Estoy usando la computadora normalmente, con el uso de oficina habitual y cada cierto tiempo se traba por completo y tengo que apagarla y encenderla manualmente. Ya me ha pasado varias veces pero no veo la causa puntual previa a que todo se quede trabado. no abro ningun programa pesado ni mas pestañas en el navegador, probe dejar de usar chrome y usar opera o firefox y me pasa lo mismo. probe sin abrir por unas horas el navegador y usarla desconectada al wifi y me pasa igual, cada cierto tiempo se traba por completo.
Esos problemas pueden ser por distintas causas.
Es un portátil o un sobremesa…??
Que version de Windows tienes en el equipo…??
Esa version es la original o se cambio-actualizo a otra version, cual…??
Cuántos años hace que tienes ese equipo…??
El disco duro es el original o se cambio en alguna ocasión…??
Hola, te cuento. Es un portatil, windows 10 se cambió- actualizó, era el windows que tenia originalmente pero luego de un formateo el tecnico me instaló nuevamente el windows y ya no el original. el equipo tiene unos 3 años. el disco duro es relativamente nuevo tiene unos 8 meses. hasta hace alrededor de un mes y medio todo funcionaba bien, luego empezó a fallar esporadicamente y ahora es casi permanente
Bien… y ese disco es mecánico(HDD) o es uno nuevo de formato memoria(SSD)…??
Hiciste alguna verificación de infecciones en el equipo, tienes informes…??
hice pero no guardé los informes me recomendas algun antivirus particular para hacerlo? usaba el panda, no detectó nada. el disco es mecánico
Bien… pues para revisar tu máquina, sigue estos pasos, en el orden indicado y leyendo todo lo explicado.
Desactiva temporalmente el Antivirus
Cómo deshabilitar temporalmente su Antivirus, mientras estemos realizando TODOS los pasos.
Vamos a descargar en TU ESCRITORIO(y NO en otro lugar ) todas las herramientas que vamos a utilizar en este procedimiento (pero no las ejecutes todavía) :
Malwarebytes’ Anti-Malware + Manual.
revisa en detalle el manual,
para que sepas usarlo y configurarlo correctamente.
Farbar Recovery Scan Tool. seleccionando la versión adecuada para la arquitectura(32 o 64bits) de tu equipo.
Como saber si Mi Windows es de 32 o 64 Bits ?.
Ejecutas las herramientas de una en una y en el orden indicado :
Instalas y Ejecutas CCleaner siguiendo los pasos indicados en el manual.
Úsalo primero en su opción de Limpiador para borrar cookies, temporales de Internet y todos los archivos que te muestre como obsoletos.
Después usa su opción de Registro para limpiar todo el registro de Windows(haciendo copia de seguridad).
Instalas y Ejecutas MBAM siguiendo los pasos indicados en el manual.
Realiza un Análisis Personalizado.
Seleccionando TODOS a Cuarentena para enviarlo a la cuarentena y Reinicias el sistema.
En el apartado del programa
Historial de detecciones
encontrarás el informe de MBAM, que debes copiar y pegar en tu próxima respuesta, para poder analizarlo.
Ejecuta Adwcleaner.exe.
Pulsamos en el botón Analizar ahora, y espera a que se realice el proceso, inmediatamente pulsa siempre sobre el botón Iniciar Reparación.
Espera a que se complete y sigue las instrucciones, si te pidiera Reiniciar el sistema Aceptas.
El log/informe lo encontramos en la pestaña “Informes”, volviendo a abrir el programa si fuese necesario, para poder copiarlo y pegarlo en tu próxima respuesta.
El informe también se puede encontrar en C:\AdwCleaner\Logs\AdwCleaner[C00].txt
Junkware Removal Tool.-
Ejecuta JRT.exe.
Y pulsar cualquier tecla para continuar, esperar pacientemente a que termine el proceso.
Si en algún momento te pide Reiniciar hazlo.
Al finalizar, un registro/informe (JRT.txt) se guardara en el escritorio y se abrirá automáticamente.
Copia y pega el contenido de JRT.txt en tu próxima respuesta.
Farbar Recovery Scan Tool.-
Ejecuta FRST.exe.
En el mensaje de la ventana del Disclaimer/Responsabilidad, pulsamos Sí/Yes
En la ventana principal pulsamos en el botón Analizar/Scan y esperamos a que concluya el proceso.
Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.
Poner los informes en tu próxima respuesta de :
- Malwarebytes, AdwCleaner, JRT, FRST + Addition.txt, y en ese orden.
Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(más de 64.000 caracteres aprox.).
Y nos cuentas como funciona tu equipo en relación al problema planteado.
-Detalles del registro-
Fecha del análisis: 17/4/20
Hora del análisis: 18:30
Archivo de registro: a1b47a48-80f2-11ea-9b6d-9c5c8ed70ede.json
-Información del software-
Versión de los componentes: 1.0.875
Versión del paquete de actualización: 1.0.22586
Licencia: Prueba
-Información del sistema-
SO: Windows 10 (Build 18362.778)
CPU: x64
Sistema de archivos: NTFS
Usuario: DESKTOP-CESQG9F\Emiliano
-Resumen del análisis-
Tipo de análisis: Análisis personalizado
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 625341
Amenazas detectadas: 1
Amenazas en cuarentena: 1
Tiempo transcurrido: 57 min, 46 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 0
(No hay elementos maliciosos detectados)
Valor del registro: 0
(No hay elementos maliciosos detectados)
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 0
(No hay elementos maliciosos detectados)
Archivo: 1
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
# -------------------------------
# Malwarebytes AdwCleaner
# -------------------------------
# Build: 04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support:
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 04-17-2020
# Duration: 00:00:13
# OS: Windows 10 Home
# Cleaned: 19
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\ProgramData\SecuritySuite
Deleted C:\ProgramData\TotalAV
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\SSProtect
Deleted HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.totalav.passwordvaultassistant
Deleted HKLM\SOFTWARE\Mozilla\NativeMessagingHosts\com.totalav.passwordvaultassistant
Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474}
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.ASUSSmartGesture Folder C:\Program Files (x86)\ASUS\ASUS SMART GESTURE
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E3A8135-62FD-4EE5-857A-C6FAD69862F1}
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Smart Gesture Launcher
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\Software\Classes\CLSID\{F31B5912-07D6-4895-B4BA-5486CF3B18B1}
Deleted Preinstalled.ASUSSmartGesture Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
Deleted Preinstalled.ASUSSmartGesture Task C:\Windows\System32\Tasks\ASUS SMART GESTURE LAUNCHER
Deleted Preinstalled.HPCoolSense Folder C:\Users\Emiliano\AppData\Local\HP\HP COOLSENSE
Deleted Preinstalled.HPRegistrationService Folder C:\ProgramData\HP\HP REGISTRATION SERVICE
Deleted Preinstalled.HPSupportAssistant Folder C:\HP\SUPPORT
Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\Users\Emiliano\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{05F81C27-62A5-4A0C-8519-60CB66CF87C6}
Deleted Preinstalled.HPSureConnect Folder C:\Program Files\HPCOMMRECOVERY
[+] Delete Tracing Keys
[+] Reset Winsock
AdwCleaner[S00].txt - [3265 octets] - [17/04/2020 19:40:57]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by Emiliano (Administrator) on vie. 17/04/2020 at 19:49:25,89
File System: 2
Successfully deleted: C:\ProgramData\mntemp (File)
Successfully deleted: C:\Users\Public\asr.dat (File)
Registry: 0
Scan was completed on vie. 17/04/2020 at 20:08:10,84
End of JRT log
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-04-2020
Ran by Emiliano (administrator) on DESKTOP-CESQG9F (ASUSTeK COMPUTER INC. X540LA) (17-04-2020 20:10:33)
Running from C:\Users\Emiliano\Desktop
Loaded Profiles: Emiliano (Available Profiles: Emiliano)
Platform: Windows 10 Home Version 1903 18362.778 (X64) Language: Inglés (Estados Unidos)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Google LLC -> Google LLC) C:\Users\Emiliano\AppData\Local\Google\Chrome\Application\chrome.exe <10>
(Huawei Technologies Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(MAGIX AG) [File not signed] C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Malwarebytes Inc -> Malwarebytes) C:\Users\Emiliano\Desktop\MBAMWsc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20022.11011.0_x64__8wekyb3d8bbwe\Music.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\oobe\UserOOBEBroker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2003.8-0\NisSrv.exe
(Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194540538\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194542522\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Lsa: [Authentication Packages] msv1_0 SshdPinAuthLsa
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {20270739-F0D7-4CAA-824A-D270832638EA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2DDBF744-64BE-4170-97E8-2AAFC477B09B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2554443758-3275583905-1075851082-1001UA1d577ef4a5c741f => C:\Users\Emiliano\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-11-24] (Google Inc -> Google Inc.)
Task: {3A3CD896-B7A9-4EEF-A93B-DB820F15421C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2554443758-3275583905-1075851082-1001Core => C:\Users\Emiliano\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-11-24] (Google Inc -> Google Inc.)
Task: {4E435573-075B-4923-B877-515F91CFCACC} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [745480 2019-04-16] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {6D0D0100-5F8F-4772-AAE3-903ED4290564} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {7A99D76D-3E92-4223-A5EF-5FDCF831BE23} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {7BA3B3C9-E665-41F4-B63C-AD086519AC17} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [668464 2017-02-24] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {7EFFBE5D-EB00-4A9A-A170-6C14FFBA1184} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Emiliano\Desktop\esetonlinescanner.exe
Task: {858252A8-6E9F-48F3-9CDC-166D73742182} - System32\Tasks\Opera scheduled Autoupdate 1543096825 => C:\Users\Emiliano\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-27] (Opera Software AS -> Opera Software)
Task: {930D407B-14C6-4179-B3F5-0C335CAE3D3B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2554443758-3275583905-1075851082-1001Core1d577ef4a46ffcc => C:\Users\Emiliano\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-11-24] (Google Inc -> Google Inc.)
Task: {98B9CDEB-9649-4F88-838E-3AE4F2F653EB} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {9D515AD0-3196-4695-A76C-91B342424529} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_pepper.exe [1453624 2020-04-02] (Adobe Inc. -> Adobe)
Task: {AE0671F5-434A-41AC-927A-4FE52320222A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {BBBA54C1-4D05-40C8-9E06-A21748DBCE3E} - System32\Tasks\NCH Software\DoxillionDowngrade => C:\Program Files (x86)\NCH Software\Doxillion\doxillion.exe [1501264 2018-12-13] (NCH Software Pty Ltd -> NCH Software)
Task: {CF0E2B5F-39F6-4728-8B68-D68D5D97B998} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407736 2015-11-16] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {D8DB1D40-53A5-4670-935F-C79CF7AED0D6} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {D8F1426A-4AE9-4059-A7B8-3C98AA99D1AA} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Emiliano\Desktop\esetonlinescanner.exe
Task: {D96AB6DB-E5A0-4F48-9531-A38A7EE0FF9C} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2015-11-16] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {E21DF3FA-A723-4E8C-B664-1C9637D263D5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MpCmdRun.exe [480272 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E7ECC55A-0D86-4DC8-BC46-2AAF00700CFE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2554443758-3275583905-1075851082-1001UA => C:\Users\Emiliano\AppData\Local\Google\Update\GoogleUpdate.exe [153168 2018-11-24] (Google Inc -> Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{3849e469-9e9a-4d78-868d-6e03505a4f7c}: [DhcpNameServer]
Tcpip\..\Interfaces\{670f0800-8bad-4ff2-844e-ae0710d7507a}: [DhcpNameServer]
Tcpip\..\Interfaces\{6b499093-07f3-4c8f-9002-8d42a7db6656}: [DhcpNameServer]
Tcpip\..\Interfaces\{7a9a06e3-9036-4107-9b9f-21dbf944f7c0}: [DhcpNameServer]
Internet Explorer:
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194540538\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194540538\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194542522\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194542522\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin:,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32:,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32:,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32:,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32:,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN -> VideoLAN)
FF Plugin HKU\S-1-5-21-2554443758-3275583905-1075851082-1001: -> C:\Users\Emiliano\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-04-08] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194540538: -> C:\Users\Emiliano\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-04-08] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-2554443758-3275583905-1075851082-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-04172020194542522: -> C:\Users\Emiliano\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-04-08] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
CHR Profile: C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default [2020-04-17]
CHR HomePage: Default -> hxxp://
CHR StartupUrls: Default -> "hxxp://"
CHR Session Restore: Default -> is enabled.
CHR Extension: (Presentaciones) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-03-01]
CHR Extension: (DocHub - Edit and Sign PDF Documents) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\adgncicbhbjfpijkdmbijninnhnmiblj [2020-03-01]
CHR Extension: (Safe Torrent Scanner) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\aegnopegbbhjeeiganiajffnalhlkkjb [2020-03-01]
CHR Extension: (Documentos) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-03-01]
CHR Extension: (Google Drive) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-03-01]
CHR Extension: (YouTube) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-03-01]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-04-06]
CHR Extension: (Hojas de cálculo) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-03-01]
CHR Extension: (Cloud SWF Player with Drive) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffhhaadihgfcgmlefioblaahpnglnkbk [2020-03-01]
CHR Extension: (EditThisCookie) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2020-03-01]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-10]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-01]
CHR Extension: (Gmail) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-03-01]
CHR Extension: (Chrome Media Router) - C:\Users\Emiliano\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-11]
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\WINDOWS\System32\drivers\AdminService.exe [382712 2019-09-04] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1272560 2015-05-21] (Disc Soft Ltd -> Disc Soft Ltd)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [1700968 2017-06-12] (Intel Corporation -> Intel Corporation)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2019-12-26] (Huawei Technologies Co., Ltd. -> ) [File not signed]
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-12-01] (Intel(R) pGFX -> Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [732448 2017-02-24] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [548648 2017-02-24] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [197264 2017-06-06] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2018-11-24] () [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-04-10] (Intel Corporation-Wireless Connectivity Solutions -> )
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2475312 2019-12-29] (Electronic Arts, Inc. -> Electronic Arts)
S2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3352376 2019-12-29] (Electronic Arts, Inc. -> Electronic Arts)
S3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [974848 2019-03-01] (Microsoft Windows -> )
S3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [290816 2020-03-14] (Microsoft Windows -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12001112 2019-08-07] (TeamViewer GmbH -> TeamViewer GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3750304 2017-04-10] (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation)
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project)
R3 AsusSGDrv; C:\WINDOWS\System32\drivers\AsusSGDrv.sys [140032 2019-08-19] (ASUSTek Computer Inc. -> ASUS Corporation)
R3 athr; C:\WINDOWS\System32\drivers\athw8x.sys [4233728 2019-03-19] (Microsoft Windows -> Qualcomm Atheros Communications, Inc.)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-03-07] (Bluestack Systems, Inc -> Bluestack System Inc. )
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69560 2017-06-12] (Intel Corporation -> Intel Corporation)
R3 dptf_pch; C:\WINDOWS\System32\drivers\dptf_pch.sys [50696 2015-08-13] (Intel(R) Software -> Intel Corporation)
R3 DroidCam; C:\WINDOWS\System32\drivers\droidcam.sys [33592 2020-03-16] (DEV47 APPS -> Dev47Apps)
R3 DroidCamVideo; C:\WINDOWS\System32\drivers\droidcamvideo.sys [229432 2020-03-16] (DEV47 APPS -> Dev47Apps)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-11-24] (Disc Soft Ltd -> Disc Soft Ltd)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [382392 2017-06-12] (Intel Corporation -> Intel Corporation)
S3 Hamachi; C:\WINDOWS\System32\drivers\Hamdrv.sys [45680 2017-02-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32680 2019-08-07] (ASUSTek Computer Inc. -> ASUS)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2019-12-26] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R0 IntelHSWPcc; C:\WINDOWS\System32\drivers\IntelPcc.sys [88256 2015-06-10] (Intel(R) Software -> Intel Corporation)
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [60504 2017-05-16] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [64600 2017-05-16] (Synaptics Incorporated -> Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ===================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-17 20:10 - 2020-04-17 20:12 - 000022142 _____ C:\Users\Emiliano\Desktop\FRST.txt
2020-04-17 20:10 - 2020-04-17 20:11 - 000000000 ____D C:\FRST
2020-04-17 20:08 - 2020-04-17 20:08 - 000000668 _____ C:\Users\Emiliano\Desktop\JRT.txt
2020-04-17 19:39 - 2020-04-17 19:43 - 000000000 ____D C:\AdwCleaner
2020-04-17 19:37 - 2020-04-17 20:08 - 000000000 ____D C:\Users\Emiliano\Desktop\para reparar compu
2020-04-17 17:19 - 2020-04-17 19:56 - 000000000 ____D C:\Users\Emiliano\Desktop\sdk
2020-04-17 17:18 - 2020-04-17 17:18 - 006009816 _____ (Malwarebytes) C:\Users\Emiliano\Desktop\MBAMInstallerService.exe
2020-04-17 17:18 - 2020-04-17 17:18 - 002376736 _____ (Malwarebytes) C:\Users\Emiliano\Desktop\MBAMWsc.exe
2020-04-17 17:18 - 2020-04-17 17:18 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-04-17 17:18 - 2020-04-17 13:39 - 001965536 _____ (Malwarebytes) C:\Users\Emiliano\Desktop\mbuns.exe
2020-04-17 14:51 - 2020-04-17 14:51 - 001214392 _____ C:\Users\Emiliano\Desktop\000 - Material para Envios a
2020-04-17 14:00 - 2020-04-17 14:00 - 000013226 _____ C:\Users\Emiliano\Documents\cc_20200417_140049.reg
2020-04-17 13:48 - 2020-04-17 19:48 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-04-17 13:48 - 2020-04-17 13:48 - 000002894 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-04-17 13:48 - 2020-04-17 13:48 - 000000870 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-04-17 13:48 - 2020-04-17 13:48 - 000000870 _____ C:\ProgramData\Desktop\CCleaner.lnk
2020-04-17 13:48 - 2020-04-17 13:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2020-04-17 13:48 - 2020-04-17 13:48 - 000000000 ____D C:\Program Files\CCleaner
2020-04-17 13:43 - 2020-04-17 13:43 - 002281472 _____ (Farbar) C:\Users\Emiliano\Desktop\FRST64.exe
2020-04-17 13:42 - 2020-04-17 13:42 - 008196784 _____ (Malwarebytes) C:\Users\Emiliano\Desktop\adwcleaner_8.0.4.exe
2020-04-17 13:40 - 2020-04-17 13:40 - 001790024 _____ (Malwarebytes) C:\Users\Emiliano\Desktop\JRT.exe
2020-04-17 13:39 - 2020-04-17 13:39 - 022267336 _____ (Piriform Software Ltd) C:\Users\Emiliano\Desktop\ccsetup565.exe
2020-04-17 13:39 - 2020-04-17 13:39 - 001965536 _____ (Malwarebytes) C:\Users\Emiliano\Desktop\MBSetup.exe
2020-04-17 09:42 - 2020-04-17 09:42 - 000003812 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2020-04-17 09:42 - 2020-04-17 09:42 - 000003370 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2020-04-16 23:42 - 2020-04-16 23:42 - 000000753 _____ C:\Users\Emiliano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2020-04-16 23:28 - 2020-04-16 23:28 - 011284138 _____ C:\Users\Emiliano\Desktop\rvn_c0y0t3_rvn_-_01x12_-__m720p.LAT.mkv.crdownload
2020-04-16 18:07 - 2020-04-16 20:10 - 749888210 _____ C:\Users\Emiliano\Desktop\rvn_c0y0t3_rvn_-_01x13_-__m720p.LAT.mkv
2020-04-16 13:36 - 2020-04-16 13:36 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 022636544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 018027520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 008013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 007756800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 006523048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 005910016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 004611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 003512320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 002951832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-04-16 13:36 - 2020-04-16 13:36 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001870408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001665216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001545216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001477112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001077064 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 001013000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000892416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000775696 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000673704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000673464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2020-04-16 13:36 - 2020-04-16 13:36 - 000538160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2020-04-16 13:36 - 2020-04-16 13:36 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000381440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\es.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-04-16 13:36 - 2020-04-16 13:36 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000268008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrad.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000185952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000123952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-04-16 13:36 - 2020-04-16 13:36 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000089336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-04-16 13:36 - 2020-04-16 13:36 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasacct.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumapi.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iaspolcy.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ias.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\
2020-04-16 13:36 - 2020-04-16 13:36 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-04-16 13:36 - 2020-04-16 13:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-04-16 13:35 - 2020-04-16 13:35 - 017790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 014818816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 007849216 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 004563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 003802624 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 003753472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 003587384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 003547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 003109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 002767928 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 002717184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 002114560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 002086656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001960448 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-04-16 13:35 - 2020-04-16 13:35 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001656904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001646048 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001603584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001512832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 001497600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 001427456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001378528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 001261808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001243648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001136128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 001011200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000915192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000811320 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000759272 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000684560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000638480 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000618296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000515600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000513576 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000487784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-04-16 13:35 - 2020-04-16 13:35 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000339304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000277864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000259776 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000251704 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000231912 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000147696 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000127280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000066624 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000058880 _____ C:\WINDOWS\system32\runexehelper.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000050544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000033080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys
2020-04-16 13:35 - 2020-04-16 13:35 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\
2020-04-16 13:35 - 2020-04-16 13:35 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wksprtPS.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2020-04-16 13:35 - 2020-04-16 13:35 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-04-16 13:35 - 2020-04-16 13:35 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 002131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 002126144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 001263856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-04-16 13:34 - 2020-04-16 13:34 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000879616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-04-16 13:34 - 2020-04-16 13:34 - 000437560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000297272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-04-16 13:34 - 2020-04-16 13:34 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-04-16 13:34 - 2020-04-16 13:34 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000151352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-04-16 13:34 - 2020-04-16 13:34 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe
2020-04-16 13:34 - 2020-04-16 13:34 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll
2020-04-16 13:34 - 2020-04-16 13:34 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\flpydisk.sys
2020-04-16 13:34 - 2020-04-16 13:34 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sfloppy.sys
2020-04-16 13:09 - 2020-03-17 00:57 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-04-16 13:09 - 2020-03-17 00:56 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-04-16 12:05 - 2020-04-16 12:05 - 000011746 _____ C:\Users\Emiliano\Documents\cc_20200416_120504.reg
2020-04-15 14:49 - 2020-04-15 14:49 - 000179290 _____ C:\Users\Emiliano\Documents\cc_20200415_144943.reg
2020-04-14 16:42 - 2020-04-14 16:43 - 000000035 _____ C:\ProgramData\droidcam-settings
2020-04-14 16:40 - 2020-04-14 16:40 - 000001102 _____ C:\Users\Emiliano\Desktop\DroidCamApp.lnk
2020-04-14 16:40 - 2020-04-14 16:40 - 000000000 ____D C:\Users\Emiliano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DroidCam
2020-04-14 16:39 - 2020-04-14 16:40 - 000000000 ____D C:\Program Files (x86)\DroidCam
2020-04-13 17:57 - 2020-04-13 17:58 - 001306629 _____ C:\Users\Emiliano\Desktop\Formación Full Coaching 2020.pdf
2020-04-13 02:30 - 2020-04-13 02:30 - 000000165 ____H C:\Users\Emiliano\Desktop\~$cobrado cdh.xlsx
2020-04-13 00:43 - 2020-04-15 04:00 - 000009318 _____ C:\Users\Emiliano\Desktop\cobrado cdh.xlsx
2020-04-11 19:02 - 2020-04-11 19:02 - 000016147 _____ C:\Users\Emiliano\Desktop\consultaaliascbu20200319120518.pdf
2020-04-11 14:16 - 2020-04-11 14:16 - 005433803 _____ C:\Users\Emiliano\Desktop\Grabación (15).m4a
2020-04-08 18:48 - 2020-04-08 18:48 - 000000000 ____D C:\Users\Emiliano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2020-04-06 20:36 - 2020-04-06 20:36 - 000080047 _____ C:\Users\Emiliano\Desktop\CD AACOP 2020-2022.jpeg
2020-04-06 17:22 - 2020-04-06 17:22 - 000000165 ____H C:\Users\Emiliano\Desktop\~$Listado Asociados incriptos habilitados a votar ASAMBELA 2020.xlsx
2020-04-05 12:41 - 2020-04-05 12:45 - 000000000 ____D C:\Users\Emiliano\Documents\Image-Line
2020-04-04 00:32 - 2020-04-16 12:47 - 000000000 ____D C:\Users\Emiliano\Desktop\Canciones con Pablo
2020-04-04 00:10 - 2020-04-04 00:10 - 000000000 ____D C:\Users\Emiliano\Desktop\inteligencia-emocional-recursos-adicionales
2020-04-03 22:21 - 2020-04-03 22:21 - 000698119 _____ C:\Users\Emiliano\Desktop\Invitacion a CD 2020 - 2022 Emiliano Pardo Guenzatti.pdf
2020-04-02 20:34 - 2020-04-02 20:35 - 022267336 _____ (Piriform Software Ltd) C:\Users\Emiliano\Downloads\ccsetup565.exe
2020-04-02 17:51 - 2020-04-02 20:38 - 000003808 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-04-02 17:50 - 2020-04-02 17:51 - 000000000 ____D C:\Users\Emiliano\AppData\Local\Adobe
2020-04-02 16:21 - 2020-04-07 12:59 - 000022347 ____H C:\Users\Emiliano\Desktop\~WRL1008.tmp
2020-04-02 10:39 - 2020-04-02 10:39 - 000001419 _____ C:\Users\Emiliano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
2020-04-02 01:09 - 2020-04-02 01:09 - 000001889 _____ C:\Users\Public\Desktop\FL Studio 20.lnk
2020-04-02 01:09 - 2020-04-02 01:09 - 000001889 _____ C:\ProgramData\Desktop\FL Studio 20.lnk
2020-04-02 01:09 - 2020-04-02 01:09 - 000000000 ____D C:\Users\Emiliano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2020-04-02 01:09 - 2020-04-02 01:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2020-04-02 01:09 - 2020-04-02 01:09 - 000000000 ____D C:\Program Files\Common Files\VST2
2020-04-02 01:09 - 2020-04-02 01:09 - 000000000 ____D C:\Program Files\Common Files\Propellerhead Software
2020-04-02 01:09 - 2020-04-02 01:09 - 000000000 ____D C:\Program Files (x86)\VstPlugins
2020-04-02 01:02 - 2020-04-02 01:10 - 000000000 ____D C:\Program Files\Image-Line
2020-04-02 00:52 - 2020-04-02 00:52 - 000000000 ____D C:\Program Files (x86)\MSXML 4.0
2020-04-01 23:29 - 2020-04-01 23:29 - 000000000 ___HD C:\OneDriveTemp
2020-04-01 22:51 - 2020-04-01 22:51 - 000000000 ____D C:\Users\Emiliano\Documents\Descargas MAGIX
2020-04-01 22:50 - 2020-04-01 23:23 - 000000000 ____D C:\Users\Emiliano\AppData\Local\MusicMaker
2020-04-01 22:48 - 2020-04-01 22:48 - 000000000 ____D C:\Users\Public\Documents\MAGIX
2020-04-01 22:48 - 2020-04-01 22:48 - 000000000 ____D C:\ProgramData\Documents\MAGIX
2020-04-01 22:47 - 2020-04-02 00:52 - 000000000 ___RD C:\Users\Emiliano\Documents\MAGIX
2020-04-01 22:47 - 2020-04-01 22:47 - 000001241 _____ C:\Users\Public\Desktop\Music Maker.lnk
2020-04-01 22:47 - 2020-04-01 22:47 - 000001241 _____ C:\ProgramData\Desktop\Music Maker.lnk
2020-04-01 22:47 - 2020-04-01 22:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2020-04-01 22:46 - 2020-04-02 00:55 - 000000000 ____D C:\ProgramData\MAGIX
2020-04-01 22:46 - 2020-04-02 00:55 - 000000000 ____D C:\Program Files (x86)\MAGIX
2020-04-01 21:52 - 2020-04-01 22:48 - 000000000 ____D C:\Users\Emiliano\AppData\Roaming\MAGIX
2020-04-01 21:52 - 2020-04-01 21:52 - 000000000 ____D C:\Users\Emiliano\Documents\MAGIX Downloads
2020-04-01 21:47 - 2020-04-01 21:47 - 003032920 _____ (MAGIX Software GmbH) C:\Users\Emiliano\Desktop\trial_musicmaker2015_dlm.exe
2020-04-01 14:47 - 2020-04-01 14:48 - 010518528 _____ C:\Users\Emiliano\Desktop\run coyote run.mp4.crdownload
2020-03-28 23:37 - 2020-03-28 23:37 - 000012721 ____H C:\Users\Emiliano\Desktop\~WRL0004.tmp
2020-03-27 19:52 - 2020-03-27 19:52 - 000000000 ____D C:\Users\Emiliano\Documents\Zoom
2020-03-22 15:11 - 2020-04-02 20:38 - 000003026 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2020-03-22 14:51 - 2020-03-22 14:51 - 000002092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks Multi-Instance Manager.lnk
2020-03-22 14:51 - 2020-03-22 14:51 - 000001771 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks.lnk
2020-03-22 14:48 - 2020-03-22 15:07 - 000000000 ____D C:\ProgramData\BlueStacks
2020-03-22 14:48 - 2020-03-22 14:48 - 000000000 ____D C:\Program Files\BlueStacks
2020-03-22 14:44 - 2020-03-22 14:48 - 000000000 ____D C:\Users\Public\BlueStacks
2020-03-22 14:44 - 2020-03-22 14:48 - 000000000 ____D C:\Users\Emiliano\AppData\Local\BlueStacks
2020-03-22 14:44 - 2020-03-22 14:47 - 000000000 ____D C:\Users\Emiliano\AppData\Local\BlueStacksSetup
==================== One month (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2020-04-17 20:09 - 2019-03-19 01:52 - 000000000 ____D C:\ProgramData\
2020-04-17 19:56 - 2019-03-19 01:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-04-17 19:46 - 2018-11-24 09:05 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-04-17 19:46 - 2018-11-24 09:05 - 000000000 __SHD C:\Users\Emiliano\IntelGraphicsProfiles
2020-04-17 19:45 - 2020-01-27 00:03 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-17 19:45 - 2019-08-21 22:02 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-04-17 19:44 - 2019-03-19 01:37 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2020-04-17 19:43 - 2020-01-26 23:37 - 000000000 ____D C:\Program Files (x86)\ASUS
2020-04-17 19:43 - 2018-11-24 20:47 - 000000000 ____D C:\Users\Emiliano\AppData\Local\HP
2020-04-17 19:43 - 2018-11-24 19:32 - 000000000 ____D C:\Users\Emiliano\AppData\Roaming\Hewlett-Packard
2020-04-17 19:43 - 2017-07-10 07:01 - 000000000 ____D C:\ProgramData\HP
==================== Files in the root of some directories ========
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2020
Ran by Emiliano (17-04-2020 20:13:39)
Ran by Emiliano (17-04-2020 20:13:39)
Running from C:\Users\Emiliano\Desktop
Windows 10 Home Version 1903 18362.778 (X64) (2020-01-27 03:04:55)
Boot Mode: Normal
==================== Accounts: =============================
Administrator (S-1-5-21-2554443758-3275583905-1075851082-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2554443758-3275583905-1075851082-503 - Limited - Disabled)
Emiliano (S-1-5-21-2554443758-3275583905-1075851082-1001 - Administrator - Enabled) => C:\Users\Emiliano
Guest (S-1-5-21-2554443758-3275583905-1075851082-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2554443758-3275583905-1075851082-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Custom CLSID (Whitelisted): ==============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-2554443758-3275583905-1075851082-1001_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\localserver32 -> C:\Users\Emiliano\AppData\Local\Google\Chrome\Application\81.0.4044.113\notification_helper.exe (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-2554443758-3275583905-1075851082-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Emiliano\AppData\Local\Google\Update\\psuser_64.dll (Google LLC -> Google LLC)
CustomCLSID: HKU\S-1-5-21-2554443758-3275583905-1075851082-1001_Classes\CLSID\{E9E7529D-7F09-410B-AF2A-CC154473B19C}\InprocServer32 -> C:\Users\Emiliano\AppData\Local\Google\Update\\psuser_64.dll (Google LLC -> Google LLC)
ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
==================== Codecs (Whitelisted) ====================
==================== Shortcuts & WMI ========================
==================== Loaded Modules (Whitelisted) =============
==================== Alternate Data Streams (Whitelisted) ========
==================== Safe Mode (Whitelisted) ==================
==================== Association (Whitelisted) =================
==================== Internet Explorer trusted/restricted ==========
==================== Hosts content: =========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
==================== Other Areas ===========================
(Currently there is no automatic fix for this section.)
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(If an entry is included in the fixlist, it will be removed.)
==================== FirewallRules (Whitelisted) ================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
10-04-2020 18:48:55 Punto de control programado
16-04-2020 13:06:59 Windows Update
17-04-2020 12:04:57 Operación de restauración
17-04-2020 19:41:44 AdwCleaner_BeforeCleaning_17/04/2020_19:41:32
17-04-2020 19:49:30 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices ============
==================== Event log errors: ========================

Application errors:
Application errors:
Windows Defender:
==================== Memory info ===========================
Ahi logré hacer todo, como te comentaba, como los cuelgues son intermitentes, recien luego de que pasa un tiempo logro saber si ahora funciona bien o no. Ahora está funcionando, pero me llevó bastante tiempo hacer todo el proceso porque se me quedó trabada varias veces en el camino. Muchisimas gracias por tu atención y ayuda, hay algo más que tenga que hacer?
Bien… y ahora sigue estos pasos, MUY Importante
Realiza una copia de seguridad del registro :
Para hacerlo descarga
DelFix.exe(en tu escritorio).
Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).
Atención, ahora marca/selecciona únicamente la casilla
Create registry backup, las demás casillas NO.
Pulsar en Run.
Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.
Con los demás programas cerrados ve a
y escribe Notepad.exe.
- Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio Esto es muy importante.
Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.
Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.
Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).
Presionar el botón FIX/Corregir y aguardar a que termine.
La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).
Pegar el contenido de este fichero en tu próxima respuesta.
Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-04-2020
Ran by Emiliano (17-04-2020 21:01:49) Run:1
Running from C:\Users\Emiliano\Desktop
Loaded Profiles: Emiliano (Available Profiles: Emiliano)
Boot Mode: Normal
fixlist content:
Restore point was successfully created.
=========== EmptyTemp: ==========
Bien… y ahora pasemos a verificar como tienes el disco duro de tu equipo, para hacerlo sigue el 3er. MÉTODO: descrito en esta Faq de ayuda ¿Cómo usar CHKDSK para realizar una comprobación del disco?, que es válida también para un Windows 10.
Una vez terminado el proceso, que puede/debe durar bastante rato, debes poner el informe que se habrá guardado por parte de Windows y que tienes que encontrar siguiendo estos pasos ¿Cuándo y cómo usar el visor de eventos (eventvwr.msc)?
Fíjate bien en como es el informe que viene en ese tema, para que busques algo similar y NO pongas cualquier otra cosa.
Nos pones el informe y comentas como sigue el problema del equipo.
Hola, no puedo abrir el CHKDSK, creo tener desactivado el windows defender y aun asi me dice que no puedo abrirlo incluso cuando quiero ejecutarlo como administrador. Como hago para desactivar por completo el windows defender?
Como que NO puedes ejecutarlo…??
Que mensaje o pantalla de aviso te sale al intentar ejecutarlo…??
Pon una imagen Como Insertar una imagen.
logré abrirlo y ejecutarlo. paso copia de informe
Nombre de registro:Application
Origen: Microsoft-Windows-Wininit
Fecha: 18/4/2020 16:56:19
Id. del evento:1001
Categoría de la tarea:Ninguno
Nivel: Información
Palabras clave:Clásico
Usuario: No disponible
Perfecto, ahora solo quedaría que comentes cómo sigue el problema inicialmente planteado…??