Infectado por Malware Adware.MailRu.BatBitRst

Ha fallado. El archivo Adware.Mail.Ru.BatBitRst sigue reproduciéndose. Sigue en su sitio.

También he puesto “Obtener las DNS automáticamente” en recomendación del amigo Alvador, por si las que usaba estaban “secuestradas” (las normales de google). Sigo con ello. Saludos.

Algo hemos tocado porque se reproduce con mucha más frecuencia, está rabioso. Esto el lo que tengo ya en cuarentena…

Hola

Vas a volver a utilizar FRST, veo que se me desmarcó una y no fue en el fix :woman_facepalming:

Inicia tu equipo desde el Modo Seguro de Windows sin función de red

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
CHR StartupUrls: Default -> "hxxp://www.google.com","hxxps://mail.ru/cnt/10445?gp=811570","hxxps://www.google.com/","hxxps://duckduckgo.com/"

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe (Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.


  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).
  • Presionar el botón FIX y aguardar a que termine.
  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pega el contenido de este fichero en tu próxima respuesta.

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Un saludo

Igual. Se ha vuelto a reproducir al reiniciar…

Ajunto Log.

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-07-2019
Ran by galeo (16-07-2019 18:12:07) Run:2
Running from C:\Users\galeo\Desktop
Loaded Profiles: galeo (Available Profiles: galeo)
Boot Mode: Safe Mode (minimal)
==============================================

fixlist content:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
CHR StartupUrls: Default -> "hxxp://www.google.com","hxxps://mail.ru/cnt/10445?gp=811570","hxxps://www.google.com/","hxxps://duckduckgo.com/"

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: Restore point can only be created in normal mode.
Processes closed successfully.
"Chrome StartupUrls" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


========= End of CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

Unable to connect to BITS - 0x8007043c
El servicio no puede iniciarse en modo a prueba de errores



========= End of CMD: =========


========= netsh advfirewall reset =========


Error al intentar ponerse en contacto con el servicio Firewall de Windows Defender. Aseg£rate de que el servicio se est  ejecutando e intenta la solicitud de nuevo.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========


Error al intentar ponerse en contacto con el servicio Firewall de Windows Defender. Aseg£rate de que el servicio se est  ejecutando e intenta la solicitud de nuevo.


========= End of CMD: =========


========= netsh int ipv4 reset =========

No hay valores configurados por el usuario para restablecer.


========= End of CMD: =========


========= netsh int ipv6 reset =========

No hay valores configurados por el usuario para restablecer.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 7626752 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11575270 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 260 B
Edge => 29696 B
Chrome => 16708729 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 11794 B
LocalService => 0 B
NetworkService => 0 B
NetworkService => 0 B
galeo => 189111 B

RecycleBin => 1591 B
EmptyTemp: => 34.5 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 18:12:12 ====

Hola

Realiza los pasos que se indican en esta guía:

Comenta como sigue el problema.

Un saludo

Ok Daniela. Me pongo ahora con ello y si acaso reabro con el tema “IF DNS” y te pongo informe, ok? Saludos.

No lo hemos conseguido. Hasta teniendo las DNS públicas de Google me ha infectado otra vez, aunque ha tardado dos horas en lugar de cinco minutos…

Hola Galeón. Con respecto al tema del DNS, hiciste click en el botón “avanzado” y pestaña DNS? (ahí es donde se alojaron conmigo, no me bastó con que pongas en DNS automáticamente). Saludos.

Hola Salvador_Trejo. Que alegría leerte, gracias por ayudarme con esta historia que llevo casi un año con ella, y no hay manera ni formateando el PC. Seguimos tu buen aporte y casi casi. Parece que los tiros van por ahí…pero aún nada. Venga, un saludo amigo.

Siguiendo instrucciones de la estupenda Staff Daniela, reabro este Post, para los que lo quieran seguir. Está en “Eliminar Malware”, bajo el título de “Infectado por Adware.MailRu.BatBitRst”

En mi caso se alojó el origen del virus en esta ruta:

C:\Users\Salvador\AppData\Local\Mail.Ru

Desde luego cambias “Salvador” por el nombre de usuario de Windows que ocupas.

Con este otro antimalware sí que limpié mucho del tema.

GridinSoft Antimalware

Finalmente, recuerda que si tienes conexión por cable y conexión por wifi en AMBAS debes revisar lo del tema del DNS. Repito, fue mi caso. No necesariamente sea el tuyo.

Espero se solucione.

Saludos!

Hola Salvador. He seguido esa ruta que me indicas en C:, y no tengo ninguna carpeta ni archivo que se llame Mail.Ru . También he probado el GridinSoft que veo está genial y te lo tomo como buena herramienta, pero en mi caso no encuentra “Adware.MailRu.BatBitRst”, mientras que Malwarebytes sí.

Hola

Vamos a ver … vamos a poner un poco de orden en el tema, @Salvador_Trejo se agradece las intenciones de ayudar pero no podemos estar dos personas dando indicaciones y más cuando se están utilizando herramientas potentes como FRST, realizando pasos que no se hayan indicado, lo único que se hace es modificar el reporte de FRST.

Para que abriste un nuevo tema con el mismo asunto? Si ya tienes abierto uno, debes seguir en este mismo.

Políticas del foro

2.5 No está permitido repetir uno o más temas con respecto al mismo asunto, ni publicar dos o más mensajes cuyos contenidos coincidan dentro de un mismo tema. Dichos temas o mensajes publicados podrán ser eliminados o unidos sin previo o posterior aviso.


De ahora en adelante, sigue solamente los pasos que te indique, no hagas nada por tu cuenta, si no en vez de adelantar, retrocedemos.

NOTA IMPORTANTE:

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo :

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA(programas/software/complementos/extensiones del navegador…)
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…)
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

Y ahora continuamos con el tema.

Descarga, instala y ejecuta Revo Uninstaller

  • Desinstala Chrome. Elige el modo avanzado de desinstalación.

Después de reiniciar, vuelve a ejecutar FRST como te indiqué aquí y trae de nuevo los dos reportes para revisar que no quede nada de Chrome.

No vuelvas a instalar Chrome hasta que yo no te lo indique.

Un saludo

Hola Daniela.

  • Reabrí el post porque me lo pediste si no funcionaba la solución hecha. O por lo menos, eso creo que leí, y aunque me extrañó, acaté tu petición.
  • Aunque pueda investigar otras opciones como las de Salvador, te hago caso a pies juntillas y hago exactamente lo que me dices. Siempre.

Bien, Chrome desinstalado de las dos particiones, de los dos sistemas operativos. Antes he quitado la sincronización, por si pudiera refugiarse el virus en mi móvil Android.

Ahí van los reportes de FRST:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2019 01
Ran by galeo (administrator) on DESKTOP-VTBCMKI (ASUSTeK COMPUTER INC. K55VD) (17-07-2019 01:23:18)
Running from C:\Users\galeo\Desktop
Loaded Profiles: galeo (Available Profiles: galeo)
Platform: Windows 10 Pro Version 1903 18362.239 (X64) Language: Español (España, internacional)
Default browser: Edge
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files\WindowsApps\microsoft.people_10.1902.633.0_x64__8wekyb3d8bbwe\PeopleApp.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG TuneUp\TuneupSvc.exe
(AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG TuneUp\TuneupUI.exe
(Gridinsoft, LLC -> GridinSoft LLC) [File not signed] C:\Program Files\GridinSoft Anti-Malware\gsam.exe
(Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxTray.exe
(Invincea, Inc. -> Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\avpui.exe
(Lagerkvist Teknisk Rådgivning i Borås HB -> Olof Lagerkvist) C:\Windows\System32\imdsksvc.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18390912 2019-06-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation - Intel® Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [124000 2018-06-20] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (Shenzhen Jia Xing Investment Co., Ltd. -> AimerSoft)
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\Run: [Opera Browser Assistant] => C:\Users\galeo\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [2299928 2019-07-10] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [23153344 2019-07-11] (Piriform Software Ltd -> Piriform Software Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVG TuneUp.lnk [2019-06-04]
ShortcutTarget: AVG TuneUp.lnk -> C:\Program Files (x86)\AVG\AVG TuneUp\TuneupUI.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Configurar RamDisk.lnk [2019-07-02]
ShortcutTarget: Configurar RamDisk.lnk -> C:\Program Files\ImDisk\RamDiskUI.exe (No File)
Startup: C:\Users\galeo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar192.lnk [2019-07-11]
ShortcutTarget: Sidebar192.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (No File)
Startup: C:\Users\galeo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar405.lnk [2019-07-11]
ShortcutTarget: Sidebar405.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (No File)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0711579E-5D0F-4C5A-BD37-A30B8A647DAD} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [124304 2017-11-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {17C072B7-032B-40C7-A726-20532DAE1A2F} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-06-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {22F53ED7-AC9D-47F1-9D76-3790B2E72523} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_223_pepper.exe [1453112 2019-07-09] (Adobe Inc. -> Adobe)
Task: {30E66AF8-D3BB-41EE-B782-25FB4080B709} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16835256 2019-07-11] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {5007E99E-8569-4A8B-A6E7-154DCF89B42A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-07-11] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {562D9E65-178E-4542-88CB-ECCBEF3F2AE4} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1506176 2019-06-11] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
Task: {6587C753-B31A-4AF7-9557-1DEAB6FFFCD0} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [124304 2017-11-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {6DEF50F2-5641-4231-AF9B-BE47A49F7557} - System32\Tasks\GridinSoft Anti-Malware => C:\Program Files\GridinSoft Anti-Malware\gsam.exe [17764816 2019-07-16] (Gridinsoft, LLC -> GridinSoft LLC) [File not signed]
Task: {6F6234D6-4627-4F31-AD00-0327D8F84CF2} - System32\Tasks\Opera scheduled Autoupdate 1559673782 => C:\Users\galeo\AppData\Local\Programs\Opera\launcher.exe [1519640 2019-07-11] (Opera Software AS -> Opera Software)
Task: {78C8452C-085A-405B-89DD-1B08D74FEC04} - System32\Tasks\USBChargerPlusUWP => C:\Program Files (x86)\ASUS\USB Charger Plus Service\StartupUSBChargerPlus.exe [150416 2018-07-04] (ASUSTeK Computer Inc. -> )
Task: {81CA7F1F-91FB-4A1F-BF6D-1D7205D09235} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-07-09] (Adobe Inc. -> Adobe)
Task: {8F3BC0A0-DC8A-4EB9-83C0-508CEBC7FC95} - System32\Tasks\Opera scheduled assistant Autoupdate 1559673789 => C:\Users\galeo\AppData\Local\Programs\Opera\launcher.exe [1519640 2019-07-11] (Opera Software AS -> Opera Software)
Task: {9022D5BA-A880-4167-BCEB-1902F36226B0} - System32\Tasks\AVG TuneUp Update => C:\Program Files (x86)\AVG\AVG TuneUp\TUNEUpdate.exe [1706528 2019-07-11] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {A26EBAC9-EC9C-408A-BCFF-AC88BF66BE66} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [1146000 2019-03-14] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.)
Task: {D995D742-8270-44F4-B3A2-26FDC835371B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1195544 2018-12-17] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
Tcpip\..\Interfaces\{919910fd-346d-4322-b1b4-00418f5db505}: [DhcpNameServer] 80.58.61.250 80.58.61.254

Internet Explorer:
==================
BHO: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\IEExt\ie_plugin.dll [2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
BHO-x32: Kaspersky Protection -> {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\IEExt\ie_plugin.dll [2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi [2019-06-30]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\FFExt\light_plugin_firefox\addon.xpi
FF HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Aimersoft\Aimersoft iTube Studio\BrowserPlugin\[email protected]_xpi
FF Extension: (iTube Studio) - C:\Program Files (x86)\Aimersoft\Aimersoft iTube Studio\BrowserPlugin\[email protected]_xpi [2019-07-03] [Legacy]
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-05-03] (Adobe Inc. -> Adobe Systems Inc.)

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [amkpcclbbgegoafihnpgomddadjhcadd] - hxxps://chrome.google.com/webstore/detail/amkpcclbbgegoafihnpgomddadjhcadd

Opera: 
=======
OPR Extension: (Adblock Plus - free ad blocker) - C:\Users\galeo\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2019-07-11]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVP19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\avp.exe [619640 2018-02-28] (Kaspersky Lab -> AO Kaspersky Lab)
R2 CleanupPSvc; C:\Program Files (x86)\AVG\AVG TuneUp\TuneupSvc.exe [10300120 2019-07-11] (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
S4 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [40016 2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [316760 2019-05-19] (Intel(R) pGFX -> Intel Corporation)
R2 ImDskSvc; C:\WINDOWS\system32\imdsksvc.exe [31544 2018-11-19] (Lagerkvist Teknisk Rådgivning i Borås HB -> Olof Lagerkvist)
S3 klvssbridge64_19.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\vssbridge64.exe [414352 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R2 SamsungRapidSvc; C:\WINDOWS\System32\RAPID\SamsungRapidSvc.exe [29280 2018-06-20] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [328344 2019-04-22] (Invincea, Inc. -> Sandboxie Holdings, LLC)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5773384 2019-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 USBChargerService; C:\Program Files (x86)\ASUS\USB Charger Plus Service\USBChargerService.exe [120720 2018-07-04] (ASUSTeK Computer Inc. -> ASUSTek COMPUTER INC.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\NisSrv.exe [2455544 2019-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1906.3-0\MsMpEng.exe [110104 2019-07-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WsDrvInst; C:\ProgramData\iTube Studio\TransferProcess\DriverInstall.exe [94208 2018-10-10] (Wondershare) [File not signed]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 AiCharger; C:\WINDOWS\System32\DRIVERS\AiCharger.sys [31032 2018-07-04] (WDKTestCert Jie,131315143419111253 -> ASUSTek Computer Inc.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [73976 2015-06-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [110544 2017-12-12] (ASUSTeK Computer Inc. -> ASUS Corporation)
R3 athr; C:\WINDOWS\System32\drivers\athw10x.sys [4321160 2019-05-14] (Qualcomm Atheros -> Qualcomm Atheros Communications, Inc.)
R1 ATKWMIACPIIO; C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [20096 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> ASUSTek Computer Inc.)
R2 AWEAlloc; C:\WINDOWS\system32\DRIVERS\awealloc.sys [21048 2018-11-19] (Lagerkvist Teknisk Radgivning i Boras HB -> Olof Lagerkvist)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [243400 2018-01-27] (Kaspersky Lab -> AO Kaspersky Lab)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [73448 2019-06-28] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [53504 2019-06-28] (Microsoft Windows Hardware Compatibility Publisher -> )
R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [22784 2019-06-28] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [341760 2019-06-28] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd)
S0 FlashBoot; C:\WINDOWS\System32\drivers\FlashBoot.sys [17616 2019-05-19] (Challenger Backup Solutions, LLC -> Challenger Backup Solutions, LLC)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [34232 2019-01-16] (ASUSTek Computer Inc. -> ASUS)
R2 ImDisk; C:\WINDOWS\system32\DRIVERS\imdisk.sys [48704 2018-11-19] (Lagerkvist Teknisk Radgivning i Boras HB -> Olof Lagerkvist)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [75600 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [125568 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [91472 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [29208 2017-03-30] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [236672 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLHK; C:\WINDOWS\System32\drivers\klhk.sys [1093248 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP19.0.0\Bases\klids.sys [197760 2019-07-14] (Kaspersky Lab -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1168000 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [58704 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [60536 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [60784 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [50304 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
S3 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [46416 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [245272 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [302368 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [116104 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [198768 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [104576 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [184960 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [218240 2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [199768 2019-07-16] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [224408 2019-07-17] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2019-07-17] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-07-17] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [116112 2019-07-17] (Malwarebytes Corporation -> Malwarebytes)
R2 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_1474122a0ce2f241\nvlddmkm.sys [17544792 2018-03-25] (NVIDIA Corporation -> NVIDIA Corporation)
R0 nvpciflt; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_1474122a0ce2f241\nvpciflt.sys [48480 2018-03-25] (NVIDIA Corporation -> NVIDIA Corporation)
S3 rdacpi; C:\WINDOWS\System32\drivers\rdacpi.sys [41784 2019-05-19] (EA Excelsior Hang Tong Computer Technology Limited -> )
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1141744 2019-05-14] (Realtek Semiconductor Corp. -> Realtek )
R0 SamsungRapidDiskFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidDiskFltr.sys [288864 2018-06-28] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\WINDOWS\System32\DRIVERS\SamsungRapidFSFltr.sys [119400 2018-06-28] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [228616 2019-04-23] (Invincea, Inc. -> Sandboxie Holdings, LLC)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [50832 2019-05-19] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [51352 2019-05-19] (Synaptics Incorporated -> Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64912 2017-05-18] (Samsung Electronics Co., Ltd. -> QUALCOMM Incorporated)
S3 TrojanKillerDriver; C:\WINDOWS\System32\DRIVERS\gtkdrv.sys [29456 2017-05-17] (GridinSoft, LLC -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [47704 2019-07-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2019-05-19] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [367032 2019-07-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-07-10] (Microsoft Windows -> Microsoft Corporation)
R1 Win10Pcap; C:\WINDOWS\system32\DRIVERS\Win10Pcap.sys [50304 2015-10-07] (SoftEther Corporation -> Daiyuu Nobori, University of Tsukuba, Japan)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2019-06-11] (Zemana Ltd. -> Zemana Ltd.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-07-17 01:23 - 2019-07-17 01:24 - 000024405 _____ C:\Users\galeo\Desktop\FRST.txt
2019-07-17 01:23 - 2019-07-17 01:23 - 000000000 ____D C:\Users\galeo\Desktop\FRST-OlderVersion
2019-07-17 00:43 - 2019-07-17 00:43 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-07-17 00:43 - 2019-07-17 00:43 - 000224408 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2019-07-17 00:43 - 2019-07-17 00:43 - 000116112 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2019-07-17 00:43 - 2019-07-17 00:43 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2019-07-17 00:24 - 2019-07-17 00:07 - 000000102 _____ C:\Users\galeo\Desktop\Infectado por Malware Adware.MailRu.BatBitRst - Eliminar Malwares - ForoSpyware.url
2019-07-16 23:26 - 2019-07-16 23:26 - 000199768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2019-07-16 23:04 - 2019-07-16 23:24 - 000001588 _____ C:\Users\galeo\Desktop\GridinSoft.lnk
2019-07-16 23:02 - 2019-07-17 00:43 - 000003330 _____ C:\WINDOWS\System32\Tasks\GridinSoft Anti-Malware
2019-07-16 22:56 - 2019-07-16 22:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Anti-Malware
2019-07-16 22:55 - 2019-07-16 22:55 - 000000000 ____D C:\Users\galeo\Desktop\GridinSoft Anti-Malware 3.0.92 Final + Patch
2019-07-16 22:25 - 2019-07-16 23:05 - 000000000 ____D C:\Program Files\GridinSoft Anti-Malware
2019-07-16 20:45 - 2019-07-16 20:57 - 000001521 _____ C:\Users\galeo\Desktop\2.txt
2019-07-16 20:02 - 2019-07-16 20:02 - 000001677 _____ C:\Users\galeo\Desktop\Informe Malwarebytes.txt
2019-07-16 19:27 - 2019-07-16 19:38 - 000000562 _____ C:\Users\galeo\Desktop\IF-DNS.txt
2019-07-16 19:27 - 2019-07-16 19:37 - 000000562 _____ C:\IF-DNS.txt
2019-07-16 19:22 - 2019-07-16 19:21 - 000341794 _____ C:\Users\galeo\Desktop\IF-DNS.exe
2019-07-16 18:12 - 2019-07-16 18:12 - 000003937 _____ C:\Users\galeo\Desktop\Fixlog.txt
2019-07-16 17:48 - 2019-07-16 17:48 - 000001653 _____ C:\Users\galeo\Desktop\malwarebytes informe.txt
2019-07-16 17:12 - 2019-07-16 17:12 - 000000873 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-07-16 16:15 - 2019-07-16 16:15 - 000000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2019-07-16 16:14 - 2019-07-16 16:14 - 000010429 _____ C:\Users\galeo\Desktop\Primer Fixlog.txt
2019-07-16 16:11 - 2019-07-17 01:23 - 002095104 _____ (Farbar) C:\Users\galeo\Desktop\FRST64.exe
2019-07-16 15:53 - 2019-07-16 18:11 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2019-07-16 15:29 - 2019-07-16 15:29 - 000000253 _____ C:\Users\galeo\Desktop\DelFix (registry backup).txt
2019-07-16 15:28 - 2019-07-16 15:28 - 000000253 _____ C:\DelFix.txt
2019-07-16 15:28 - 2019-07-16 15:28 - 000000000 ____D C:\WINDOWS\ERUNT
2019-07-15 22:03 - 2019-07-15 22:02 - 000797760 _____ C:\Users\galeo\Desktop\delfix.exe
2019-07-15 18:32 - 2019-07-16 23:05 - 000000000 ____D C:\Users\galeo\Desktop\Nueva carpeta
2019-07-15 17:45 - 2019-07-15 17:45 - 000000000 ____D C:\ProgramData\adaware
2019-07-15 14:27 - 2019-07-15 14:27 - 000000097 _____ C:\Users\galeo\Desktop\Colorado América El Turismo - Foto gratis en Pixabay.url
2019-07-15 04:40 - 2019-07-17 01:23 - 000000000 ____D C:\FRST
2019-07-14 02:00 - 2019-07-14 00:11 - 000001025 _____ C:\WINDOWS\system32\Drivers\etc\hosts.old
2019-07-14 00:45 - 2019-07-14 01:09 - 000295656 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-07-14 00:01 - 2019-07-15 04:34 - 000000000 ____D C:\Users\galeo\AppData\Roaming\ZHP
2019-07-14 00:01 - 2019-07-14 00:01 - 000000000 ____D C:\Users\galeo\AppData\Local\ZHP
2019-07-13 01:08 - 2019-07-13 01:08 - 000000000 ____D C:\Program Files\FolderPainter
2019-07-13 00:36 - 2019-07-13 00:36 - 000004096 ___SH C:\{397730BD-2520-4E63-8D90-5273178CDB52}.CBM
2019-07-12 21:26 - 2019-07-12 21:26 - 000000000 ____D C:\Program Files (x86)\XPE Windows 10 DPI Fix
2019-07-12 17:36 - 2019-07-17 00:02 - 000000000 ____D C:\Program Files (x86)\Google
2019-07-12 17:19 - 2019-07-12 17:19 - 000001422 _____ C:\Users\Public\Desktop\EaseUS Todo Backup Free 11.5.lnk
2019-07-12 17:19 - 2019-07-12 17:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Todo Backup 11.5
2019-07-12 17:18 - 2019-07-01 16:09 - 000026192 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\WINDOWS\system32\fbnative.exe
2019-07-12 15:11 - 2019-07-13 00:42 - 000000000 ___RD C:\Users\galeo\Desktop\Alerta
2019-07-12 11:44 - 2019-07-12 11:44 - 000000000 ___RD C:\Users\galeo\Desktop\Folderico
2019-07-11 21:05 - 2019-07-11 21:05 - 000000080 ___SH C:\bootTel.dat
2019-07-11 21:01 - 2019-07-11 21:01 - 000000000 ____D C:\Users\galeo\AppData\Local\AWL
2019-07-11 20:00 - 2019-07-11 20:00 - 000000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled
2019-07-11 19:58 - 2019-07-11 20:00 - 000000000 ____D C:\ProgramData\ProductData
2019-07-11 13:38 - 2019-07-17 01:23 - 000051953 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2019-07-11 13:38 - 2019-07-12 16:42 - 000160044 _____ C:\WINDOWS\ZAM.krnl.trace
2019-07-11 03:17 - 2019-07-11 13:38 - 000000000 ____D C:\Users\galeo\Tor Browser
2019-07-11 02:58 - 2019-07-11 02:58 - 000000000 ____D C:\easeus_tb_cloud
2019-07-11 02:04 - 2018-11-25 05:06 - 000053880 _____ (Olof Lagerkvist) C:\WINDOWS\SysWOW64\imdisk.exe
2019-07-11 02:04 - 2018-11-25 04:42 - 000053368 _____ (Olof Lagerkvist) C:\WINDOWS\system32\imdisk.exe
2019-07-11 02:04 - 2018-11-19 06:55 - 000133968 _____ (Olof Lagerkvist) C:\WINDOWS\system32\imdisk.cpl
2019-07-11 02:04 - 2018-11-19 06:55 - 000123216 _____ (Olof Lagerkvist) C:\WINDOWS\SysWOW64\imdisk.cpl
2019-07-11 02:04 - 2016-08-23 23:57 - 000001547 _____ C:\WINDOWS\system32\uninstall_imdisk.cmd
2019-07-10 23:53 - 2019-07-10 23:53 - 025444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 019811328 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 018017792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 008011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 007008768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 005919744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 003837440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-07-10 23:53 - 2019-07-10 23:53 - 001715000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 001608192 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2019-07-10 23:53 - 2019-07-10 23:53 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-10 23:53 - 2019-07-10 23:53 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000093312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-10 23:53 - 2019-07-10 23:53 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\srmlib.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-07-10 23:53 - 2019-07-10 23:53 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 025902080 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 022625280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 009917752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 007887440 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 007758336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 007636616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 007242312 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 006534712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 006068840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 005745504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 004863488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 004562920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 004012032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 003725312 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 003698176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 003372952 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002798592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 002763552 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-07-10 23:52 - 2019-07-10 23:52 - 002725376 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 002656768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002587328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002576384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002449456 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002281984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002117160 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001954960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001754232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-10 23:52 - 2019-07-10 23:52 - 001745920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001717560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001697280 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001647280 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001633648 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001535288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001509936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 001480704 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001458176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001391416 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-10 23:52 - 2019-07-10 23:52 - 001337656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001273344 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001261568 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001260032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001182232 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 001149928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 001146880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001071928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 001067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 001007104 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000928776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000910272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000889656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000879792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000830976 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000829544 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000821696 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000818656 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000782120 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000774152 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000769336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000751256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000679368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000673152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000667272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000588464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000523912 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000481592 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000472064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000425264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000415800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000386016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000350208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000339520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000336928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000316216 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000301568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000283152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000270336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000268216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000248088 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000220680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000210440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-10 23:52 - 2019-07-10 23:52 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000199176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000193800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000146920 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000127296 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000123912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000120352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000088560 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-07-10 23:52 - 2019-07-10 23:52 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanhlp.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3r.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-07-10 23:52 - 2019-07-10 23:52 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3r.dll
2019-07-10 22:14 - 2019-07-10 22:14 - 000000000 ____D C:\Program Files (x86)\Win10Pcap
2019-07-10 22:14 - 2013-03-01 03:49 - 000370424 _____ (Riverbed Technology, Inc.) C:\WINDOWS\system32\wpcap.dll.bak
2019-07-10 22:14 - 2013-03-01 03:49 - 000282360 _____ (Riverbed Technology, Inc.) C:\WINDOWS\SysWOW64\wpcap.dll.bak
2019-07-10 22:14 - 2013-03-01 03:49 - 000107768 _____ (Riverbed Technology, Inc.) C:\WINDOWS\system32\Packet.dll.bak
2019-07-10 22:14 - 2013-03-01 03:49 - 000098040 _____ (Riverbed Technology, Inc.) C:\WINDOWS\SysWOW64\Packet.dll.bak
2019-07-10 16:19 - 2019-07-10 16:21 - 000000000 ____D C:\Users\galeo\AppData\Local\NPE
2019-07-10 16:19 - 2019-07-10 16:19 - 000000000 ____D C:\ProgramData\Norton
2019-07-10 03:33 - 2019-07-13 01:44 - 000000000 ____D C:\Users\galeo\AppData\LocalLow\Mozilla
2019-07-10 03:33 - 2019-07-11 03:17 - 000001089 _____ C:\Users\galeo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2019-07-10 03:32 - 2019-07-10 03:33 - 000000000 ____D C:\Users\galeo\Browser
2019-07-10 01:16 - 2019-07-10 01:16 - 000000000 ____D C:\Users\galeo\.cache
2019-07-09 05:03 - 2019-07-09 06:34 - 000000000 ____D C:\AdwCleaner
2019-07-09 04:44 - 2019-07-09 04:44 - 000000000 ____D C:\ProgramData\GridinSoft
2019-07-09 03:34 - 2019-07-10 21:22 - 000290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subinacl.exe
2019-07-09 03:34 - 2019-07-09 03:34 - 000000000 ____D C:\Program Files (x86)\Adware Removal Tool by TSA
2019-07-08 12:17 - 2019-07-08 12:17 - 000000000 ____D C:\Users\galeo\AppData\LocalLow\Adobe
2019-07-06 20:15 - 2019-07-06 20:15 - 000000000 ____D C:\Users\galeo\.QtWebEngineProcess
2019-07-06 20:15 - 2019-07-06 20:15 - 000000000 ____D C:\Users\galeo\.AdvertisingPopup
2019-07-06 15:44 - 2019-07-10 22:09 - 000000000 ____D C:\Program Files (x86)\WinPcap
2019-07-06 15:44 - 2019-07-06 15:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
2019-07-06 07:04 - 2019-07-15 17:08 - 000000000 ____D C:\Users\galeo\AppData\Roaming\vlc
2019-07-06 01:33 - 2019-07-16 23:40 - 000004220 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{ACDC18F7-ACC8-47C1-B362-541960B7E9BC}
2019-07-06 01:32 - 2019-07-06 01:32 - 000000000 ____D C:\Users\galeo\AppData\Local\Engelmann_Software
2019-07-06 01:32 - 2019-07-06 01:32 - 000000000 ____D C:\ProgramData\Engelmann Software
2019-07-05 16:15 - 2019-07-05 16:15 - 000000000 ____D C:\Users\galeo\AppData\Local\ASHelper
2019-07-04 16:15 - 2019-07-04 16:15 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 007175168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 006218752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 005500416 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 004578816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 004306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 003914480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 003748864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 003487232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 003243080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002956984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002771008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002697728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002494232 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002490712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002398208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002306048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002258336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002235936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002216448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002190648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 002072152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001866064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001815040 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001721344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001690624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001651848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001611576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001555688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001501496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001383736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001366528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001345024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001304888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001273176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001192096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001124864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CBDHSvc.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001101312 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001063944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001043768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001006592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000957240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000919040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000827192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000816440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000801592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2019-07-04 16:15 - 2019-07-04 16:15 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000743424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000741176 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000739328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000700928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000674816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000665912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000649016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000645632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000611328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000602432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000531464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000516752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000509440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-07-04 16:15 - 2019-07-04 16:15 - 000494904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000460288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2019-07-04 16:15 - 2019-07-04 16:15 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-07-04 16:15 - 2019-07-04 16:15 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DispBroker.Desktop.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000394040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\provplatformdesktop.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000366184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000333824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000317952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscobj.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AnalogShell.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000267528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000257848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\provplatformdesktop.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000231432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000228664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscobj.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000187920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ifsutil.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000181560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000177664 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetpp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000172856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVNice.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000149512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ulib.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwclientres.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000129088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleprn.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2019-07-04 16:15 - 2019-07-04 16:15 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000099712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FsIso.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-07-04 16:15 - 2019-07-04 16:15 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000058825 _____ C:\WINDOWS\system32\srms.dat
2019-07-04 16:15 - 2019-07-04 16:15 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efsext.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000037904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2019-07-04 16:15 - 2019-07-04 16:15 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000022024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScriptRunner.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwstreamingux.dll
2019-07-04 16:15 - 2019-07-04 16:15 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2019-07-04 16:15 - 2019-07-04 16:15 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 017786368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 006224296 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 004552336 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 004470784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 004008960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Service.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 003654656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 003550720 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 003327256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 003261440 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 003106304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 002990608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 002871824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 002550584 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 002443264 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 002232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001999440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001979392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConstraintIndex.Search.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001841152 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001781248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001761792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001687552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001635328 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001608704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001437184 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001362432 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001262864 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001250432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 001042944 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2019-07-04 16:14 - 2019-07-04 16:14 - 001040896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2019-07-04 16:14 - 2019-07-04 16:14 - 000876856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000862720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000810512 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000771584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000706544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000680760 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000637968 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000586552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2019-07-04 16:14 - 2019-07-04 16:14 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2019-07-04 16:14 - 2019-07-04 16:14 - 000474112 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2019-07-04 16:14 - 2019-07-04 16:14 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000435000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000390456 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000336752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000312320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000296976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000257536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbaudio2.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000242688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000214032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ifsutil.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000182072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000180536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000180024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ulib.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleprn.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000142136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000129848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000071720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000065064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2019-07-04 16:14 - 2019-07-04 16:14 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2019-07-04 16:14 - 2019-07-04 16:14 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-07-04 16:14 - 2019-07-04 16:14 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-07-04 16:04 - 2019-07-04 16:04 - 000000000 ____D C:\Program Files (x86)\EdgeDeflector
2019-07-04 15:27 - 2019-07-04 15:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-07-04 15:27 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-07-04 15:27 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-07-04 12:04 - 2019-07-12 16:42 - 000000000 ____D C:\Users\galeo\AppData\Local\AMSDK
2019-07-04 01:34 - 2019-07-04 01:34 - 000000000 ____D C:\Users\galeo\AppData\Roaming\TransferSupport
2019-07-04 01:34 - 2019-07-04 01:34 - 000000000 ____D C:\Users\galeo\.android
2019-07-03 20:55 - 2019-07-03 20:55 - 000001489 _____ C:\Users\Public\Desktop\iTube Studio.lnk
2019-07-03 20:55 - 2019-07-03 20:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTube Studio
2019-07-03 20:55 - 2019-07-03 20:55 - 000000000 ____D C:\Program Files (x86)\Aimersoft
2019-07-03 19:41 - 2019-07-10 03:58 - 000000000 ____D C:\ProgramData\iTube Studio
2019-07-03 19:41 - 2019-07-10 03:55 - 000000000 ____D C:\Users\galeo\AppData\Roaming\iTube Studio
2019-07-03 19:41 - 2019-07-03 19:42 - 000000000 ____D C:\ProgramData\Aimersoft
2019-07-03 19:41 - 2019-07-03 19:41 - 000000000 ____D C:\Users\galeo\AppData\Local\iTube Studio
2019-07-03 19:41 - 2019-07-03 19:41 - 000000000 ____D C:\Users\galeo\AppData\Local\Aimersoft
2019-07-03 19:40 - 2019-07-03 20:55 - 000000000 ____D C:\Users\Public\Documents\Aimersoft
2019-07-03 18:05 - 2019-07-09 14:28 - 000004584 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2019-07-03 18:05 - 2019-07-09 14:28 - 000004388 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2019-07-03 11:15 - 2005-04-15 19:58 - 001351392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.ocx
2019-07-03 02:21 - 2019-07-03 03:14 - 000000032 _____ C:\WINDOWS\SysWOW64\Eu(13-20190422).OD
2019-07-03 02:21 - 2019-07-03 02:21 - 000000000 ____D C:\ProgramData\EaseUS
2019-07-03 01:35 - 2019-07-03 01:56 - 000000032 _____ C:\WINDOWS\SysWOW64\Eu(13-20181015).OD
2019-07-02 23:57 - 2019-07-16 16:14 - 000000000 ____D C:\Program Files\ImDisk
2019-07-02 23:57 - 2019-07-16 14:54 - 000000989 _____ C:\Users\galeo\Desktop\Configurar RamDisk.lnk
2019-07-02 23:57 - 2019-07-11 13:38 - 000000000 ____D C:\Users\galeo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ImDisk
2019-07-02 23:57 - 2018-11-19 06:55 - 000048704 _____ (Olof Lagerkvist) C:\WINDOWS\system32\Drivers\imdisk.sys
2019-07-02 23:57 - 2018-11-19 06:55 - 000031544 _____ (Olof Lagerkvist) C:\WINDOWS\system32\imdsksvc.exe
2019-07-02 23:57 - 2018-11-19 06:55 - 000021048 _____ (Olof Lagerkvist) C:\WINDOWS\system32\Drivers\awealloc.sys
2019-07-02 15:57 - 2019-07-11 00:35 - 000000000 ____D C:\Users\galeo\AppData\Local\ElevatedDiagnostics
2019-07-01 15:28 - 2019-07-16 23:24 - 000002275 _____ C:\Users\galeo\Desktop\WhatsApp.lnk
2019-07-01 15:28 - 2019-07-08 18:14 - 000000000 ____D C:\Users\galeo\AppData\Local\WhatsApp
2019-07-01 15:28 - 2019-07-01 15:28 - 000000000 ____D C:\Users\galeo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WhatsApp
2019-07-01 15:28 - 2019-07-01 15:28 - 000000000 ____D C:\Users\galeo\AppData\Local\SquirrelTemp
2019-07-01 14:59 - 2019-07-09 11:34 - 000000000 ____D C:\Users\galeo\AppData\Roaming\WhatsApp
2019-07-01 02:25 - 2019-07-01 03:01 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2019-06-30 21:33 - 2019-06-30 21:33 - 000302368 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2019-06-30 21:23 - 2019-07-12 16:40 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2019-06-30 21:23 - 2019-06-30 21:39 - 001168000 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2019-06-30 21:23 - 2019-06-30 21:39 - 001093248 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2019-06-30 21:23 - 2019-06-30 21:39 - 000236672 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2019-06-30 21:23 - 2019-06-30 21:39 - 000152288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\klhkum.dll
2019-06-30 21:23 - 2019-06-30 21:23 - 000245272 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2019-06-30 21:23 - 2019-06-30 21:23 - 000198768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2019-06-30 21:23 - 2019-06-30 21:23 - 000116104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2019-06-30 21:23 - 2019-06-30 21:23 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2019-06-30 21:23 - 2019-06-30 21:23 - 000002219 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2019-06-30 21:23 - 2019-06-30 21:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2019-06-30 21:23 - 2013-05-06 08:13 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2019-06-30 20:17 - 2019-07-13 00:41 - 000000000 ___RD C:\Users\galeo\Desktop\Leona
2019-06-30 12:25 - 2019-07-16 17:12 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-06-30 12:25 - 2019-07-14 20:59 - 000000000 ____D C:\Program Files\CCleaner
2019-06-30 12:25 - 2019-07-06 19:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-06-30 10:52 - 2019-06-30 10:54 - 000000000 ____D C:\Users\galeo\AppData\Roaming\Easeware
2019-06-30 10:38 - 2019-07-14 00:07 - 000001089 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2019-06-30 10:38 - 2019-07-14 00:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2019-06-30 10:38 - 2019-06-30 10:38 - 000000000 ____D C:\Program Files\VS Revo Group

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-07-17 01:23 - 2019-06-14 13:26 - 000000000 ____D C:\Users\galeo\AppData\Roaming\NetSpeedMonitor
2019-07-17 01:20 - 2019-06-15 12:20 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2019-07-17 00:53 - 2019-06-01 07:32 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-07-17 00:48 - 2019-06-01 07:34 - 000790868 _____ C:\WINDOWS\system32\perfh00A.dat
2019-07-17 00:48 - 2019-06-01 07:34 - 000156620 _____ C:\WINDOWS\system32\perfc00A.dat
2019-07-17 00:48 - 2019-06-01 07:30 - 000000000 ____D C:\WINDOWS\INF
2019-07-17 00:48 - 2019-06-01 06:45 - 001776860 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-17 00:43 - 2019-06-11 07:14 - 000000000 ____D C:\Users\galeo\AppData\Local\CrashDumps
2019-07-17 00:43 - 2019-06-01 06:52 - 000000000 __SHD C:\Users\galeo\IntelGraphicsProfiles
2019-07-17 00:43 - 2019-06-01 06:39 - 000000000 ____D C:\ProgramData\NVIDIA
2019-07-17 00:43 - 2019-06-01 06:38 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-07-17 00:25 - 2019-06-01 07:27 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-07-17 00:02 - 2019-06-01 15:49 - 000000000 ____D C:\Users\galeo\AppData\Local\Google
2019-07-16 23:24 - 2019-06-04 23:49 - 000001262 _____ C:\Users\galeo\Desktop\AIDA64 Extreme.lnk
2019-07-16 23:24 - 2019-06-03 21:03 - 000001073 _____ C:\Users\galeo\Desktop\Navegador Web Aislado en una Sandbox.lnk
2019-07-16 23:24 - 2019-06-01 15:48 - 000001895 _____ C:\Users\galeo\Desktop\CrystalDiskMark 6.lnk
2019-07-16 20:24 - 2019-06-01 06:38 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-16 19:49 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-07-16 19:48 - 2019-06-01 06:52 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-16 17:33 - 2019-06-01 15:27 - 000000000 ____D C:\Users\galeo\AppData\Local\D3DSCache
2019-07-16 16:15 - 2019-06-15 01:27 - 000000008 __RSH C:\ProgramData\ntuser.pol
2019-07-16 16:14 - 2019-06-01 07:32 - 000000000 ___SD C:\Program Files\Windows Sidebar
2019-07-16 16:14 - 2019-06-01 07:32 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2019-07-15 18:47 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-07-15 16:23 - 2019-06-04 20:43 - 000004218 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1559673782
2019-07-15 16:23 - 2019-06-04 20:43 - 000001413 _____ C:\Users\galeo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
2019-07-14 20:29 - 2019-06-01 07:27 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2019-07-14 01:45 - 2019-06-15 12:40 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-07-13 03:12 - 2019-06-03 21:03 - 000001744 _____ C:\WINDOWS\Sandboxie.ini
2019-07-13 00:33 - 2019-06-03 15:02 - 000287744 ___SH C:\EUMONBMP.SYS
2019-07-13 00:33 - 2019-06-03 15:02 - 000000000 ____D C:\WINDOWS\system32\config\regsave
2019-07-12 21:28 - 2019-06-03 15:58 - 000000000 ____D C:\Program Files\Bandizip
2019-07-12 20:36 - 2019-06-01 07:32 - 000000000 ___HD C:\Program Files\WindowsApps
2019-07-12 17:18 - 2019-06-03 14:50 - 000000000 ____D C:\Program Files (x86)\EaseUS
2019-07-12 16:42 - 2019-06-11 02:30 - 000000000 ____D C:\Users\galeo\AppData\Local\Zemana
2019-07-12 16:16 - 2019-06-01 07:27 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-12 03:08 - 2019-06-14 11:51 - 000000000 ____D C:\Program Files (x86)\epson
2019-07-12 03:06 - 2019-06-14 11:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2019-07-11 20:55 - 2019-06-14 19:35 - 000002238 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2019-07-11 18:50 - 2019-06-11 08:44 - 000002406 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_ListenToDevice
2019-07-11 18:50 - 2019-06-11 08:44 - 000002362 _____ C:\WINDOWS\System32\Tasks\RTKCPL
2019-07-11 18:47 - 2019-06-04 20:43 - 000003828 _____ C:\WINDOWS\System32\Tasks\Opera scheduled assistant Autoupdate 1559673789
2019-07-11 13:56 - 2019-06-04 22:38 - 000004246 _____ C:\WINDOWS\System32\Tasks\AVG TuneUp Update
2019-07-11 13:38 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-07-11 13:38 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\Containers
2019-07-11 13:38 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-11 13:38 - 2019-06-01 07:32 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-11 13:38 - 2019-06-01 07:27 - 000000000 ____D C:\WINDOWS\servicing
2019-07-11 13:38 - 2019-06-01 06:52 - 000000000 ___RD C:\Users\galeo\3D Objects
2019-07-11 13:37 - 2019-06-01 07:32 - 000000000 ___SD C:\WINDOWS\system32\AppV
2019-07-11 13:37 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\SystemResources
2019-07-11 13:37 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2019-07-11 13:37 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-11 13:36 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\registration
2019-07-11 03:17 - 2019-06-01 06:48 - 000000000 ____D C:\Users\galeo
2019-07-11 00:47 - 2019-06-01 06:55 - 000000000 ____D C:\Users\galeo\AppData\Local\PlaceholderTileLogoFolder
2019-07-11 00:14 - 2019-06-01 06:52 - 000000000 ____D C:\Users\galeo\AppData\Local\Packages
2019-07-11 00:14 - 2019-06-01 06:52 - 000000000 ____D C:\ProgramData\Packages
2019-07-11 00:03 - 2019-06-04 20:28 - 000003542 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-07-10 23:56 - 2019-06-01 09:01 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-07-10 23:54 - 2019-06-01 09:01 - 136618864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-07-10 23:02 - 2019-06-01 06:57 - 000741432 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-10 23:02 - 2019-06-01 06:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-07-09 14:28 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-07-09 14:28 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-07-08 13:55 - 2019-06-01 06:52 - 000000000 ____D C:\Users\galeo\AppData\Local\VirtualStore
2019-07-08 12:17 - 2019-06-04 20:27 - 000000000 ____D C:\Users\galeo\AppData\Local\Adobe
2019-07-08 12:17 - 2019-06-01 06:52 - 000000000 ____D C:\Users\galeo\AppData\Roaming\Adobe
2019-07-06 04:00 - 2019-06-01 07:32 - 000000000 ___SD C:\Program Files (x86)\Windows Sidebar
2019-07-04 16:21 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-07-04 16:21 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-04 16:21 - 2019-06-01 07:32 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-07-04 15:27 - 2019-06-01 07:32 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-07-03 22:27 - 2019-06-01 06:53 - 000000000 ____D C:\Users\galeo\AppData\Local\Comms
2019-07-03 02:05 - 2019-06-03 14:52 - 000000032 _____ C:\WINDOWS\SysWOW64\Eu(12-20190422).OD
2019-06-30 21:39 - 2019-02-19 05:44 - 000184960 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwtp.sys
2019-06-30 21:39 - 2019-02-19 05:44 - 000125568 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupflt.sys
2019-06-30 21:39 - 2019-02-19 05:44 - 000091472 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kldisk.sys
2019-06-30 21:39 - 2019-02-19 05:44 - 000075600 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klbackupdisk.sys
2019-06-30 21:39 - 2019-02-19 05:44 - 000046416 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpnpflt.sys
2019-06-30 21:39 - 2018-02-24 05:17 - 000218240 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2019-06-30 21:39 - 2018-02-17 02:50 - 000104576 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klwfp.sys
2019-06-30 21:39 - 2018-02-12 04:17 - 000058704 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klim6.sys
2019-06-30 21:39 - 2018-01-15 05:13 - 000060536 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2019-06-30 21:39 - 2017-12-11 11:49 - 000060784 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klmouflt.sys
2019-06-30 21:39 - 2017-05-30 18:51 - 000050304 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klpd.sys
2019-06-30 21:23 - 2019-06-15 12:21 - 000000000 ____D C:\Program Files\Common Files\AV
2019-06-30 11:20 - 2019-06-01 15:19 - 000001134 _____ C:\WINDOWS\system32\config\VSMIDK
2019-06-30 10:46 - 2019-06-11 02:52 - 000000000 ____D C:\Users\galeo\AppData\Local\Avg
2019-06-30 10:46 - 2019-06-04 22:39 - 000000000 ____D C:\Users\galeo\AppData\Roaming\AVG
2019-06-30 10:46 - 2019-06-04 22:38 - 000000000 ____D C:\ProgramData\AVG
2019-06-30 07:44 - 2019-06-14 19:40 - 000000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2019-06-30 07:44 - 2019-06-11 07:20 - 000002534 _____ C:\WINDOWS\System32\Tasks\SamsungMagician
2019-06-28 11:09 - 2019-06-03 14:52 - 000341760 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\WINDOWS\system32\Drivers\EuFdDisk.sys
2019-06-28 11:09 - 2019-06-03 14:52 - 000073448 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\WINDOWS\system32\Drivers\eubakup.sys
2019-06-28 11:09 - 2019-06-03 14:52 - 000053504 _____ C:\WINDOWS\system32\Drivers\EUBKMON.sys
2019-06-28 11:09 - 2019-06-03 14:52 - 000022784 _____ (CHENGDU YIWO Tech Development Co., Ltd) C:\WINDOWS\system32\Drivers\eudskacs.sys

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2019 01
Ran by galeo (17-07-2019 01:24:32)
Running from C:\Users\galeo\Desktop
Windows 10 Pro Version 1903 18362.239 (X64) (2019-06-01 04:41:23)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-3519385873-1241429883-2487059262-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3519385873-1241429883-2487059262-503 - Limited - Disabled)
galeo (S-1-5-21-3519385873-1241429883-2487059262-1001 - Administrator - Enabled) => C:\Users\galeo
Invitado (S-1-5-21-3519385873-1241429883-2487059262-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3519385873-1241429883-2487059262-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Kaspersky Internet Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
FW: Kaspersky Internet Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 19.012.20035 - Adobe Systems Incorporated)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.223 - Adobe)
AIDA64 Extreme v5.99 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.99 - FinalWire Ltd.)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 4.2.2 - ASUS)
ATK Package (ASUS Keyboard Hotkeys) (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0060 - ASUSTeK COMPUTER INC.)
AVG TuneUp (HKLM-x32\...\{949BE04F-D7E8-4C19-9F89-8B304AB4308A}_is1) (Version: 19.1.1158 - AVG Technologies)
Bandizip (HKLM\...\Bandizip) (Version: 6.24 - Bandisoft.com)
CCleaner (HKLM\...\CCleaner) (Version: 5.60 - Piriform)
CrystalDiskMark 6.0.2 (HKLM\...\CrystalDiskMark6_is1) (Version: 6.0.2 - Crystal Dew World)
Desinstalar impresora EPSON SX218 Series (HKLM\...\EPSON SX218 Series) (Version:  - SEIKO EPSON Corporation)
EaseUS Todo Backup Free 11.5 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 11.5 - CHENGDU YIWO Tech Development Co., Ltd)
EdgeDeflector (HKLM-x32\...\EdgeDeflector) (Version:  - )
GridinSoft Anti-Malware (HKLM\...\GridinSoft Anti-Malware) (Version: 3.0.92 - GridinSoft LLC)
ImDisk Toolkit (HKLM\...\ImDiskApp) (Version: 20190407 - )
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.9.0.1001 - Intel Corporation)
iTube Studio(Build 7.4.3.1) (HKLM-x32\...\iTube Studio_is1) (Version: 7.4.3.1 - iTube Studio)
Kaspersky Internet Security (HKLM-x32\...\{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{718613F4-492D-4272-ACC3-D04A8EF0F883}) (Version: 19.0.0.1088 - Kaspersky Lab)
Malwarebytes versión 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
NetSpeedMonitor 2.5.4.0 x64 (HKLM\...\{88F41EE2-949B-4B52-933D-C7F8F67BC1D2}) (Version: 2.5.4.0 - Florian Gilles)
OpenOffice 4.1.6 (HKLM-x32\...\{ABA77258-70D6-4A14-9AB7-3FA087C470DB}) (Version: 4.16.9790 - Apache Software Foundation)
Opera Stable 62.0.3331.72 (HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\Opera 62.0.3331.72) (Version: 62.0.3331.72 - Opera Software)
Panel de control de NVIDIA 391.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 391.35 - NVIDIA Corporation) Hidden
RAPID Mode (HKLM\...\{0EBB0FA7-1DBA-4B97-9B44-BD5CC451EEF2}) (Version: 1.0.0.103 - Samsung Electronics Co., Ltd.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0022 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8648 - Realtek Semiconductor Corp.)
Revo Uninstaller 2.1.0 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.1.0 - VS Revo Group, Ltd.)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.3.1.2010 - Samsung Electronics)
Sandboxie 5.30 (64-bit) (HKLM\...\Sandboxie) (Version: 5.30 - Sandboxie Holdings, LLC)
USB Charger Plus Service (HKLM-x32\...\{452B3493-18D3-4B36-9F59-78AF7963FFCC}) (Version: 5.0.6 - ASUS)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.7.1 - VideoLAN)
WhatsApp (HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\WhatsApp) (Version: 0.3.3793 - WhatsApp)
Win10Pcap (HKLM-x32\...\{B5B58F8A-1984-4F3E-B400-235A6E005002}) (Version: 10.2.5002 - Daiyuu Nobori, University of Tsukuba, Japan)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WizFile v2.06 (HKLM\...\WizFile_is1) (Version: 2.06 - Antibody Software)
WizTree v3.29 (HKLM\...\WizTree_is1) (Version: 3.29 - Antibody Software)

Packages:
=========
Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11629.20316.0_x64__8wekyb3d8bbwe [2019-07-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-07-11] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-07-11] (Microsoft Corporation) [MS Ad]
WhatsApp Desktop -> C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_0.3.3794.0_x64__cv1g1gvanyjgm [2019-07-11] (WhatsApp Inc.)
WiFi Analyzer -> C:\Program Files\WindowsApps\19965MattHafner.WifiAnalyzer_2.4.1.0_x64__gs5k5vmxr2ste [2019-07-11] (Matt Hafner)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3519385873-1241429883-2487059262-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Users\galeo\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter.gadget\CoreTempReader.dll (AddGadgets IT -> )
ContextMenuHandlers1: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers1: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} =>  -> No File
ContextMenuHandlers1: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\ShellEx.dll [2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers2: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers2: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} =>  -> No File
ContextMenuHandlers2: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\ShellEx.dll [2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers2: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers4: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} =>  -> No File
ContextMenuHandlers4: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\ShellEx.dll [2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers4: [SimpleShlExt] -> {45203D3B-3D73-4497-8AFE-D29950AC6C55} => C:\Program Files (x86)\EaseUS\Todo Backup\bin\x64\ImageSh.dll [2019-07-01] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co.,Ltd)
ContextMenuHandlers5: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2019-05-19] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-03-24] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [GridinSoft Anti-Malware] -> {F77F27A6-89F3-471A-AFA8-3B280940A10C} =>  -> No File
ContextMenuHandlers6: [Kaspersky Anti-Virus 19.0.0] -> {755D388B-420B-4692-A974-84AAF0E577D3} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\ShellEx.dll [2019-06-30] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers1_S-1-5-21-3519385873-1241429883-2487059262-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers2_S-1-5-21-3519385873-1241429883-2487059262-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers4_S-1-5-21-3519385873-1241429883-2487059262-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)
ContextMenuHandlers5_S-1-5-21-3519385873-1241429883-2487059262-1001: [AABdzCtx] -> {5B69A6B4-393B-459C-8EBB-214237A9E7AC} => C:\Program Files\Bandizip\bdzshl64.dll [2019-07-12] (Bandisoft -> Bandisoft.com)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2019-06-04 22:38 - 2016-09-12 15:53 - 048936448 _____ () [File not signed] C:\Program Files (x86)\AVG\AVG TuneUp\libcef.dll
2010-04-04 23:08 - 2010-04-04 23:08 - 001253376 _____ (Florian Gilles) [File not signed] C:\Program Files\NetSpeedMonitor\nsm.dll
2017-05-26 19:35 - 2019-07-16 23:00 - 017764816 _____ (Gridinsoft, LLC -> GridinSoft LLC) [File not signed] C:\Program Files\GridinSoft Anti-Malware\gsam.exe
2017-05-17 17:21 - 2017-05-17 17:21 - 001422336 _____ (Igor Pavlov) [File not signed] C:\Program Files\GridinSoft Anti-Malware\7z.dll
2013-11-21 08:31 - 2013-11-21 08:31 - 000499200 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\ISDI2.dll
2013-11-21 08:31 - 2013-11-21 08:31 - 000286720 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\PsiData.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DFServ => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2019-06-01 07:32 - 2019-07-16 18:12 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1       localhost

2019-06-01 15:22 - 2019-06-04 10:15 - 000000532 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics

192.168.71.212 918b143d-0a98-46e8-8c9b-458dfe63240f.mshome.net # 2019 6 2 11 8 15 59 955
192.168.71.209 DESKTOP-VTBCMKI.mshome.net # 2024 6 0 2 8 15 59 955

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\galeo\AppData\Roaming\Microsoft\Windows Photo Viewer\Papel tapiz de Visualizador de fotos de Windows.jpg
DNS Servers: 80.58.61.250 - 80.58.61.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\StartupFolder: => "Configurar RamDisk.lnk"
HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "RtHDVCpl"
HKLM\...\StartupApproved\Run32: => "Aimersoft Helper Compact.exe"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar660.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar406.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar320.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar110.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar486.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar761.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar537.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar264.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar457.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar621.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar192.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\StartupFolder: => "Sidebar405.lnk"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\Run: => "Opera Browser Assistant"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\Run: => "Epson Stylus SX218"
HKU\S-1-5-21-3519385873-1241429883-2487059262-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{FBF09C26-4532-4F10-95B4-CA3AD6079757}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{41A40DDF-63BD-4DE4-98AF-BBB20F69A78E}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{3FF19D77-F3B7-484D-969C-4FCA257B4474}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{0206336A-85ED-45EA-B5E7-D82FCBF0C2B5}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd)
FirewallRules: [{2C6A72A4-BBCD-42A2-88DA-103E6C3822E6}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{CE2117CC-C957-454B-B12D-F64FE8BDBE78}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{BC06615F-FE7D-4584-A28F-9117B647D962}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{F39ABCC4-FEC2-483C-8B85-5E09850F67A1}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> )
FirewallRules: [{A8D99221-EF47-4B27-86FD-F043A8A86CCE}] => (Allow) C:\Users\galeo\AppData\Local\Programs\Opera\62.0.3331.66\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{416703DB-5283-4CDF-B666-0EBD677EBDFC}] => (Allow) C:\Users\galeo\AppData\Local\Programs\Opera\62.0.3331.72\opera.exe (Opera Software AS -> Opera Software)

==================== Restore Points =========================

15-07-2019 20:51:15 Punto de control programado
16-07-2019 23:04:25 Revo Uninstaller's restore point - Cain & Abel 4.9.56
17-07-2019 00:02:01 Revo Uninstaller's restore point - Google Chrome

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/17/2019 12:43:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: MicrosoftEdgeSH.exe, versión: 11.0.18362.1, marca de tiempo: 0x3538007c
Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x000000000000008c
Identificador del proceso con errores: 0x26b4
Hora de inicio de la aplicación con errores: 0x01d53c27f0ca0084
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Ruta de acceso del módulo con errores: unknown
Identificador del informe: 96d2f485-bc92-49e5-a6fd-671789ba4759
Nombre completo del paquete con errores: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Identificador de aplicación relativa del paquete con errores: MicrosoftEdge

Error: (07/17/2019 12:17:33 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: MicrosoftEdgeSH.exe, versión: 11.0.18362.1, marca de tiempo: 0x3538007c
Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x000000000000008c
Identificador del proceso con errores: 0x28dc
Hora de inicio de la aplicación con errores: 0x01d53c244328bd87
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Ruta de acceso del módulo con errores: unknown
Identificador del informe: b12e899b-a4db-4b1e-b9ed-4eef8ae5f3fc
Nombre completo del paquete con errores: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Identificador de aplicación relativa del paquete con errores: MicrosoftEdge

Error: (07/17/2019 12:13:20 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: MicrosoftEdgeSH.exe, versión: 11.0.18362.1, marca de tiempo: 0x3538007c
Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x000000000000008c
Identificador del proceso con errores: 0x2a10
Hora de inicio de la aplicación con errores: 0x01d53c23ac8b82b9
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Ruta de acceso del módulo con errores: unknown
Identificador del informe: df44fa27-2b9d-4180-b70c-b778730b2794
Nombre completo del paquete con errores: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Identificador de aplicación relativa del paquete con errores: MicrosoftEdge

Error: (07/17/2019 12:05:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: MicrosoftEdgeSH.exe, versión: 11.0.18362.1, marca de tiempo: 0x3538007c
Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x000000000000008c
Identificador del proceso con errores: 0x26d0
Hora de inicio de la aplicación con errores: 0x01d53c2290f5354a
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Ruta de acceso del módulo con errores: unknown
Identificador del informe: dda89b54-8662-4511-bcdc-a603eda794a1
Nombre completo del paquete con errores: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Identificador de aplicación relativa del paquete con errores: MicrosoftEdge

Error: (07/17/2019 12:02:00 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al consultar la interfaz IVssWriterCallback. HR = 0x80070005, Acceso denegado.
.
A menudo ocurre por una configuración de seguridad incorrecta en el proceso de escritura o de solicitud.


Operación:
   Recopilando datos del escritor

Contexto:
   Id. de clase del escritor: {e8132975-6f93-4464-a53e-1050253ae220}
   Nombre del escritor: System Writer
   Id. de instancia del escritor: {e5d0e18e-5017-4109-9560-4b9560d2a703}

Error: (07/16/2019 11:21:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: MicrosoftEdgeSH.exe, versión: 11.0.18362.1, marca de tiempo: 0x3538007c
Nombre del módulo con errores: unknown, versión: 0.0.0.0, marca de tiempo: 0x00000000
Código de excepción: 0xc0000409
Desplazamiento de errores: 0x000000000000008c
Identificador del proceso con errores: 0x15c0
Hora de inicio de la aplicación con errores: 0x01d53c1c776b2331
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\MicrosoftEdgeSH.exe
Ruta de acceso del módulo con errores: unknown
Identificador del informe: 196357aa-fd2a-480e-b6e6-fac7d118ff81
Nombre completo del paquete con errores: Microsoft.MicrosoftEdge_44.18362.1.0_neutral__8wekyb3d8bbwe
Identificador de aplicación relativa del paquete con errores: MicrosoftEdge

Error: (07/16/2019 11:18:42 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al llamar a la rutina CoCreateInstance. HR = 0x8007045b, Se está cerrando el sistema.
.

Error: (07/16/2019 11:18:42 PM) (Source: VSS) (EventID: 13) (User: )
Description: Información del Servicio de instantáneas de volumen: el servidor COM con CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} y el nombre CEventSystem no puede iniciarse. [0x8007045b, Se está cerrando el sistema.
]


System errors:
=============
Error: (07/16/2019 07:49:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor {F9717507-6651-4EDB-BFF7-AE615179BCCF} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/16/2019 07:49:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor {F9717507-6651-4EDB-BFF7-AE615179BCCF} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/16/2019 07:49:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor {F9717507-6651-4EDB-BFF7-AE615179BCCF} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/16/2019 07:49:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor Microsoft.Windows.ShellExperienceHost_10.0.18362.145_neutral_neutral_cw5n1h2txyewy!App no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/16/2019 07:47:34 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe!App no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/16/2019 07:47:34 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor {B9B05098-3E30-483F-87F7-027CA78DA287} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (07/16/2019 07:40:17 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-VTBCMKI)
Description: No se puede iniciar un servidor DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Error 
"2147942767"
al iniciar este comando:
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}

Error: (07/16/2019 06:27:00 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-VTBCMKI)
Description: El servidor Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe!App no se registró con DCOM dentro del tiempo de espera requerido.


Windows Defender:
===================================
Date: 2019-07-06 15:36:43.907
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Cain&threatid=2147680436&enterprise=0
Nombre: HackTool:Win32/Cain
Id.: 2147680436
Gravedad: Alta
Categoría: Herramienta
Ruta de acceso: file:_C:\Users\galeo\Desktop\ca_setup.exe
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Protección en tiempo real
Usuario: DESKTOP-VTBCMKI\galeo
Nombre de proceso: C:\Windows\System32\svchost.exe
Versión de inteligencia de seguridad: AV: 1.297.537.0, AS: 1.297.537.0, NIS: 1.297.537.0
Versión de motor: AM: 1.1.16100.4, NIS: 1.1.16100.4

Date: 2019-07-06 15:29:08.850
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Cain&threatid=2147680436&enterprise=0
Nombre: HackTool:Win32/Cain
Id.: 2147680436
Gravedad: Alta
Categoría: Herramienta
Ruta de acceso: file:_C:\Users\galeo\Desktop\ca_setup (2)\ca_setup.exe
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Protección en tiempo real
Usuario: DESKTOP-VTBCMKI\galeo
Nombre de proceso: C:\Windows\explorer.exe
Versión de inteligencia de seguridad: AV: 1.297.537.0, AS: 1.297.537.0, NIS: 1.297.537.0
Versión de motor: AM: 1.1.16100.4, NIS: 1.1.16100.4

Date: 2019-07-06 15:28:49.425
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Cain&threatid=2147680436&enterprise=0
Nombre: HackTool:Win32/Cain
Id.: 2147680436
Gravedad: Alta
Categoría: Herramienta
Ruta de acceso: file:_C:\Users\galeo\Desktop\ca_setup (2)\ca_setup.exe
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Protección en tiempo real
Usuario: DESKTOP-VTBCMKI\galeo
Nombre de proceso: C:\Windows\explorer.exe
Versión de inteligencia de seguridad: AV: 1.297.537.0, AS: 1.297.537.0, NIS: 1.297.537.0
Versión de motor: AM: 1.1.16100.4, NIS: 1.1.16100.4

Date: 2019-07-06 15:28:43.739
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Cain&threatid=2147680436&enterprise=0
Nombre: HackTool:Win32/Cain
Id.: 2147680436
Gravedad: Alta
Categoría: Herramienta
Ruta de acceso: file:_C:\Users\galeo\Desktop\ca_setup (2)\ca_setup.exe
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Protección en tiempo real
Usuario: DESKTOP-VTBCMKI\galeo
Nombre de proceso: C:\Program Files\Bandizip\Bandizip.exe
Versión de inteligencia de seguridad: AV: 1.297.537.0, AS: 1.297.537.0, NIS: 1.297.537.0
Versión de motor: AM: 1.1.16100.4, NIS: 1.1.16100.4

Date: 2019-07-06 15:25:25.315
Description: 
Antivirus de Windows Defender detectó malware u otro software potencialmente no deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/Cain&threatid=2147680436&enterprise=0
Nombre: HackTool:Win32/Cain
Id.: 2147680436
Gravedad: Alta
Categoría: Herramienta
Ruta de acceso: file:_C:\Sandbox\galeo\DefaultBox\drive\F\Biblioteca\.DESCARGAS DE NUEVO SOFTWARE\CainAbel\ca_setup\ca_setup.exe
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Protección en tiempo real
Usuario: DESKTOP-VTBCMKI\galeo
Nombre de proceso: C:\Windows\explorer.exe
Versión de inteligencia de seguridad: AV: 1.297.537.0, AS: 1.297.537.0, NIS: 1.297.537.0
Versión de motor: AM: 1.1.16100.4, NIS: 1.1.16100.4

Date: 2019-06-30 10:48:40.563
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Supervisión de comportamiento
Código de error: 0x80508023
Descripción del error: El programa no encontró malware ni otro software potencialmente no deseado en este dispositivo. 
Motivo: La inteligencia de seguridad antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

Date: 2019-06-29 15:13:55.087
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.295.783.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor: 
Versión anterior del motor: 1.1.16000.6
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2019-06-29 15:13:55.086
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.295.783.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiSpyware
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor: 
Versión anterior del motor: 1.1.16000.6
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2019-06-29 15:13:55.086
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.295.783.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor: 
Versión anterior del motor: 1.1.16000.6
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2019-06-29 15:13:55.069
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.295.783.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor: 
Versión anterior del motor: 1.1.16000.6
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

CodeIntegrity:
===================================

Date: 2019-07-17 00:45:42.097
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:45:42.067
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:45:39.643
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:45:39.609
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:45:38.663
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:45:38.643
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:25:02.295
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2019-07-17 00:25:02.276
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 19.0.0\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

==================== Memory info =========================== 

BIOS: American Megatrends Inc. K55VD.411 03/11/2013
Motherboard: ASUSTeK COMPUTER INC. K55VD
Processor: Intel(R) Core(TM) i7-3610QM CPU @ 2.30GHz
Percentage of memory in use: 32%
Total physical RAM: 16269.48 MB
Available physical RAM: 10901.87 MB
Total Virtual: 17293.48 MB
Available Virtual: 11885.86 MB

==================== Drives ================================

Drive c: (Win 10 Pro) (Fixed) (Total:70 GB) (Free:46 GB) NTFS
Drive d: (Win 10 Home) (Fixed) (Total:40 GB) (Free:10.53 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive f: (Biblioteca) (Fixed) (Total:127.71 GB) (Free:16.36 GB) NTFS

\\?\Volume{18481848-0000-0000-0000-100000000000}\ () (Fixed) (Total:0.75 GB) (Free:0.74 GB) NTFS
\\?\Volume{76f14a03-842f-11e9-bec9-806e6f6e6963}\ () (CDROM) (Total:0 GB) (Free:0 GB) 

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 238.5 GB) (Disk ID: 18481848)
Partition 1: (Not Active) - (Size=771 MB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=40 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=70 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=127.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Listo, enviados los informes. Espero salgan bien.

Espero instrucciones…

Hace días me avisó Google y otro proveedor que estaba generando tráfico inusual desde mi red de ordenadores. Me hicieron la prueba del Captcha para ver si era un robot, la rellené y olvidé. Acabo de hacer un NetStat en la consola Cmd para ver el tráfico que pudiera generar y…sorpresa!. Esto es sin ningún navegador abierto.

Y para colmo, recibo un email de Microsoft diciéndome que me cambian las condiciones del contrato con ellos introduciendo dos cosas: Pago por sus servicios y rescisión de los mismos. No dicen que lo vayan a hacer, pero sí que “lo pueden hacer”.

Con lo cual, tiro la toalla. Es demasiado para mí, y no avanzamos yendo tan despacio. Voy a FORMATEAR todo a bajo nivel, y recomenzar.

Hoy han ganado los Virus y el Malware.