Lentitud pc y correo electronico

Instalo el ESET oc y me sale un error del sistema: el programa no puede iniciarse porque falta api-ms-core-winrt-error- [1-1-0.dll en el equipo. Intente reinstalar el programa para corregir este probema

Lo he hecho varias veces y sale lo mismo

ya me ha dejado.


30/06/2020 12:14:13
Archivos analizados: 240460
Archivos detectados: 14
Archivos desinfectados: 14
Tiempo total de análisis 04:12:05
Estado del análisis: Finalizado


C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.7_42330.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.8_42449.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.8_42576.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.9_42606.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.9_42973.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.9_43085.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.9_43295.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.4.9_43388.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.5.0_43580.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.5.0_44090.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.5.4_44632.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Users\usuario\AppData\Roaming\uTorrent\updates\3.5.5_45395.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Windows\AutoKMS\AutoKMS.exe	MSIL/HackKMS.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
C:\Windows\KMSEmulator.exe	Win32/HackKMS.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado

Hola

Siento la demora, no recibí aviso de tu respuesta.

Cómo sigue el problema.

Un saludo

Hola. Ok , pues sigue con lentitud. Había virus no?

Hola

1. Descarga CCleaner a Tu escritorio. Siguiendo Su manual, lo instalas y ejecutas y utiliza las dos opciones del Uso Simple (Limpiador y Registro) del mismo, tal como se explican en el manual.

2. Realiza un análisis completo del Disco duro, siguiendo esta guía: Análisis y Escaneo del Disco Duro

3. Libera espacio de los discos siguiendo esta guía: Liberar espacios en Discos y Particiones

4. Desfragmenta el/los discos duros y particiones del PC, siguiendo esta guía: Desfragmentar Discos y Particiones

Nos comentas como sigue el funcionamiento del PC.

Un saludo

algo mejor habia virus?

Hola

Estaba bastante infectado ese equipo.

Prueba en modo seguro a ver que tal funciona.

Un saludo

Hola , en modo seguro mejor pero no tengo acceso a internet , no se si es así o no.

Por otra parte tengo avast anti virus y no se si me recomiendas otro y donde lo puedo obtener

Gracias

Hola

Perdona el retraso, no recibí aviso de tu respuesta :flushed:

Vas a desinstalar el antivirus Avast y comprobar si sigue lento.

Utiliza su herramienta de desinstalación.

Comenta como sigue el funcionamiento.

Un saludo

Hola, ya he hecho todo y algo mejor ahora no tengo antivirus cual me recomiendas y que sa gratis? mil gracias

Hola

Vuelve a analizar con FRST con las indicaciones que te di aquí para ver si quedan restos del antivirus antes de instalar otro.

Un saludo


Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 26-07-2020
Ejecutado por usuario (administrador) sobre USUARIO-PC (HP HP Notebook) (27-07-2020 10:41:24)
Ejecutado desde C:\Users\usuario\Desktop
Perfiles cargados: usuario
Platform: Windows 7 Professional Service Pack 1 (X64) Idioma: Español (España, internacional)
Internet Explorer Versión 11 (Navegador predeterminado: "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" -- "%1")
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleFirefoxHost.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
(Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc. -> Apple, Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\secd.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <7>
(Hewlett Packard -> Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8100\Bin\HPNetworkCommunicatorCom.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <7>
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(RealVNC Ltd -> RealVNC Ltd) C:\Program Files\RealVNC\VNC Server\vncagent.exe
(RealVNC Ltd -> RealVNC Ltd) C:\Program Files\RealVNC\VNC Server\vncserver.exe
(RealVNC Ltd -> RealVNC Ltd) C:\Program Files\RealVNC\VNC Server\vncserverui.exe
(Spotify AB -> Spotify Ltd) C:\Users\usuario\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TeamViewer -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe
(Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302392 2020-05-20] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-05-07] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restricción <==== ATENCIÓN
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd -> Disc Soft Ltd)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [110392 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [Spotify Web Helper] => C:\Users\usuario\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2017-01-15] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [68408 2020-05-07] (Apple Inc. -> Apple Inc.)
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [GoogleChromeAutoLaunch_16162356186E4CC670F4882E63992D2D] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [28990136 2020-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\...\Print\Monitors\HP 5B12 Status Monitor: C:\Windows\system32\hpinksts5B12LM.dll [331664 2012-06-13] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP DeskJet 3630 series): C:\Windows\system32\HPDiscoPME311.dll [840096 2019-03-19] (HP Inc -> HP Inc.)
HKLM\...\Print\Monitors\HP Discovery Port Monitor (HP Officejet Pro 8100): C:\Windows\system32\HPDiscoPM5B12.dll [741480 2012-11-01] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP E311 Status Monitor: C:\Windows\system32\hpinkstsE311LM.dll [392200 2019-03-15] (HP Inc -> HP Inc.)
HKLM\...\Print\Monitors\MONVNC: C:\Windows\system32\VNCpm.dll [37704 2015-12-07] (RealVNC Ltd -> RealVNC Ltd)
HKLM\...\Print\Monitors\pdfcmon: C:\Windows\system32\pdfcmon.dll [120072 2016-03-18] (pdfforge GmbH -> pdfforge GmbH)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.89\Installer\chrmstp.exe [2020-07-14] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\83.1.4957.116\Installer\chrmstp.exe [2020-07-14] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de pantalla y Selector de OneNote 2010.lnk [2019-11-04]
ShortcutTarget: Recorte de pantalla y Selector de OneNote 2010.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Supervisar alertas de tinta - HP Officejet Pro 8100 (Red).lnk [2020-07-27]
ShortcutAndArgument: Supervisar alertas de tinta - HP Officejet Pro 8100 (Red).lnk -> C:\Windows\system32\RunDll32.exe => "C:\Program Files\HP\HP Officejet Pro 8100\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN4CIHV1XP05MX;CONNECTION=NW;MONITOR=1;
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {026C4D81-5E5B-4FA0-82A9-AEC8A37BAC2F} - System32\Tasks\HPCustParticipation HP DeskJet 3630 series => C:\Program Files\HP\HP DeskJet 3630 series\Bin\HPCustPartic.exe [6437792 2019-03-19] (HP Inc -> HP Inc.)
Task: {22C5CD7D-769B-4BB2-8FA5-7858C66134C4} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1954104 2020-07-02] (Avast Software s.r.o. -> AVAST Software)
Task: {2CBE0600-8D15-4192-9E94-B00458EDD069} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\usuario\Desktop\ESETOnlineScanner_ESL(1).exe
Task: {31AFAAFC-33FB-46EF-9BDB-FE6FA624FC14} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe
Task: {34983FEE-06F2-4E03-B716-9202534D4CFC} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\usuario\Desktop\ESETOnlineScanner_ESL(1).exe
Task: {39BE1D27-683D-4DDD-B73F-91CDBEA514FD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe
Task: {3D3710B1-36C9-4AD7-A1B8-EC3FD2B684F6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-23] (Google Inc -> Google Inc.)
Task: {4664AD29-3BE0-4609-9AD1-A61DBDB5ED8B} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
Task: {4A705DB5-CEA8-4B7E-AEB9-DD9A204B9B32} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe
Task: {556ECC5D-20BE-4344-9987-BC23807A6C1B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {61E8C387-8B3E-4F4B-B459-68301A575B28} - System32\Tasks\HPCustParticipation HP Officejet Pro 8100 => C:\Program Files\HP\HP Officejet Pro 8100\Bin\HPCustPartic.exe [4119656 2012-11-01] (Hewlett Packard -> Hewlett-Packard Co.)
Task: {7C093CD0-D540-4D64-884B-F25AFE0FD9A7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-01-23] (Google Inc -> Google Inc.)
Task: {86F84DD4-D4A9-4E06-BE7A-4A74B8C0C7F6} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe)
Task: {8F4F3B62-DA9B-4E53-A117-D9F882CFC3A6} - System32\Tasks\SafeZone scheduled Autoupdate 1458839839 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe
Task: {97CC74B0-E502-4C4A-9754-5F75FF2FF90A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A2F637C2-6A36-400F-B3CB-28C205EAC088} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater – Install HPSA => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe
Task: {A38105BD-FBE3-4166-9D2B-B28D32B7A2E1} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [67896 2020-05-07] (Apple Inc. -> Apple Inc.)
Task: {A65FF4F4-7C0F-414F-9AC8-A93FCD17472F} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [124112 2020-07-11] (Mozilla Corporation -> Mozilla Foundation)
Task: {A74693E6-573F-4F50-95E7-26B22E1A0973} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe
Task: {A8A67CFF-5E7A-494C-A743-822901A166E5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
Task: {C06F0C2E-1EC4-48B4-ACE7-6E7A36B882CE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe)
Task: {C1BE1A83-2ACD-41AD-A296-230C092DCD5C} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {D7856F99-3FD7-48AA-BE25-B14E56E28AAC} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
Task: {DB0A668C-94EF-4DF1-BC32-B037FE007A56} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
Task: {E1ED6606-A91F-4720-A259-EBE6B125C4B3} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1954104 2020-07-02] (Avast Software s.r.o. -> AVAST Software)
Task: {E55FB4BB-097F-4D07-9D24-7B4EE6491D2E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24584376 2020-06-17] (Piriform Software Ltd -> Piriform Software Ltd)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 10 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 10 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3DB4291E-5AF2-40B3-A101-2BC64C75114F}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A0F487C7-090E-4ADA-A0DE-12784EFB1591}: [DhcpNameServer] 192.168.0.10

Internet Explorer:
==================
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.es/
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Aplicación auxiliar de inicio de sesión en la cuenta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)

FireFox:
========
FF DefaultProfile: ebblgn1f.default-1488485703866
FF ProfilePath: C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866 [2020-07-27]
FF DownloadDir: C:\Users\usuario\Desktop
FF Homepage: Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866 -> hxxp://www.google.es/
FF Notifications: Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866 -> hxxps://web.telegram.org; hxxps://web.whatsapp.com; hxxps://www.latostadora.com; hxxps://www.viagogo.es; hxxps://1.nextyourcontent.com; hxxps://www.facebook.com; hxxps://www.casadellibro.com
FF Extension: (Favoritos de iCloud) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2018-08-15]
FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2020-07-04]
FF Extension: (Avast Online Security) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2020-03-09] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/aos/update.json]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1232202.dll [2018-03-09] (Adobe Systems, Inc.) [Archivo no firmado]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-12-01] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)

Chrome: 
=======
CHR Profile: C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default [2020-07-27]
CHR Notifications: Default -> hxxps://drive.google.com
CHR Extension: (Presentaciones) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Documentos) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-21]
CHR Extension: (YouTube) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-21]
CHR Extension: (Save Emails to PDF by cloudHQ) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\dngbhajancmfmdnmhhdknhooljkddgnk [2020-05-18]
CHR Extension: (Hojas de cálculo) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-05-28]
CHR Extension: (Multi Forward for Gmail) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjmdplljmniahpamcmabdnahmjdlikpm [2017-08-09]
CHR Extension: (Player para ver Movistar+) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\kenfcfndncbbggmafjjeihkdclggbojn [2020-04-02]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-03-30]
CHR Extension: (Gmail) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-04]
CHR Extension: (Chrome Media Router) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-07-16]

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-05-20] (Apple Inc. -> Apple Inc.)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\83.1.4957.116\elevation_service.exe [1063088 2020-07-02] (Avast Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-02-28] (BattlEye Innovations e.K. -> )
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [370784 2018-11-14] (Intel Corporation -> Intel Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer -> TeamViewer GmbH)
R2 vncserver; C:\Program Files\RealVNC\VNC Server\vncserver.exe [5653736 2015-12-07] (RealVNC Ltd -> RealVNC Ltd)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe [495720 2018-07-04] (Wondershare Technology Co.,Ltd -> Wondershare)
R2 WsDrvInst; C:\Program Files (x86)\Wondershare\dr.fone\Library\DriverInstaller\DriverInstall.exe [120016 2018-07-04] (Wondershare Technology Co.,Ltd -> Wondershare)

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

S3 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [226616 2009-07-14] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc)
S3 amdide64; C:\Windows\system32\drivers\amdide64.sys [11904 2011-12-18] (Advanced Micro Devices, Inc. -> Advanced Micro Devices Inc.)
S3 amd_sata; C:\Windows\system32\drivers\amd_sata.sys [82560 2012-04-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [42624 2012-04-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
S3 DC133; C:\Windows\system32\drivers\DC133.sys [39320 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
S3 DC150; C:\Windows\system32\drivers\DC150.sys [39832 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
S3 DC154; C:\Windows\system32\drivers\DC154.sys [48136 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
S3 DC300e; C:\Windows\system32\drivers\DC300e.sys [40344 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
S3 DC324e; C:\Windows\system32\drivers\DC324e.sys [49752 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
R0 DC3410; C:\Windows\System32\drivers\DC3410.sys [48328 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
S3 DC4300; C:\Windows\system32\drivers\DC4300.sys [48360 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
S3 DC600e; C:\Windows\system32\drivers\DC600e.sys [40744 2011-05-02] (Dawicontrol Computersysteme GmbH -> Dawicontrol GmbH)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2016-03-21] (Disc Soft Ltd -> Disc Soft Ltd)
S3 LSI_SAS; C:\Windows\system32\drivers\lsi_sas.sys [133712 2010-12-20] (LSI Corporation -> LSI Corporation)
S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51496 2012-02-28] (LSI Corporation -> LSI Corporation)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-11-05] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
R3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2015-12-07] (Microsoft Windows Hardware Compatibility Publisher -> RealVNC Ltd.)
S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae64.sys [X]
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]

S3 MBAMFarflt; system32\DRIVERS\farflt.sys [X]

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) ===================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-07-27 10:41 - 2020-07-27 10:44 - 000030165 _____ C:\Users\usuario\Desktop\FRST.txt
2020-07-27 10:35 - 2020-07-27 10:40 - 002295808 _____ (Farbar) C:\Users\usuario\Desktop\FRST64.exe
2020-07-26 11:22 - 2020-07-26 11:22 - 000001590 _____ C:\Users\usuario\Desktop\cc_20200726_112207.reg
2020-07-26 11:09 - 2020-07-26 11:09 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update
2020-07-26 11:09 - 2020-07-26 11:09 - 000002816 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC
2020-07-26 11:09 - 2020-07-26 11:09 - 000000782 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-07-26 11:09 - 2020-07-26 11:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2020-07-26 11:08 - 2020-07-26 11:09 - 000000000 ____D C:\Program Files\CCleaner
2020-07-26 11:07 - 2020-07-26 11:07 - 025838336 _____ (Piriform Software Ltd) C:\Users\usuario\Desktop\ccsetup568(1).exe
2020-07-26 11:01 - 2020-07-26 11:01 - 025838336 _____ (Piriform Software Ltd) C:\Users\usuario\Desktop\ccsetup568.exe
2020-07-26 10:43 - 2020-07-26 10:43 - 010890336 _____ (AVAST Software) C:\Users\usuario\Desktop\avastclear.exe
2020-07-17 11:23 - 2020-07-17 11:23 - 000520542 _____ C:\Users\usuario\Desktop\PARTE URGENCIAS 170720 NISSA ALJARAFE.pdf
2020-07-13 11:37 - 2020-07-27 10:16 - 000000000 ____D C:\Users\usuario\Desktop\ISLA MAGICA
2020-07-11 09:15 - 2020-07-12 07:48 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-07-06 16:53 - 2020-07-06 16:53 - 000062048 _____ C:\Users\usuario\Desktop\entradas.pdf
2020-07-06 09:44 - 2020-07-06 09:44 - 000130130 _____ C:\Users\usuario\Desktop\ORDEN NO RENOVACION PELAYO AUTO 060720.pdf
2020-07-04 19:18 - 2020-07-04 19:18 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2020-07-03 10:06 - 2020-07-03 10:06 - 000176731 _____ C:\Users\usuario\Desktop\Aviso de renovación_0000M7032710.pdf
2020-06-30 12:19 - 2020-06-30 12:20 - 000000000 ____D C:\KVRT_Data
2020-06-30 12:15 - 2020-07-19 20:38 - 000003730 _____ C:\Windows\system32\Tasks\EOSv3 Scheduler onLogOn
2020-06-30 12:15 - 2020-07-19 20:38 - 000003290 _____ C:\Windows\system32\Tasks\EOSv3 Scheduler onTime
2020-06-30 07:48 - 2020-06-30 07:48 - 000000000 ____D C:\Users\usuario\AppData\Local\ESET
2020-06-28 07:25 - 2020-07-27 10:08 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-06-27 15:59 - 2020-06-27 15:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2020-06-27 15:56 - 2020-06-27 15:56 - 000001747 _____ C:\Users\Public\Desktop\iTunes.lnk
2020-06-27 15:56 - 2020-06-27 15:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2020-06-27 15:56 - 2020-06-27 15:56 - 000000000 ____D C:\Program Files\iPod
2020-06-27 15:54 - 2020-06-27 15:56 - 000000000 ____D C:\Program Files\iTunes
2020-06-27 07:56 - 2020-06-27 07:56 - 002290688 _____ (Farbar) C:\Users\usuario\Downloads\FRST64(2).exe
2020-06-27 07:50 - 2020-06-27 07:50 - 002290688 _____ (Farbar) C:\Users\usuario\Downloads\FRST64(1).exe

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-07-27 10:43 - 2020-06-21 08:58 - 000000000 ____D C:\FRST
2020-07-27 10:21 - 2009-07-14 06:45 - 000037184 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-07-27 10:21 - 2009-07-14 06:45 - 000037184 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-07-27 10:17 - 2016-11-29 11:29 - 000000000 ____D C:\Users\usuario\AppData\LocalLow\Mozilla
2020-07-27 10:10 - 2016-03-25 13:25 - 000000000 ___RD C:\Users\usuario\iCloudDrive
2020-07-27 10:08 - 2016-03-21 13:18 - 000000000 __SHD C:\Users\usuario\IntelGraphicsProfiles
2020-07-27 10:08 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2020-07-27 10:07 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-07-26 10:56 - 2016-03-18 14:58 - 000000000 ____D C:\ProgramData\AVAST Software
2020-07-26 10:31 - 2018-05-09 18:41 - 000000000 ____D C:\Users\usuario\AppData\Local\AVAST Software
2020-07-19 20:38 - 2019-01-23 14:10 - 000003536 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-07-19 20:38 - 2019-01-23 14:10 - 000003408 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-07-19 20:38 - 2016-03-18 14:59 - 000000000 ____D C:\Windows\system32\Tasks\AVAST Software
2020-07-14 21:58 - 2019-01-23 14:11 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-07-14 21:58 - 2019-01-23 14:11 - 000002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-07-14 21:50 - 2019-04-12 08:47 - 000003732 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-07-14 21:50 - 2018-05-09 18:43 - 000002427 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-07-14 21:50 - 2018-05-09 18:43 - 000002384 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2020-07-14 09:26 - 2020-06-08 09:32 - 000000000 ____D C:\Users\usuario\Desktop\MUSICA
2020-07-13 11:37 - 2017-03-10 17:02 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2020-07-12 07:48 - 2018-11-20 12:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-07-06 09:56 - 2016-03-18 14:58 - 000000000 ____D C:\Users\usuario\AppData\Local\PDFCreator
2020-07-04 13:00 - 2020-02-09 13:02 - 000000000 ____D C:\Users\usuario\Desktop\VIRUS
2020-07-04 12:58 - 2020-05-12 16:15 - 000000000 ____D C:\Users\usuario\AppData\Roaming\Zoom
2020-06-30 20:16 - 2016-03-25 13:33 - 000000000 ____D C:\Users\usuario\AppData\Local\54C7DF88-CF0E-4F28-A385-835F39CFA749.aplzod
2020-06-30 11:05 - 2016-03-21 13:46 - 000000000 ____D C:\Windows\AutoKMS
2020-06-29 18:02 - 2016-03-28 12:55 - 000000000 ____D C:\Users\usuario\Documents\DOCUMENTOS PERSONALES
2020-06-29 17:00 - 2019-05-15 20:48 - 000000000 _____ C:\Windows\system32\last.dump
2020-06-28 06:19 - 2016-03-18 13:44 - 000000000 ____D C:\Users\usuario
2020-06-27 12:14 - 2016-07-04 10:56 - 000000000 ____D C:\Users\usuario\AppData\Roaming\uTorrent
2020-06-27 10:24 - 2020-06-08 09:33 - 000000000 ____D C:\Users\usuario\Desktop\NIÑOS
2020-06-27 10:23 - 2016-11-14 23:21 - 000000000 ____D C:\Users\usuario\Documents\SEGUROS
2020-06-27 08:31 - 2020-02-06 19:29 - 000000265 _____ C:\DelFix.txt

==================== Archivos en la raíz de algunos directorios ========

2020-06-22 09:53 - 2020-06-22 09:53 - 000000000 ____H () C:\Users\usuario\AppData\Local\BITD96D.tmp
2020-06-22 09:47 - 2020-06-22 09:47 - 000000000 _____ () C:\Users\usuario\AppData\Local\{AA134E08-5493-44EA-850D-7F498BFC1467}

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)


LastRegBack: 2020-07-26 12:39
==================== Final de FRST.txt ======================== 

 Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 26-07-2020
Ejecutado por usuario (27-07-2020 10:45:25)
Ejecutado desde C:\Users\usuario\Desktop
Windows 7 Professional Service Pack 1 (X64) (2016-03-18 11:44:26)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-1779699512-3134601836-353050797-500 - Administrator - Disabled)
HomeGroupUser$ (S-1-5-21-1779699512-3134601836-353050797-1002 - Limited - Enabled)
Invitado (S-1-5-21-1779699512-3134601836-353050797-501 - Limited - Enabled) => C:\Users\Invitado
usuario (S-1-5-21-1779699512-3134601836-353050797-1005 - Administrator - Enabled) => C:\Users\usuario

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 29.0.0.112 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.293 - Adobe)
Adobe Shockwave Player 12.3 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.3.2.202 - Adobe Systems, Inc.)
AnyTrans 4.4.2 (HKLM-x32\...\{E580ED1F-AAF8-4F7E-B174-54BFA2B94E0B}}_is1) (Version: 4.4.2 - iMobie Inc.)
Apple Application Support (32 bits) (HKLM-x32\...\{11C4575B-4B32-44D2-A097-D59A00BA60DE}) (Version: 8.5 - Apple Inc.)
Apple Application Support (64 bits) (HKLM\...\{D39B163A-9E12-442C-95E9-33FA5746AB21}) (Version: 8.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C788AE25-3D4E-4D18-811B-3219F778487E}) (Version: 13.5.1.2 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 83.1.4957.116 - Los creadores de Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.136.333 - AVAST Software) Hidden
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.68 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Estudio para la mejora del producto HP DeskJet 3630 series (HKLM\...\{1CFA98AE-D205-4511-AC2E-3689CDC8B54C}) (Version: 40.13.1176.1978 - HP Inc.)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 9.0.1.1049 - Foxit Software Inc.)
Galería de fotos (HKLM-x32\...\{198CEF22-A27F-4DC7-9B66-2C22A4B1CA09}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 84.0.4147.89 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
HP DeskJet 3630 series Ayuda (HKLM-x32\...\{B53FAA7E-9898-42BE-8C80-A9CA84298CAB}) (Version: 35.0.0 - Hewlett Packard)
HP DeskJet 3630 series Software básico del dispositivo (HKLM\...\{E90EF0BD-36D2-4304-BAB1-271D3C069CE4}) (Version: 40.13.1176.1978 - HP Inc.)
HP Dropbox Plugin (HKLM-x32\...\{EDCB09F0-C5AF-4052-9C60-5BBCEC13818C}) (Version: 40.13.54.81239 - HP)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Google Drive Plugin (HKLM-x32\...\{CE60824D-9857-407B-8D39-A1A25E9812A4}) (Version: 40.13.54.81239 - HP)
HP Officejet Pro 8100 Ayuda (HKLM-x32\...\{5DF9A4C1-DA2D-4279-A85C-066F815F6A8A}) (Version: 28.0.0 - Hewlett Packard)
HP Officejet Pro 8100 Estudio para la mejora del producto (HKLM\...\{E1EA832F-5397-4F91-B84D-7C1B2499CE85}) (Version: 28.0.1321.0 - Hewlett-Packard Co.)
HP Officejet Pro 8100 Software básico del dispositivo (HKLM\...\{BD24905D-E2BE-4DFB-9F00-EE02994DCB28}) (Version: 28.0.1321.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Solutions Framework (HKLM-x32\...\{E8FF0A82-0696-4347-B4AE-708DE306FFE9}) (Version: 12.14.49.15 - HP Inc.)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
iCloud (HKLM\...\{F0AD317D-AE18-45D0-BE5B-30074AFE6740}) (Version: 7.19.0.10 - Apple Inc.)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.5058 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.0.27 - Intel Corporation)
iTunes (HKLM\...\{3DF04B5D-B611-49AE-BE15-B185AFBF8134}) (Version: 12.10.7.3 - Apple Inc.)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Microsoft .NET Framework 4.8 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.8.03761 - Microsoft Corporation)
Microsoft .NET Framework 4.8 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.8.03761 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{9C82436F-F19C-42A4-B476-F87A28A95BF9}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 78.0.2 (x64 es-ES) (HKLM\...\Mozilla Firefox 78.0.2 (x64 es-ES)) (Version: 78.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 63.0.3 - Mozilla)
Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.3.0 - pdfforge GmbH)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.30182 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.61 - REALTEK Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version:  - Microsoft)
Skype versión 8.53 (HKLM-x32\...\Skype_is1) (Version: 8.53 - Skype Technologies S.A.)
Software para dispositivos de chipset Intel® (HKLM-x32\...\{4b42e8de-255e-495f-a650-cc88d23c1ee4}) (Version: 10.0.26 - Intel(R) Corporation) Hidden
Spotify (HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\Spotify) (Version: 1.0.45.186.g3b5036d6 - Spotify AB)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated)
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.56083 - TeamViewer)
Telegram Desktop versión 1.7.10 (HKU\S-1-5-21-1779699512-3134601836-353050797-1005\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.7.10 - Telegram Messenger LLP)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN)
VNC Server 5.3.0 (HKLM\...\{612C8634-34CD-4358-B042-63F7462D1954}) (Version: 5.3.0.15303 - RealVNC Ltd)
VNC Viewer 5.3.0 (HKLM\...\{B89A3744-846A-4537-B7B5-013DB2FFFC89}) (Version: 5.3.0.15303 - RealVNC Ltd)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Wondershare Filmora(Build 8.5.1) (HKLM\...\Wondershare Filmora_is1) (Version:  - Wondershare Software)
Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [6671064 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [4171480 2013-12-19] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ningún archivo
ContextMenuHandlers1: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-12-11] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [PDFCreator.ShellContextMenu] -> {d9cea52e-100d-4159-89ea-76e845bc13e1} => C:\Program Files\PDFCreator\PDFCreatorShell.DLL [2016-02-19] (pdfforge GmbH -> pdfforge GmbH)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2020-05-07] (Apple Inc. -> Apple Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2018-11-14] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Foxit_ConvertToPDF_Reader] -> {A94757A0-0226-426F-B4F1-4DF381C630D3} => C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\ConvertToPDFShellExtension_x64.dll [2017-12-11] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Lista blanca) ====================

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2020-05-12 16:06 - 2016-07-21 10:54 - 000137728 _____ () [Archivo no firmado] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2020-05-12 16:06 - 2017-09-12 10:34 - 001506304 _____ () [Archivo no firmado] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2016-03-21 18:03 - 2015-05-07 22:47 - 000074240 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.dll
2016-03-21 10:12 - 2013-04-02 00:19 - 000574464 _____ (Realtek Semiconductor Corp.) [Archivo no firmado] C:\Windows\system32\Rtlihvs.dll
2020-05-12 16:06 - 2017-09-12 10:36 - 000708608 _____ (Wondershare) [Archivo no firmado] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSProducstInfo.dll

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2009-07-14 04:34 - 2020-06-28 07:18 - 000000035 _____ C:\Windows\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-1779699512-3134601836-353050797-1005\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spotify => "C:\Users\usuario\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) C:\Windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [SPPSVC-In-TCP] => (Allow) C:\Windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{CC8FB09D-D8FC-442F-B990-ED7222F3F787}C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [UDP Query User{FFC54088-1611-4D95-B344-72672F8178D9}C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [TCP Query User{8EDF9302-B655-4E23-9126-6BD4EE1F56B7}C:\program files\HP\hp deskjet 3630 series\Bin\HPNetworkCommunicatorCom.exe] => (Allow) C:\program files\HP\hp deskjet 3630 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc -> HP Inc.)
FirewallRules: [UDP Query User{A082E42E-4DA4-4A9B-9B9A-F0A0C1A3113F}C:\program files\HP\hp deskjet 3630 series\Bin\HPNetworkCommunicatorCom.exe] => (Allow) C:\program files\HP\hp deskjet 3630 series\Bin\HPNetworkCommunicatorCom.exe (HP Inc -> HP Inc.)
FirewallRules: [TCP Query User{55281CA3-430C-4023-8547-3607B2C7CF97}C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [UDP Query User{1CA78AB4-2527-42F2-AF30-C2FA560D1C2C}C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp officejet pro 8100\bin\hpnetworkcommunicatorcom.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{0BAE602C-8CE4-45F9-947A-CCA49C17B9F9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7154C0AD-2963-429C-9BC4-CA7C71B5123D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{A49F270F-7DB8-45AA-8BC2-0E8C3E1D4F36}C:\program files\hp\hp deskjet 3630 series\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp deskjet 3630 series\bin\hpnetworkcommunicatorcom.exe (HP Inc -> HP Inc.)
FirewallRules: [UDP Query User{4A245B59-ED37-433E-8FFD-87FEF599BFB6}C:\program files\hp\hp deskjet 3630 series\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp deskjet 3630 series\bin\hpnetworkcommunicatorcom.exe (HP Inc -> HP Inc.)
FirewallRules: [{E8C5A042-9F84-4380-9C72-8A7038F98021}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{FDE329D0-0922-4BAD-8643-F92E9076BD20}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Puntos de Restauración =========================

12-07-2020 10:25:26 Punto de control programado
15-07-2020 21:33:25 Windows Update
26-07-2020 13:36:30 Punto de control programado

==================== Dispositivos defectuosos en el Administrador de dispositivos ============

Name: Intel(R) Atom(TM)/Celeron(R)/Pentium(R) Processor Intel DPTF Thermal Framework Device - 3400
Description: Intel(R) Atom(TM)/Celeron(R)/Pentium(R) Processor Intel DPTF Thermal Framework Device - 3400
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Malwarebytes Anti-Exploit
Description: Malwarebytes Anti-Exploit
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: ESProtectionDriver
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Mobile 5th Generation Intel(R) Core(TM) Camarillo Device - 1603
Description: Mobile 5th Generation Intel(R) Core(TM) Camarillo Device - 1603
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Teredo Tunneling Pseudo-Interface
Description: Adaptador de tunelización Teredo de Microsoft
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (07/27/2020 10:20:45 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: La copia de seguridad no se completó debido a un error al escribir en la ubicación de copia de seguridad E:\. Error: La ubicación de copia de seguridad especificada no es válida o no se encuentra. Revise la configuración de copia de seguridad y compruebe la ubicación de copia de seguridad. (0x81000006).

Error: (07/27/2020 10:09:01 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: No se puede inicializar el índice.

Detalles:
	El catálogo del índice de contenido está dañado.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/27/2020 10:09:01 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: No se puede inicializar la aplicación.

Contexto: aplicación Windows

Detalles:
	El catálogo del índice de contenido está dañado.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/27/2020 10:09:01 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: No se puede inicializar el objeto Recopilador.

Contexto: aplicación Windows, catálogo SystemIndex

Detalles:
	El catálogo del índice de contenido está dañado.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/27/2020 10:09:01 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: No se puede inicializar el complemento <Search.TripoliIndexer>.

Contexto: aplicación Windows, catálogo SystemIndex

Detalles:
	No se ha encontrado el elemento.  (HRESULT : 0x80070490) (0x80070490)

Error: (07/27/2020 10:08:54 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: No se puede inicializar el complemento <Search.JetPropStore>.

Contexto: aplicación Windows, catálogo SystemIndex

Detalles:
	El catálogo del índice de contenido está dañado.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (07/27/2020 10:08:54 AM) (Source: Windows Search Service) (EventID: 9002) (User: )
Description: El servicio Windows Search no puede cargar la información del almacén de propiedades.

Contexto: aplicación Windows, catálogo SystemIndex

Detalles:
	La base de datos del índice de contenido está dañada.  (HRESULT : 0xc0041800) (0xc0041800)

Error: (07/27/2020 10:08:54 AM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: El servicio Windows Search se está deteniendo porque hay un problema con el indizador: The catalog is corrupt.

Detalles:
	El catálogo del índice de contenido está dañado.  (HRESULT : 0xc0041801) (0xc0041801)


Errores del sistema:
=============
Error: (07/27/2020 10:09:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: El servicio Agrupación de red del mismo nivel depende del servicio Protocolo de resolución de nombres de mismo nivel, el cual no pudo iniciarse debido al siguiente error: 
%%-2140993535

Error: (07/27/2020 10:09:46 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: El servicio Protocolo de resolución de nombres de mismo nivel se cerró con el siguiente error: 
%%-2140993535

Error: (07/27/2020 10:09:46 AM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: El Protocolo de resolución de nombres de mismo nivel no se inició debido a un error de creación de la identidad predeterminada con código de error: 0x80630801.

Error: (07/27/2020 10:09:46 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: El servicio Agrupación de red del mismo nivel depende del servicio Protocolo de resolución de nombres de mismo nivel, el cual no pudo iniciarse debido al siguiente error: 
%%-2140993535

Error: (07/27/2020 10:09:46 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: El servicio Protocolo de resolución de nombres de mismo nivel se cerró con el siguiente error: 
%%-2140993535

Error: (07/27/2020 10:09:46 AM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: El Protocolo de resolución de nombres de mismo nivel no se inició debido a un error de creación de la identidad predeterminada con código de error: 0x80630801.

Error: (07/27/2020 10:09:37 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: El servicio Agrupación de red del mismo nivel depende del servicio Protocolo de resolución de nombres de mismo nivel, el cual no pudo iniciarse debido al siguiente error: 
%%-2140993535

Error: (07/27/2020 10:09:37 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: El servicio Protocolo de resolución de nombres de mismo nivel se cerró con el siguiente error: 
%%-2140993535


==================== Información de la memoria =========================== 

BIOS: Insyde F.11 07/23/2015
Placa base: HP 80C1
Procesador: Intel(R) Core(TM) i3-5005U CPU @ 2.00GHz
Porcentaje de memoria en uso: 96%
RAM física total: 4016.67 MB
RAM física disponible: 154.27 MB
Virtual total: 7070.82 MB
Virtual disponible: 2288.98 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:465.27 GB) (Free:329.78 GB) NTFS

\\?\Volume{64642f43-ecf8-11e5-b677-806e6f6e6963}\ () (Fixed) (Total:0.49 GB) (Free:0.46 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 1530B495)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.3 GB) - (Type=07 NTFS)

==================== Final de Addition.txt =======================

Hola

:arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe( en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla "Create registry backup", las demás NO.

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

A continuación :warning: con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restricción <==== ATENCIÓN
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\83.1.4957.116\Installer\chrmstp.exe [2020-07-14] (Avast Software s.r.o. -> AVAST Software)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN
Task: {22C5CD7D-769B-4BB2-8FA5-7858C66134C4} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1954104 2020-07-02] (Avast Software s.r.o. -> AVAST Software)
Task: {31AFAAFC-33FB-46EF-9BDB-FE6FA624FC14} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe
Task: {4664AD29-3BE0-4609-9AD1-A61DBDB5ED8B} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
Task: {556ECC5D-20BE-4344-9987-BC23807A6C1B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {A8A67CFF-5E7A-494C-A743-822901A166E5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
Task: {E1ED6606-A91F-4720-A259-EBE6B125C4B3} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1954104 2020-07-02] (Avast Software s.r.o. -> AVAST Software)
FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2020-07-04]
FF Extension: (Avast Online Security) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2020-03-09] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/aos/update.json]
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ningún archivo]
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\83.1.4957.116\elevation_service.exe [1063088 2020-07-02] (Avast Software s.r.o. -> AVAST Software)
S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae64.sys [X]
S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]
S3 MBAMFarflt; system32\DRIVERS\farflt.sys [X]
2020-07-26 10:43 - 2020-07-26 10:43 - 010890336 _____ (AVAST Software) C:\Users\usuario\Desktop\avastclear.exe
2020-06-28 07:25 - 2020-07-27 10:08 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-07-26 10:56 - 2016-03-18 14:58 - 000000000 ____D C:\ProgramData\AVAST Software
2020-07-26 10:31 - 2018-05-09 18:41 - 000000000 ____D C:\Users\usuario\AppData\Local\AVAST Software
2020-07-19 20:38 - 2016-03-18 14:59 - 000000000 ____D C:\Windows\system32\Tasks\AVAST Software
2020-07-14 21:50 - 2019-04-12 08:47 - 000003732 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-07-14 21:50 - 2018-05-09 18:43 - 000002427 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-07-14 21:50 - 2018-05-09 18:43 - 000002384 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2020-07-13 11:37 - 2017-03-10 17:02 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2020-06-22 09:47 - 2020-06-22 09:47 - 000000000 _____ () C:\Users\usuario\AppData\Local\{AA134E08-5493-44EA-850D-7F498BFC1467}
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 83.1.4957.116 - Los creadores de Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.136.333 - AVAST Software) Hidden
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ningún archivo

HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe (Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.


Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).
  • Presionar el botón FIX/Corregir y aguardar a que termine.
  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pega el contenido de este fichero en tu próxima respuesta.

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Un saludo

Hola, lo del modo seguro no va, como la ultima vez que me lo pediste pasó lo mismo, he hecho el paso en modo normal tal y como me indicaste


Resultados de la corrección de Farbar Recovery Scan Tool (x64) Versión: 02-08-2020
Ejecutado por usuario (04-08-2020 14:07:20) Run:2
Ejecutado desde C:\Users\usuario\Desktop
Perfiles cargados: usuario
Modo de Inicio: Normal
==============================================

fixlist contenido:
*****************
START

CREATERESTOREPOINT:

CLOSEPROCESSES:

(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update.4.136.333\AvastBrowserCrashHandler.exe

(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update.4.136.333\AvastBrowserCrashHandler64.exe

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restricci�n <==== ATENCI�N

HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application3.1.4957.116\Installer\chrmstp.exe [2020-07-14] (Avast Software s.r.o. -> AVAST Software)

FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricci�n <==== ATENCI�N

Task: {22C5CD7D-769B-4BB2-8FA5-7858C66134C4} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1954104 2020-07-02] (Avast Software s.r.o. -> AVAST Software)

Task: {31AFAAFC-33FB-46EF-9BDB-FE6FA624FC14} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe

Task: {4664AD29-3BE0-4609-9AD1-A61DBDB5ED8B} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)

Task: {556ECC5D-20BE-4344-9987-BC23807A6C1B} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe

Task: {A8A67CFF-5E7A-494C-A743-822901A166E5} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe

Task: {E1ED6606-A91F-4720-A259-EBE6B125C4B3} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1954104 2020-07-02] (Avast Software s.r.o. -> AVAST Software)

FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2020-07-04]

FF Extension: (Avast Online Security) - C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] [2020-03-09] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/aos/update.json]

FF Plugin: @microsoft.com/GENUINE -> disabled [Ning�n archivo]

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ning�n archivo]

S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)

S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-05-09] (AVAST Software s.r.o. -> AVAST Software)

S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application3.1.4957.116\elevation_service.exe [1063088 2020-07-02] (Avast Software s.r.o. -> AVAST Software)

S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae64.sys [X]

S2 MBAMChameleon; \SystemRoot\System32\Drivers\MbamChameleon.sys [X]

S3 MBAMFarflt; system32\DRIVERS\farflt.sys [X]

2020-07-26 10:43 - 2020-07-26 10:43 - 010890336 _____ (AVAST Software) C:\Users\usuario\Desktop\avastclear.exe

2020-06-28 07:25 - 2020-07-27 10:08 - 000000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat

2020-07-26 10:56 - 2016-03-18 14:58 - 000000000 ____D C:\ProgramData\AVAST Software

2020-07-26 10:31 - 2018-05-09 18:41 - 000000000 ____D C:\Users\usuario\AppData\Local\AVAST Software

2020-07-19 20:38 - 2016-03-18 14:59 - 000000000 ____D C:\Windows\system32\Tasks\AVAST Software

2020-07-14 21:50 - 2019-04-12 08:47 - 000003732 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)

2020-07-14 21:50 - 2018-05-09 18:43 - 000002427 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk

2020-07-14 21:50 - 2018-05-09 18:43 - 000002384 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk

2020-07-13 11:37 - 2017-03-10 17:02 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update

2020-06-22 09:47 - 2020-06-22 09:47 - 000000000 _____ () C:\Users\usuario\AppData\Local\{AA134E08-5493-44EA-850D-7F498BFC1467}

Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 83.1.4957.116 - Los creadores de Avast Secure Browser)

Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.136.333 - AVAST Software) Hidden

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ning�n archivo

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ning�n archivo



HOSTS:

REMOVEPROXY:

EMPTYTEMP:

CMD: netsh winsock reset

CMD: ipconfig /renew

CMD: ipconfig /flushdns

CMD: bitsadmin /reset /allusers

CMD: netsh advfirewall reset

CMD: netsh advfirewall set allprofiles state ON

CMD: netsh int ipv4 reset

CMD: netsh int ipv6 reset

END
*****************

El punto de restauración fue creado correctamente.
Procesos cerrados correctamente.
C:\Program Files (x86)\AVAST Software\Browser\Update.4.136.333\AvastBrowserCrashHandler.exe => No se encontró ningún proceso en ejecución
C:\Program Files (x86)\AVAST Software\Browser\Update.4.136.333\AvastBrowserCrashHandler64.exe => No se encontró ningún proceso en ejecución
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => eliminado correctamente
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{30C521FB-255B-46C8-9F0D-EE5AE371C9AA} => eliminado correctamente
HKLM\SOFTWARE\Policies\Mozilla => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{22C5CD7D-769B-4BB2-8FA5-7858C66134C4}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22C5CD7D-769B-4BB2-8FA5-7858C66134C4}" => eliminado correctamente
C:\Windows\System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Secure Browser Heartbeat Task (Logon)" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{31AFAAFC-33FB-46EF-9BDB-FE6FA624FC14}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31AFAAFC-33FB-46EF-9BDB-FE6FA624FC14}" => eliminado correctamente
C:\Windows\System32\Tasks\Avast Software\Overseer => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4664AD29-3BE0-4609-9AD1-A61DBDB5ED8B}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4664AD29-3BE0-4609-9AD1-A61DBDB5ED8B}" => eliminado correctamente
C:\Windows\System32\Tasks\AvastUpdateTaskMachineCore => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AvastUpdateTaskMachineCore" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{556ECC5D-20BE-4344-9987-BC23807A6C1B}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{556ECC5D-20BE-4344-9987-BC23807A6C1B}" => eliminado correctamente
C:\Windows\System32\Tasks\AVAST Software\Avast settings backup => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{A8A67CFF-5E7A-494C-A743-822901A166E5}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8A67CFF-5E7A-494C-A743-822901A166E5}" => eliminado correctamente
C:\Windows\System32\Tasks\Avast Emergency Update => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Emergency Update" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E1ED6606-A91F-4720-A259-EBE6B125C4B3}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1ED6606-A91F-4720-A259-EBE6B125C4B3}" => eliminado correctamente
C:\Windows\System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Secure Browser Heartbeat Task (Hourly)" => eliminado correctamente
C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] => movido correctamente
C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\ebblgn1f.default-1488485703866\Extensions\[email protected] => movido correctamente
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => eliminado correctamente
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => eliminado correctamente
HKLM\System\CurrentControlSet\Services\avast => eliminado correctamente
avast => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\avastm => eliminado correctamente
avastm => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\AvastSecureBrowserElevationService => eliminado correctamente
AvastSecureBrowserElevationService => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\ESProtectionDriver => eliminado correctamente
ESProtectionDriver => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\MBAMChameleon => eliminado correctamente
MBAMChameleon => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\MBAMFarflt => eliminado correctamente
MBAMFarflt => servicio eliminado correctamente
C:\Users\usuario\Desktop\avastclear.exe => movido correctamente
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => movido correctamente
C:\ProgramData\AVAST Software => movido correctamente
C:\Users\usuario\AppData\Local\AVAST Software => movido correctamente
C:\Windows\system32\Tasks\AVAST Software => movido correctamente
"C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)" => no encontrado
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk => movido correctamente
C:\Users\Public\Desktop\Avast Secure Browser.lnk => movido correctamente
"C:\Windows\system32\Tasks\Avast Emergency Update" => no encontrado
C:\Users\usuario\AppData\Local\{AA134E08-5493-44EA-850D-7F498BFC1467} => movido correctamente
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 83.1.4957.116 - Los creadores de Avast Secure Browser) => Error: Ninguna corrección automática encontrada para esta entrada.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}\\SystemComponent" => eliminado correctamente
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => eliminado correctamente
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => eliminado correctamente
C:\Windows\System32\Drivers\etc\hosts => movido correctamente
Hosts restaurado correctamente.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-21-1779699512-3134601836-353050797-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-21-1779699512-3134601836-353050797-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente


========= Final de RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= Final de CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Conexi¢n de red inal mbrica 2 mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Conexi¢n de red Bluetooth mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Conexi¢n de  rea local mientras los medios
est‚n desconectados.

Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica 2:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de Ethernet Conexi¢n de red Bluetooth:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica:

   Sufijo DNS espec¡fico para la conexi¢n. . : 
   V¡nculo: direcci¢n IPv6 local. . . : fe80::c12:130:57bc:686c%12
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.10
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.0.1

Adaptador de Ethernet Conexi¢n de  rea local:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : yumitel.com

Adaptador de t£nel isatap.{3DB4291E-5AF2-40B3-A101-2BC64C75114F}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel isatap.{59BE2B5E-D7DE-4D14-A85E-2EE0452FF0BE}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

========= Final de CMD: =========



========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= Final de CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

{CA457B59-6299-4328-8E89-9F351829CF30} canceled.
1 out of 1 jobs canceled.

========= Final de CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= Final de CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= Final de CMD: =========


========= netsh int ipv4 reset =========

Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


========= netsh int ipv6 reset =========

No hay valores configurados por el usuario para restablecer.


========= Final de CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 4446166 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 2579260 B
Edge => 0 B
Chrome => 3398351 B
Firefox => 272407252 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 256 B
LocalService => 256 B
NetworkService => 256 B
Dimitry => 256 B
usuario => 6844772 B
Invitado => 6844772 B

RecycleBin => 0 B
EmptyTemp: => 290.8 MB datos temporales eliminados.

================================


El sistema necesita reiniciarse.

==== Final de Fixlog 14:09:16 ====