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000463672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000408800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000402576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000398416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000387384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000375544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000353488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000320000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000306704 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000300024 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000298296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000294072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000276488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MTF.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000275768 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000273920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000203280 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MTF.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netiohlp.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000195896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000193032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000178696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spacebridge.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSrv.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000164344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000164288 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000157192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netiohlp.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000148480 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000140808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.NetworkOperators.HotspotAuthentication.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000132104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000114856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000102392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000097592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storqosflt.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000090632 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000083472 _____ (Microsoft Corporation) C:\WINDOWS\system32\vid.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000080400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo-overrides.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mmcss.sys
2019-01-28 10:52 - 2019-01-28 10:52 - 000047112 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2019-01-28 10:52 - 2019-01-28 10:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-01-28 10:52 - 2019-01-28 10:52 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-01-28 10:47 - 2019-01-28 10:47 - 001167960 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2019-01-28 10:47 - 2019-01-28 10:47 - 000780376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2019-01-28 10:47 - 2019-01-28 10:47 - 000126064 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2019-01-28 10:47 - 2019-01-28 10:47 - 000104560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2019-01-28 10:47 - 2019-01-28 10:47 - 000036896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2019-01-28 10:47 - 2019-01-28 10:47 - 000035440 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2019-01-28 10:47 - 2019-01-28 10:47 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2019-01-28 10:47 - 2019-01-28 10:47 - 000000000 ____D C:\Program Files\Reference Assemblies
2019-01-28 10:47 - 2019-01-28 10:47 - 000000000 ____D C:\Program Files\MSBuild
2019-01-28 10:47 - 2019-01-28 10:47 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2019-01-28 10:47 - 2019-01-28 10:47 - 000000000 ____D C:\Program Files (x86)\MSBuild
2019-01-28 10:24 - 2019-01-28 10:24 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2019-01-28 09:39 - 2019-02-08 13:11 - 000000000 ___DC C:\WINDOWS\Panther
2019-01-28 09:22 - 2019-01-28 17:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnScreen Control
2019-01-28 09:22 - 2019-01-28 09:22 - 000002096 _____ C:\Users\Public\Desktop\OnScreen Control.lnk
2019-01-28 09:22 - 2019-01-28 09:22 - 000000000 ____D C:\Program Files (x86)\LG Electronics
2019-01-28 09:22 - 2018-05-21 10:58 - 000196608 _____ (LG Soft India) C:\WINDOWS\SysWOW64\LGDeviceManager.dll
2019-01-28 09:22 - 2018-05-21 10:58 - 000135168 _____ (LG Soft India) C:\WINDOWS\SysWOW64\LGMonitorDDCCISDK.dll
2019-01-28 09:22 - 2018-05-21 10:58 - 000102400 _____ (LG Soft India) C:\WINDOWS\SysWOW64\LGProtocolEngine.dll
2019-01-28 09:22 - 2018-05-21 10:58 - 000049152 _____ () C:\WINDOWS\SysWOW64\LGErrorHandler.dll
2019-01-18 12:38 - 2019-01-18 12:38 - 000000656 _____ C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2019-01-16 12:21 - 2019-01-16 12:22 - 000127748 _____ C:\TDSSKiller.3.1.0.25_16.01.2019_12.21.15_log.txt
2019-01-15 17:17 - 2019-01-28 17:17 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AdWords Editor

#11
Editor

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-02-11 11:07 - 2018-07-14 11:08 - 000000000 ____D C:\wifidata
2019-02-11 11:05 - 2016-03-07 21:15 - 000000000 _____ C:\WINDOWS\Path.idx
2019-02-11 10:28 - 2018-11-29 10:07 - 000000000 ____D C:\Program Files\Emsisoft Anti-Malware
2019-02-11 10:21 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2019-02-11 09:42 - 2017-01-09 16:56 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\WhatsApp
2019-02-11 09:42 - 2017-01-09 16:56 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2019-02-11 09:42 - 2016-06-11 09:20 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\SquirrelTemp
2019-02-11 09:39 - 2015-04-10 19:41 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\CrashDumps
2019-02-11 09:33 - 2018-09-15 17:37 - 000788392 _____ C:\WINDOWS\system32\perfh00A.dat
2019-02-11 09:33 - 2018-09-15 17:37 - 000155682 _____ C:\WINDOWS\system32\perfc00A.dat
2019-02-11 09:33 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-02-11 09:33 - 2018-09-15 08:31 - 000000000 ____D C:\WINDOWS\INF
2019-02-11 09:33 - 2016-10-25 18:43 - 000000000 ____D C:\Program Files (x86)\Dropbox
2019-02-11 09:33 - 2014-08-26 08:00 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\Adobe
2019-02-11 09:30 - 2016-03-07 21:10 - 001048576 _____ C:\WINDOWS\PE_Rom.dll
2019-02-11 09:29 - 2018-08-14 10:25 - 000000000 ___RD C:\Users\FrancsicoJosé\OneDrive
2019-02-11 09:28 - 2018-09-15 07:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-02-11 09:28 - 2016-11-18 17:15 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\LocalLow\Mozilla
2019-02-11 09:28 - 2016-09-23 19:11 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\Eye-FiX2
2019-02-11 09:28 - 2013-01-04 18:09 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\GoodSync
2019-02-11 09:27 - 2018-06-11 19:22 - 000000000 ____D C:\Program Files (x86)\TunnelBear
2019-02-08 20:34 - 2018-09-15 07:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-02-08 20:34 - 2017-06-09 19:36 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2019-02-08 20:01 - 2018-09-15 08:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-02-08 19:43 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-02-08 19:43 - 2012-12-31 08:57 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\ElevatedDiagnostics
2019-02-08 13:22 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-02-08 13:22 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-02-08 13:22 - 2018-06-13 15:58 - 000000000 ____D C:\ProgramData\Packages
2019-02-08 13:11 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-02-08 13:11 - 2015-05-02 09:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-02-08 13:11 - 2013-04-06 11:12 - 000000000 ____D C:\ProgramData\Wondershare Video Converter Ultimate
2019-02-08 13:06 - 2016-10-25 18:43 - 000001026 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2019-02-08 13:06 - 2016-10-25 18:43 - 000001022 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2019-02-08 13:03 - 2017-03-11 11:47 - 000000000 ____D C:\AdwCleaner
2019-02-08 10:14 - 2013-02-25 16:37 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-02-06 18:18 - 2014-09-04 10:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-02-06 17:55 - 2018-09-15 08:33 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-02-06 12:38 - 2018-10-17 16:18 - 000089491 _____ C:\ads_err.dbf
2019-02-06 09:24 - 2012-12-24 20:41 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-02-05 19:34 - 2013-02-03 09:32 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\FileZilla
2019-02-05 16:53 - 2012-12-24 20:41 - 000000000 ____D C:\ProgramData\Mozilla
2019-02-05 16:52 - 2016-02-12 10:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-02-05 16:52 - 2012-12-24 20:41 - 000001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-02-05 09:28 - 2018-08-14 12:22 - 000000600 _____ C:\WINDOWS\Tasks\TrackerAutoUpdate.job
2019-02-05 09:28 - 2017-07-24 09:07 - 000000939 _____ C:\WINDOWS\Tasks\EPSON WF-5690 Series Update {4AA1307B-C9C4-4154-BB5C-738F17DA99B9}.job
2019-02-05 09:28 - 2017-07-24 09:07 - 000000753 _____ C:\WINDOWS\Tasks\EPSON WF-5690 Series Invitation {4AA1307B-C9C4-4154-BB5C-738F17DA99B9}.job
2019-02-05 09:28 - 2016-11-30 12:16 - 000001162 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001UA.job
2019-02-05 09:28 - 2016-11-30 12:16 - 000001110 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001Core.job
2019-02-05 09:28 - 2016-02-11 19:32 - 000000939 _____ C:\WINDOWS\Tasks\EPSON WF-5690 Series Update {6A80B607-4BF1-41F0-965D-526FFB89733D}.job
2019-02-05 09:28 - 2016-02-11 19:32 - 000000753 _____ C:\WINDOWS\Tasks\EPSON WF-5690 Series Invitation {6A80B607-4BF1-41F0-965D-526FFB89733D}.job
2019-02-04 18:37 - 2018-01-20 10:24 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Mazda
2019-02-04 18:36 - 2017-11-09 12:54 - 000000000 ____D C:\Program Files (x86)\Mazda
2019-02-01 11:28 - 2016-02-09 17:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2019-02-01 11:28 - 2016-02-09 17:47 - 000000000 ____D C:\Program Files (x86)\epson
2019-02-01 11:28 - 2016-02-09 17:00 - 000000000 ____D C:\ProgramData\Epson
2019-01-31 17:01 - 2015-02-21 11:36 - 000000000 ____D C:\Program Files (x86)\AVG
2019-01-31 16:58 - 2013-10-21 17:47 - 000000000 ____D C:\ProgramData\AVG
2019-01-31 13:00 - 2013-02-03 09:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2019-01-29 20:00 - 2017-11-22 20:03 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Wondershare
2019-01-29 20:00 - 2017-11-22 20:02 - 000000000 ____D C:\Program Files (x86)\Wondershare
2019-01-29 19:57 - 2015-01-30 18:55 - 000000000 ____D C:\ProgramData\Wondershare
2019-01-29 19:57 - 2013-04-06 11:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2019-01-29 11:30 - 2016-11-24 13:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2019-01-29 11:30 - 2016-11-24 13:27 - 000000000 ____D C:\Program Files (x86)\Java
2019-01-29 11:30 - 2013-08-27 18:43 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2019-01-29 11:30 - 2013-08-27 18:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2019-01-29 11:30 - 2012-12-28 11:54 - 000000000 ____D C:\Program Files\WinRAR
2019-01-29 11:08 - 2014-10-23 19:35 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\TeamViewer
2019-01-29 09:37 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\appcompat
2019-01-28 20:18 - 2015-01-16 16:34 - 000000807 _____ C:\Users\FrancsicoJosé\Desktop\Kodi.lnk
2019-01-28 20:18 - 2015-01-16 16:34 - 000000000 ____D C:\Users\comercio\AppData\Roaming\Kodi
2019-01-28 19:41 - 2018-09-15 08:33 - 000000000 ___RD C:\Program Files\Windows Defender
2019-01-28 19:41 - 2018-02-17 12:45 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-01-28 17:58 - 2018-01-20 12:59 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\Packages
2019-01-28 17:46 - 2012-12-24 20:19 - 000592616 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-01-28 17:43 - 2018-02-21 12:17 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\PlaceholderTileLogoFolder
2019-01-28 17:40 - 2017-06-09 20:16 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Local\ConnectedDevicesPlatform
2019-01-28 17:40 - 2017-05-30 19:30 - 000000000 ___RD C:\Users\FrancsicoJosé\3D Objects
2019-01-28 17:40 - 2012-12-24 19:25 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-01-28 17:39 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\windows nt
2019-01-28 17:37 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Registration
2019-01-28 17:34 - 2018-09-15 08:33 - 000000000 __RSD C:\WINDOWS\media
2019-01-28 17:34 - 2018-09-15 08:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-01-28 17:34 - 2013-11-02 12:05 - 000023172 _____ C:\WINDOWS\system32\emptyregdb.dat
2019-01-28 17:17 - 2018-10-26 20:23 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
2019-01-28 17:17 - 2018-09-26 17:50 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASG PartiPlus
2019-01-28 17:17 - 2018-05-25 18:15 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVDFab 10 (x64)
2019-01-28 17:17 - 2018-05-25 16:30 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2019-01-28 17:17 - 2018-03-29 17:37 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QNAP
2019-01-28 17:17 - 2018-03-03 11:31 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinDirStat
2019-01-28 17:17 - 2018-02-22 18:20 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2019-01-28 17:17 - 2018-02-14 11:26 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome
2019-01-28 17:17 - 2017-11-09 12:54 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mazda
2019-01-28 17:17 - 2017-09-04 11:57 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
2019-01-28 17:17 - 2017-06-05 17:32 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\muCommander
2019-01-28 17:17 - 2017-01-26 12:04 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logitech
2019-01-28 17:17 - 2016-09-23 19:11 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eye-Fi
2019-01-28 17:17 - 2016-08-08 11:18 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Android SDK Tools
2019-01-28 17:17 - 2016-04-23 10:51 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager
2019-01-28 17:17 - 2016-02-12 09:50 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\pdfFactory Pro
2019-01-28 17:17 - 2016-02-11 19:54 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FinePrint
2019-01-28 17:17 - 2015-05-17 12:02 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IETester
2019-01-28 17:17 - 2015-02-03 15:52 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2019-01-28 17:17 - 2014-05-09 08:41 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\No-IP DUC
2019-01-28 17:17 - 2013-12-08 11:22 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WBFS Manager
2019-01-28 17:17 - 2013-07-01 08:37 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2019-01-28 17:17 - 2013-06-07 18:16 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plex Media Center
2019-01-28 17:17 - 2013-01-22 13:32 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2019-01-28 17:17 - 2013-01-03 16:22 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Apache Friends
2019-01-28 17:17 - 2012-12-26 12:13 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LaserSoft Imaging
2019-01-28 17:16 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\USOPrivate
2019-01-28 17:16 - 2014-04-30 09:04 - 000000000 ____D C:\Users\comercio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XBMC
2019-01-28 17:16 - 2014-04-29 18:54 - 000000000 ____D C:\Users\comercio\AppData\Local\Packages
2019-01-28 17:15 - 2017-06-09 19:36 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-01-28 17:15 - 2017-06-09 19:36 - 000000000 ____D C:\WINDOWS\system32\DAX2
2019-01-28 17:14 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ServiceState
2019-01-28 17:13 - 2019-01-04 19:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free EML File Viewer
2019-01-28 17:13 - 2018-11-29 10:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
2019-01-28 17:13 - 2018-09-15 17:37 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\spool
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\System
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Resources
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\InputMethod
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Cursors
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\system
2019-01-28 17:13 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-01-28 17:13 - 2018-09-15 08:31 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2019-01-28 17:13 - 2018-08-03 13:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2019-01-28 17:13 - 2018-06-19 10:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mobirise4
2019-01-28 17:13 - 2018-06-11 19:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TunnelBear
2019-01-28 17:13 - 2018-05-25 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 10 (x64)
2019-01-28 17:13 - 2018-05-25 17:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix
2019-01-28 17:13 - 2018-05-25 16:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU
2019-01-28 17:13 - 2018-05-11 09:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2019-01-28 17:13 - 2018-04-30 17:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2019-01-28 17:13 - 2018-04-26 16:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AM-DeadLink
2019-01-28 17:13 - 2018-04-18 16:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 6.0
2019-01-28 17:13 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2019-01-28 17:13 - 2018-02-24 10:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2019-01-28 17:13 - 2018-02-07 18:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoodSync
2019-01-28 17:13 - 2018-01-04 17:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SILKYPIX Developer Studio 4.4 SE
2019-01-28 17:13 - 2018-01-02 20:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Icecream Image Resizer
2019-01-28 17:13 - 2017-12-21 17:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodi
2019-01-28 17:13 - 2017-11-08 19:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer
2019-01-28 17:13 - 2017-09-05 11:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF
2019-01-28 17:13 - 2017-08-01 13:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2019-01-28 17:13 - 2017-06-21 19:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoFirma
2019-01-28 17:13 - 2017-06-09 19:36 - 000000000 ____D C:\Program Files\AMD
2019-01-28 17:13 - 2017-05-08 13:18 - 000000000 ____D C:\WINDOWS\system32\PÆwër
2019-01-28 17:13 - 2017-05-02 12:31 - 000000000 ____D C:\WINDOWS\system32\PÄçï
2019-01-28 17:13 - 2017-04-28 19:36 - 000000000 ____D C:\WINDOWS\system32\PÇß_§
2019-01-28 17:13 - 2017-04-27 19:38 - 000000000 ____D C:\WINDOWS\system32\PÄG­`
2019-01-28 17:13 - 2017-04-26 19:22 - 000000000 ____D C:\WINDOWS\system32\pËoÔÅ
2019-01-28 17:13 - 2017-04-12 12:43 - 000000000 ____D C:\WINDOWS\system32\PÄ—˜µ
2019-01-28 17:13 - 2017-04-11 12:26 - 000000000 ____D C:\WINDOWS\system32\PÉoÏG
2019-01-28 17:13 - 2017-04-03 09:10 - 000000000 ____D C:\WINDOWS\system32\pʿiT
2019-01-28 17:13 - 2017-03-28 19:32 - 000000000 ____D C:\WINDOWS\system32\pÆßF9
2019-01-28 17:13 - 2017-03-27 12:39 - 000000000 ____D C:\WINDOWS\system32\p˯Ñæ
2019-01-28 17:13 - 2017-03-10 13:34 - 000000000 ____D C:\WINDOWS\system32\pÉç±z
2019-01-28 17:13 - 2017-03-08 19:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel PaintShop Pro X8
2019-01-28 17:13 - 2017-03-08 16:13 - 000000000 ____D C:\WINDOWS\system32\PÆ·Pê
2019-01-28 17:13 - 2017-03-01 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediBackup
2019-01-28 17:13 - 2017-03-01 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail
2019-01-28 17:13 - 2017-02-25 11:50 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Connect Center
2019-01-28 17:13 - 2017-02-25 11:50 - 000000000 ____D C:\Program Files\Intel
2019-01-28 17:13 - 2017-02-08 10:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2019-01-28 17:13 - 2017-02-06 13:48 - 000000000 ____D C:\WINDOWS\system32\PËÿ;D
2019-01-28 17:13 - 2017-02-01 13:23 - 000000000 ____D C:\WINDOWS\system32\PÉo”y
2019-01-28 17:13 - 2017-01-26 19:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Multilizer PDF Translator
2019-01-28 17:13 - 2017-01-16 20:30 - 000000000 ____D C:\WINDOWS\system32\PLJ;7
2019-01-28 17:13 - 2017-01-02 20:59 - 000000000 ____D C:\WINDOWS\system32\pÄÇ$÷
2019-01-28 17:13 - 2016-12-19 13:34 - 000000000 ____D C:\WINDOWS\system32\pÄ¿šË
2019-01-28 17:13 - 2016-12-13 20:42 - 000000000 ____D C:\WINDOWS\system32\pÆGz^
2019-01-28 17:13 - 2016-12-05 12:28 - 000000000 ____D C:\WINDOWS\system32\PƯÿã
2019-01-28 17:13 - 2016-11-23 16:31 - 000000000 ____D C:\WINDOWS\system32\PÉWéÆ
2019-01-28 17:13 - 2016-11-17 13:26 - 000000000 ____D C:\WINDOWS\system32\Pɯn¸
2019-01-28 17:13 - 2016-10-29 08:33 - 000000000 ____D C:\WINDOWS\system32\m32
2019-01-28 17:13 - 2016-10-27 12:39 - 000000000 ____D C:\WINDOWS\system32\ÿÿÿÿÿÿÿÿ
2019-01-28 17:13 - 2016-10-26 19:17 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
2019-01-28 17:13 - 2016-07-14 09:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FOSCAM
2019-01-28 17:13 - 2016-05-16 08:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT
2019-01-28 17:13 - 2016-02-09 18:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
2019-01-28 17:13 - 2016-01-09 10:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2019-01-28 17:13 - 2015-09-30 10:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IPCWebComponents
2019-01-28 17:13 - 2015-07-13 18:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskMark4
2019-01-28 17:13 - 2015-05-13 15:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2019-01-28 17:13 - 2015-04-09 18:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2019-01-28 17:13 - 2015-03-22 12:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant Pro
2019-01-28 17:13 - 2015-03-07 10:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Transmission-Qt
2019-01-28 17:13 - 2015-01-23 10:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
2019-01-28 17:13 - 2014-11-30 11:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Passware
2019-01-28 17:13 - 2014-10-23 18:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PuTTY
2019-01-28 17:13 - 2014-09-13 10:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced RAR Repair
2019-01-28 17:13 - 2014-09-06 09:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ISO to USB
2019-01-28 17:13 - 2014-09-05 11:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2019-01-28 17:13 - 2014-09-02 12:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Argente Utilities
2019-01-28 17:13 - 2014-08-23 10:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter
2019-01-28 17:13 - 2014-08-08 09:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSD Tweaker
2019-01-28 17:13 - 2014-08-03 10:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft TotalMedia Theatre 6
2019-01-28 17:13 - 2014-07-15 17:53 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
2019-01-28 17:13 - 2014-06-04 15:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SopCast
2019-01-28 17:13 - 2014-04-28 09:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2019-01-28 17:13 - 2014-03-10 17:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 9.3.0
2019-01-28 17:13 - 2014-02-19 19:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eac3to µGUI
2019-01-28 17:13 - 2014-02-18 17:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\dBpoweramp Music Converter
2019-01-28 17:13 - 2014-02-15 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genymotion
2019-01-28 17:13 - 2014-01-08 11:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cámara IP Super Cliente
2019-01-28 17:13 - 2014-01-02 16:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 9
2019-01-28 17:13 - 2013-12-24 09:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2019-01-28 17:13 - 2013-12-13 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Toolbox for RAR
2019-01-28 17:13 - 2013-12-07 15:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
2019-01-28 17:13 - 2013-12-07 13:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CloneDVD5
2019-01-28 17:13 - 2013-10-07 15:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
2019-01-28 17:13 - 2013-09-26 18:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Resident Evil Revelations
2019-01-28 17:13 - 2013-09-18 17:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMP WinOFF
2019-01-28 17:13 - 2013-08-30 17:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RIOT
2019-01-28 17:13 - 2013-08-22 16:36 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2019-01-28 17:13 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2019-01-28 17:13 - 2013-08-22 16:36 - 000000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2019-01-28 17:13 - 2013-08-20 08:03 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-01-28 17:13 - 2013-07-22 18:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinMerge
2019-01-28 17:13 - 2013-07-04 08:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClearProg
2019-01-28 17:13 - 2013-05-21 09:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB2.0 PC CAMERA
2019-01-28 17:13 - 2013-05-16 16:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dinahosting
2019-01-28 17:13 - 2013-05-13 17:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PY Software
2019-01-28 17:13 - 2013-05-03 09:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belvedere
2019-01-28 17:13 - 2013-04-07 11:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2019-01-28 17:13 - 2013-03-30 12:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX710 series Manual
2019-01-28 17:13 - 2013-03-30 12:03 - 000000000 ____D C:\WINDOWS\system32\STRING
2019-01-28 17:13 - 2013-03-04 10:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FILEminimizer Pictures 3.0
2019-01-28 17:13 - 2013-02-22 12:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro
2019-01-28 17:13 - 2013-01-16 11:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JMicron Technology Corp
2019-01-28 17:13 - 2013-01-04 17:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2019-01-28 17:13 - 2013-01-04 13:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Golden .NET para Expansión
2019-01-28 17:13 - 2013-01-03 18:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Who Is On My Wifi
2019-01-28 17:13 - 2013-01-03 10:19 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2019-01-28 17:13 - 2013-01-02 19:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lotus SmartSuite
2019-01-28 17:13 - 2012-12-28 11:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2019-01-28 17:13 - 2012-12-27 10:34 - 000000000 ____D C:\WINDOWS\system32\appmgmt
2019-01-28 17:13 - 2012-12-26 12:03 - 000000000 ___HD C:\WINDOWS\system32\CanonIJ Uninstaller Information
2019-01-28 17:13 - 2012-12-26 12:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CanoScan 9000F
2019-01-28 17:11 - 2013-11-02 11:44 - 000008192 __RSH C:\BOOTSECT.BAK
2019-01-28 11:26 - 2018-09-15 08:36 - 000000000 ____D C:\WINDOWS\Setup
2019-01-28 11:14 - 2018-09-15 08:33 - 000000000 __RHD C:\Users\Public\Libraries
2019-01-28 11:14 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2019-01-28 11:03 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2019-01-28 11:02 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2019-01-28 11:02 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\IME
2019-01-28 11:01 - 2018-10-03 18:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xolido Systems
2019-01-28 11:01 - 2018-10-02 19:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Franzis
2019-01-28 11:01 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Help
2019-01-28 11:01 - 2018-04-17 16:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software DELSOL
2019-01-28 11:01 - 2018-04-12 16:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2019-01-28 11:01 - 2018-02-28 19:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eMagicOne
2019-01-28 11:01 - 2017-11-22 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QNAP
2019-01-28 11:01 - 2017-06-09 19:36 - 000000000 ____D C:\Program Files\Realtek
2019-01-28 11:01 - 2017-06-09 19:36 - 000000000 ____D C:\Program Files\CONEXANT
2019-01-28 11:01 - 2017-06-09 19:36 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
2019-01-28 11:01 - 2017-01-26 13:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2019-01-28 11:01 - 2016-04-20 15:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vulkan 1.0.3.1
2019-01-28 11:01 - 2016-03-07 21:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2019-01-28 11:01 - 2016-02-09 19:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EpsonNet
2019-01-28 11:01 - 2015-03-09 11:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tipard
2019-01-28 11:01 - 2015-01-07 12:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2019-01-28 11:01 - 2014-09-17 19:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capcom
2019-01-28 11:01 - 2014-04-25 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire
2019-01-28 11:01 - 2014-04-24 15:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD
2019-01-28 11:01 - 2014-02-19 09:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OJOsoft
2019-01-28 11:01 - 2014-01-07 11:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panasonic
2019-01-28 11:01 - 2013-08-30 08:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firetrust
2019-01-28 11:01 - 2013-01-11 20:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Agencia Tributaria
2019-01-28 11:01 - 2013-01-07 11:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2019-01-28 11:01 - 2013-01-04 17:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies
2019-01-28 11:01 - 2013-01-02 17:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\r2 Studios
2019-01-28 11:01 - 2012-12-31 12:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
2019-01-28 10:55 - 2018-09-15 17:40 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2019-01-28 10:55 - 2018-09-15 17:40 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-01-28 10:55 - 2018-09-15 17:40 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\TextInput
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-01-28 10:55 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-01-28 10:55 - 2018-09-15 07:09 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-01-28 10:47 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2019-01-28 10:47 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\MUI
2019-01-28 09:22 - 2013-01-16 11:10 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2019-01-22 13:22 - 2017-08-01 13:49 - 000000000 ____D C:\Users\FrancsicoJosé\AppData\Roaming\vlc
2019-01-18 09:42 - 2018-01-12 09:39 - 000000000 ____D C:\Program Files\rempl
2019-01-16 16:53 - 2014-04-28 09:11 - 000000000 ____D C:\Program Files\Microsoft Silverlight
2019-01-16 16:53 - 2014-04-28 09:11 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight

==================== Files in the root of some directories =======

2013-12-07 13:52 - 2013-12-07 15:06 - 000002667 _____ () C:\ProgramData\MainApp.dll
2018-05-25 17:52 - 2018-05-25 17:52 - 000000171 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\1eb766f2-fed1-4d33-9c39-2c8a972fd11f
2018-05-25 17:52 - 2018-05-25 17:52 - 000000304 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\4e93aa11-2d46-4980-a421-0a4ac759e5bf
2018-05-25 17:52 - 2018-05-25 17:52 - 000000175 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\fc19ece2-6b3f-4f22-8758-9651ab9ca388
2013-12-07 13:50 - 2013-12-07 13:50 - 000099384 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\inst.exe
2013-12-07 13:50 - 2013-12-07 13:50 - 000007859 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\pcouffin.cat
2013-12-07 13:50 - 2013-12-07 13:50 - 000001167 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\pcouffin.inf
2013-12-07 13:50 - 2013-12-07 13:50 - 000000034 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\pcouffin.log
2013-12-07 13:50 - 2013-12-07 13:50 - 000082816 _____ (VSO Software) C:\Users\FrancsicoJosé\AppData\Roaming\pcouffin.sys
2015-02-26 12:46 - 2015-02-26 12:46 - 000000132 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\Prefs. de formato GIF de Adobe CC
2015-03-06 17:00 - 2015-03-06 17:00 - 000000132 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\Prefs. de formato PNG de Adobe CC
2014-11-30 11:25 - 2014-11-30 11:25 - 000038495 _____ () C:\Users\FrancsicoJosé\AppData\Roaming\Valores separados por comas (DOS).ADR
2015-10-01 16:32 - 2015-10-01 16:32 - 000002615 _____ () C:\Users\FrancsicoJosé\AppData\Local\ACCCx3_3_0_151.zip.aamdownload.aamd
2014-08-03 10:30 - 2015-03-07 11:04 - 001484288 _____ () C:\Users\FrancsicoJosé\AppData\Local\ASbs.ac
2017-04-08 11:47 - 2017-04-08 11:47 - 000003584 _____ () C:\Users\FrancsicoJosé\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-05-03 19:16 - 2018-05-03 19:16 - 000465408 _____ (Dirección General de la Policía) C:\Users\FrancsicoJosé\AppData\Local\DNIeService.exe
2014-08-23 08:25 - 2014-08-23 08:25 - 000000001 _____ () C:\Users\FrancsicoJosé\AppData\Local\llftool.4.40.agreement
2014-10-27 10:04 - 2014-10-27 10:04 - 000000233 _____ () C:\Users\FrancsicoJosé\AppData\Local\poetsch.bat
2018-03-02 19:06 - 2018-03-02 19:06 - 000000001 _____ () C:\Users\FrancsicoJosé\AppData\Local\RawCopy.1.10.agreement
2014-04-17 19:56 - 2014-07-09 19:01 - 000007643 _____ () C:\Users\FrancsicoJosé\AppData\Local\Resmon.ResmonCfg
2019-02-11 09:42 - 2019-02-11 09:42 - 000000000 ____N () C:\Users\FrancsicoJosé\AppData\Local\slc5E77.tmp
2019-02-08 20:20 - 2019-02-08 20:20 - 000000000 ____N () C:\Users\FrancsicoJosé\AppData\Local\slc6DF0.tmp

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

#12
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10.02.2019 01
Ran by FranciscoJosé (11-02-2019 11:17:12)
Running from J:\Mis documentos C\Descargas
Windows 10 Pro Version 1809 17763.292 (X64) (2019-01-28 16:39:53)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-390596928-2417218115-2686252066-500 - Administrator - Disabled)
comercio (S-1-5-21-390596928-2417218115-2686252066-1003 - Administrator - Enabled) => C:\Users\comercio
DefaultAccount (S-1-5-21-390596928-2417218115-2686252066-503 - Limited - Disabled)
FranciscoJosé (S-1-5-21-390596928-2417218115-2686252066-1001 - Administrator - Enabled) => C:\Users\FrancsicoJosé
Invitado (S-1-5-21-390596928-2417218115-2686252066-501 - Limited - Disabled)
lourdes (S-1-5-21-390596928-2417218115-2686252066-1002 - Administrator - Enabled) => C:\Users\lourdes
WDAGUtilityAccount (S-1-5-21-390596928-2417218115-2686252066-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Emsisoft Anti-Malware (Disabled - Up to date) {67773CDD-EA83-AD98-A2ED-386463EB3B0D}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {4FC75CA5-1654-5411-7CFB-1893D506BCF4}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Emsisoft Anti-Malware (Disabled - Up to date) {DC16DD39-CCB9-A216-985D-0316186C71B0}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F4A6BD41-306E-5B9F-464B-23E1AE81F649}
FW: AVG Antivirus (Enabled) {77FCDD80-5C3B-5549-57A4-B1A62BD5FB8F}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acronis True Image 2015 (HKLM-x32\...\{7578E92F-C9D1-4C3D-9D2B-DC9908F6FF1B}) (Version: 18.0.6615 - Acronis) Hidden
Acronis True Image 2015 (HKLM-x32\...\{7578E92F-C9D1-4C3D-9D2B-DC9908F6FF1B}Visible) (Version: 18.0.6615 - Acronis)
Active WebCam (HKLM-x32\...\Active WebCam) (Version:  - )
Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 19.010.20069 - Adobe Systems Incorporated)
Adobe Fireworks CS6 (HKLM-x32\...\{CA7C485C-7A89-11E1-B2C8-CD54B377BC52}) (Version: 12.0.1 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.114 - Adobe Systems Incorporated)
Advanced RAR Repair v1.2 (HKLM-x32\...\Advanced RAR Repair v1.2) (Version:  - )
AdWords Editor (HKLM-x32\...\{F3A741C0-183C-11E9-BE2C-DC4A3E998CF6}) (Version: 12.6.1.0 - Google)
AI Suite II (HKLM-x32\...\{34D3688E-A737-44C5-9E2A-FF73618728E1}) (Version: 2.04.01 - ASUSTeK Computer Inc.)
AIDA64 Extreme v5.97 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.97 - FinalWire Ltd.)
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\{838DA1F1-23F8-4C70-B190-AC51CB5A5ECD}) (Version: 3.1.45.72435 - Alcor Micro Corp.) Hidden
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\InstallShield_{838DA1F1-23F8-4C70-B190-AC51CB5A5ECD}) (Version: 3.1.45.72435 - Alcor Micro Corp.)
ALPS Touch Pad Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.201.1711.122 - Alps Electric)
Amazon Drive (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Amazon Drive) (Version: 5.1.1 - Amazon.com, Inc.)
AM-DeadLink 4.7 (HKLM-x32\...\aignesamdeadlink_is1) (Version: 4.7 - www.aignes.com)
AMP WinOFF 5.0.1 (HKLM-x32\...\AMP WinOFF) (Version: 5.0.1 - Alberto Martinez Perez)
Android SDK Tools (HKLM-x32\...\Android SDK Tools) (Version: 1.16 - Google Inc.)
AOMEI Partition Assistant Pro Edition 5.6 (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-5498165BF300}_is1) (Version:  - AOMEI Technology Co., Ltd.)
ArcSoft TotalMedia Theatre 6 (HKLM-x32\...\{5232358C-7C23-4319-8271-E43F924196AC}) (Version: 6.7.1.199 - ArcSoft) Hidden
ArcSoft TotalMedia Theatre 6 (HKLM-x32\...\InstallShield_{5232358C-7C23-4319-8271-E43F924196AC}) (Version: 6.7.1.199 - ArcSoft)
Argente Utilities 1.0.6.1 (HKLM-x32\...\Argente Utilities_is1) (Version: 1.0.6.1 - Argente Software)
ASG PartiPlus (HKLM-x32\...\ASG PartiPlus) (Version:  - )
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
Asterisk Key 10.0 (HKLM-x32\...\asterisk key) (Version:  - )
ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.030 - ASUSTek Computer Inc.)
ASUS Share Link (HKLM-x32\...\{c3bcc1e3-f950-439c-bcae-f01283e9f2a4}_is1) (Version: 1.0.27.0911 - ASUSTEK)
AutoFirma (HKLM-x32\...\AutoFirma) (Version: 1.5.0 - Gobierno de España)
AVG Internet Security (HKLM-x32\...\AVG Antivirus) (Version: 19.2.3079 - AVG Technologies)
AVS Video Converter 10.1.1 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 10.1.1.621 - Online Media Technologies Ltd.)
Backup and Sync from Google (HKLM\...\{693CADB0-962B-4AC1-A939-9524B258C997}) (Version: 3.43.2448.9071 - Google, Inc.)
Belvedere 0.7.1 (HKLM-x32\...\Belvedere) (Version: 0.7.1 - Lifehacker)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre 64bit (HKLM\...\{D089AE9E-F9B3-4ED4-9883-08E88768236D}) (Version: 3.38.0 - Kovid Goyal)
Cámara IP Super Cliente 1.0.4.556 (HKLM-x32\...\{BE59011C-CE48-45DC-9345-73D5C20C0EBB}_is1) (Version:  - Shenzhen VStarcam Technology Co., Ltd)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version:  - )
Canon MP Navigator EX 3.1 (HKLM-x32\...\MP Navigator EX 3.1) (Version:  - )
Canon MP Navigator EX 5.1 (HKLM-x32\...\MP Navigator EX 5.1) (Version:  - )
Canon Utilidad de marcación rápida (HKLM-x32\...\Speed Dial Utility) (Version:  - )
Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.12.52.0 - Canon Inc.)
Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.12.3.1 - Canon Inc.)
CanoScan 9000F Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ9602) (Version:  - )
Capicom 2.1.0.2 FNMT-RCM (HKLM-x32\...\{E06DBD80-CD9B-4A3F-BD83-ED1AA4CB1E3A}) (Version: 1.00.0000 - FNMT-RCM)
Catalyst Control Center Next Localization BR (HKLM\...\{118C2119-84B6-E32C-63E2-B56DBCF41CE5}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{3E245378-BF77-6946-C6F6-096DBE5EAB82}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{51F85784-6799-5CA3-97B2-2E5904FC3E58}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{A16E186C-58C4-3BDC-5CCE-714EFEF5F27F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{45907537-804A-514F-5280-5F4F12A6DCBC}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{5A083A57-10D6-D4E5-292C-F274870E73A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{8E6F5592-ED7E-9C50-74AC-BF417B1FE291}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{E42911E5-48F8-8557-ED20-D72AD1907D25}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{962364E4-08BB-347D-32E7-2B789F37BF8A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{AD28960A-6190-C991-C964-308B86EAA2E2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B4C30EF4-B2C5-1395-B534-7B63BCB6E8E4}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{DF0D7C1C-72B6-9FFB-DF66-B3720237BB80}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{238F6F6F-2544-86CF-3AB6-2CDADAB58CF0}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{62098A5F-E03B-31A3-5F9C-51A7F7D25744}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{84C3F2C5-F7B2-2F08-CDF4-79EF7CC55D74}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{A0407E39-2AA4-60B3-885F-3C5347B6909E}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0989D0EA-AFF3-5F9A-3D25-20EE133E409B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0E8A3B17-D603-B1B6-C205-1685EBDD23E9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{1757AD9B-0E3C-05F9-FE43-4343BED7DA85}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{EC688BD0-240D-AE40-55F3-234E54919AE6}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{1E7D3072-1D28-E33A-99DF-85D9F7ECD06E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{66B06F29-EE4F-9130-D96A-754826093FEA}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{A8689A0F-5928-7300-B82B-C5E85131B7BA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{E27224E3-7913-DA1E-5B08-9BEEC8FEE3D1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{76AAF56B-93D8-161D-809A-EC05F3B913DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{821D0A0E-F246-BE40-0D68-93883C14C410}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{95A52FC1-C728-841D-1BFC-CC793B77B0A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{BA26B70C-3D8C-2D14-4122-211FB3E6F691}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{063CED74-F5F0-870E-DC9C-2D78FDEDA3EE}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{5FEACE78-C338-9AED-FF05-7DE7E273C774}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{88BD74C4-23AB-4554-915C-6E1F0C81F6CD}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{A22CDEBA-6DB5-12CD-F6CE-6238C2D78363}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{13BB60AA-88F7-4B1F-2DEC-D81EEDE8B3AA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A3795528-F572-6314-C4E3-EE9DAF0FBF02}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A48E2AB0-0866-7783-9657-E1709EB18D02}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{C0BFC67D-E447-02C8-6046-C078DFE9EC97}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{37AA6227-FF2C-95AC-87C0-45DCC0BB87DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{4853A56D-7931-A08B-5BA7-8E2D61043DF9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{94C72EBE-2908-F0AC-62DA-D61951830F8F}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{E61CEF9A-BAC3-EAEE-F735-E257D2354DF2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{5B987681-3652-492B-6A11-E02AC0FE5959}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{B28CF677-E2C8-12CA-52BB-19B6F066D36A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{DA0326BB-657D-AAFC-752C-363E8FA33755}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{EB328356-1DF0-1CCE-3607-6361DD329219}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{43F6D22B-E0E9-EE90-9B62-1C5FC5D15A55}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{86BFE5B4-1FCE-3C02-6373-92B1AE6431E8}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{87E6EC29-AEC5-28CB-F773-93EB6C1B8A2B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{B873A1FB-5EA0-EE5F-A861-1E38880AD08E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0742432E-42D9-2240-4CA1-8595CCCBAA77}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{CA55697D-BD74-3ED8-6B21-D7EDAD3B7D02}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{D4490E0F-8E7B-1097-B56A-7643C75F1C28}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{EC9DF9FF-9D75-4CDD-1D58-A2E887B0A42E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{7ABACA7E-6E59-0EF9-8FA3-6B32E5F58127}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{CFC860C8-4F51-E08C-A74C-2E444ED06160}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{DAB44116-0266-C65B-B643-AC11217C3041}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{EAEAA839-44F4-22DF-D1CC-88C3B2A3D4B1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3AF70346-52C7-0334-606F-118D1C1CB7A2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3E196AAF-F81C-B384-E2AB-28EE2398FE5F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{9338D693-38B7-1ED4-9B42-BFA1D5600CCB}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A3973655-E448-4A1B-477C-988A79D132D9}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{53AE8AC7-5213-67AF-0DC0-CED696B77643}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{6DC92550-D065-4B36-C4D3-D8D7A702A7A7}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{C971C145-258D-6650-7088-13DDB161327A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DAEFFE0C-CD05-1355-6AFC-7B3D4106A820}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{B2A83706-3F14-1532-20CD-B4EE715A8945}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{DC9DFCBF-87DA-892C-6151-99CC9EF46E3E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{E392A425-53A7-DF90-96A0-E287A75DD3B2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{EBA09DAF-14B4-7BE7-676E-6E2FB21EDBDD}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{44ED2CDA-4197-E9E9-B328-26E1FB749116}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{9AA4DD93-94BF-22EA-C9D2-7084F304A31B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{C1EFF2A2-DF4A-F6D1-B99C-1ED194AE9E78}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{D6F47BB4-700A-F612-0671-5F69EA311BB7}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{01FD9A26-3F61-9236-B360-BE5D043D82C0}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{3450566C-4561-0EE8-B1AB-D5C79CCE8D2C}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{379D900B-A785-6DB0-012E-434356A365B3}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{46EB68BE-8AAC-8C2B-7284-8DEDE6B5CD2A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{366C4FB5-CF6E-258B-418D-E6D29549A278}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{64D4CCC3-63DF-252D-D29D-03491670225D}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{7A6E431B-CF43-EC3E-FD7E-0A0AAB1B25FC}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{FCE8438C-3272-D63F-479F-670F082B294B}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{25D1751E-7CA2-5F6D-0125-0A16E47AF9FE}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{89A1F076-19B8-A2B1-D5A3-E8247EFAF157}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{8DF90937-B869-9F76-5D45-5A8BDA0A33B6}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{B10089DE-934F-6E0F-683A-B788F89348DF}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.52 - Piriform)
ClearProg 1.6.0 Final (HKLM-x32\...\ClearProg) (Version: 1.6.0 Final - Sven Hoffman)
CloneDVD 5.6.1.2 (HKLM-x32\...\CloneDVD5_is1) (Version:  - Copyright (C) 2003-2012 Aviosoft.)
Configurador_FNMT (HKLM-x32\...\{438D4C4C-B703-4971-9C3D-33FF8A010ADB}) (Version: 3.7 - FNMT-RCM)
Corel PaintShop Pro X8 (HKLM-x32\...\_{85C69B9B-F9BD-4A60-BD83-F2B7E081ED39}) (Version: 18.3.0.13 - Corel Corporation)
Corel PaintShop Pro X8 (HKLM-x32\...\{8239357B-E792-4EEB-9F8B-F2535730A315}) (Version: 18.0.0.124 - Corel Corporation) Hidden
CPUID CPU-Z 1.84 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.84 - CPUID, Inc.)
CryptoPrevent (HKLM-x32\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
Crystal Reports Basic Runtime for Visual Studio 2008 (HKLM-x32\...\{CE26F10F-C80F-4377-908B-1B7882AE2CE3}) (Version: 10.5.0.0 - Business Objects)
Crystal Reports Basic Runtime Spanish Language Pack for Visual Studio 2008 (HKLM-x32\...\{8C1ACF3F-C718-44FA-9BBE-18527E9393CC}) (Version: 10.5.0.0 - Business Objects)
CrystalDiskMark 4.1.0 (HKLM\...\CrystalDiskMark4_is1) (Version: 4.1.0 - Crystal Dew World)
dBpoweramp [Calculate Audio CRC] Codec (HKLM-x32\...\dBpoweramp [Calculate Audio CRC] Codec) (Version: Release 1 - Illustrate)
dBpoweramp Dalet Codec (HKLM-x32\...\dBpoweramp Dalet Codec) (Version: Release 5 - Illustrate)
dBpoweramp DSP Effects (HKLM-x32\...\dBpoweramp DSP Effects) (Version: Release 9 - Illustrate)
dBpoweramp Monkeys Audio Codec (HKLM-x32\...\dBpoweramp Monkeys Audio Codec) (Version: Release 11 (Monkeys v4.06 PP) - Illustrate)
dBPowerAMP Mp2 and BwfMp2 codec (HKLM-x32\...\dBPowerAMP Mp2 and BwfMp2 codec) (Version: Release 6 - Illustrate)
dBpoweramp mp3 (Fraunhofer IIS) Codec (HKLM-x32\...\dBpoweramp mp3 (Fraunhofer IIS) Codec) (Version: Release 2a (v4.0.3) - Illustrate)
dBpoweramp Music Converter (HKLM-x32\...\dBpoweramp Music Converter) (Version: Release 14.4 - Illustrate)
dBpoweramp Ogg Vorbis Codec (HKLM-x32\...\dBpoweramp Ogg Vorbis Codec) (Version: Release 22 (Vorbis v1.3.3) - Illustrate)
dBPowerAMP Real Audio (Helix) Encoder (HKLM-x32\...\dBPowerAMP Real Audio (Helix) Encoder) (Version: Release 6 - Illustrate)
dBPoweramp tooLame MP2 codec (HKLM-x32\...\dBPoweramp tooLame MP2 codec) (Version:  - )
dBpoweramp Wave64 Codec (HKLM-x32\...\dBpoweramp Wave64 Codec) (Version:  - )
dBpoweramp WavPack Codec (HKLM-x32\...\dBpoweramp WavPack Codec) (Version: Release 8 (WavPack v4.60) - Illustrate)
Dead Rising III (HKLM-x32\...\Dead Rising III_is1) (Version: Dead Rising III - )
Desinstalar impresora EPSON WF-5690 Series (HKLM\...\EPSON WF-5690 Series) (Version:  - SEIKO EPSON Corporation)
dinaSMS 2.1.8 (HKLM-x32\...\dinaSMS_is1) (Version:  - Dinahosting S.L.)
dinaSync 1.1.1 (HKLM-x32\...\dinaSync_is1) (Version:  - Dinahosting S.L.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 67.3.78 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.191.1 - Dropbox, Inc.) Hidden
DVDFab (x64) 10.0.9.2 (10/05/2018) (HKLM-x32\...\DVDFab 10(x64)) (Version: 10.0.9.2 - DVDFab.cn.)
DVDFab 9.1.1.9 (18/12/2013) (HKLM-x32\...\DVDFab 9_is1) (Version:  - Fengtao Software Inc.)
eac3to µGUI version 0.7.2 (HKLM-x32\...\{C21B8D64-350C-4FCA-899F-9FBEA69A92D1}_is1) (Version: 0.7.2 - )
EaseUS Partition Master 9.3.0 (HKLM-x32\...\EaseUS Partition Master_is1) (Version:  - EaseUS)
EasyBCD 2.2 (HKLM-x32\...\EasyBCD) (Version: 2.2 - NeoSmart Technologies)
eMagicOne Store Manager for PrestaShop PROFESSIONAL 2.45.1.2019 (HKLM-x32\...\{A07B5EA3-DA77-42CB-A8F6-2813B36BDDB6}_is1) (Version: 2.45.1.2019 - eMagicOne)
Emsisoft Anti-Malware (HKLM\...\{CA975286-D816-410C-B6C9-F7213CA84695}) (Version: 18.10.1.9026 - Emsisoft Ltd.)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION)
Epson E-Web Print (HKLM-x32\...\{6BF9F374-EC67-4808-A90C-F127DE6D989D}) (Version: 1.23.0000 - SEIKO EPSON CORPORATION)
Epson FAX Utility (HKLM-x32\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 2.50.00 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON Scan PDF Extensions (HKLM-x32\...\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.03.0001 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\...\{4830989D-5FA5-41DF-A02F-5D1B4D5C73B8}) (Version: 4.4.10 - Seiko Epson Corporation)
EPSON Universal Print Driver Printer Uninstall (HKLM\...\EPSON Universal Print Driver) (Version:  - SEIKO EPSON Corporation)
EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.6.0 - Seiko Epson Corporation)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
ESTIMASOL (HKLM-x32\...\{FA4C7995-2BC8-4373-AF61-2C9B63A6014C}) (Version: 1.02.000010 - Software del Sol, S.A.)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.118 - Etron Technology) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.118 - Etron Technology)
Eye-Fi X2 Utility (HKLM-x32\...\{6D9F40B7-4BEA-45C4-8833-BC070C2DB6C0}) (Version: 1.1.1.0 - Eye-Fi, Inc)
EZ CD Audio Converter (32-bit) (HKLM-x32\...\EZ CD Audio Converter (32-bit)) (Version: 2.0.4 - Poikosoft)
FaxRedist (HKLM-x32\...\{2C8CC208-965C-48A1-90A8-DFB484358F1C}) (Version: 1.0.0 -  )
FILEminimizer Pictures (HKLM-x32\...\FILEminimizer Pictures_is1) (Version:  - balesio AG)
FileZilla Client 3.40.0 (HKLM-x32\...\FileZilla Client) (Version: 3.40.0 - Tim Kosse)
FinePrint (HKLM\...\FinePrint) (Version: 8.37 - FinePrint Software, LLC)
foobar2000 v1.3.1 (HKLM-x32\...\foobar2000) (Version: 1.3.1 - Peter Pawlowski)
FOSCAM Client (HKLM-x32\...\{9F9CDA0B-2291-4061-85C4-441A75BE6713}) (Version: 1.4.13 - FOSCAM)
Foxit PhantomPDF (HKLM-x32\...\{859A6FD4-5C95-11E7-AC97-000C29C1951D}) (Version: 8.3.1.21155 - Foxit Software Inc.)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free EML File Viewer version 2.0 (HKLM-x32\...\{1FD090C1-5C0F-4764-AE25-176AECA5DEAB}_is1) (Version: 2.0 - SysTools Software)
Genymotion version 2.1.1 (HKLM\...\{6D180286-D4DF-40EF-9227-923B9C07C08A}_is1) (Version: 2.1.1 - Genymobile)
GIMP 2.10.2 (HKLM\...\GIMP-2_is1) (Version: 2.10.2 - The GIMP Team)
Golden .NET para Expansión (Entrega 4) (HKLM-x32\...\{72D3BB6D-7863-445E-9811-5B9B3CF12445}) (Version: 1.5.5.11 - Golden Soft)
GoodSync (HKLM\...\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 10.7.6.7 - Siber Systems)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 72.0.3626.96 - Google Inc.)
Google Earth Pro (HKLM\...\{F914BC59-918A-498F-B2E3-B274C9CB48A8}) (Version: 7.3.2.5491 - Google)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Harmony Remote Update (HKLM-x32\...\HarmonyRemoteUpdate) (Version: 7.7.1 - Logitech - HarmonyRemoteClient)
HD Tune Pro 5.00 (HKLM-x32\...\HD Tune Pro_is1) (Version:  - EFD Software)
ICA (HKLM-x32\...\{85C69B9B-F9BD-4A60-BD83-F2B7E081ED39}) (Version: 18.0.0.124 - Corel Corporation) Hidden
Icecream Image Resizer versión 1.50 (HKLM-x32\...\{2F8F5694-F482-481A-B05F-4A6D8A275B84}_is1) (Version: 1.50 - Icecream Apps)
IETester v0.5.4 (remove only) (HKLM-x32\...\IETester) (Version: 0.5.4 - Core Services)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
IncrediBackup (HKLM-x32\...\{D44222FB-31A2-4D2B-B222-D0C5599F28D0}) (Version: 1.0.0.1039 - IncrediMail) Hidden
IncrediBackup (HKLM-x32\...\IncrediBackup) (Version: 1.0.0.1039 - IncrediMail Ltd.)
IncrediMail (HKLM-x32\...\{7EE0B72B-D460-4DBA-AFF5-E7D8FB0E696F}) (Version: 6.6.0.5328 - IncrediMail) Hidden
IncrediMail 2.5 (HKLM-x32\...\IncrediMail) (Version: 6.6.0.5328 - IncrediMail Ltd.)
IncrediMail JunkFilter Plus (HKLM-x32\...\JunkFilterPlus) (Version: 6001167 - IncrediMail Ltd.)
Informativas 11.00 (HKLM-x32\...\4292-5894-1006-6413) (Version: 12.02 - AEAT)
Instalable DNIe (HKLM\...\{B4A6EF31-AC22-4BE2-A714-581FC66DBFAF}) (Version: 13.1.0 - Cuerpo Nacional de Policía)
Intel® CCF Manager (HKLM-x32\...\{0f3d8dd5-54af-4404-a01c-4967e485a065}) (Version: 3.0.13.2211 - Intel Corporation)
IP Camera Viewer 1.0 (HKLM-x32\...\IP Camera Viewer_is1) (Version:  - DeskShare Inc.)
IPCWebComponents 3.1.0.9 (HKLM-x32\...\{4740E1B2-51CF-4083-8976-D6B3B5A5064F}_is1) (Version: 3.1.0.9 - )
IPM_PSP_COM (HKLM-x32\...\{80A28CA4-189A-4EB2-9F76-7845A0A83D2A}) (Version: 18.0.0.124 - Corel Corporation) Hidden
IPM_PSP_COM64 (HKLM\...\{842A3E2E-15B2-4D49-A50F-05964CA93374}) (Version: 18.0.0.124 - Corel Corporation) Hidden
IrfanView 4.50 (64-bit) (HKLM\...\IrfanView64) (Version: 4.50 - Irfan Skiljan)
ISO to USB (HKLM-x32\...\{D08A30AC-A663-4EA8-8D81-B98E17F19F1C}_is1) (Version:  - isotousb.com)
Java 8 Update 201 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180201F0}) (Version: 8.0.2010.9 - Oracle Corporation)
JunkFilterPlus (HKLM-x32\...\{DC754D8F-1D06-4016-BF57-8D21F97E1F0A}) (Version: 6.0.0.1167 - IncrediMail) Hidden
Kodi (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Kodi) (Version:  - XBMC-Foundation)
LibreOffice 6.0.3.2 (HKLM\...\{9739EFFE-C402-4A4B-AE2E-092682D1D07B}) (Version: 6.0.3.2 - The Document Foundation)
LightScribe Applications (HKLM-x32\...\{7373184D-8E8F-4308-912A-3901071FA1AD}) (Version: 1.4.128.1 - Nombre de su organización)
LightScribe System Software (HKLM-x32\...\{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}) (Version: 1.18.24.1 - LightScribe)
Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Lotus SmartSuite - Español (HKLM-x32\...\{536D6172-7453-7569-7465-392E3730040A}) (Version: 9.7.0 - Lotus Development Corporation)
MailWasherPro (HKLM-x32\...\{6657DA03-A39B-472C-8458-6292E128A3D9}) (Version: 7.2.0 - Firetrust)
Malwarebytes versión 3.7.1.2839 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.7.1.2839 - Malwarebytes)
Manuales de EPSON (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.54.0.0 - Seiko Epson Corporation)
Mazda Toolbox (HKLM-x32\...\Mazda Toolbox) (Version:  - )
MediaInfo 18.05 (HKLM\...\MediaInfo) (Version: 18.05 - MediaArea.net)
MEGAsync (HKLM-x32\...\MEGAsync) (Version:  - Mega Limited)
Microsoft Access database engine 2010 (Spanish) (HKLM\...\{90140000-00D1-0C0A-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\OneDriveSetup.exe) (Version: 19.002.0107.0008 - Microsoft Corporation)
Microsoft Robocopy GUI (HKLM-x32\...\{107C666F-63C5-4263-8D40-8B9CFB5FED08}) (Version: 1.0.0 - Microsoft)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
MKVToolNix 23.0.0 (64-bit) (HKLM-x32\...\MKVToolNix) (Version: 23.0.0 - Moritz Bunkus)
Mobirise4 (HKLM-x32\...\Mobirise4_is1) (Version:  - Mobirise.com)
Mozilla Firefox 65.0 (x64 es-ES) (HKLM\...\Mozilla Firefox 65.0 (x64 es-ES)) (Version: 65.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 65.0.0.6963 - Mozilla)
Mozilla Thunderbird 31.2.0 (x86 es-ES) (HKLM-x32\...\Mozilla Thunderbird 31.2.0 (x86 es-ES)) (Version: 31.2.0 - Mozilla)
Mozilla Thunderbird 60.5.0 (x86 es-ES) (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Mozilla Thunderbird 60.5.0 (x86 es-ES)) (Version: 60.5.0 - Mozilla)
MSVC80_x64_v2 (HKLM\...\{4D668D4F-FAA2-4726-834C-31F4614F312E}) (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (HKLM-x32\...\{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}) (Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (HKLM\...\{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}) (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (HKLM-x32\...\{AF111648-99A1-453E-81DD-80DBBF6DAD0D}) (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
muCommander (remove only) (HKLM-x32\...\muCommander) (Version:  - )
Multilizer PDF Translator (Build 10.3.2) (HKLM-x32\...\Multilizer PDF Translator_is1) (Version:  - Rex Partners)
Music Manager (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\MusicManager) (Version:  - Google, Inc.)
MyHarmony (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\036a0e4fc6a247ec) (Version: 1.0.1.257 - Logitech)
No-IP DUC (HKLM-x32\...\NoIPDUC) (Version: 4.1.0 - Vitalwerks Internet Solutions LLC)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
OJOsoft Audio Converter (HKLM-x32\...\OJOsoft Audio Converter_is1) (Version: 2.7.6.0419 - OJOsoft)
OnScreen Control (HKLM-x32\...\{E5C1B339-0E4E-49A5-859E-5E1DE1938706}) (Version: 2.95 - LG Electronics Inc)
Oracle VM VirtualBox 5.2.10 (HKLM\...\{DA347D3B-067A-42F2-A0BE-B6B0DA7C0EDF}) (Version: 5.2.10 - Oracle Corporation)
Paquete de controladores de Windows - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/28/2014 11.0.0000.00000) (HKLM\...\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
Paquete de controladores de Windows - MediaTek Inc. (usbser) Ports  (01/05/2012 2.0000.0.1) (HKLM\...\49D9ABA9270C5BDFD7AE1BEB607D36B26BB90235) (Version: 01/05/2012 2.0000.0.1 - MediaTek Inc.)
Paquete de controladores de Windows - MediaTek Inc. (usbser) Ports  (12/24/2011 2.0000.0.0) (HKLM\...\D0E6296D177F42BB31C0200E49412003DB6C4633) (Version: 12/24/2011 2.0000.0.0 - MediaTek Inc.)
Paquete de controladores de Windows - RemoteControl (RemoteControlUSBLAN) Net  (06/02/2016 02.04.10.001) (HKLM\...\A14D4158722037A4DD816446D7339B41F11276D9) (Version: 06/02/2016 02.04.10.001 - RemoteControl)
PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
PCI SoftV92 Modem (HKLM\...\CNXT_MODEM_PCI_HSF) (Version: 7.80.5.0 - Conexant Systems)
PDF Settings CC (HKLM-x32\...\{1FBAE18D-4DE4-47AA-83EC-D1B046F262DC}) (Version: 12.0 - Adobe Systems Incorporated) Hidden
pdfFactory Pro (HKLM\...\pdfFactory Pro) (Version: 5.37 - FinePrint Software, LLC)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.322.9 - Tracker Software Products Ltd)
PHOTOfunSTUDIO 9.2 AE (HKLM-x32\...\{84F0A157-75D1-45C7-A209-EDFAB5C85F24}) (Version: 9.02.513 - Panasonic Corporation)
Plex (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Plex) (Version: 0.9.504 - Plex, Inc)
Plex Media Server (HKLM-x32\...\{82C831F3-71D9-482D-8A82-11B4FF679033}) (Version: 1.13.5291 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{ee1563ba-f9e1-4222-a38b-e88c26fc0f1c}) (Version: 1.13.5.5291 - Plex, Inc.)
PPT Viewer 2.0 (HKLM-x32\...\PPT Viewer 2.0) (Version:  - )
PSPPContent (HKLM-x32\...\{89E018D8-558F-4051-BB26-64DD9B90DF68}) (Version: 18.0.0.124 - Corel Corporation) Hidden
PSPPHelp (HKLM-x32\...\{88340123-2A5C-48D4-98C1-58C18D12F09C}) (Version: 18.0.0.124 - Corel Corporation) Hidden
PSPPro64 (HKLM\...\{88CFC59F-1491-4359-819F-87DFAFF9CCF4}) (Version: 18.0.0.124 - Corel Corporation) Hidden
PuTTY development snapshot 2014-10-22.r10287 (HKLM-x32\...\PuTTY_is1) (Version: 2014-10-22.r10287 - Simon Tatham)
qBittorrent 4.0.4 (HKLM-x32\...\qBittorrent) (Version: 4.0.4 - The qBittorrent project)
QNAP Qsync Client (HKLM-x32\...\Qsync) (Version: 4.3.2.1214 - QNAP Systems, Inc.)
QNAP QVHelper (HKLM-x32\...\QNAP_QVHelper) (Version: 1.1.0.18025 - QNAP Systems, Inc.)
QNAP QVR Client (HKLM-x32\...\QNAPQVR) (Version: 5.1.2.43140 - QNAP Systems, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Recovery Toolbox for RAR 1.2 (HKLM-x32\...\Recovery Toolbox for RAR_is1) (Version:  - Recovery Toolbox, Inc.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Renta 2012 1.21 (HKLM-x32\...\8421-7800-2226-7659) (Version: 1.21 - AEAT)
Renta 2013 1.21 (HKLM-x32\...\2285-3920-8902-9260) (Version: 1.21 - AEAT)
Renta 2014 1.25 (HKLM-x32\...\8330-1526-1221-2374) (Version: 1.25 - AEAT)
Renta 2015 1.09 (HKLM-x32\...\9648-5771-9114-3169) (Version: 1.09 - AEAT)
Resident Evil Revelations (HKLM-x32\...\Resident Evil Revelations_is1) (Version:  - Capcom)
Revo Uninstaller Pro 3.2.0 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.2.0 - VS Revo Group, Ltd.)
Riot - Radical Image Optimization Tool (HKLM-x32\...\Riot) (Version:  - )
RoboForm 8-5-5-5 (All Users) (HKLM-x32\...\AI RoboForm) (Version: 8-5-5-5 - Siber Systems)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung Data Migration (HKLM-x32\...\{D4DE3DB4-7734-47E5-8D92-B80146311406}) (Version: 2.7 - Samsung)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.6 - Samsung Electronics)
Samsung Universal Print Driver 2 (HKLM-x32\...\Samsung Universal Print Driver 2) (Version: 2.50.06.00 - Samsung Electronics Co., Ltd.)
SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Setup (HKLM-x32\...\{8BFA76B5-47DD-4C88-9C9B-7407019F0E13}) (Version: 18.0.0.124 - Nombre de su organización) Hidden
SHARPEN projects (64-Bit) (HKLM\...\SHARPEN_PROJECTS_1_2_FCDF957E_is1) (Version: 1.19 - Franzis Verlag GmbH)
SILKYPIX Developer Studio 4.4 SE (HKLM-x32\...\{73506320-CCDD-46FF-AE91-1032FAAD56F7}) (Version: 4 - Ichikawa Soft Laboratory)
SilverFast 8.8.0r8 (64bit) (HKLM-x32\...\SilverFast 8 x64) (Version: 8.8.0r8 - LaserSoft Imaging AG)
SopCast 3.9.6 (HKLM-x32\...\SopCast) (Version: 3.9.6 - www.sopcast.com)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version:  - )
SSD Tweaker version 3.3 (HKLM-x32\...\{83FA601A-241A-4956-8A21-F7D525C4422F}_is1) (Version: 3.3 - Elpamsoft.com)
Startup Delayer v3.0 (build 366) (HKLM-x32\...\Startup Delayer) (Version: 3.0 (build 366) - r2 Studios)
STCServ (HKLM\...\{A954D353-9DAF-4916-8E71-F1E959EBCD1E}) (Version: 3.0.0.1783 - Intel Corporation) Hidden
Stopping Plex (HKLM-x32\...\{2505AB18-0108-47B3-B335-3FE067556E95}) (Version: 1.13.5291 - Plex, Inc.) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1028 - SUPERAntiSpyware.com)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.132598 - TeamViewer)
Telegram Desktop version 1.5.11 (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.5.11 - Telegram Messenger LLP)
Tipard Blu-ray Player 6.1.16 (HKLM-x32\...\{3827AA3A-CC6F-4260-AF59-46AAD9A2F6A8}_is1) (Version: 6.1.16 - Tipard Studio)
Transmission-Qt (HKLM\...\Transmission-Qt) (Version: 2.84 - Transmission)
TuneUp Utilities Language Pack (es-ES) (HKLM-x32\...\{03D87880-1EEE-45F7-9BBA-D82ADD9460D0}) (Version: 13.0.3000.143 - TuneUp Software) Hidden
TunnelBear (HKLM-x32\...\{0BF72A98-D573-42F6-8AC2-D56DAD1A7092}) (Version: 3.3.2.1 - TunnelBear) Hidden
TunnelBear (HKLM-x32\...\{bee5e42c-31b0-447d-ba41-fed0b4678c1e}) (Version: 3.3.2.1 - TunnelBear)
Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.67 - Samsung Electronics CO., LTD.)
Universal Adb Driver (HKLM-x32\...\{D9C4202E-6D51-4B06-A8F1-22316E654BCA}) (Version: 1.0.0 - ClockworkMod)
Unlocker 1.9.1-x64 (HKLM\...\Unlocker) (Version: 1.9.1 - Cedrick Collomb)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F814D094-197F-43C8-87FA-3210BB780486}) (Version: 2.53.0.0 - Microsoft Corporation)
USB2.0 PC CAMERA (HKLM-x32\...\{58D4FB3A-98E9-4B9B-B01E-7F005AEFE019}) (Version: 1.00.0000 - USB 2.0 PC CAMERA)
Uso a distancia de tu PS4 (HKLM-x32\...\{AFE1B39B-EA0C-47BD-BAFD-A1CABDE234B1}) (Version: 2.6.0.02270 - Sony Interactive Entertainment Inc.)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.)
WBFS Manager 3.0 (HKLM-x32\...\WBFS Manager 3.0) (Version: 3.0 - AlexDP)
WhatsApp (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\WhatsApp) (Version: 0.3.2043 - WhatsApp)
Who Is On My Wifi version 4.0.5 (HKLM-x32\...\{010D45A1-093D-4534-8147-4E10E80F81CC}_is1) (Version: 4.0.5 - IO3O LLC)
Win32DiskImager version 1.0.0 (HKLM-x32\...\{3DFFA293-DF2C-4B23-92E5-3433BDC310E1}}_is1) (Version: 1.0.0 - ImageWriter Developers)
WinDirStat 1.1.2 (HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\WinDirStat) (Version:  - )
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Driver Package - Dirección General de la Policía (UMPass) SmartCard  (12/15/2016 1.0.2.5) (HKLM\...\3A8235ACF0CF89B7EACE136B69B0B68ADC94D283) (Version: 12/15/2016 1.0.2.5 - Dirección General de la Policía)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinMerge 2.14.0 (HKLM-x32\...\WinMerge_is1) (Version: 2.14.0 - Thingamahoochie Software)
WinRAR 5.61 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH)
Wondershare Video Converter Ultimate(Build 8.0.0.10) (HKLM-x32\...\Wondershare Video Converter Ultimate_is1) (Version: 8.0.0.10 - Wondershare Software)
XolidoSign V 2.2.1.36 (HKLM\...\{56b061b8-fa68-4231-8aaf-548576387ae3}_is1) (Version: 2.2.1.36 - Xolido Systems, S.A.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-AA22-08DD0A3ADC4B}\InprocServer32 -> {1ED23424-9468-D082-72A4-A3EF85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1EED9644-9468-D082-1206-9CEF85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> G:\MediaInfo\MediaInfo_InfoTip.dll (MediaArea.net -> MediaArea.net)
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{A804CF1A-91E5-4F0C-9E8C-DB39E74056DD}\InprocServer32 -> C:\Users\FrancsicoJosé\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll (Google Inc -> Google Inc.)
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822AA-3A0A-4BDC-B749-4B00B9115850}\InprocServer32 -> {564C0C8B-9468-D082-DD9C-3DA785889A47} => No File

#13
r32 -> {564C0C8B-9468-D082-DD9C-3DA785889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5CD8000B-9468-D082-5D90-A9AD85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\FrancsicoJosé\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll (Google Inc -> Google Inc.)
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ShellIconOverlayIdentifiers: [      QsyncEx_Icon1] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [      QsyncEx_Icon2] -> {DAD72D69-9DE7-4806-B921-E4555DC4A4F7} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [      QsyncEx_Icon3] -> {A960CC73-D845-4E17-B076-65708DC291B8} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [      QsyncEx_Icon4] -> {4E425D46-B457-41E1-8E91-E656960BB593} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-12-07] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-12-07] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-12-07] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis International GmbH -> Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis International GmbH -> Acronis)
ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis International GmbH -> Acronis)
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShell.dll [2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => G:\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2017-06-29] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-12-07] (Google Inc -> Google)
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ContextMenuHandlers1: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ContextMenuHandlers1: [ShellConverter] -> {30A4E07E-068A-4d91-8F05-691283A1336B} => C:\Program Files (x86)\Common Files\AVSMedia\ActiveX\AVSShellConverter64.dll [2017-12-18] (Online Media Technologies Ltd. -> Online Media Technologies Ltd.)
ContextMenuHandlers1: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll [2014-09-09] (Acronis International GmbH -> Acronis)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\Windows\SysWOW64\WSCM64.dll [2014-10-24] ()
ContextMenuHandlers2-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU.DLL [2015-10-21] (Emsisoft Ltd -> Emsisoft Ltd)
ContextMenuHandlers2-x32: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU64.DLL [2015-10-21] (Emsisoft Ltd -> Emsisoft Ltd)
ContextMenuHandlers2-x32: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU.DLL [2015-10-21] (Emsisoft Ltd -> Emsisoft Ltd)
ContextMenuHandlers3-x32: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU64.DLL [2015-10-21] (Emsisoft Ltd -> Emsisoft Ltd)
ContextMenuHandlers3-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers3-x32: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ContextMenuHandlers3-x32: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] (Empty Loop -> )
ContextMenuHandlers3-x32: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [###MegaContextMenuExt] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-12-07] (Google Inc -> Google)
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll [2017-06-07] ()
ContextMenuHandlers4: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-09-22] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-02-06] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ContextMenuHandlers5: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} =>  -> No File
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShell.dll [2019-02-06] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers6-x32: [Emsisoft Shell Extension] -> {AB77609F-2178-4E6F-9C4B-44AC179D937A} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU.DLL [2015-10-21] (Emsisoft Ltd -> Emsisoft Ltd)
ContextMenuHandlers6-x32: [Emsisoft Shell Extension x64] -> {E3F21FC7-6D65-48E7-B62B-E9ED8200C764} => C:\Program Files\Emsisoft Anti-Malware\A2CONTMENU64.DLL [2015-10-21] (Emsisoft Ltd -> Emsisoft Ltd)
ContextMenuHandlers6-x32: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => G:\Foxit Software\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2017-06-29] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers6-x32: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-02-01] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6-x32: [QsyncExt] -> {17affcaf-2e65-4b1b-98a1-a7b3b4d8ad36} => C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll [2017-04-17] (QNAP Systems, Inc. -> )
ContextMenuHandlers6-x32: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6-x32: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2012-12-29] (VS Revo Group -> VS Revo Group)
ContextMenuHandlers6-x32: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] (Empty Loop -> )
ContextMenuHandlers6-x32: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\x64\versions_page.dll [2014-09-09] (Acronis International GmbH -> Acronis)
ContextMenuHandlers6-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00A282C8-79B9-4FDC-A828-10E622C7385A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {02C9BE57-CB0B-4A2D-BA7E-765118BDEDFB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001Core => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {04998E0F-823F-420B-B112-556BC1610E44} - System32\Tasks\ASUS\ASUS Network iControl Help Execute => G:\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelpEntry.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {0C642023-778C-49A2-B823-9C1777BD53EA} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.)
Task: {0D78D214-B0E2-4EF9-BFC5-3BD90E10FC4D} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {11830009-6B00-43E5-B5A9-55BF82FA6CBC} - System32\Tasks\Open URL by RoboForm => C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMIMHMNLJMKLMLLLMMCNJLOLLMKLCNMLMLJLMMCNJLMMPMJMCNJMNLLLJMKMOLGMOMNLJLMLPMJNJICMHMCNKMCNKMFMOMOMCNLMIMOMCNOMIMOMMMLMFMPMCNPMCNOMIMOMMMLMCNNMJNPICMOMFMEKMICNJJCKFMNMGMPMMMJNHICMEKMICNJJCKJNBJCMJLNIOJBJMJMIGJMJAJFLAJMIAMJNKJCMJ (the data entry has 102 more characters).
Task: {186F5F87-313C-40A5-95E2-B1187F2FBE40} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {1EC6E0D3-8C5F-408C-B4F6-7D5E351E8ADA} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems -> Siber Systems)
Task: {1FD432EE-1F46-4A50-9182-F9F25278A262} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001UA => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {29AB2C98-D312-4091-9768-920C76883996} - System32\Tasks\ASUS\ASUS WiFi GO! Server Execute => G:\ASUS\AI Suite II\Remote GO!\AssistTools\WiFi GO! Server.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {316DB8D0-2E1F-4075-987A-6F1C8162F489} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001Core1d24afb38840a5c => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {34E87C47-1F85-4853-9A2A-1485AEAE97FB} - System32\Tasks\AdobeAAMUpdater-1.0-AMDFX8120-FranciscoJosé => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {388237EE-3AB8-44BD-A555-8AB73208A55C} - System32\Tasks\ASUS\ASUS AI Suite II Execute => G:\ASUS\AI Suite II\AsRoutineController.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {3DC1226E-FDE5-4E4E-925F-BDA3B587D448} - System32\Tasks\ASUS\ASUS DigiPowerControl Help => G:\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {3E6CA6F8-2C9F-4C52-BE68-14DD34DFB044} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Oracle America, Inc. -> Oracle Corporation)
Task: {3F7753BA-C1AB-4AAE-BAFC-9F117143CF09} - System32\Tasks\EPSON WF-5690 Series Update {6A80B607-4BF1-41F0-965D-526FFB89733D} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {43827470-7210-473B-9532-47AC66D90AF3} - System32\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084 => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {4C4C86B7-CA4C-450A-B444-5949B1196DF4} - System32\Tasks\Programa de actualización online de Adobe => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {4CD0B9C5-70B7-4477-BF6F-7D3C67621A68} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {4D48C4D1-2C42-43ED-97C3-2C19F2C3EB4D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.)
Task: {53959028-2E70-4FC9-9703-82ED32C7E98B} - System32\Tasks\TrackerAutoUpdate => G:\PDF-XChange\Update\TrackerUpdate.exe (Tracker Software Products (Canada) Ltd. -> Tracker Software Products (Canada) Ltd.)
Task: {53C31CEF-38E0-492B-AAF0-5E442704093B} - System32\Tasks\EPSON WF-5690 Series Invitation {6A80B607-4BF1-41F0-965D-526FFB89733D} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {553843FD-57A6-4582-9C10-82862E1D06E9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe (Piriform Software Ltd -> Piriform Software Ltd)
Task: {5989C124-76CB-4F97-9A54-2D42742D3DEC} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {5C5A1FB2-EBA1-44C0-A069-AD14D9258C54} - System32\Tasks\ASUS\Easy Update => G:\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe (ASUSTeK Computer Inc. -> )
Task: {5F460DDE-E557-4CCE-AEB5-DFC4E30C9463} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
Task: {5F4A8B49-69F3-4F37-9646-1D16CB8873BE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {671388E1-014D-4799-9C25-44762BC9A7F4} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {6DB05D09-6845-4542-89C7-ED288B7125BB} - System32\Tasks\SamsungMagician => g:\Samsung Magician\Samsung Magician.exe (Samsung Electronics Co., Ltd. -> Samsung Electronics.)
Task: {712170E9-262E-483F-B6FD-2F7D03CF633F} - System32\Tasks\{A3C2207C-CAFC-403B-A0D4-ED1AA0FB6038} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe" -c /uninstallProduct /addon:incredimail
Task: {72364B70-80F9-4276-B391-BFB35E802D58} - System32\Tasks\EPSON WF-5690 Series Update {4AA1307B-C9C4-4154-BB5C-738F17DA99B9} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {7EF79A04-4D8E-4889-A83C-5FFCF40744AC} - System32\Tasks\ASUS\ASUS Product Register Service => G:\ASUS\APRP\aprp.exe (ASUSTeK Computer Inc. -> ) [File not signed]
Task: {89E9117F-FC74-47BB-894E-0AD7951A25A9} - System32\Tasks\EPSON WF-5690 Series Update {B7BA0920-412D-44E8-9642-EFBD23A801AF} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {8F226C54-F33E-4D87-96C7-09566E9D2DFD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8F38C4AC-6D1D-49A9-AD43-77309CE18C22} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8F41CD88-CE1C-447A-BFE2-CA2F7FB1B221} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {8F4BA30E-C793-4E22-9DB4-E8426568CD41} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001UA1d24afb388b31ab => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {937117D6-0A99-4357-9B72-DB0AB35EC792} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {986FCC1D-2332-4831-8764-D2902A1403B0} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {9BFDF45A-4224-4D43-80C7-CD112B72C6F3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {A2FBD2CF-8CB6-4DA6-B1F5-28B2498270F0} - System32\Tasks\Run RoboForm Process => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems -> Siber Systems)
Task: {A5125863-232C-4586-97AC-D32A24F3A2CD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {A69870BA-FCD8-4D7B-A3F2-81F6D2B319D6} - System32\Tasks\EPSON WF-5690 Series Invitation {4AA1307B-C9C4-4154-BB5C-738F17DA99B9} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {A78D1A50-BD5D-4291-A6A4-AE1E4FAB4643} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {B445ABE5-44D6-4DEF-9421-D7A3F949E3B5} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {B6056017-2E61-4E7E-80D8-E2AE6CF9D13D} - System32\Tasks\S-1-5-21-390596928-2417218115-2686252066-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe (Microsoft Windows -> Microsoft Corporation)
Task: {B73F416B-EE39-47BA-ADD5-C118A334CC3B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {B9077A43-3057-4AE3-A827-5B3333801158} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {B9F2D748-3808-4CEF-9FD5-979069065E16} - System32\Tasks\{D692D5C7-4088-4D47-B4CA-C115F3EBB7E9} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Canon\IJ Manual\Canon MX710 series\uninstall.exe"
Task: {BFE59D9F-F6B6-422C-AA15-2759CF465EBE} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_114_Plugin.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {C99DACE9-7718-4632-9D1E-880F1D8EA78F} - System32\Tasks\ASUS\USB 3.0 Boost Service => G:\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe () [File not signed]
Task: {D2F9290A-FA21-4910-A648-604BDA24DB3B} - System32\Tasks\Google Updater and Installer => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {DB45ED13-5D74-4136-94E3-8BC53DBBB19E} - System32\Tasks\SUPERAntiSpyware Scheduled Task 845e393e-1f26-419c-a61c-ff12915eb8f7 => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {E00EACB7-B29B-45E5-844B-A97D46A55B5D} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {E4381567-2670-41B1-97F1-CA629702A896} - System32\Tasks\IntelBootstrapCCDashExe => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe (Intel® Corporation) [File not signed]
Task: {EE7C0FF6-C997-443D-ADD0-D5322EAE25AC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {F43CB3E0-2CA0-4D73-93D6-DB89121E2542} - System32\Tasks\EPSON WF-5690 Series Invitation {B7BA0920-412D-44E8-9642-EFBD23A801AF} => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE (SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION)
Task: {F4CFE185-4630-42F0-8C8A-8CF470FDED2D} - System32\Tasks\{B6059D5D-E6A7-41D7-9398-17773B1CE5EC} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriver.exe" -d "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIGABYTE\ET6" -c /M{457D7505-D665-4F95-91C3-ECB8C56E9ACA}
Task: {FBF993A0-BB1E-4928-B782-D88B7A0CD703} - \avast! Emergency Update -> No File <==== ATTENTION
Task: {FC0DDF91-4002-4E42-A741-4EC1EDB6CA24} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe (Adobe Systems Incorporated -> Adobe Systems, Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\EPSON WF-5690 Series Invitation {4AA1307B-C9C4-4154-BB5C-738F17DA99B9}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-5690 Series Invitation {6A80B607-4BF1-41F0-965D-526FFB89733D}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-5690 Series Invitation {B7BA0920-412D-44E8-9642-EFBD23A801AF}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE
Task: C:\WINDOWS\Tasks\EPSON WF-5690 Series Update {4AA1307B-C9C4-4154-BB5C-738F17DA99B9}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE:/EXE:{4AA1307B-C9C4-4154-BB5C-738F17DA99B9} /F:UpdateWORKGROUP\AMDFX8120$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON WF-5690 Series Update {6A80B607-4BF1-41F0-965D-526FFB89733D}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE:/EXE:{6A80B607-4BF1-41F0-965D-526FFB89733D} /F:UpdateWORKGROUP\AMDFX8120$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\EPSON WF-5690 Series Update {B7BA0920-412D-44E8-9642-EFBD23A801AF}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSKNE.EXE:/EXE:{B7BA0920-412D-44E8-9642-EFBD23A801AF} /F:UpdateWORKGROUP\AMDFX8120$ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001Core.job => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-390596928-2417218115-2686252066-1001UA.job => C:\Users\FrancsicoJosé\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 845e393e-1f26-419c-a61c-ff12915eb8f7.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\WINDOWS\Tasks\TrackerAutoUpdate.job => G:\PDF-XChange\Update\TrackerUpdate.exe-CheckUpdate(Tracker Software Products (Canada) Ltd.Kee

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DVDFab 10 (x64)\DVDFab (x64) Online.lnk -> hxxp://www.dvdfab.cn/?s=dvdfab10&p=x64&v=10.0.9.

ShortcutWithArgument: C:\Users\FrancsicoJosé\Desktop\Clean Google Calendar.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=magodclodecbbnbdfpmoehfdddkhlfmm
ShortcutWithArgument: C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Menú de aplicaciones de Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Menú de aplicaciones de Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --show-app-list
ShortcutWithArgument: C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Clean Google Calendar (1).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=magodclodecbbnbdfpmoehfdddkhlfmm
ShortcutWithArgument: C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Clean Google Calendar.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=magodclodecbbnbdfpmoehfdddkhlfmm
ShortcutWithArgument: C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Hangouts de Google.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=knipolnnllmklapflnccelgolnpehhpl

==================== Loaded Modules (Whitelisted) ==============

2019-01-28 09:22 - 2017-01-18 18:31 - 000066048 _____ () C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\ScreenSplitterHook641.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 000834088 _____ () C:\Windows\System32\InputHost.dll
2016-03-07 21:04 - 2013-10-18 18:04 - 001426232 _____ () G:\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
2014-01-15 16:26 - 2014-01-15 16:26 - 000034304 _____ () C:\WINDOWS\System32\spd__l.dll
2011-06-22 06:48 - 2011-06-22 06:48 - 000034304 _____ () C:\WINDOWS\System32\ssp7ml6.dll
2018-10-18 09:47 - 2015-03-12 03:43 - 000022528 _____ () C:\WINDOWS\System32\us013lm.dll
2016-10-26 19:17 - 2014-04-16 09:22 - 000029184 _____ () C:\WINDOWS\System32\usp02l.dll
2019-02-06 13:34 - 2019-02-06 13:34 - 000650672 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2019-02-06 13:34 - 2019-02-06 13:34 - 000321968 _____ () C:\Program Files (x86)\AVG\Antivirus\serialization.dll
2017-04-17 11:37 - 2017-04-17 11:37 - 000375096 _____ () C:\Program Files (x86)\QNAP\Qsync\QsyncExt.dll
2017-06-07 21:09 - 2017-06-07 21:09 - 000598528 _____ () C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX64.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 000474624 _____ () C:\Windows\ShellExperiences\TileControl.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 002801152 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2010-07-15 05:44 - 2010-07-15 05:44 - 000020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
2018-02-14 15:47 - 2018-02-14 15:47 - 000073728 _____ () C:\Program Files (x86)\QNAP\QVR\QVRService.exe
2018-10-18 09:47 - 2018-10-18 09:47 - 000143664 _____ () C:\WINDOWS\SysWoW64\SecUPDUtilSvc.exe
2018-05-07 15:25 - 2018-05-07 15:25 - 000117120 _____ () C:\Program Files (x86)\TunnelBear\TunnelBear.Maintenance.exe
2018-01-25 03:30 - 2018-01-25 03:30 - 000199168 _____ () G:\QNAP\QVHelper\websockets.dll
2018-01-25 03:30 - 2018-01-25 03:30 - 000056320 _____ () G:\QNAP\QVHelper\QtSolutions_Service-head.dll
2016-03-07 21:02 - 2013-09-17 11:58 - 000920736 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
2019-02-11 09:29 - 2019-02-11 09:29 - 006862024 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\19021004\algo64.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 002013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2016-09-13 02:01 - 2016-09-13 02:01 - 000191488 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Dialogs\dialogplugin.dll
2019-01-28 10:53 - 2019-01-28 10:53 - 001740800 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2019-01-30 09:42 - 2019-01-30 09:43 - 000182272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.38.138.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
2019-01-28 18:00 - 2019-01-28 18:00 - 005172224 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\YourPhone.exe
2019-01-28 18:00 - 2019-01-28 18:00 - 002172928 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\YourPhone.AppCore.dll
2019-01-28 18:00 - 2019-01-28 18:00 - 001795584 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\PhoneContentDataStore.dll
2018-10-27 11:37 - 2018-10-27 11:37 - 001004032 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2019-01-28 18:00 - 2019-01-28 18:00 - 002907136 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\PhoneCommunicationAppService.dll
2014-05-02 23:55 - 2014-05-02 23:55 - 000346624 _____ () G:\No-IP\DUC40.exe
2016-09-08 18:19 - 2016-09-08 18:19 - 005064992 _____ () C:\Program Files (x86)\Eye-Fi\EyeFiX2Receiver.exe
2019-01-07 09:33 - 2019-01-07 09:33 - 093696960 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2018-02-03 23:09 - 2018-02-03 23:09 - 014365920 _____ () C:\Program Files\Siber Systems\GoodSync\GoodSync-v10.exe
2018-12-07 03:37 - 2018-12-07 03:37 - 046504696 _____ () C:\Program Files\Google\Drive\googledrivesync.exe
2019-01-10 11:01 - 2019-01-10 11:01 - 000103560 _____ () C:\Program Files\CCleaner\lang\lang-1034.dll
2019-02-11 09:28 - 2019-02-11 09:28 - 000113664 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_ctypes.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000080896 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\bz2.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 001792512 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_hashlib.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000128512 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32api.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000137728 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\pywintypes27.dll
2019-02-11 09:28 - 2019-02-11 09:28 - 000548864 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\pythoncom27.dll
2019-02-11 09:28 - 2019-02-11 09:28 - 000689664 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\unicodedata.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000438784 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32com.shell.shell.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 001489408 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\wx._core_.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 001007104 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\wx._gdi_.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 001039872 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\wx._windows_.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 001325056 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\wx._controls_.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000916992 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\wx._misc_.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 001084416 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\pysqlite2._sqlite.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000149504 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32file.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000136192 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32security.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000007680 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\hashobjs_ext.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000020992 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\thumbnails_ext.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000118784 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\usb_ext.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000047616 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_socket.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 002224640 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_ssl.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000014848 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\common.time34.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000023040 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32event.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000034304 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\windows.conditional.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000020480 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\windows.winwrap.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000110080 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\windows.volumes.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000223232 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32gui.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000173568 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_elementtree.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000169472 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\pyexpat.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000048128 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32inet.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000103424 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\wx._html2.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000046080 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_psutil_windows.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000633272 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\windows._cacheinvalidation.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000011776 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32crypt.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000301568 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\PIL._imaging.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000032256 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_multiprocessing.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 005752320 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\cello.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000026112 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\_yappi.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000044032 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32process.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000027648 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32pipe.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000010752 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\select.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000029696 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32pdh.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000038400 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\windows.connectivity.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000073216 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\windows.device_monitor.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000020480 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32profile.pyd
2019-02-11 09:28 - 2019-02-11 09:28 - 000026624 _____ () C:\Users\FrancsicoJosé\AppData\Local\Temp\_MEI126802\win32ts.pyd
2019-01-28 09:22 - 2018-06-14 17:39 - 030012856 _____ () C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe
2018-02-03 23:09 - 2018-02-03 23:09 - 008086240 _____ () C:\Program Files\Siber Systems\GoodSync\gs-server.exe
2014-04-18 10:04 - 2014-04-18 10:04 - 000550400 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\fsIPcam.exe
2019-02-11 09:41 - 2019-02-11 09:41 - 001840568 _____ () C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\ffmpeg.dll
2019-02-11 09:42 - 2019-02-11 09:42 - 000497152 _____ () \\?\C:\Users\FrancsicoJosé\AppData\Local\Temp\c5916ea0-953e-4f4c-afb1-87e6fd4354e9.tmp.node
2019-02-11 09:41 - 2019-02-11 09:41 - 003861944 _____ () C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\libglesv2.dll
2019-02-11 09:41 - 2019-02-11 09:41 - 000027064 _____ () C:\Users\FrancsicoJosé\AppData\Local\WhatsApp\app-0.3.2043\libegl.dll
2019-02-11 09:42 - 2019-02-11 09:42 - 000497152 _____ () \\?\C:\Users\FrancsicoJosé\AppData\Local\Temp\a172b6c1-6848-4d33-a594-05ef1136002e.tmp.node
2018-10-03 18:20 - 2018-03-26 17:10 - 000042496 _____ () C:\Program Files\XolidoSystems\XolidoSign\PKCS11_proxy.dll
2018-10-03 18:20 - 2017-10-18 12:48 - 000139264 _____ () C:\Program Files\XolidoSystems\XolidoSign\Messages\es\XolidoSign.Messages.resources.dll
2018-10-03 18:20 - 2018-03-26 17:10 - 002183168 _____ () C:\Program Files\XolidoSystems\XolidoSign\basedll\itextsharp.dll
2016-03-07 21:04 - 2013-10-18 18:04 - 005777616 _____ () G:\ASUS\AI Suite II\EasyUpdate\EzULIB.dll
2016-03-07 21:04 - 2013-05-08 16:22 - 000208896 _____ () G:\ASUS\AI Suite II\EasyUpdate\ImageHelper.dll
2016-03-07 21:05 - 2012-05-02 18:04 - 000233472 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\AudioProjection.dll
2016-03-07 21:05 - 2013-08-05 11:14 - 000176128 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\DLCapPP.dll
2016-03-07 21:05 - 2010-12-14 17:46 - 000067584 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\CoreAudioCap.dll
2016-03-07 21:05 - 2013-06-11 12:06 - 000425984 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\awiscale.DLL
2016-03-07 21:05 - 2010-10-29 18:58 - 000221184 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\JpegCD.DLL
2016-03-07 21:05 - 2013-08-06 20:04 - 002502656 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\xH264E.DLL
2016-03-07 21:05 - 2012-01-12 16:44 - 000475136 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\WiFiGO_HookKey.dll
2016-03-07 21:05 - 2013-06-13 17:37 - 000156160 _____ () C:\Program Files (x86)\InstallShield Installation Information\{104BE4B8-D1DB-4170-977B-364960893DC8}\CloudAPI\CloudAPI.dll
2016-03-07 21:05 - 2013-03-21 19:38 - 000716800 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\WiMoveHelp.dll
2016-03-07 21:05 - 2012-04-25 14:47 - 000659456 _____ () G:\ASUS\AI Suite II\Remote GO!\AssistTools\PhoneCtrlAPI.dll
2018-02-14 15:47 - 2018-02-14 15:47 - 001025024 _____ () C:\Program Files (x86)\QNAP\QVR\QVRWebSocket.dll
2018-05-07 15:24 - 2018-05-07 15:24 - 000166912 _____ () C:\Program Files (x86)\TunnelBear\TunnelBear.VigilantBear.Wrapper.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000083432 _____ () G:\Plex\Plex Media Server\zlib.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000203240 _____ () G:\Plex\Plex Media Server\libidn.dll
2019-02-11 09:27 - 2019-02-11 09:27 - 000037376 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.19\PEbiosinterface32.dll
2016-03-07 21:02 - 2010-06-29 03:58 - 000104448 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.19\ATKEX.dll
2019-01-28 09:22 - 2017-01-18 18:31 - 000059392 _____ () C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\ScreenSplitterHook1.dll
2016-03-07 21:04 - 2011-07-12 19:14 - 000147456 _____ () G:\ASUS\AI Suite II\AssistFunc.dll
2016-03-07 21:04 - 2010-10-05 08:22 - 000253952 _____ () G:\ASUS\AI Suite II\pngio.dll
2016-03-07 21:04 - 2013-12-04 11:57 - 000870912 _____ () G:\ASUS\AI Suite II\AI Charger+\AIChargerPlus.dll
2016-03-07 21:04 - 2012-10-08 17:07 - 000972288 _____ () G:\ASUS\AI Suite II\BarGadget\BarGadget.dll
2016-03-07 21:04 - 2013-05-08 16:22 - 001040896 _____ () G:\ASUS\AI Suite II\EasyUpdate\EasyUpdt.dll
2016-03-07 21:04 - 2012-06-19 12:56 - 001305600 _____ () G:\ASUS\AI Suite II\MyLogo\MyLogo.dll
2016-03-07 21:04 - 2013-06-24 15:59 - 001173504 _____ () G:\ASUS\AI Suite II\Network iControl\Network iControl.dll
2016-03-07 21:05 - 2013-06-24 17:48 - 002055168 _____ () G:\ASUS\AI Suite II\Remote GO!\WiFiGO.dll
2016-03-07 21:04 - 2013-04-15 14:19 - 000883712 _____ () G:\ASUS\AI Suite II\Sensor\Sensor.dll
2016-03-07 21:04 - 2012-05-28 21:27 - 001622528 _____ () G:\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll
2016-03-07 21:04 - 2011-09-19 20:18 - 001243136 _____ () G:\ASUS\AI Suite II\Settings\Settings.dll
2016-03-07 21:04 - 2011-07-21 09:06 - 000846848 _____ () G:\ASUS\AI Suite II\Splitter\Splitter.dll
2016-03-07 21:04 - 2012-08-29 18:09 - 000875520 _____ () G:\ASUS\AI Suite II\TabGadget\TabGadget.dll
2016-03-07 21:06 - 2011-06-08 11:15 - 000651264 _____ () G:\ASUS\AI Suite II\Thermal Radar\ThermalRadar.dll
2016-03-07 21:02 - 2010-08-23 03:17 - 000662016 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMLib.dll
2016-03-07 21:04 - 2010-10-05 08:22 - 000208896 _____ () G:\ASUS\AI Suite II\ImageHelper.dll
2016-03-07 21:07 - 2012-01-19 09:39 - 000028672 _____ () G:\ASUS\AI Suite II\USB BIOS Flashback\PEInfo.dll
2016-03-07 21:07 - 2010-09-23 11:51 - 000114688 _____ () G:\ASUS\AI Suite II\USB BIOS Flashback\AsIdxParser.dll
2016-03-07 21:07 - 2010-02-25 14:01 - 000139264 _____ () G:\ASUS\AI Suite II\USB BIOS Flashback\Aszip.dll
2016-03-07 21:04 - 2009-08-12 20:15 - 000253952 _____ () G:\ASUS\AI Suite II\Sensor\AlertHelper\pngio.dll
2014-05-02 23:55 - 2014-05-02 23:55 - 000071680 _____ () G:\No-IP\ducapi.dll
2018-09-03 08:14 - 2015-07-09 11:26 - 000839680 _____ () G:\Who Is On My Wifi\System.Data.SQLite.dll
2018-12-10 04:59 - 2018-12-10 04:59 - 000163840 _____ () C:\Program Files (x86)\QNAP\Qsync\IOTCAPIs.dll
2018-12-10 04:59 - 2018-12-10 04:59 - 000086016 _____ () C:\Program Files (x86)\QNAP\Qsync\P2PTunnelAPIs.dll
2018-12-10 04:59 - 2018-12-10 04:59 - 000116224 _____ () C:\Program Files (x86)\QNAP\Qsync\RdiffDll.dll
2018-12-10 04:59 - 2018-12-10 04:59 - 000094208 _____ () C:\Program Files (x86)\QNAP\Qsync\RDTAPIs.dll
2019-01-28 09:22 - 2018-06-15 10:57 - 001822720 _____ () C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\FirmwareUpdateDLL.dll
2019-01-28 09:22 - 2017-09-05 09:24 - 000099328 _____ () C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\lpcusbsio.dll
2015-07-21 14:50 - 2015-07-21 14:50 - 000034624 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll
2015-07-21 14:57 - 2015-07-21 14:57 - 000420160 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll
2014-09-25 15:20 - 2014-09-25 15:20 - 000129344 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll
2013-06-07 15:49 - 2013-06-07 15:49 - 000061952 _____ () C:\Program Files (x86)\Firetrust\MailWasher\MWPBridgeDLL.dll
2013-06-07 15:49 - 2013-06-07 15:49 - 004642816 _____ () C:\Program Files (x86)\Firetrust\MailWasher\MWPappDLL.dll
2011-04-26 14:37 - 2011-04-26 14:37 - 000061952 _____ () C:\Program Files (x86)\Firetrust\MailWasher\FTBridge.dll
2011-04-26 14:37 - 2011-04-26 14:37 - 000272384 _____ () C:\Program Files (x86)\Firetrust\MailWasher\FTClientNode.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000479232 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\DuiLib.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000061952 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\fsAudio.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000160256 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\fsnet_2.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000070656 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\AVDecoder.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000059904 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\AUEncoder.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000604160 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\Sqlite3x.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000096256 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\Video.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000402432 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\fs_udt.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000139264 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\IOTCAPIs.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000090112 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\RDTAPIs.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000014848 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\CGIParse.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 001210894 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\avcodec-54.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000146446 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\avutil-52.dll
2014-04-18 10:04 - 2014-04-18 10:04 - 000305166 _____ () C:\Program Files (x86)\FOSCAM\FOSCAM Client\FOSCAM\swscale-2.dll
2015-07-21 14:49 - 2015-07-21 14:49 - 000037696 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\qt_icontray_ex.dll
2017-06-07 21:07 - 2017-06-07 21:07 - 000569856 _____ () C:\Users\FrancsicoJosé\AppData\Local\MEGAsync\ShellExtX32.dll
2012-05-11 16:39 - 2012-08-21 10:34 - 009449472 _____ () Z:\GES2012\EXE\facturae.dll
2012-05-11 16:39 - 2011-10-06 12:50 - 000212992 _____ () Z:\GES2012\EXE\HBTwain.dll
2012-05-11 16:39 - 2011-10-06 12:50 - 000091136 _____ () Z:\GES2012\EXE\HBOleCnt.dll
2012-05-11 16:39 - 2011-10-06 12:50 - 000073728 _____ () Z:\GES2012\EXE\EInforma.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 001083368 _____ () G:\Plex\Plex Media Server\libxml2.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000115688 _____ () G:\Plex\Plex Media Server\soci_core-vc80-3_0.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000059880 _____ () G:\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000772072 _____ () G:\Plex\Plex Media Server\tag.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 001741288 _____ () G:\Plex\Plex Media Server\opencv_imgproc2411.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 001962984 _____ () G:\Plex\Plex Media Server\opencv_core2411.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000025576 _____ () G:\Plex\Plex Media Server\lyric_lite.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 001549104 _____ () G:\Plex\Plex Media Server\libstdc++-6.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000127136 _____ () G:\Plex\Plex Media Server\libgcc_s_dw2-1.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000050152 _____ () G:\Plex\Plex Media Server\DLLs\_socket.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000071656 _____ () G:\Plex\Plex Media Server\DLLs\_ssl.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000024552 _____ () G:\Plex\Plex Media Server\DLLs\_hashlib.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000041448 _____ () G:\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000930280 _____ () G:\Plex\Plex Media Server\Exts\lxml\etree.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000074728 _____ () G:\Plex\Plex Media Server\libexslt.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000190952 _____ () G:\Plex\Plex Media Server\libxslt.dll
2018-07-23 21:52 - 2018-07-23 21:52 - 000218088 _____ () G:\Plex\Plex Media Server\Exts\lxml\objectify.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000018920 _____ () G:\Plex\Plex Media Server\DLLs\select.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000095720 _____ () G:\Plex\Plex Media Server\DLLs\_ctypes.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000143336 _____ () G:\Plex\Plex Media Server\DLLs\pyexpat.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000694248 _____ () G:\Plex\Plex Media Server\DLLs\unicodedata.pyd
2018-07-23 21:52 - 2018-07-23 21:52 - 000064488 _____ () G:\Plex\Plex Media Server\TeVii.dll
2012-05-11 16:39 - 2011-10-06 12:50 - 000337920 _____ () Z:\GES2012\EXE\Sage.UI.WorkingArea.dll
2012-05-11 16:39 - 2012-08-21 10:32 - 000024576 _____ () Z:\GES2012\EXE\WebModulesGadget.dll

#14
2012-05-11 16:39 - 2011-10-06 12:51 - 000240128 _____ () Z:\GES2012\EXE\DevExpress.XtraGauges.v9.2.Win.dll
2012-05-11 16:39 - 2012-08-21 10:34 - 000105984 _____ () Z:\GES2012\EXE\DashboardDataAdapter.dll
2019-02-11 09:31 - 2019-02-06 10:44 - 001220936 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2019-02-11 09:31 - 2019-02-06 10:44 - 002103112 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2019-02-11 09:31 - 2019-02-06 10:47 - 000023376 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000025456 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000148968 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 001878888 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000118232 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes36.dll
2019-02-11 09:31 - 2019-02-06 10:44 - 000109024 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000074072 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000049128 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000131552 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000034664 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000082760 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000418776 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom36.dll
2019-02-11 09:31 - 2019-02-06 10:45 - 000025944 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000026600 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000182752 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000119272 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000401752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000062304 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000023520 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 001457488 _____ () C:\Program Files (x86)\Dropbox\Client\dbxlog._dbxlog.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:45 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000053736 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000065504 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000068968 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000032224 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 001755472 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000101200 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt592.sip.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 001886032 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000523600 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 003755344 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000061408 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000169304 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000061784 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000042840 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000202584 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000099664 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shell32.compiled._winffi_shell32.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000028008 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000033632 _____ () C:\Program Files (x86)\Dropbox\Client\winreindex.compiled._winreindex.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000117584 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000214872 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000027624 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000031600 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000486880 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000051552 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000029040 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 012484944 _____ () C:\Program Files (x86)\Dropbox\Client\nucleus_python.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000029024 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:44 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2019-02-11 09:31 - 2019-02-06 10:46 - 000036712 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000272208 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2019-02-11 09:31 - 2019-02-06 10:47 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000433992 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2019-02-11 09:31 - 2019-02-06 10:47 - 000038240 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000026432 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2019-02-11 09:31 - 2019-02-06 10:46 - 001967936 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2019-02-11 09:31 - 2019-02-06 10:47 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shcore.compiled._winffi_shcore.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000095592 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000054096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:47 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.gdi32.compiled._winffi_gdi32.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000556880 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp36-win32.pyd
2019-02-11 09:31 - 2019-02-06 10:46 - 000335184 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp36-win32.pyd

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:07BF512B [152]
AlternateDataStreams: C:\ProgramData\TEMP:9D1B94FD [115]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\.scr: CryptoPreventSCR => "C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPreventFilterMod.CryptoPreventEXEC" "%1" /S %*

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\fnmt.es -> hxxp://fnmt.es
IE trusted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\fnmt.es -> hxxps://fnmt.es
IE trusted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\fnmt.gob.es -> hxxps://fnmt.gob.es
IE trusted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\fnmt.gob.es -> hxxp://fnmt.gob.es
IE trusted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\gob.es -> hxxps://agenciatributaria.gob.es
IE trusted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\samsungsetup.com -> hxxp://www.samsungsetup.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\1-se.com -> 1-se.com

There are 11596 more sites.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-07-26 18:53 - 2019-02-11 09:27 - 000452928 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1	localhost
127.0.0.1	activate.adobe.com
127.0.0.1	practivate.adobe.com
127.0.0.1	ereg.adobe.com
127.0.0.1	activate.wip3.adobe.com
127.0.0.1	wip3.adobe.com
127.0.0.1	3dns-3.adobe.com
127.0.0.1	3dns-2.adobe.com
127.0.0.1	adobe-dns.adobe.com
127.0.0.1	adobe-dns-2.adobe.com
127.0.0.1	adobe-dns-3.adobe.com
127.0.0.1	ereg.wip3.adobe.com
127.0.0.1	activate-sea.adobe.com
127.0.0.1	wwis-dubc1-vip60.adobe.com
127.0.0.1	activate-sjc0.adobe.com
127.0.0.1	start.spoon.net
127.0.0.1	activation.acronis.com
127.0.0.1	license.superantispyware.com
127.0.0.1	www.007guard.com
127.0.0.1	007guard.com
127.0.0.1	008i.com
127.0.0.1	www.008k.com
127.0.0.1	008k.com
127.0.0.1	www.00hq.com
127.0.0.1	00hq.com
127.0.0.1	010402.com
127.0.0.1	www.032439.com
127.0.0.1	032439.com
127.0.0.1	www.0scan.com
127.0.0.1	0scan.com

There are 15494 more lines.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Java\jre1.8.0_111\bin;C:\Program Files (x86)\PC Connectivity Solution\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Common Files\Acronis\SnapAPI\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;G:\Calibre2\;g:\My Screen Recorder Pro 4\;C:\Program Files (x86)\AMD\ATI.ACE\Core-Static;g:\Cracklock\Bin;C:\adb;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\GtkSharp\2.12\bin;C:\Program Files (x86)\AutoFirma\AutoFirma;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\FrancsicoJosé\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "AdobeCS5ServiceManager"
HKLM\...\StartupApproved\Run32: => "EaseUS EPM tray"
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\StartupApproved\Run: => "NokiaSuite.exe"
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\StartupApproved\Run: => "Viber"
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\StartupApproved\Run: => "Plex Media Server"
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\StartupApproved\Run: => "Speccy"
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\StartupApproved\Run: => "EPLTarget\P0000000000000000"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1C73BE3A-59AB-46D7-9EAA-B9CAF032D04D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{FC0460BB-F20D-4A74-A506-31B041C992B9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{B0BDFE3F-4F91-49EF-8877-7D171771233D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{D14BF553-49A0-42F5-B017-D22F8225FA95}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{2E9EDE81-52A4-40B5-A6F7-9DE95919FAEC}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Center\SamsungPrinterCenter.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{730F4810-E4EE-43C6-BDFE-04DC5FF480A6}] => (Allow) G:\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> Plex)
FirewallRules: [{4F5636B4-A83D-4D6C-9451-E13AB76C4C71}] => (Allow) G:\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{533AFCAE-FAFC-45D5-9C82-E9916CDE8A93}] => (Allow) G:\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{919D2A01-0EEF-4760-A21A-5561210632E7}] => (Allow) G:\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{F987B982-E3CD-4F04-8A84-E2D40333E832}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{333F4790-016C-4D3F-A47F-C64C8C297467}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [UDP Query User{6DF149D5-9438-45D5-A0AF-1A35286F0E2A}G:\vlc\vlc.exe] => (Allow) G:\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{E64D10F6-0B30-4134-A371-87B9594B312B}G:\vlc\vlc.exe] => (Allow) G:\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{60952976-5F76-45F0-9216-9078D214CA93}C:\program files (x86)\qnap\qsync\qsync.exe] => (Allow) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [TCP Query User{612D4621-C160-4CAB-9460-087E6EFE2551}C:\program files (x86)\qnap\qsync\qsync.exe] => (Allow) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [{4C5E603D-6A9F-4B4E-932E-E835C4DA2541}] => (Allow) C:\Program Files (x86)\Eye-Fi\EyeFiX2Receiver.exe (Eye-Fi, Inc -> )
FirewallRules: [{4ECE5EF7-3D7D-4224-AF9F-D02D39D3E290}] => (Allow) C:\Program Files (x86)\Eye-Fi\EyeFiX2Receiver.exe (Eye-Fi, Inc -> )
FirewallRules: [UDP Query User{BE0BC53C-B114-4626-A5F5-B4143F48D016}G:\plex\plex media server\plex dlna server.exe] => (Allow) G:\plex\plex media server\plex dlna server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [TCP Query User{40159B74-A4E7-4FF6-B1C0-972B181992EF}G:\plex\plex media server\plex dlna server.exe] => (Allow) G:\plex\plex media server\plex dlna server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [UDP Query User{B92D6A9F-5EF7-4A57-88CD-62AC884BABFC}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe] => (Allow) C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe ()
FirewallRules: [TCP Query User{660EB015-6A01-40B2-ADCE-13C97354BD0F}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe] => (Allow) C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe ()
FirewallRules: [{55DA21A7-FF78-4CD7-8CB6-1B9F92A27D62}] => (Allow) G:\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
FirewallRules: [{C302C114-0595-47B1-A75D-773EEDCE9889}] => (Allow) G:\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
FirewallRules: [{A26B7DC9-C8C4-4CCC-9613-F1A7FEAF83CA}] => (Allow) LPort=1900
FirewallRules: [{83045FC2-77C4-4F71-9128-0A97E5A1CD7D}] => (Allow) LPort=2869
FirewallRules: [UDP Query User{ED372FDE-ACCD-4F8D-AB53-BBAD6AA9F9ED}G:\video converter ultimate\dscheck.exe] => (Allow) G:\video converter ultimate\dscheck.exe (Shenzhen Wondershare Information Technology Co., Ltd. -> Wondershare Software)
FirewallRules: [TCP Query User{7AFAAAA8-1D42-4CED-9963-121E53B4807A}G:\video converter ultimate\dscheck.exe] => (Allow) G:\video converter ultimate\dscheck.exe (Shenzhen Wondershare Information Technology Co., Ltd. -> Wondershare Software)
FirewallRules: [UDP Query User{633D3B19-1074-4445-AA40-4346EFFB6FA3}G:\video converter ultimate\mediaserver.exe] => (Allow) G:\video converter ultimate\mediaserver.exe (Shenzhen Wondershare Information Technology Co., Ltd. -> MediaServer)
FirewallRules: [TCP Query User{FB0A46BD-9079-4EA6-81C2-33DDC6F68FAD}G:\video converter ultimate\mediaserver.exe] => (Allow) G:\video converter ultimate\mediaserver.exe (Shenzhen Wondershare Information Technology Co., Ltd. -> MediaServer)
FirewallRules: [{F99AF2C7-8FF1-4D95-9C63-8D40DD48A2C1}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{F2E0C8D9-A0D5-49CE-B2D6-AC9BF32569F0}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
FirewallRules: [{8556ED22-75A8-4CEF-BDC3-1A52FBCF8A9C}] => (Allow) C:\Windows\System32\SUPDSvc2.exe (Samsung Electronics CO., LTD. -> Samsung Electronics)
FirewallRules: [{05A31FDD-4C5D-4A3B-B107-7582BAA28FD9}] => (Allow) C:\Windows\System32\SUPDSvc2.exe (Samsung Electronics CO., LTD. -> Samsung Electronics)
FirewallRules: [{77D3ADA6-5F4D-4EC9-B794-55B8A542EBF6}] => (Allow) C:\Windows\System32\SUPDSvc2.exe (Samsung Electronics CO., LTD. -> Samsung Electronics)
FirewallRules: [{1BF4887A-B2C1-4378-B8F0-0508E11C8703}] => (Allow) C:\Windows\System32\SUPDSvc2.exe (Samsung Electronics CO., LTD. -> Samsung Electronics)
FirewallRules: [UDP Query User{2D4A3D50-6479-45FC-9741-CE984452C93E}G:\kodi\kodi.exe] => (Allow) G:\kodi\kodi.exe (XBMC-Foundation)
FirewallRules: [TCP Query User{A604E9C1-0BA4-4324-A1C2-E0B1C1B15FD5}G:\kodi\kodi.exe] => (Allow) G:\kodi\kodi.exe (XBMC-Foundation)
FirewallRules: [UDP Query User{0BAE5560-E019-4207-9111-2BB237D91FEA}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{882CDAA8-5316-4A51-A245-10489A808A81}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{5EE60553-6666-4F88-888B-1C7BED73FD9F}] => (Block) G:\transmission\transmission-qt.exe (Open Source Developer, René Berber -> )
FirewallRules: [{8E66E20E-B2E9-4362-BCDC-C0A150A166EE}] => (Block) G:\transmission\transmission-qt.exe (Open Source Developer, René Berber -> )
FirewallRules: [UDP Query User{5CE0489D-0FF9-4138-AA34-0703FB4B8EA2}G:\transmission\transmission-qt.exe] => (Allow) G:\transmission\transmission-qt.exe (Open Source Developer, René Berber -> )
FirewallRules: [TCP Query User{BD4E087C-CDA4-47F0-8B8D-9D70B26813D7}G:\transmission\transmission-qt.exe] => (Allow) G:\transmission\transmission-qt.exe (Open Source Developer, René Berber -> )
FirewallRules: [{58E4556F-8550-4E09-B06F-8176649AB735}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{D1EDA7F9-5145-41FE-9E68-A09198E27E72}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{3898051A-6301-4156-9BCF-97EF221B646B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{656A9631-9EAB-4376-BD49-C174ECA7C791}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{79F523A5-AB89-4258-9B97-8945FD5A2F7D}G:\kodi\kodi.exe] => (Allow) G:\kodi\kodi.exe (XBMC-Foundation)
FirewallRules: [TCP Query User{E4199CF4-B506-46B2-B3FC-AF28F020BBA0}G:\kodi\kodi.exe] => (Allow) G:\kodi\kodi.exe (XBMC-Foundation)
FirewallRules: [UDP Query User{F184A134-3B59-4848-81A6-0DC2E25F3873}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Block) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{8C89B46B-6E4C-420B-BF59-ECBC92039A65}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Block) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1C9F01BF-41E9-4DA2-AF87-FC4F9FC11952}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{38BC8864-DB77-4975-989B-CB6EB658A79E}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{CF7E9D17-428B-4F21-94D2-3E1F116A63C8}] => (Allow) LPort=26675
FirewallRules: [{929B8DDF-8E38-4E81-8EF5-C904AB2A3C80}] => (Block) G:\totalmedia theatre 6\totalmedia server\tm server.exe (ArcSoft, Inc. -> ArcSoft Inc.)
FirewallRules: [{39BB77B8-3BB4-4BA8-86DC-16A223206938}] => (Block) G:\totalmedia theatre 6\totalmedia server\tm server.exe (ArcSoft, Inc. -> ArcSoft Inc.)
FirewallRules: [UDP Query User{6C73B97E-39A9-4D17-8670-D31D8749DE90}G:\totalmedia theatre 6\totalmedia server\tm server.exe] => (Allow) G:\totalmedia theatre 6\totalmedia server\tm server.exe (ArcSoft, Inc. -> ArcSoft Inc.)
FirewallRules: [TCP Query User{9B31F22C-BD94-440E-84C9-063D17EFE426}G:\totalmedia theatre 6\totalmedia server\tm server.exe] => (Allow) G:\totalmedia theatre 6\totalmedia server\tm server.exe (ArcSoft, Inc. -> ArcSoft Inc.)
FirewallRules: [{4CFE36E0-275F-465A-AD18-BA9E0E373B8C}] => (Block) G:\sopcast\sopcast.exe (www.sopcast.com)
FirewallRules: [{2782BA6F-80E9-4C26-BA50-2D52F80D15BC}] => (Block) G:\sopcast\sopcast.exe (www.sopcast.com)
FirewallRules: [UDP Query User{0812DC5C-8334-4AE9-B008-72CC6783E7B4}G:\sopcast\sopcast.exe] => (Allow) G:\sopcast\sopcast.exe (www.sopcast.com)
FirewallRules: [TCP Query User{34F6AF75-855A-4155-8A6B-1195C894A512}G:\sopcast\sopcast.exe] => (Allow) G:\sopcast\sopcast.exe (www.sopcast.com)
FirewallRules: [{CE20D834-F3E9-4C19-8ACC-9BA84F07FB0F}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{26710D31-C513-4BDF-8DF7-5C7DCAB30DA6}] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [UDP Query User{3723EC31-D890-4BB0-9780-C2DABED0F1FD}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [TCP Query User{5AFBF989-368D-4864-A5E0-C085941DA2BD}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{EF74C683-C933-486C-A0A0-3755B9F18066}] => (Block) G:\cámara ip super cliente\superipcam.exe (Shenzhen VStarcam Technology Co., Ltd -> )
FirewallRules: [{33B8EBB0-5EEF-403B-9B68-958552704C1C}] => (Block) G:\cámara ip super cliente\superipcam.exe (Shenzhen VStarcam Technology Co., Ltd -> )
FirewallRules: [UDP Query User{FF9476CC-DC3B-4D6A-86F8-78F9D93D83E2}G:\cámara ip super cliente\superipcam.exe] => (Allow) G:\cámara ip super cliente\superipcam.exe (Shenzhen VStarcam Technology Co., Ltd -> )
FirewallRules: [TCP Query User{A7636F8E-CB34-417A-AEDA-DB7B423ECEB1}G:\cámara ip super cliente\superipcam.exe] => (Allow) G:\cámara ip super cliente\superipcam.exe (Shenzhen VStarcam Technology Co., Ltd -> )
FirewallRules: [{6DC9AD53-8499-411C-B191-79049F6048EB}] => (Allow) G:\IP Camera Viewer 1.0\IP Camera Viewer.exe (Deskshare, Inc. -> DeskShare)
FirewallRules: [{5627381A-20C6-499C-81D1-B8324452464E}] => (Allow) G:\IP Camera Viewer 1.0\IP Camera Viewer.exe (Deskshare, Inc. -> DeskShare)
FirewallRules: [{8F7397E9-4ADF-4B57-9FA8-7FD2374C2201}] => (Allow) LPort=135
FirewallRules: [{BFBD380E-FD28-40DF-9AAD-2F89C11880A7}] => (Allow) LPort=5000
FirewallRules: [{CC3B0108-B0F3-4B5D-8D7D-EA5D467AC9D3}] => (Allow) LPort=5001
FirewallRules: [{ABADC2C2-202A-4E5D-96D7-DAD234EECC5A}] => (Allow) LPort=5002
FirewallRules: [{03227507-77E7-4FC2-8A60-47E121B46A1B}] => (Allow) LPort=5003
FirewallRules: [{4A627CC2-ADDB-4AF7-83D5-855DC2A74605}] => (Allow) LPort=5004
FirewallRules: [{C2429293-767F-417D-BCA4-67A2DB24B1A1}] => (Allow) LPort=5005
FirewallRules: [{25926D4D-2FC2-4369-8E15-EF00688D36B4}] => (Allow) LPort=5006
FirewallRules: [{003BEB35-D351-4F09-A11D-BC0C83EABD03}] => (Allow) LPort=5007
FirewallRules: [{13701CAF-05C6-4584-AB9E-B7D5FCF76FF4}] => (Allow) LPort=5008
FirewallRules: [{B58208F1-3D36-40B5-8D43-0CCFFD8F9A4A}] => (Allow) LPort=5009
FirewallRules: [{9AF36E76-EB6A-4C26-B5B0-ABF26772F9AB}] => (Allow) LPort=5010
FirewallRules: [{98604A1F-1E5C-42E1-AC04-3601B04759CF}] => (Allow) LPort=5011
FirewallRules: [{DD56983D-6BF7-4DAD-95E8-3B1ADFD9F150}] => (Allow) LPort=5012
FirewallRules: [{59AC63BA-E794-4D86-95CE-37673024F213}] => (Allow) LPort=5013
FirewallRules: [{D6A060CE-0341-49B5-B47E-1601202962A8}] => (Allow) LPort=5014
FirewallRules: [{3E6E58D7-64AE-4BB9-BB92-781139D48A25}] => (Allow) LPort=5015
FirewallRules: [{19D3FF49-DFAE-4B72-9F19-0851BEA8305C}] => (Allow) LPort=5016
FirewallRules: [{220A4F73-B8F6-4B3E-A979-3890A0C538A1}] => (Allow) LPort=5017
FirewallRules: [{E67F3724-6DA3-47F0-898B-5C3C25C872A5}] => (Allow) LPort=5018
FirewallRules: [{68C58B96-7B56-4B5D-A45C-267A111D9041}] => (Allow) LPort=5019
FirewallRules: [{5842EBA1-CC6E-4AD6-A85F-EE79AC883D84}] => (Allow) LPort=5020
FirewallRules: [TCP Query User{C1A07D22-B61D-4479-987A-D85078C75742}G:\lphant\elephantclient.exe] => (Allow) G:\lphant\elephantclient.exe (www.lphant.com)
FirewallRules: [UDP Query User{4DB1CDBE-27BC-4532-A92A-37380B4A5111}G:\lphant\elephantclient.exe] => (Allow) G:\lphant\elephantclient.exe (www.lphant.com)
FirewallRules: [TCP Query User{C7D87726-B5BC-4DD3-8800-5558E67FC113}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{55815CE6-48F5-4F81-8402-153203E0C97B}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{F9F01AF7-6FB2-46E3-8978-CB86A43291A8}G:\xampp\apache\bin\httpd.exe] => (Allow) G:\xampp\apache\bin\httpd.exe (Apache Software Foundation)
FirewallRules: [UDP Query User{D1EA5FE2-C96E-4ADB-98B0-F2FDA4902B57}G:\xampp\apache\bin\httpd.exe] => (Allow) G:\xampp\apache\bin\httpd.exe (Apache Software Foundation)
FirewallRules: [TCP Query User{96051B50-9EDE-4FD9-A5F4-B3EE894AE355}G:\xampp\mysql\bin\mysqld.exe] => (Allow) G:\xampp\mysql\bin\mysqld.exe (MariaDB Corporation Ab -> )
FirewallRules: [UDP Query User{9D9045D1-6D17-457C-A041-9DDCC01FE754}G:\xampp\mysql\bin\mysqld.exe] => (Allow) G:\xampp\mysql\bin\mysqld.exe (MariaDB Corporation Ab -> )
FirewallRules: [TCP Query User{B61E8670-B5C7-469E-9A09-C923C4EDA40D}G:\xampp\mercurymail\mercury.exe] => (Allow) G:\xampp\mercurymail\mercury.exe (David Harris)
FirewallRules: [UDP Query User{CFA811AB-E7C2-40CD-9FA8-E52E8D0132F4}G:\xampp\mercurymail\mercury.exe] => (Allow) G:\xampp\mercurymail\mercury.exe (David Harris)
FirewallRules: [{F6401A27-8CAB-463B-8986-3CF3F49E4D06}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\WFTPairing\EOSUPNPSV.exe (CANON INC.)
FirewallRules: [{88BD4224-4B68-4AEB-AD9E-5A2D7FF4985A}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\WFTPairing\EOSUPNPSV.exe (CANON INC.)
FirewallRules: [{B3E0934F-2B4F-48D7-AC4B-9DAA2B7B2847}] => (Block) \\LOURDES-PC\GrupoSP\SPPanel\SPPG.EXE No File
FirewallRules: [TCP Query User{E72A9E00-B54F-407A-A83D-66381A091A11}C:\program files (x86)\adobe\adobe dreamweaver cs5\dreamweaver.exe] => (Allow) C:\program files (x86)\adobe\adobe dreamweaver cs5\dreamweaver.exe (Adobe Systems Incorporated. -> Adobe Systems, Inc.)
FirewallRules: [UDP Query User{BE601369-2000-4B2D-BCED-380205832DE4}C:\program files (x86)\adobe\adobe dreamweaver cs5\dreamweaver.exe] => (Allow) C:\program files (x86)\adobe\adobe dreamweaver cs5\dreamweaver.exe (Adobe Systems Incorporated. -> Adobe Systems, Inc.)
FirewallRules: [{8752A7A2-488E-4B42-9C03-4F773253E12D}] => (Block) \\LOURDES-PC\GrupoSP\SPPanel\SPPG.EXE No File
FirewallRules: [TCP Query User{8D378A7A-2EAD-43AD-B680-2277EF3D2660}G:\xampp\filezillaftp\filezillaserver.exe] => (Allow) G:\xampp\filezillaftp\filezillaserver.exe (FileZilla Project)
FirewallRules: [UDP Query User{E15F5CCF-8617-4C91-B16A-01B8ECA31C72}G:\xampp\filezillaftp\filezillaserver.exe] => (Allow) G:\xampp\filezillaftp\filezillaserver.exe (FileZilla Project)
FirewallRules: [{9B4F7CBC-975B-491D-B0F0-36A55FE61FD0}] => (Allow) G:\IP Camera Viewer 1.0\IP Camera Viewer.exe (Deskshare, Inc. -> DeskShare)
FirewallRules: [{B6CA530B-EDC0-4CF5-8349-2D823EEC70FC}] => (Allow) G:\IP Camera Viewer 1.0\IP Camera Viewer.exe (Deskshare, Inc. -> DeskShare)
FirewallRules: [TCP Query User{AD4D35C6-74E4-4467-9D16-7C950FBE79AF}G:\active webcam\webcam.exe] => (Allow) G:\active webcam\webcam.exe (PY SOFTWARE -> PY Software)
FirewallRules: [UDP Query User{C81D6993-CCD3-460D-BA97-1C7A911333A4}G:\active webcam\webcam.exe] => (Allow) G:\active webcam\webcam.exe (PY SOFTWARE -> PY Software)
FirewallRules: [TCP Query User{3989289F-96B9-48FE-90EA-37FEB62A3641}G:\plex\plex media center\plex.exe] => (Allow) G:\plex\plex media center\plex.exe (Plex, Inc.)
FirewallRules: [UDP Query User{9856FCDF-5BC1-410F-A716-91B7585E5D41}G:\plex\plex media center\plex.exe] => (Allow) G:\plex\plex media center\plex.exe (Plex, Inc.)
FirewallRules: [{581456F3-BB29-499E-9757-2506C84E59F6}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [{1BBAE095-7FE5-4A3D-8F7E-2B99CA62F41C}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Acronis International GmbH -> Acronis)
FirewallRules: [TCP Query User{9E14AE69-C847-423A-92F2-AB06D6871A9A}C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe ()
FirewallRules: [UDP Query User{2742572E-D862-4E49-92D7-3D0A192BFA19}C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe ()
FirewallRules: [TCP Query User{87BEEF33-659F-4145-883E-7D040D9B01F9}C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe ()
FirewallRules: [UDP Query User{03DD0BD8-5815-4473-B9F6-F4E1F8D394DF}C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe ()
FirewallRules: [TCP Query User{72D12E7B-9A6D-4C8E-9915-EAA25698A689}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{84D510C0-2DBF-4CF2-A08A-874F7DD2E0C2}C:\windows\explorer.exe] => (Allow) C:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{1572F9B9-5756-4850-AC1A-9E65FA5C092A}C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe ()
FirewallRules: [UDP Query User{3CD629B8-7A39-4269-9000-F7ADDE398888}C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe ()
FirewallRules: [TCP Query User{CB1F2269-08A5-4CEC-B58D-5F320712185F}C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe ()
FirewallRules: [UDP Query User{AF4BB479-5DA1-40C7-8EF4-9537374295D0}C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\fsipcam.exe ()
FirewallRules: [TCP Query User{4B87C726-BEFC-4559-9B9E-9237E062289B}C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe ()
FirewallRules: [UDP Query User{9E3A3C1D-B9FF-4187-9C73-8686ACC8BCF2}C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\hi3507exe.exe ()
FirewallRules: [TCP Query User{63DD04A6-E8AE-4FBF-9F0E-51CF9C0C2C92}C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe ()
FirewallRules: [UDP Query User{6206FEDE-E3FF-4AAA-A98C-C9294F8FD4BE}C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe] => (Allow) C:\program files (x86)\foscam\foscam client\foscam\zymjexe.exe ()
FirewallRules: [{E1B192A6-D546-4AF4-8FAA-36A4821A61B5}] => (Allow) LPort=5357
FirewallRules: [{F7799F46-97AA-45DF-BEB2-6EC68F7F9B1D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{3288B787-B125-4307-9417-4EE3DAF8A210}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{76E13ED7-3731-4A49-A3F7-97329A3A0261}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Universal Print Driver 2\PrinterSelector\SUPDApp.exe (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{EBD13EE0-430C-4C38-A523-BA7F96969CBE}] => (Allow) G:\MultilizerPDFTranslator\PDFTRanslationWizard.exe ()
FirewallRules: [{80C903C8-8312-4585-9FE5-B08665A728FB}] => (Allow) G:\MultilizerPDFTranslator\PDFTRanslationWizard.exe ()
FirewallRules: [{0BDC7C9F-6D0B-46E4-90D9-4E5D418A0D6B}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe (Intel(R) iCDG WINS WSS CCF -> Intel Corporation)
FirewallRules: [{80DFF554-7CF3-46C0-ADE6-7E565D688F7B}] => (Allow) C:\Program Files (x86)\ASUS\Share Link\ShareLink.exe (ASUSTeK Computer Inc. -> ASUS)
FirewallRules: [{2A9E0CD9-3A4D-46D8-ACE4-0F5E4F931CE6}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe (Intel(R) iCDG WINS WSS CCF -> Intel Corporation)
FirewallRules: [{F0B2D6E5-6096-4141-BAF7-AF9DC6793799}] => (Allow) C:\Program Files\Intel\STCServ\STCServ.exe (Intel(R) iCDG WINS WSS CCF -> Intel Corporation)
FirewallRules: [{CFA6E5CE-F931-4977-9373-CE0EF148599E}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{71D72A4E-80B4-44A1-BB5E-2963642D791B}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{48B5F582-9D4D-4E81-9681-1DE90AF488D6}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{FE890E15-7785-4C7F-9FDE-5AE92F869CC4}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{7B7D1FCF-3FA2-4A2A-97A8-3C6D21ED05ED}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{4887E66C-34FF-4306-AED0-64D15EAFC1AD}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{9AB1EBBD-8E6F-4913-A6D4-742B99AE204F}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{D59705FC-E4D1-4311-9287-A81AED125D43}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{FA6A2ED2-4B96-4A18-9EA0-E15C809C28E5}] => (Allow) LPort=2869
FirewallRules: [{3EF17EDE-DAA5-430F-A38A-3BCF3AF7AA69}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{BCDC34FA-EAC8-4409-B5B3-2987DCE30164}C:\program files (x86)\qnap\qsync\qsync.exe] => (Allow) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [UDP Query User{EF5D4F0F-3D9B-4A8D-9C86-3004EF66B36F}C:\program files (x86)\qnap\qsync\qsync.exe] => (Allow) C:\program files (x86)\qnap\qsync\qsync.exe (QNAP Systems, Inc. -> QNAP Systems, Inc.)
FirewallRules: [TCP Query User{A435D0B2-C4FF-405B-9914-319AB2811AFD}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe] => (Allow) C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe ()
FirewallRules: [UDP Query User{2875BDEF-6D02-4342-9B1A-FA162FB708E0}C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe] => (Allow) C:\users\comercio\appdata\roaming\kodi\userdata\addon_data\plugin.video.quasar\bin\windows_x64\quasar.exe ()
FirewallRules: [{E342E3DE-EEED-4978-A9B6-6A9C29A565A7}] => (Allow) G:\qBittorrent\qbittorrent.exe ()
FirewallRules: [{CA8DCD13-D088-49BD-9552-317DE675A3EE}] => (Allow) G:\qBittorrent\qbittorrent.exe ()
FirewallRules: [{FEE8C9CA-04DE-4326-B23F-72D3EE128040}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{C3E5B277-67D4-46F3-A015-A1EFCBA52063}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{E70395E3-FA8F-4509-9F0B-B00D04FAC1E7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{AF8F931B-872F-4B95-A7F0-709E8B1D2C4D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5527C796-AC29-4274-8B59-E12C95AB3E57}] => (Allow) C:\Program Files\Siber Systems\GoodSync\gs-server.exe (Siber Systems -> )
FirewallRules: [{D097EF56-37C2-4384-A756-927C45AD95D5}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{A9B65EC0-C734-4100-A23B-1F23DE05DC01}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe (IncrediMail, Inc. -> IncrediMail Ltd.)
FirewallRules: [{A256F4CE-5A79-4937-B969-D379C3B35A9F}] => (Allow) G:\qBittorrent\qbittorrent.exe ()
FirewallRules: [{3D765CCB-E81E-4076-8A6B-48387E42E22E}] => (Allow) G:\qBittorrent\qbittorrent.exe ()
FirewallRules: [{02CD8BED-C7EE-41DB-B227-CDD3BEE72D43}] => (Block) %ProgramFiles% (x86)\eMagicOne\Store Manager for PrestaShop\PrestaShop_Manager.exe No File
FirewallRules: [{14449EC8-2CB5-45D3-86E3-6BF0C290B551}] => (Block) %ProgramFiles% (x86)\eMagicOne\Store Manager for PrestaShop\Updater.exe No File
FirewallRules: [{B25B3162-5BD7-4D10-B567-8BE9F8E1689A}] => (Block) %ProgramFiles% (x86)\eMagicOne\Store Manager for PrestaShop\PrestaShop_Manager.exe No File
FirewallRules: [{CCE367AF-3B00-4507-9F47-D6B7824F7D9F}] => (Block) %ProgramFiles% (x86)\eMagicOne\Store Manager for PrestaShop\Updater.exe No File
FirewallRules: [{2A137D14-0474-45B2-9DFD-667C54C34327}] => (Allow) G:\PS4 Remote Play\RemotePlay.exe (Sony Interactive Entertainment Inc. -> Sony Interactive Entertainment Inc.)
FirewallRules: [{B4510DE1-0324-4DDD-8819-21A76586F73B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8CC468BE-69FD-448F-9D6A-4E25853D06CC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{43A0A9B0-48E0-4A32-B6C3-82D75FE645A2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{506FFC01-0E98-49AB-A465-2924EE205697}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{D5ED4C8C-D345-43ED-9194-20639DE9D308}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FE106798-DFD8-4BA3-8B6B-F976C8DBB8DA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{2265B114-75C8-4069-981B-6342D81D7D43}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{82C90F33-A958-4E12-8D1C-861CF7B739EE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.99.250.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3A2EB42F-EE4B-4E63-A901-07427F21A5D8}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{59A6E311-4E1B-4A1B-AA82-43E11F7E079C}] => (Allow) C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
FirewallRules: [{73365381-4F7E-4C09-990A-149BDE8DE31F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{FDA15012-7CB8-4066-BBAD-5C2B674F64A8}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{388FD153-631B-4C4E-A1E5-F5B2F80E5B7C}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{97DD27D8-402F-4A41-B2AF-B1EC86466375}] => (Allow) G:\ASUS\AI Suite II\Remote GO!\AssistTools\WiFi GO! Server.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
FirewallRules: [{4C05ED1F-1CBF-4898-898D-EC0A65A3D52A}] => (Allow) G:\ASUS\AI Suite II\Remote GO!\AssistTools\WiFi GO! Server.exe (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
FirewallRules: [{4CEE3A22-103D-4A42-8AAC-EE4921EFE330}] => (Allow) G:\ASUS\AI Suite II\Remote GO!\ASUSDMS.exe (ASUSTeK Computer Inc. -> )
FirewallRules: [{602BE86F-E8EB-40F9-B505-C46852363488}] => (Allow) G:\ASUS\AI Suite II\Remote GO!\ASUSDMS.exe (ASUSTeK Computer Inc. -> )
FirewallRules: [{96B3766A-33D8-4233-82A8-D8574AACF0F7}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/11/2019 10:28:23 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Security Center no pudo validar al autor de la llamada con el error %1.

Error: (02/11/2019 09:45:11 AM) (Source: DbxSvc) (EventID: 281) (User: )
Description: CertFindCertificateInStore failed with: (-2146885628) No puede encontrar el objeto o propiedad

#15



System errors:
=============
Error: (02/11/2019 09:30:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Intel(R) Common Connectivity Framework no pudo iniciarse debido al siguiente error: 
El servicio no respondió a tiempo a la solicitud de inicio o de control.

Error: (02/11/2019 09:30:30 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Intel(R) Common Connectivity Framework.

Error: (02/11/2019 09:27:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 y APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (02/11/2019 09:27:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 y APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

Error: (02/11/2019 09:27:07 AM) (Source: VBoxNetLwf) (EventID: 12) (User: )
Description: El controlador detectó un error interno del controlador en \Device\VBoxNetLwf.

Error: (02/11/2019 09:27:07 AM) (Source: VBoxNetLwf) (EventID: 12) (User: )
Description: El controlador detectó un error interno del controlador en \Device\VBoxNetLwf.

Error: (02/08/2019 08:34:28 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Error de DCOM "1115" al intentar iniciar el servicio SecurityHealthService con argumentos "No disponible" para ejecutar el servidor:
{2D15188C-D298-4E10-83B2-64666CCBEBBD}

Error: (02/08/2019 08:34:28 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: Error de DCOM "1115" al intentar iniciar el servicio SecurityHealthService con argumentos "No disponible" para ejecutar el servidor:
{2D15188C-D298-4E10-83B2-64666CCBEBBD}


Windows Defender:
===================================
Date: 2019-02-07 20:01:51.959
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para obtener más información consulte lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Java/Jaraut.B&threatid=2147718490&enterprise=0
Nombre: Trojan:Java/Jaraut.B
Id.: 2147718490
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: file:_C:\Windows\Temp\tmp00000224\tmp00004245; file:_C:\Windows\Temp\tmp00000224\tmp00007a59
Origen de detección: Equipo local
Tipo de detección: Concreto
Fuente de detección: Protección en tiempo real
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Versión de firma: AV: 1.285.1062.0, AS: 1.285.1062.0, NIS: 1.285.1062.0
Versión de motor: AM: 1.1.15600.4, NIS: 1.1.15600.4

Date: 2019-02-07 20:01:47.240
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para obtener más información consulte lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Tiggre!rfn&threatid=2147723625&enterprise=0
Nombre: Trojan:Win32/Tiggre!rfn
Id.: 2147723625
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: file:_C:\Windows\Temp\tmp00000224\tmp0000262c; file:_C:\Windows\Temp\tmp00000224\tmp00007a44
Origen de detección: Equipo local
Tipo de detección: Concreto
Fuente de detección: Protección en tiempo real
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Versión de firma: AV: 1.285.1062.0, AS: 1.285.1062.0, NIS: 1.285.1062.0
Versión de motor: AM: 1.1.15600.4, NIS: 1.1.15600.4

Date: 2019-02-07 20:01:40.244
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para obtener más información consulte lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/AutoKMS!rfn&threatid=2147692752&enterprise=0
Nombre: HackTool:Win32/AutoKMS!rfn
Id.: 2147692752
Gravedad: Alta
Categoría: Herramienta
Ruta de acceso: file:_C:\Windows\Temp\tmp00000224\tmp00006792
Origen de detección: Equipo local
Tipo de detección: Concreto
Fuente de detección: Protección en tiempo real
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Versión de firma: AV: 1.285.1062.0, AS: 1.285.1062.0, NIS: 1.285.1062.0
Versión de motor: AM: 1.1.15600.4, NIS: 1.1.15600.4

Date: 2019-02-07 20:01:33.932
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para obtener más información consulte lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Dynamer!dtc&threatid=2147638124&enterprise=0
Nombre: Trojan:Win32/Dynamer!dtc
Id.: 2147638124
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: file:_C:\Windows\Temp\tmp00000224\tmp00006743
Origen de detección: Equipo local
Tipo de detección: Concreto
Fuente de detección: Protección en tiempo real
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
Versión de firma: AV: 1.285.1062.0, AS: 1.285.1062.0, NIS: 1.285.1062.0
Versión de motor: AM: 1.1.15600.4, NIS: 1.1.15600.4

Date: 2019-02-07 20:01:28.023
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para obtener más información consulte lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Dynamer!dtc&threatid=2147638124&enterprise=0
Nombre: Trojan:Win32/Dynamer!dtc
Id.: 2147638124
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: file:_C:\Windows\Temp\tmp00000224\tmp00006743
Origen de detección: Equipo local
Tipo de detección: Concreto
Fuente de detección: Protección en tiempo real
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Versión de firma: AV: 1.285.1062.0, AS: 1.285.1062.0, NIS: 1.285.1062.0
Versión de motor: AM: 1.1.15600.4, NIS: 1.1.15600.4

Date: 2019-02-11 09:28:20.252
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Supervisión de comportamiento
Código de error: 0x80508023
Descripción del error: El programa no encontró malware ni otro software potencialmente no deseado en este dispositivo. 
Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

Date: 2019-02-07 16:58:52.651
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Supervisión de comportamiento
Código de error: 0x80508023
Descripción del error: El programa no encontró malware ni otro software potencialmente no deseado en este dispositivo. 
Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

Date: 2019-02-06 18:54:03.449
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 
Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

Date: 2019-02-06 18:51:20.626
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Supervisión de comportamiento
Código de error: 0x80508023
Descripción del error: El programa no encontró malware ni otro software potencialmente no deseado en este dispositivo. 
Motivo: La protección antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

CodeIntegrity:
===================================

Date: 2019-02-11 09:42:19.757
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume1\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.

Date: 2019-02-11 09:33:45.218
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume1\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.

Date: 2019-02-11 09:33:30.246
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.

Date: 2019-02-11 09:32:27.057
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume1\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.

Date: 2019-02-11 09:30:28.453
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.

Date: 2019-02-11 09:30:28.427
Description: 
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.

Date: 2019-02-11 09:28:50.361
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe) attempted to load \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2019-02-11 09:28:42.657
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files (x86)\AVG\Antivirus\wsc_proxy.exe) attempted to load \Device\HarddiskVolume1\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info =========================== 

Processor: AMD FX(tm)-8120 Eight-Core Processor 
Percentage of memory in use: 43%
Total physical RAM: 16281.05 MB
Available physical RAM: 9157.27 MB
Total Virtual: 21281.05 MB
Available Virtual: 11703.16 MB

==================== Drives ================================

Drive c: (SSDSis) (Fixed) (Total:118.76 GB) (Free:41.83 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive e: (Gigante) (Fixed) (Total:931.51 GB) (Free:426.18 GB) NTFS
Drive f: (Isos) (Fixed) (Total:45 GB) (Free:4.96 GB) NTFS
Drive g: (Programa) (Fixed) (Total:165.31 GB) (Free:114.38 GB) NTFS
Drive h: (Ocio) (Fixed) (Total:255.44 GB) (Free:155.29 GB) NTFS
Drive j: (Maxtor USB) (Fixed) (Total:465.76 GB) (Free:154.66 GB) NTFS
Drive z: (Sistema) (Network) (Total:43.96 GB) (Free:10.83 GB) NTFS

\\?\Volume{78d38e42-0000-0000-0000-b0b01d000000}\ () (Fixed) (Total:0.48 GB) (Free:0.05 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 3F2991F2)
Partition 1: (Active) - (Size=45 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=165.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=255.4 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 465.8 GB) (Disk ID: E93B0994)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (Size: 931.5 GB) (Disk ID: 012B3256)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

#16

Hola

No descargaste ni ejecutaste Frst desde el escritorio como te indiqué, muevelo para realizar el paso siguiente si no no funcionará.

:arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe( en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla "Create registry backup", las demás NO.

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKLM\...\Run: [StartupDelayer] => G:\Startup Delayer\Startup Launcher.exe [1254400 2015-12-18] (r2 Studios) [File not signed]
HKLM\...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel® Corporation) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION
HKLM Group Policy restriction on software: ** <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Foxit PhantomPDF Create PDF ToolBar - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2017-06-29] (Foxit Software Incorporated -> )
Toolbar: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> No Name - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} -  No File
FF NewTab: Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault -> about:newtab
FF NewTab: Mozilla\Firefox\Profiles\vrbqafih.Dani -> about:newtab
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected] [2015-01-30] [Legacy] [not signed]
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-02-09] [Legacy] [not signed]
FF HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - G:\Video Converter Ultimate\SVRFirefoxExt => not found
CHR Extension: (Easy Auto Refresh) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2017-10-13]
CHR Extension: (Play to Kodi) - C:\Users\FrancsicoJosé\AppData\Local\Google\Chrome\User Data\Default\Extensions\fncjhcjfnnooidlkijollckpakkebden [2018-03-28]
2019-02-08 13:26 - 2019-02-08 16:54 - 000000546 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084.job
2019-01-28 17:39 - 2019-02-04 20:28 - 000002326 _____ C:\WINDOWS\System32\Tasks\{B6059D5D-E6A7-41D7-9398-17773B1CE5EC}
2019-01-28 17:39 - 2019-02-04 20:28 - 000002288 _____ C:\WINDOWS\System32\Tasks\{D692D5C7-4088-4D47-B4CA-C115F3EBB7E9}
2019-01-28 17:39 - 2019-02-04 20:28 - 000002116 _____ C:\WINDOWS\System32\Tasks\{A3C2207C-CAFC-403B-A0D4-ED1AA0FB6038}
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-AA22-08DD0A3ADC4B}\InprocServer32 -> {1ED23424-9468-D082-72A4-A3EF85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1EED9644-9468-D082-1206-9CEF85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822AA-3A0A-4BDC-B749-4B00B9115850}\InprocServer32 -> {564C0C8B-9468-D082-DD9C-3DA785889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5CD8000B-9468-D082-5D90-A9AD85889A47} => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3-x32: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers5: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
Task: {00A282C8-79B9-4FDC-A828-10E622C7385A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {11830009-6B00-43E5-B5A9-55BF82FA6CBC} - System32\Tasks\Open URL by RoboForm => C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMIMHMNLJMKLMLLLMMCNJLOLLMKLCNMLMLJLMMCNJLMMPMJMCNJMNLLLJMKMOLGMOMNLJLMLPMJNJICMHMCNKMCNKMFMOMOMCNLMIMOMCNOMIMOMMMLMFMPMCNPMCNOMIMOMMMLMCNNMJNPICMOMFMEKMICNJJCKFMNMGMPMMMJNHICMEKMICNJJCKJNBJCMJLNIOJBJMJMIGJMJAJFLAJMIAMJNKJCMJ (the data entry has 102 more characters).
Task: {4CD0B9C5-70B7-4477-BF6F-7D3C67621A68} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {5989C124-76CB-4F97-9A54-2D42742D3DEC} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {671388E1-014D-4799-9C25-44762BC9A7F4} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {7EF79A04-4D8E-4889-A83C-5FFCF40744AC} - System32\Tasks\ASUS\ASUS Product Register Service => G:\ASUS\APRP\aprp.exe (ASUSTeK Computer Inc. -> ) [File not signed]
Task: {8F226C54-F33E-4D87-96C7-09566E9D2DFD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8F38C4AC-6D1D-49A9-AD43-77309CE18C22} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8F41CD88-CE1C-447A-BFE2-CA2F7FB1B221} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {937117D6-0A99-4357-9B72-DB0AB35EC792} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9BFDF45A-4224-4D43-80C7-CD112B72C6F3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {A78D1A50-BD5D-4291-A6A4-AE1E4FAB4643} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {B9077A43-3057-4AE3-A827-5B3333801158} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {C99DACE9-7718-4632-9D1E-880F1D8EA78F} - System32\Tasks\ASUS\USB 3.0 Boost Service => G:\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe () [File not signed]
Task: {E4381567-2670-41B1-97F1-CA629702A896} - System32\Tasks\IntelBootstrapCCDashExe => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe (Intel® Corporation) [File not signed]
Task: {EE7C0FF6-C997-443D-ADD0-D5322EAE25AC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {FBF993A0-BB1E-4928-B782-D88B7A0CD703} - \avast! Emergency Update -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:07BF512B [152]
AlternateDataStreams: C:\ProgramData\TEMP:9D1B94FD [115]

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe (Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.


  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).
  • Presionar el botón FIX y aguardar a que termine.
  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pega el contenido de este fichero en tu próxima respuesta.

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Un saludo


#17

Hola:

Si, la vez anterior no ejecuté el programa desde el escritorio, no me dí cuenta de ese detalle, disculpa.

He hecho todo lo que comentas, directamente desde el escritorio. He reiniciado el equipo, y al cabo de un rato, me han vuelto a salir las amenazas detectadas por AVG. Esto es desesperante.

En este caso, a cuenta de comprobarlo mejor, me han salido al ejecutar el programa WhatsAppSetup.exe. No se si ha sido coincidencia, o tiene algo que ver.

Te adjunto el log solicitadao

Fix result of Farbar Recovery Scan Tool (x64) Version: 10.02.2019 01
Ran by FranciscoJosé (11-02-2019 17:20:31) Run:1
Running from C:\Users\FrancsicoJosé\Desktop
Loaded Profiles: FranciscoJosé (Available Profiles: FranciscoJosé & lourdes & comercio)
Boot Mode: Normal
==============================================

fixlist content:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKLM\...\Run: [StartupDelayer] => G:\Startup Delayer\Startup Launcher.exe [1254400 2015-12-18] (r2 Studios) [File not signed]
HKLM\...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel� Corporation) [File not signed]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION
HKLM Group Policy restriction on software: ** <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION -> SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Foxit PhantomPDF Create PDF ToolBar - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - G:\Foxit Software\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2017-06-29] (Foxit Software Incorporated -> )
Toolbar: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-12-13] (Siber Systems -> Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-390596928-2417218115-2686252066-1001 -> No Name - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} -  No File
FF NewTab: Mozilla\Firefox\Profiles\ml89f1kh.pcpacodefault -> about:newtab
FF NewTab: Mozilla\Firefox\Profiles\vrbqafih.Dani -> about:newtab
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected] [2015-01-30] [Legacy] [not signed]
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-02-09] [Legacy] [not signed]
FF HKU\S-1-5-21-390596928-2417218115-2686252066-1001\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - G:\Video Converter Ultimate\SVRFirefoxExt => not found
CHR Extension: (Easy Auto Refresh) - C:\Users\FrancsicoJos�\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2017-10-13]
CHR Extension: (Play to Kodi) - C:\Users\FrancsicoJos�\AppData\Local\Google\Chrome\User Data\Default\Extensions\fncjhcjfnnooidlkijollckpakkebden [2018-03-28]
2019-02-08 13:26 - 2019-02-08 16:54 - 000000546 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084.job
2019-01-28 17:39 - 2019-02-04 20:28 - 000002326 _____ C:\WINDOWS\System32\Tasks\{B6059D5D-E6A7-41D7-9398-17773B1CE5EC}
2019-01-28 17:39 - 2019-02-04 20:28 - 000002288 _____ C:\WINDOWS\System32\Tasks\{D692D5C7-4088-4D47-B4CA-C115F3EBB7E9}
2019-01-28 17:39 - 2019-02-04 20:28 - 000002116 _____ C:\WINDOWS\System32\Tasks\{A3C2207C-CAFC-403B-A0D4-ED1AA0FB6038}
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-AA22-08DD0A3ADC4B}\InprocServer32 -> {1ED23424-9468-D082-72A4-A3EF85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1EED9644-9468-D082-1206-9CEF85889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822AA-3A0A-4BDC-B749-4B00B9115850}\InprocServer32 -> {564C0C8B-9468-D082-DD9C-3DA785889A47} => No File
CustomCLSID: HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5CD8000B-9468-D082-5D90-A9AD85889A47} => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3-x32: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} =>  -> No File
ContextMenuHandlers5: [WinMerge] -> {4E716236-AA30-4C65-B225-D68BBA81E9C2} =>  -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} =>  -> No File
Task: {00A282C8-79B9-4FDC-A828-10E622C7385A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {11830009-6B00-43E5-B5A9-55BF82FA6CBC} - System32\Tasks\Open URL by RoboForm => C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMIMHMNLJMKLMLLLMMCNJLOLLMKLCNMLMLJLMMCNJLMMPMJMCNJMNLLLJMKMOLGMOMNLJLMLPMJNJICMHMCNKMCNKMFMOMOMCNLMIMOMCNOMIMOMMMLMFMPMCNPMCNOMIMOMMMLMCNNMJNPICMOMFMEKMICNJJCKFMNMGMPMMMJNHICMEKMICNJJCKJNBJCMJLNIOJBJMJMIGJMJAJFLAJMIAMJNKJCMJ (the data entry has 102 more characters).
Task: {4CD0B9C5-70B7-4477-BF6F-7D3C67621A68} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {5989C124-76CB-4F97-9A54-2D42742D3DEC} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {671388E1-014D-4799-9C25-44762BC9A7F4} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {7EF79A04-4D8E-4889-A83C-5FFCF40744AC} - System32\Tasks\ASUS\ASUS Product Register Service => G:\ASUS\APRP\aprp.exe (ASUSTeK Computer Inc. -> ) [File not signed]
Task: {8F226C54-F33E-4D87-96C7-09566E9D2DFD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8F38C4AC-6D1D-49A9-AD43-77309CE18C22} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {8F41CD88-CE1C-447A-BFE2-CA2F7FB1B221} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {937117D6-0A99-4357-9B72-DB0AB35EC792} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {9BFDF45A-4224-4D43-80C7-CD112B72C6F3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {A78D1A50-BD5D-4291-A6A4-AE1E4FAB4643} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {B9077A43-3057-4AE3-A827-5B3333801158} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {C99DACE9-7718-4632-9D1E-880F1D8EA78F} - System32\Tasks\ASUS\USB 3.0 Boost Service => G:\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe () [File not signed]
Task: {E4381567-2670-41B1-97F1-CA629702A896} - System32\Tasks\IntelBootstrapCCDashExe => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe (Intel� Corporation) [File not signed]
Task: {EE7C0FF6-C997-443D-ADD0-D5322EAE25AC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {FBF993A0-BB1E-4928-B782-D88B7A0CD703} - \avast! Emergency Update -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:07BF512B [152]
AlternateDataStreams: C:\ProgramData\TEMP:9D1B94FD [115]

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: (0) Failed to create a restore point.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\StartupDelayer" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\IntelConnectCenter" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: cipher.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *:\$Recycle.Bin <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: vssadmin.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: lsassw86s.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: syskey.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: ** <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <==== ATTENTION => restored successfully

#18
HKLM Group Policy restriction on software: *.mp3*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: scsvserv.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.doc*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wav*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: C:\Users\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpg*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.jpeg*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xls*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: lsassvrtdbks.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.zip*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pptx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.ppt*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rtf*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wma*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.avi*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.wmv*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.com <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.gif*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %allusersprofile%\*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.txt*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.7z*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.bmp*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.docx*.jse <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pub*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.rar*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %userprofile%\*.pif <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.png*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp3*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.mp4*.exe <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.js <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.divx*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.pdf*.bat <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: *.xlsx*.pif <==== ATTENTION => restored successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Google => removed successfully
HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Policies\Google => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a} => removed successfully
HKLM\Software\Classes\CLSID\{724d43a9-0d85-11d4-9908-00400523e39a} => removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{724d43a0-0d85-11d4-9908-00400523e39a}" => removed successfully
HKLM\Software\Classes\CLSID\{724d43a0-0d85-11d4-9908-00400523e39a} => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{724d43a0-0d85-11d4-9908-00400523e39a}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{724d43a0-0d85-11d4-9908-00400523e39a} => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{201CF130-E29C-4E5C-A73F-CD197DEFA6AE}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{201CF130-E29C-4E5C-A73F-CD197DEFA6AE} => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{BFD9D8A8-57FF-488A-B919-065EC77CF82F}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{BFD9D8A8-57FF-488A-B919-065EC77CF82F} => removed successfully
"HKU\S-1-5-21-390596928-2417218115-2686252066-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A}" => removed successfully
HKLM\Software\Classes\CLSID\{724D43A0-0D85-11D4-9908-00400523E39A} => not found
"HKU\S-1-5-21-390596928-2417218115-2686252066-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BFD9D8A8-57FF-488A-B919-065EC77CF82F}" => removed successfully
HKLM\Software\Classes\CLSID\{BFD9D8A8-57FF-488A-B919-065EC77CF82F} => not found
"Firefox newtab" => removed successfully
"Firefox newtab" => removed successfully
C:\ProgramData\Wondershare\Video Converter Ultimate\[email protected] => moved successfully
C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on => moved successfully
"HKU\S-1-5-21-390596928-2417218115-2686252066-1001\Software\Mozilla\Firefox\Extensions\\{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}" => removed successfully
CHR Extension: (Easy Auto Refresh) - C:\Users\FrancsicoJos�\AppData\Local\Google\Chrome\User Data\Default\Extensions\aabcgdmkeabbnleenpncegpcngjpnjkc [2017-10-13] => Error: No automatic fix found for this entry.
CHR Extension: (Play to Kodi) - C:\Users\FrancsicoJos�\AppData\Local\Google\Chrome\User Data\Default\Extensions\fncjhcjfnnooidlkijollckpakkebden [2018-03-28] => Error: No automatic fix found for this entry.
C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 7d5b9d93-a507-429e-925d-529e964c4084.job => moved successfully
C:\WINDOWS\System32\Tasks\{B6059D5D-E6A7-41D7-9398-17773B1CE5EC} => moved successfully
C:\WINDOWS\System32\Tasks\{D692D5C7-4088-4D47-B4CA-C115F3EBB7E9} => moved successfully
C:\WINDOWS\System32\Tasks\{A3C2207C-CAFC-403B-A0D4-ED1AA0FB6038} => moved successfully
HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-AA22-08DD0A3ADC4B} => removed successfully
HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B} => removed successfully
HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822AA-3A0A-4BDC-B749-4B00B9115850} => removed successfully
HKU\S-1-5-21-390596928-2417218115-2686252066-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\CLSID\{B298D29A-A6ED-11DE-BA8C-A68E55D89593} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\WinMerge => removed successfully
HKLM\Software\Classes\CLSID\{4E716236-AA30-4C65-B225-D68BBA81E9C2} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{00A282C8-79B9-4FDC-A828-10E622C7385A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00A282C8-79B9-4FDC-A828-10E622C7385A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11830009-6B00-43E5-B5A9-55BF82FA6CBC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11830009-6B00-43E5-B5A9-55BF82FA6CBC}" => removed successfully
C:\WINDOWS\System32\Tasks\Open URL by RoboForm => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Open URL by RoboForm" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4CD0B9C5-70B7-4477-BF6F-7D3C67621A68}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CD0B9C5-70B7-4477-BF6F-7D3C67621A68}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5989C124-76CB-4F97-9A54-2D42742D3DEC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5989C124-76CB-4F97-9A54-2D42742D3DEC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{671388E1-014D-4799-9C25-44762BC9A7F4}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{671388E1-014D-4799-9C25-44762BC9A7F4}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7EF79A04-4D8E-4889-A83C-5FFCF40744AC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7EF79A04-4D8E-4889-A83C-5FFCF40744AC}" => removed successfully
C:\WINDOWS\System32\Tasks\ASUS\ASUS Product Register Service => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS\ASUS Product Register Service" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F226C54-F33E-4D87-96C7-09566E9D2DFD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F226C54-F33E-4D87-96C7-09566E9D2DFD}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F38C4AC-6D1D-49A9-AD43-77309CE18C22}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F38C4AC-6D1D-49A9-AD43-77309CE18C22}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F41CD88-CE1C-447A-BFE2-CA2F7FB1B221}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F41CD88-CE1C-447A-BFE2-CA2F7FB1B221}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{937117D6-0A99-4357-9B72-DB0AB35EC792}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{937117D6-0A99-4357-9B72-DB0AB35EC792}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BFDF45A-4224-4D43-80C7-CD112B72C6F3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BFDF45A-4224-4D43-80C7-CD112B72C6F3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A78D1A50-BD5D-4291-A6A4-AE1E4FAB4643}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A78D1A50-BD5D-4291-A6A4-AE1E4FAB4643}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B9077A43-3057-4AE3-A827-5B3333801158}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B9077A43-3057-4AE3-A827-5B3333801158}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C99DACE9-7718-4632-9D1E-880F1D8EA78F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C99DACE9-7718-4632-9D1E-880F1D8EA78F}" => removed successfully
C:\WINDOWS\System32\Tasks\ASUS\USB 3.0 Boost Service => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS\USB 3.0 Boost Service" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E4381567-2670-41B1-97F1-CA629702A896}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E4381567-2670-41B1-97F1-CA629702A896}" => removed successfully
C:\WINDOWS\System32\Tasks\IntelBootstrapCCDashExe => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IntelBootstrapCCDashExe" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EE7C0FF6-C997-443D-ADD0-D5322EAE25AC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EE7C0FF6-C997-443D-ADD0-D5322EAE25AC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FBF993A0-BB1E-4928-B782-D88B7A0CD703}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FBF993A0-BB1E-4928-B782-D88B7A0CD703}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avast! Emergency Update" => removed successfully
C:\ProgramData\TEMP => ":07BF512B" ADS removed successfully
C:\ProgramData\TEMP => ":9D1B94FD" ADS removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-390596928-2417218115-2686252066-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Ethernet 3 mientras los medios
est‚n desconectados.
Error al renovar la interfaz Ethernet : El usuario ha cancelado la operaci¢n.
 
Error al renovar la interfaz Ethernet 2: no se puede establecer contacto con el
servidor DHCP. La solicitud super¢ el tiempo de espera.
No se puede realizar ninguna operaci¢n en Ethernet 4 mientras los medios
est‚n desconectados.

========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

{CA9E4818-2FBE-4645-ADF0-8FED200C9FB3} canceled.
1 out of 1 jobs canceled.

========= End of CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= End of CMD: =========


========= netsh int ipv4 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 12869632 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 154000626 B
Java, Flash, Steam htmlcache => 1218 B
Windows/system/drivers => 372772 B
Edge => 182298 B
Chrome => 583434 B
Firefox => 36374164 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 7680 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 1822 B
LocalService => 0 B
NetworkService => 0 B
NetworkService => 0 B
FrancsicoJosé => 123211391 B
lourdes => 6656 B
comercio => 19575 B

RecycleBin => 0 B
EmptyTemp: => 312.5 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:25:59 ====

#19

Hola

No se que habrás realizado para comprobar el equipo, has tocado algo que haya provocado que ocurriera? Es el instalador de WhatsApp.

Realiza un análisis con EsetOnline, sigue los pasos del manual.

Trae el reporte y comenta como sigue el problema.

Un saludo


#20

Hola de nuevo.

No hay manera de quitar lo que este infectado. He cambiado de antivirus. Ahora con el bitdefender, me bloquea las amenazas de c://windows/system32. Los bloqueos, son con mensajes similares a este

Característica:

Antivirus El archivo C:\Windows\System32\tmp000018ad\tmp00007a66 está infectado con Application.Hacktool.ZX. Se ha bloqueado correctamente la amenaza y su dispositivo está a salvo.

Me falta la comprobación que comentas con eset online, pero como dura más de 5 horas, lo dejaré para mañana.

El bitdefender me ha hecho un escaner completo, de más de 6 horas, Ha detectado alguna cosilla, pero no ha solucionado nada.

El problema persiste, y cada x horas, me salen las pantallas de “amenazas bloqueadas”.

Ya no se que más hacer.