"Malwarebytes dejó de funcionar"

Ok, hice el analisis y detectó 11 archivos:

Dejé las opciones por defecto y le di a continuar. El programa terminó la desinfeccion, aunque el Malwarebytes sigue sin funcionar. Tomé las capturas del reporte:

Dejó algunos archivos en cuarentena, ¿deberia eliminarlos?. Saludos

OK perfecto @ManU has actuado correctamente y conforme a las isntrucciones que te dije.

OK.

Déjalos a la Cuarentena. Cuando estos se encuentran en esta ya no suponen un peligro/amenaza.

1) Realizas un análisis con Dr Web CureIt siguiendo las instrucciones de su manual perfectamente explicadas. Lo descargas de donde se indica en su manual.

Traes el reporte de este.

Salu2.

Ok copié la ultima parte del reporte, el programa detectó 11 archivos:


Start curing
-----------------------------------------------------------------------------

C:\Windows\system32\drivers\etc\hosts - cured
C:\System Volume Information\SystemRestore\FRStaging\Users\Compaq\AppData\Local\Temp\nsb3D3D.tmp\Fusion.dll - quarantined
C:\System Volume Information\SystemRestore\FRStaging\Users\Compaq\AppData\Local\Temp\ns7402FA9C\34AA4056_stp\bytefence-installer-5.6.4.3.exe - quarantined
C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\01 age king\GOODIES\MACHINE\MACHINE.EXE - quarantined
C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\02 age Conquerors\GOODIES\MACHINE\MACHINE.EXE - quarantined
C:\Users\Compaq\Documents\RemoveWAT 2.2.6\removewat.exe  - quarantined
C:\Users\Compaq\Documents\dpr\Tools\DrvUpdater.exe - quarantined
C:\Users\Compaq\Documents\dpr\Tools\modules\CPU\OpenHardwareMonitorReportNet2.exe - quarantined
C:\Users\Compaq\Documents\dpr\Tools\modules\CPU\OpenHardwareMonitorReportNet4.exe - quarantined
C:\Users\Compaq\Documents\dpr\Tools\modules\bugreport\SysInfo.exe - quarantined
C:\Users\Compaq\Downloads\Programas\Daemon Tools\DAEMON TOOLS LITE 10 2018\DAEMON Tools Lite.exe - quarantined

Total 176304173668 bytes in 217233 files scanned (437665 objects)
Total 217123 files (437480 objects) are clean
Total 10 files (28 objects) are infected
Total 1 file are suspicious
Total 11 files (12 objects) are neutralized
Total 156 files are raised error condition
Scan time is 05:39:25.652

(5:40 horas escaneando, lol)

Neutralizó las amenazas y dejo 11 archivos en cuarentena, aunque Malwarebytes aun no abre.

¿Debo eliminar o conservar alguno?, Saludos.

Hola, buenas @ManU

:+1: primero estamos desinfectando tu máquina. Después nos encargaremos de reparar/hacer que funcione Malwarebytes un poco de paciencia.

De momento déjalos en la Cuarentena ya te indicaré yo cuando sea el momento.

Todo y que por lo que veo dice:

Total 156 files are raised error condition

Así que en todo el reporte que es super extenso, busca en alguna parte que diga: Total 156 files are raised error condition o algo parecido y tendrían que acabar con la palabra read error.

Pues traes toda esa parte donde aparezcan los 156 archivos (será así o algo parecido en cuanto a los mensajes que indico).

0) Descarga, instala y ejecuta ZHP Cleaner siguiendo su manual, lo descargas de aquí, instalas y ejecutas. Cuando termine, elimina todo lo que encuentre.

Finalmente traes lo pedido del Dr Web CureIt y el reporte del ZHP Cleaner.

Salu2.

Hola,

Al usar el buscador del bloc de notas, solo hay dos partes en las que aparece " Total 156 files are raised error condition", una es la que esta en la respuesta anterior y la otra es la siguiente:

La mayoria de lo que se ve ahi, como dije antes, ya esta en la respuesta anterior. Busqué " read error" y copié uno por uno los archivos que terminaran asi, en total solo encontré 71 archivos que terminan asi; aunque revisé detenidamente dos veces siento que se me pudo haber escapado alguno.

C:\Users\Compaq\AppData\Local\Microsoft\Windows\UsrClass.dat - read error
C:\Users\Compaq\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - read error
C:\Users\Compaq\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - read error
C:\Users\Compaq\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\c4c1ea5d31795b8922f50a599a26c6d5_fce8395f8fd8a805_6229ccd76215aea1_0_0.bin - read error
C:\Users\Compaq\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\c4c1ea5d31795b8922f50a599a26c6d5_fce8395f8fd8a805_6229ccd76215aea1_0_0.toc - read error
C:\Windows\ServiceProfiles\LocalService\ntuser.dat - read error
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 - read error
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2 - read error
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - read error
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - read error
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat - read error
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 - read error
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 - read error
C:\Windows\SoftwareDistribution\EventCache\{D0C9B514-B013-4079-8F48-A30F4DAA4EB3}.bin - read error
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 - read error
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 - read error
C:\Windows\System32\catroot2\edb.log - read error
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
C:\Windows\System32\config\default - read error
C:\Windows\System32\config\DEFAULT.LOG1 - read error
C:\Windows\System32\config\DEFAULT.LOG2 - read error
C:\Windows\System32\config\sam - read error
C:\Windows\System32\config\SAM.LOG1 - read error
C:\Windows\System32\config\SAM.LOG2 - read error
C:\Windows\System32\config\security - read error
C:\Windows\System32\config\SECURITY.LOG1 - read error
C:\Windows\System32\config\SECURITY.LOG2 - read error
C:\Windows\system32\config\software - read error
C:\Windows\System32\config\SOFTWARE.LOG1 - read error
C:\Windows\System32\config\SOFTWARE.LOG2 - read error
C:\Windows\System32\config\system - read error
C:\Windows\System32\config\software - read error
C:\Windows\System32\config\SYSTEM.LOG1 - read error
C:\Windows\System32\config\SYSTEM.LOG2 - read error
C:\Windows\System32\config\RegBack\DEFAULT - read error
C:\Windows\System32\config\RegBack\SAM - read error
C:\Windows\System32\config\RegBack\SECURITY - read error
C:\Windows\system32\config\RegBack\SOFTWARE - read error
C:\Windows\System32\config\RegBack\SYSTEM - read error
C:\Windows\System32\config\RegBack\SOFTWARE - read error
D: - read error
C:\hiberfil.sys - read error
C:\pagefile.sys - read error
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 - read error
C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 - read error
C:\Windows\system32\catroot2\edb.log - read error
C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
C:\Windows\system32\config\default - read error
C:\Windows\system32\config\DEFAULT.LOG1 - read error
C:\Windows\system32\config\DEFAULT.LOG2 - read error
C:\Windows\system32\config\sam - read error
C:\Windows\system32\config\SAM.LOG1 - read error
C:\Windows\system32\config\SAM.LOG2 - read error
C:\Windows\system32\config\security - read error
C:\Windows\system32\config\SECURITY.LOG1 - read error
C:\Windows\system32\config\SECURITY.LOG2 - read error
C:\Windows\system32\config\software - read error
C:\Windows\system32\config\SOFTWARE.LOG1 - read error
C:\Windows\system32\config\SOFTWARE.LOG2 - read error
C:\Windows\system32\config\system - read error
C:\Windows\system32\config\SYSTEM.LOG1 - read error
C:\Windows\system32\config\SYSTEM.LOG2 - read error
C:\Windows\system32\config\RegBack\DEFAULT - read error
C:\Windows\system32\config\RegBack\SAM - read error
C:\Windows\system32\config\RegBack\SECURITY - read error
C:\Windows\system32\config\RegBack\SOFTWARE - read error
C:\Windows\system32\config\RegBack\SYSTEM - read error
C:\Users\Compaq\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\c4c1ea5d31795b8922f50a599a26c6d5_fce8395f8fd8a805_6229ccd76215aea1_0_0.bin - read error
C:\Users\Compaq\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\c4c1ea5d31795b8922f50a599a26c6d5_fce8395f8fd8a805_6229ccd76215aea1_0_0.toc - read error

Ejecuté el ZHP Cleaner y al finalizar el proceso de reparación eliminé los archivos que dejo en cuarentena, aqui esta el reporte:

~ ZHPCleaner v2021.4.3.289 by Nicolas Coolman (2021/04/03)
~ Run by Compaq (Administrator)  (10/04/2021 14:49:23)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : 
~ Type : Reparar
~ Report : C:\Users\Compaq\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Compaq\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : 
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601)


---\\  Alternate Data Stream (ADS). (0)
~ No malintencionados o innecesarios artículos encontrados.


---\\  Servicios (0)
~ No malintencionados o innecesarios artículos encontrados.


---\\  Navegadores de Internet (0)
~ No malintencionados o innecesarios artículos encontrados.


---\\  Hosts carpeta (1)
~ El archivo hosts es legítimo (26)


---\\  Tareas automáticas programadas. (0)
~ No malintencionados o innecesarios artículos encontrados.


---\\  Explorador ( Archivos, Carpetas ) (2)
MOVIDO carpeta: C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Preferences    =>Préférences Chromium
MOVIDO archivo: C:\Users\Compaq\AppData\Local\MSfree Inc  =>HackTool.WinActivator


---\\  Registro ( Claves, Valores, Datos) (7)
BORRADOS clave*: HKCU\Software\drpsu [AdditionalScan 65]  =>.SUP.DriverPack
BORRADOS clave*: HKLM\SOFTWARE\Wow6432Node\ByteFence [AdditionalScan 292]  =>SUP.Optional.ByteFence
BORRADOS clave**: HKLM\SOFTWARE\ByteFence [AdditionalScan 406]  =>SUP.Optional.ByteFence
BORRADOS clave**: HKEY_USERS\S-1-5-21-2564166442-1154501177-2247460648-1000\SOFTWARE\drpsu []  =>.SUP.DriverPack
BORRADOS clave**: HKCU\Software\drpsu []  =>.SUP.DriverPack
BORRADOS clave*: HKLM\SOFTWARE\Microsoft\Tracing\Flash Player 18 debug_RASAPI32 []  =>Riskware.FlashPlayer
BORRADOS clave*: HKLM\SOFTWARE\Microsoft\Tracing\Flash Player 18 debug_RASMANCS []  =>Riskware.FlashPlayer


---\\  Resumen de elementos en su estación de trabajo (5)
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/  =>Préférences Chromium
https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/  =>HackTool.WinActivator
https://nicolascoolman.eu/2018/07/04/sup-driverpack/  =>.SUP.DriverPack
https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/  =>SUP.Optional.ByteFence
https://nicolascoolman.eu/forum/Topic/flashplayer-logiciel-a-risque-riskware/  =>Riskware.FlashPlayer


---\\ Limpieza adicional. (43)
~ Clave de registro Tracing borrados (43)
~ Quitar los antiguos informes de ZHPCleaner. (0)


---\\ Resultado de la reparación.
~ Reparación llevada a cabo con éxito
~ Google Chrome OK
~ Mozilla Firefox OK
~ Internet Explorer OK


---\\ STATISTIQUES
~ Items escaneado : 1406
~ Items encontrado : 0
~ artículos cancelados : 0
~ Ahorro de espacio (bytes) : 0
~ Items opciones : 9/17


---\\ OPCIONES NO ACTIVAS
~ Análisis temporal de archivos
~ Análisis temporal de carpetas
~ Análisis de CLSID de carpetas vacías
~ Vaciar otro análisis de carpetas
~ Análisis de carpetas locales vacías
~ Análisis de carpetas locales vacías
~ Análisis de archivos de instalación obsoleto
~ Iniciar navegadores con extensiones eliminadas





~ End of clean in 00h00mn32s

---\\  Reporte (2)
ZHPCleaner-[S]-10042021-14_43_05.txt
ZHPCleaner-[R]-10042021-14_49_55.txt

Saludos.

Hola, buenas @ManU

Respecto a lo del DR Web >> OK. No hay nada extraño. :+1:

Respecto a lo del ZHPCleaner >> OK. Este ha hecho lo que tenía que hacer :+1:.

Ahora quitaremos el Malwarebytes que tienes en tu máquina, para ello ve a: Herramientas de desinstalación de Antivirus, AntiSpyware y Firewall y utilizas la siguiente herramienta: MB-Clean.exe esta se encuentra en el apartado de Malwarebytes para su uso sigues las instrucciones que se encuentran allí detalladas. Una vez hayas reiniciado la máquina me traes el reporte de MB-Clean.exe.

Y también:

0) Descarga IFS

  • Desactiva tu antivirus :arrow_forward: Como deshabilitar temporalmente un antivirus y cualquier programa de seguridad que tengas activado.
  • Cierra todos los programas que tengas abiertos.
  • Ejecuta IFS.exe (Si usas Windows Vista/7/8 u 10 presiona clic derecho y selecciona “Ejecutar como Administrador.”)
  • Pulsar en el botón Analizar, y espera a que se realice el proceso. Puede tardar varios minutos.
  • Al terminar se abrirá un informe, lo adjuntas en tu próxima respuesta (puedes encontrarlo en C:\IFS.log).
  • Activa de nuevo tu antivirus y cualquier programa de seguridad que tengas activado.

Traes el reporte de MB-Clean.exe y el de IFS en tu próxima respuesta.

Salu2.

Hola, descargue y ejecute el MB-Clean.exe, aqui esta el reporte:

2021-04-12 01:04:30.137   mb-clean:3.1.0.1035  @ Malwarebytes. All rights reserved.
2021-04-12 01:04:32.204   Find Malwarebytes 3 installation location from C:\Program Files\Malwarebytes\Anti-Malware\.
2021-04-12 01:04:32.242   Warning!!! license key is empty.
2021-04-12 01:04:32.709   Trying to change the start type of MBAMChameleon.
2021-04-12 01:04:32.998   MBAMChameleon is disabled successfully.
2021-04-12 01:04:32.999   Trying to disable self-protection.
2021-04-12 01:04:33.007   Launching process:C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /log="C:\Users\Compaq\AppData\Local\Temp\Mbam3x.log"
2021-04-12 01:04:33.033   Failed to launch C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /log="C:\Users\Compaq\AppData\Local\Temp\Mbam3x.log", reason:((error=2))
2021-04-12 01:04:33.038   >>>>>> Starting 2nd phase cleanup for Malwarebytes version 3.x.x.xxxx <<<<<<
2021-04-12 01:04:33.042   Trying to stop service: ESProtectionDriver
2021-04-12 01:04:33.082   Service: ESProtectionDriver was stopped successfully
2021-04-12 01:04:33.086   Trying to delete file or folder: C:\Windows\system32\drivers\mbae.sys
2021-04-12 01:04:33.090   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Services\ESProtectionDriver
2021-04-12 01:04:33.125   Trying to stop service: MBAMChameleon
2021-04-12 01:04:33.129   Failed to stop service:MBAMChameleon, reason:((error=1052))
2021-04-12 01:04:33.133   Trying to delete file or folder: C:\Windows\system32\drivers\MbamChameleon.sys
2021-04-12 01:04:33.136   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Services\MBAMChameleon
2021-04-12 01:04:33.334   Trying to stop service: MBAMFarflt
2021-04-12 01:04:33.340   Service: MBAMFarflt was stopped successfully
2021-04-12 01:04:33.341   Trying to delete file or folder: C:\Windows\system32\drivers\farflt.sys
2021-04-12 01:04:33.342   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Services\MBAMFarflt
2021-04-12 01:04:33.343   Trying to stop service: MBAMProtection
2021-04-12 01:04:33.346   Service: MBAMProtection was stopped successfully
2021-04-12 01:04:33.347   Trying to delete file or folder: C:\Windows\system32\drivers\mbam.sys
2021-04-12 01:04:33.370   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Services\MBAMProtection
2021-04-12 01:04:33.371   Trying to stop service: MBAMService
2021-04-12 01:04:50.775   Service: MBAMService was stopped successfully
2021-04-12 01:04:50.775   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
2021-04-12 01:04:50.775   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe, reason:((error=5))
2021-04-12 01:04:50.775   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe on reboot
2021-04-12 01:04:50.775   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Services\MBAMService
2021-04-12 01:04:50.775   Trying to delete file or folder: C:\Windows\system32\drivers\mbamswissarmy.sys
2021-04-12 01:04:50.775   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Services\MBAMSwissArmy
2021-04-12 01:04:50.775   HKLM\SYSTEM\CurrentControlSet\Services\MBAMWebProtection does not exist.
2021-04-12 01:04:50.869   Trying to delete REG key: HKCR\TypeLib\{5709DEEB-F05E-4D5C-8DC4-3B0D924EE08F}
2021-04-12 01:04:51.009   Trying to delete REG key: HKCR\CLSID\{03141A2A-5C3A-458E-ABEC-0812AD7FF497}
2021-04-12 01:04:51.087   Trying to delete REG key: HKCR\TypeLib\{A82129F1-32E1-4D79-A39F-EBFEE53A70BF}
2021-04-12 01:04:51.103   Trying to delete REG key: HKCR\MB.CleanController.1
2021-04-12 01:04:51.103   Trying to delete REG key: HKCR\MB.CleanController
2021-04-12 01:04:51.134   Trying to delete REG key: HKCR\AppID\{1F7896AD-8886-42CD-8ABD-7A1315A3A5F2}
2021-04-12 01:04:51.134   Trying to delete REG key: HKCR\CLSID\{11D1E5E8-14E1-4B5B-AE1A-2678CB91E8E5}
2021-04-12 01:04:51.134   Trying to delete REG key: HKCR\CLSID\{130CD414-6BFD-4F6C-9362-A2264B222E76}
2021-04-12 01:04:51.134   Trying to delete REG key: HKCR\CLSID\{17BE78EE-B40A-4B9E-835F-38EC62F9D479}
2021-04-12 01:04:51.165   Trying to delete REG key: HKCR\TypeLib\{C731375E-3199-4C88-8326-9F81D3224DAD}
2021-04-12 01:04:51.165   Trying to delete REG key: HKCR\MB.LogController.1
2021-04-12 01:04:51.165   Trying to delete REG key: HKCR\MB.LogController
2021-04-12 01:04:51.165   Trying to delete REG key: HKCR\CLSID\{251AD013-20AD-4C3F-8FE2-F66A429B4819}
2021-04-12 01:04:51.259   Trying to delete REG key: HKCR\TypeLib\{A23C190D-C714-42C7-BDBB-F4E1DE65AF27}
2021-04-12 01:04:51.274   Trying to delete REG key: HKCR\MB.ArwController.1
2021-04-12 01:04:51.274   Trying to delete REG key: HKCR\MB.ArwController
2021-04-12 01:04:51.274   Trying to delete REG key: HKCR\CLSID\{278637DA-FDFB-45C7-8CD8-F2D8A9199AB0}
2021-04-12 01:04:51.306   Trying to delete REG key: HKCR\TypeLib\{59DBD1B8-A7BD-4322-998F-41B0D2516FA0}
2021-04-12 01:04:51.352   Trying to delete REG key: HKCR\MB.SPController.1
2021-04-12 01:04:51.352   Trying to delete REG key: HKCR\MB.SPController
2021-04-12 01:04:51.368   Trying to delete REG key: HKCR\CLSID\{36A65E46-6CC1-4CA2-B51E-F4DD8C993DDC}
2021-04-12 01:04:51.384   Trying to delete REG key: HKCR\TypeLib\{74630AE8-C170-4A8F-A90A-F42D63EFE1E8}
2021-04-12 01:04:51.384   Trying to delete REG key: HKCR\MB.UpdateController.1
2021-04-12 01:04:51.384   Trying to delete REG key: HKCR\MB.UpdateController
2021-04-12 01:04:51.399   Trying to delete REG key: HKCR\CLSID\{376BE474-56D4-4177-BB4E-5610156F36C8}
2021-04-12 01:04:51.446   Launching process:regsvr32.exe /u /s "C:\Program Files\Malwarebytes\Anti-Malware\\C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll"
2021-04-12 01:04:51.664   Trying to delete REG key: HKCR\TypeLib\{AFF1A83B-6C83-4342-8E68-1648DE06CB65}
2021-04-12 01:04:51.664   Trying to delete REG key: HKCR\MBAMExt.MBAMShlExt.1
2021-04-12 01:04:51.680   Trying to delete REG key: HKCR\MBAMExt.MBAMShlExt
2021-04-12 01:04:51.680   Trying to delete REG key: HKCR\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}
2021-04-12 01:04:51.696   Trying to delete REG key: HKCR\TypeLib\{332AFEBA-9341-4CEC-8EA6-DB155A99DF63}
2021-04-12 01:04:51.711   Trying to delete REG key: HKCR\MB.LicenseController.1
2021-04-12 01:04:51.711   Trying to delete REG key: HKCR\MB.LicenseController
2021-04-12 01:04:51.711   Trying to delete REG key: HKCR\CLSID\{580243BF-3CEE-4131-A599-C6FED66BEB1B}
2021-04-12 01:04:51.867   Trying to delete REG key: HKCR\TypeLib\{49F6AC60-2104-42C6-8F71-B3916D5AA732}
2021-04-12 01:04:51.867   Trying to delete REG key: HKCR\MB.MWACController.1
2021-04-12 01:04:51.883   Trying to delete REG key: HKCR\MB.MWACController
2021-04-12 01:04:51.883   Trying to delete REG key: HKCR\CLSID\{8F1C46F8-E697-4175-B240-CDE682A4BA2D}
2021-04-12 01:04:51.914   Trying to delete REG key: HKCR\TypeLib\{0E2822AB-0447-4F28-AF4C-FFDB1E8595AE}
2021-04-12 01:04:51.914   Trying to delete REG key: HKCR\MB.PoliciesController.1
2021-04-12 01:04:51.914   Trying to delete REG key: HKCR\MB.PoliciesController
2021-04-12 01:04:51.914   Trying to delete REG key: HKCR\CLSID\{9D372F21-E6DA-4B82-881A-79F6CA6B6AE1}
2021-04-12 01:04:51.961   Trying to delete REG key: HKCR\TypeLib\{F5BCAC7E-75E7-4971-B3F3-B197A510F495}
2021-04-12 01:04:51.976   Trying to delete REG key: HKCR\MB.CloudController.1
2021-04-12 01:04:51.992   Trying to delete REG key: HKCR\MB.CloudController
2021-04-12 01:04:51.992   Trying to delete REG key: HKCR\CLSID\{BF474111-9116-45C6-AF53-209E64F1BB53}
2021-04-12 01:04:52.054   Trying to delete REG key: HKCR\MB.ScanController.1
2021-04-12 01:04:52.054   Trying to delete REG key: HKCR\MB.ScanController
2021-04-12 01:04:52.054   Trying to delete REG key: HKCR\CLSID\{D5599B6B-FA0C-45B5-8309-853B003EA412}
2021-04-12 01:04:52.070   Trying to delete REG key: HKCR\TypeLib\{226C1698-A075-4315-BB5D-9C164A96ACE7}
2021-04-12 01:04:52.070   Trying to delete REG key: HKCR\MB.TelemetryController.1
2021-04-12 01:04:52.070   Trying to delete REG key: HKCR\MB.TelemetryController
2021-04-12 01:04:52.070   Trying to delete REG key: HKCR\CLSID\{DE03E614-112D-43E0-8E15-E7236CC32108}
2021-04-12 01:04:52.101   Trying to delete REG key: HKCR\TypeLib\{FFB94DF8-FC15-411C-B443-E937085E2AC1}
2021-04-12 01:04:52.101   Trying to delete REG key: HKCR\MB.RTPController.1
2021-04-12 01:04:52.101   Trying to delete REG key: HKCR\MB.RTPController
2021-04-12 01:04:52.101   Trying to delete REG key: HKCR\CLSID\{E1AC7139-D1FF-4DE9-84A4-92E2B47F5D2A}
2021-04-12 01:04:52.132   Trying to delete REG key: HKCR\CLSID\{EE8A9269-9E6E-4683-BCD3-41E9B16696DC}
2021-04-12 01:04:52.148   Trying to delete REG key: HKCR\TypeLib\{783B187E-360F-419C-B6DA-592892764A01}
2021-04-12 01:04:52.148   Trying to delete REG key: HKCR\MB.MBAMServiceController.1
2021-04-12 01:04:52.148   Trying to delete REG key: HKCR\MB.MBAMServiceController
2021-04-12 01:04:52.148   Trying to delete REG key: HKCR\CLSID\{F36AD0D0-B5F0-4C69-AF08-603D177FEF0E}
2021-04-12 01:04:52.164   Trying to delete REG key: HKCR\TypeLib\{2446F405-83F0-460F-B837-F04540BB330C}
2021-04-12 01:04:52.179   Trying to delete REG key: HKCR\MB.AEController.1
2021-04-12 01:04:52.179   Trying to delete REG key: HKCR\MB.AEController
2021-04-12 01:04:52.179   Trying to delete REG key: HKCR\CLSID\{F415899A-1576-4C8B-BC9F-4854781F8A20}
2021-04-12 01:04:52.179   Trying to delete REG key: HKCR\CLSID\{F6D29500-933C-447C-9D88-9D814AF73808}
2021-04-12 01:04:52.788   Trying to delete path C:\ProgramData\Malwarebytes\
2021-04-12 01:04:52.788   Trying to delete path C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\
2021-04-12 01:04:52.803   Trying to delete path C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\
2021-04-12 01:04:52.803   Trying to delete file or folder: C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\
2021-04-12 01:04:52.819   Trying to delete file or folder: C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\
2021-04-12 01:04:52.819   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\
2021-04-12 01:04:52.819   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\AeDetections\
2021-04-12 01:04:52.834   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\AeDetections\
2021-04-12 01:04:52.834   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\AMECls
2021-04-12 01:04:52.834   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\ARW\
2021-04-12 01:04:52.834   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\ARWFI.dat
2021-04-12 01:04:52.850   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-00.arw
2021-04-12 01:04:52.897   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-01.arw
2021-04-12 01:04:52.928   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-02.arw
2021-04-12 01:04:52.928   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-03.arw
2021-04-12 01:04:52.928   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-04.arw
2021-04-12 01:04:52.928   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-05.arw
2021-04-12 01:04:52.944   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\mbarwind-06.arw
2021-04-12 01:04:52.959   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ARW\
2021-04-12 01:04:52.959   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\ArwDetections\
2021-04-12 01:04:52.959   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ArwDetections\
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\cfg.bin
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\clean.mbdb
2021-04-12 01:04:52.975   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\config\
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\AeConfig.json
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\AeConfig.json.bak
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\ArwControllerConfig.json
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\ArwControllerConfig.json.bak
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\CleanControllerConfig.json
2021-04-12 01:04:52.975   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\CleanControllerConfig.json.bak
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\CloudConfig.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\CloudConfig.json.bak
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\IrisData.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\LicenseConfig.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\LicenseConfig.json.bak
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\MbamClientConfig.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\MwacControllerConfig.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\MwacControllerConfig.json.bak
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\PoliciesConfig.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\PoliciesConfig.json.bak
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\RtpConfig.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\RtpConfig.json.bak
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\SpConfigFile.json
2021-04-12 01:04:52.990   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\SpConfigFile.json.bak
2021-04-12 01:04:53.131   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\TelemCtrlConfig.json
2021-04-12 01:04:53.162   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\TelemCtrlConfig.json.bak
2021-04-12 01:04:53.162   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\telemetry.json
2021-04-12 01:04:53.162   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\UpdateControllerConfig.json
2021-04-12 01:04:53.162   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\UpdateControllerConfig.json.bak
2021-04-12 01:04:53.178   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\config\
2021-04-12 01:04:53.178   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\ctlrpkg\
2021-04-12 01:04:53.193   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ctlrpkg\
2021-04-12 01:04:53.271   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\dbmanifest2.dat
2021-04-12 01:04:53.365   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\dbupdate.log
2021-04-12 01:04:53.365   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\DDSCls
2021-04-12 01:04:53.365   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\dynconfig.dat
2021-04-12 01:04:53.365   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\exclusions.txt
2021-04-12 01:04:53.365   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Global.nm
2021-04-12 01:04:53.365   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Global.sr
2021-04-12 01:04:53.380   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\HubbleCache
2021-04-12 01:04:53.380   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\IrisPlugins\
2021-04-12 01:04:53.474   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\IrisPlugins\mbam_scanresults_r01_drawer.1.0.0.dll
2021-04-12 01:04:53.474   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\IrisPlugins\mbam_scanresults_r01_drawer.2.0.0.dll
2021-04-12 01:04:53.474   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\IrisPlugins\mbam_scanresults_r02_drawer.2.0.0.dll
2021-04-12 01:04:53.474   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\IrisPlugins\mbam_scanresults_r03_drawer.2.0.0.dll
2021-04-12 01:04:53.474   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\IrisPlugins\
2021-04-12 01:04:53.474   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\IrisRePlugins\
2021-04-12 01:04:53.505   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\IrisRePlugins\
2021-04-12 01:04:53.505   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\lkg_db\
2021-04-12 01:04:53.521   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\Actions.dll
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\BrowserSDKDLL.dll
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\cfg.bin
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\clean.mbdb
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\dbmanifest2.dat
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\dynconfig.dat
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\exclusions.txt
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\Global.nm
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\Global.sr
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\ig.exe
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\MBAMCore.dll
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\mbdigsig2.dat
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\prot.mbdb
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\rdefs.mbdb
2021-04-12 01:04:53.677   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\rules.mbdb
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\sample.dll
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\scan.mbdb
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\tids.mbdb
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\version.dat
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\wprot2.mbdb
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\lkg_db\
2021-04-12 01:04:53.786   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\LOGS\
2021-04-12 01:04:53.786   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\mbae-default.log
2021-04-12 01:04:53.817   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\mbae-protector.xpe
2021-04-12 01:04:53.880   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\mbae-protector.xpe.bak
2021-04-12 01:04:53.880   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\MBAMSERVICE.LOG
2021-04-12 01:04:53.895   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\MBAMSERVICE.LOG.bk1
2021-04-12 01:04:53.895   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\MBAMSERVICE.LOG.bk2
2021-04-12 01:04:53.911   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\mbupdatr.log
2021-04-12 01:04:53.911   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\LOGS\
2021-04-12 01:04:53.911   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\mbdigsig2.dat
2021-04-12 01:04:53.911   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\MwacDetections\
2021-04-12 01:04:53.911   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\MwacDetections\b0a37440-9894-11eb-8177-001f1650fe9f.json
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\MwacDetections\
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\prot.mbdb
2021-04-12 01:04:53.926   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\
2021-04-12 01:04:53.926   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\cert.db
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\Malwarebytes Web Protection.cer
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\x2.db
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\xtls2.db
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\xv2.db
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\SSL\
2021-04-12 01:04:53.926   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ProtocolFilters\
2021-04-12 01:04:53.926   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\Quarantine\
2021-04-12 01:04:53.942   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Quarantine\ae50cce1-98f0-11eb-82ca-001f1650fe9f.data
2021-04-12 01:04:53.958   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Quarantine\ae50cce1-98f0-11eb-82ca-001f1650fe9f.quar
2021-04-12 01:04:53.958   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Quarantine\aed6fba1-98a3-11eb-88ed-001f1650fe9f.data
2021-04-12 01:04:53.973   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Quarantine\aed6fba1-98a3-11eb-88ed-001f1650fe9f.quar
2021-04-12 01:04:53.973   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\Quarantine\
2021-04-12 01:04:53.973   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\rdefs.mbdb
2021-04-12 01:04:53.973   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\RTPCls
2021-04-12 01:04:53.973   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\RtpDetections\
2021-04-12 01:04:53.989   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\RtpDetections\ae50cce0-98f0-11eb-aef5-001f1650fe9f.json
2021-04-12 01:04:53.989   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\RtpDetections\aed6fba0-98a3-11eb-aac4-001f1650fe9f.json
2021-04-12 01:04:53.989   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\RtpDetections\
2021-04-12 01:04:54.004   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\RtpDetectionSamples\
2021-04-12 01:04:54.004   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\RtpDetectionSamples\
2021-04-12 01:04:54.004   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\rules.mbdb
2021-04-12 01:04:54.020   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\scan.mbdb
2021-04-12 01:04:54.020   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\ScanResults\
2021-04-12 01:04:54.020   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\ScanResults\
2021-04-12 01:04:54.020   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\tids.mbdb
2021-04-12 01:04:54.020   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\tmp\
2021-04-12 01:04:54.020   Trying to delete path C:\ProgramData\Malwarebytes\MBAMService\tmp\55859b90932311ebaa87001f1650fe9f\
2021-04-12 01:04:54.036   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\tmp\55859b90932311ebaa87001f1650fe9f\55859b90932311ebaa87001f1650fe9f.zip
2021-04-12 01:04:54.036   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\tmp\55859b90932311ebaa87001f1650fe9f\
2021-04-12 01:04:54.036   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\tmp\
2021-04-12 01:04:54.036   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\version.dat
2021-04-12 01:04:54.036   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\wprot2.mbdb
2021-04-12 01:04:54.051   Trying to delete file or folder: C:\ProgramData\Malwarebytes\MBAMService\
2021-04-12 01:04:54.051   Trying to delete file or folder: C:\ProgramData\Malwarebytes\
2021-04-12 01:04:54.051   Trying to delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\
2021-04-12 01:04:54.051   Cannot delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\, reason:((error=3))
2021-04-12 01:04:54.067   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\
2021-04-12 01:04:54.067   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\7z.dll
2021-04-12 01:04:54.067   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Actions.dll
2021-04-12 01:04:54.067   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\ActionsShim.dll
2021-04-12 01:04:54.082   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\AEControllerImpl.dll
2021-04-12 01:04:54.082   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\AeShim.dll
2021-04-12 01:04:54.082   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\ArwControllerImpl.dll
2021-04-12 01:04:54.082   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\arwlib.dll
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\ArwSdkShim.dll
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\assistant.exe
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\CleanControllerImpl.dll
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\CloudControllerImpl.dll
2021-04-12 01:04:54.098   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\iconengines\
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\iconengines\qsvgicon.dll
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\iconengines\
2021-04-12 01:04:54.098   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\imageformats\
2021-04-12 01:04:54.098   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
2021-04-12 01:04:54.114   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qjpeg.dll
2021-04-12 01:04:54.114   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
2021-04-12 01:04:54.114   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\imageformats\
2021-04-12 01:04:54.114   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\languages\
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_bg.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_cs.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_da.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_de.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_en_GB.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_en_US.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_es.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_fi.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_fr.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_hr.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_hu.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_it.qm
2021-04-12 01:04:54.145   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_ja.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_ko.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_nl.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_no.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_pl.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_pt_BR.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_pt_PT.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_ro.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_ru.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_sk.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_sl.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_sv.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\lang_zh_TW.qm
2021-04-12 01:04:54.160   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\languages\
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\LicenseControllerImpl.dll
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\malwarebytes_assistant.exe
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbae-api-na.dll
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbae.dll
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MBAMCore.dll
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MbamPt.exe
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MBAMShim.dll
2021-04-12 01:04:54.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MWACControllerImpl.dll
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MwacLib.dll
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\MwacSdkShim.dll
2021-04-12 01:04:54.192   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\platforms\
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\platforms\
2021-04-12 01:04:54.192   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\PoliciesControllerImpl.dll
2021-04-12 01:04:54.192   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\Qt\
2021-04-12 01:04:54.192   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\
2021-04-12 01:04:54.192   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\folderlistmodel\
2021-04-12 01:04:54.207   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\folderlistmodel\plugins.qmltypes
2021-04-12 01:04:54.207   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\folderlistmodel\qmldir
2021-04-12 01:04:54.207   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dll
2021-04-12 01:04:54.207   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\folderlistmodel\
2021-04-12 01:04:54.223   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\settings\
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\settings\plugins.qmltypes
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\settings\qmldir
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\settings\qmlsettingsplugin.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\settings\
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\labs\
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt\
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
2021-04-12 01:04:54.223   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
2021-04-12 01:04:54.223   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQml\
2021-04-12 01:04:54.223   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\plugins.qmltypes
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\qmldir
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\plugins.qmltypes
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\qmldir
2021-04-12 01:04:54.238   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\
2021-04-12 01:04:54.238   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQml\, reason:((error=145))
2021-04-12 01:04:54.238   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQml\ on reboot
2021-04-12 01:04:54.238   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\
2021-04-12 01:04:54.238   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\
2021-04-12 01:04:54.254   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\plugins.qmltypes
2021-04-12 01:04:54.254   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\
2021-04-12 01:04:54.270   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\qmldir
2021-04-12 01:04:54.270   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\
2021-04-12 01:04:54.270   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\, reason:((error=145))
2021-04-12 01:04:54.270   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\ on reboot
2021-04-12 01:04:54.270   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qmldir
2021-04-12 01:04:54.270   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
2021-04-12 01:04:54.270   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\
2021-04-12 01:04:54.270   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\
2021-04-12 01:04:54.285   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\
2021-04-12 01:04:54.285   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\, reason:((error=145))
2021-04-12 01:04:54.285   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\ on reboot
2021-04-12 01:04:54.285   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\
2021-04-12 01:04:54.316   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\qmldir
2021-04-12 01:04:54.316   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\
2021-04-12 01:04:54.316   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\, reason:((error=145))
2021-04-12 01:04:54.316   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\ on reboot
2021-04-12 01:04:54.316   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Flat\
2021-04-12 01:04:54.316   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Flat\plugins.qmltypes
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Flat\qmldir
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Flat\qtquickextrasflatplugin.dll
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Flat\
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\qmldir
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\
2021-04-12 01:04:54.332   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\, reason:((error=145))
2021-04-12 01:04:54.332   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\ on reboot
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\
2021-04-12 01:04:54.332   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\, reason:((error=145))
2021-04-12 01:04:54.332   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\ on reboot
2021-04-12 01:04:54.332   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\plugins.qmltypes
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\qmldir
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\
2021-04-12 01:04:54.332   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\, reason:((error=145))
2021-04-12 01:04:54.332   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\ on reboot
2021-04-12 01:04:54.332   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\
2021-04-12 01:04:54.332   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
2021-04-12 01:04:54.332   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\
2021-04-12 01:04:54.363   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\
2021-04-12 01:04:54.363   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\, reason:((error=145))
2021-04-12 01:04:54.363   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\ on reboot
2021-04-12 01:04:54.363   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\plugins.qmltypes
2021-04-12 01:04:54.363   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\Private\
2021-04-12 01:04:54.363   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\Private\dialogsprivateplugin.dll
2021-04-12 01:04:54.363   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\Private\plugins.qmltypes
2021-04-12 01:04:54.363   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\Private\qmldir
2021-04-12 01:04:54.363   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\Private\
2021-04-12 01:04:54.363   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\
2021-04-12 01:04:54.379   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\qmldir
2021-04-12 01:04:54.379   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\
2021-04-12 01:04:54.379   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\, reason:((error=145))
2021-04-12 01:04:54.379   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\ on reboot
2021-04-12 01:04:54.379   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qmldir
2021-04-12 01:04:54.379   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\
2021-04-12 01:04:54.379   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\, reason:((error=145))
2021-04-12 01:04:54.379   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\ on reboot
2021-04-12 01:04:54.379   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\
2021-04-12 01:04:54.394   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\plugins.qmltypes
2021-04-12 01:04:54.394   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\
2021-04-12 01:04:54.394   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\qmldir
2021-04-12 01:04:54.394   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\
2021-04-12 01:04:54.394   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\, reason:((error=145))
2021-04-12 01:04:54.394   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\ on reboot
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\qmldir
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\qtquickextrasplugin.dll
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\
2021-04-12 01:04:54.410   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\, reason:((error=145))
2021-04-12 01:04:54.410   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\ on reboot
2021-04-12 01:04:54.410   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\plugins.qmltypes
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qmldir
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
2021-04-12 01:04:54.410   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\
2021-04-12 01:04:54.410   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\
2021-04-12 01:04:54.426   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\plugins.qmltypes
2021-04-12 01:04:54.426   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\qmldir
2021-04-12 01:04:54.426   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
2021-04-12 01:04:54.426   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\
2021-04-12 01:04:54.441   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\plugins.qmltypes
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\qmldir
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\
2021-04-12 01:04:54.441   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\, reason:((error=145))
2021-04-12 01:04:54.441   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\ on reboot
2021-04-12 01:04:54.441   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\plugins.qmltypes
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\qmldir
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\
2021-04-12 01:04:54.441   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\plugins.qmltypes
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\qmldir
2021-04-12 01:04:54.441   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\
2021-04-12 01:04:54.441   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\, reason:((error=145))
2021-04-12 01:04:54.457   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\ on reboot
2021-04-12 01:04:54.457   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\
2021-04-12 01:04:54.457   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\, reason:((error=145))
2021-04-12 01:04:54.457   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\ on reboot
2021-04-12 01:04:54.457   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\
2021-04-12 01:04:54.457   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\plugins.qmltypes
2021-04-12 01:04:54.457   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qmldir
2021-04-12 01:04:54.457   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
2021-04-12 01:04:54.457   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\
2021-04-12 01:04:54.457   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\JumpListDestination.qml
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\JumpListLink.qml
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\JumpListSeparator.qml
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\plugins.qmltypes
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\qmldir
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\qml_winextras.dll
2021-04-12 01:04:54.488   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtWinExtras\
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\rtp.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\RTPControllerImpl.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\RtpShim.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\ScanControllerImpl.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\SelfProtectionSdk.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\SelfProtectionShim.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\ServiceConfig.json
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\SPControllerImpl.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\Swissarmy.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\SwissarmyShim.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\TelemetryControllerImpl.dll
2021-04-12 01:04:54.504   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\UpdateControllerImpl.dll
2021-04-12 01:04:54.519   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\
2021-04-12 01:04:54.519   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\, reason:((error=145))
2021-04-12 01:04:54.519   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\ on reboot
2021-04-12 01:04:54.519   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService
2021-04-12 01:04:54.519   Trying to delete REG key: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService
2021-04-12 01:05:06.775   --------END OF LOG FILE ----------
2021-04-12 01:06:15.709   >>>>>Starting post reboot phase cleanup for Malwarebytes version 3.x.x.xxxx <<<<<<<<.
2021-04-12 01:06:15.803   Trying to delete REG key: HKCU\SOFTWARE\Malwarebytes
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\ESProtectionDriver does not exist.
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\MBAMChameleon does not exist.
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\MBAMFarflt does not exist.
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\MBAMProtection does not exist.
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\MBAMService does not exist.
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\MBAMSwissArmy does not exist.
2021-04-12 01:06:15.803   HKLM\SYSTEM\CurrentControlSet\Services\MBAMWebProtection does not exist.
2021-04-12 01:06:16.520   Trying to delete path C:\ProgramData\Malwarebytes\
2021-04-12 01:06:16.614   Cannot delete path C:\ProgramData\Malwarebytes\, reason:((error=3))
2021-04-12 01:06:16.614   Trying to delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\
2021-04-12 01:06:16.614   Cannot delete path C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\, reason:((error=3))
2021-04-12 01:06:16.614   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\
2021-04-12 01:06:16.614   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQml\
2021-04-12 01:06:16.614   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQml\
2021-04-12 01:06:16.614   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQml\, reason:((error=145))
2021-04-12 01:06:16.614   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQml\ on reboot
2021-04-12 01:06:16.614   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\
2021-04-12 01:06:16.614   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\
2021-04-12 01:06:16.614   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\
2021-04-12 01:06:17.176   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\
2021-04-12 01:06:17.176   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\, reason:((error=145))
2021-04-12 01:06:17.176   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Private\ on reboot
2021-04-12 01:06:17.176   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\
2021-04-12 01:06:17.176   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\
2021-04-12 01:06:17.191   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\
2021-04-12 01:06:17.191   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\, reason:((error=145))
2021-04-12 01:06:17.191   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Base\ on reboot
2021-04-12 01:06:17.191   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\
2021-04-12 01:06:17.254   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\
2021-04-12 01:06:17.254   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\, reason:((error=145))
2021-04-12 01:06:17.254   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\Desktop\ on reboot
2021-04-12 01:06:17.254   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\
2021-04-12 01:06:17.254   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\, reason:((error=145))
2021-04-12 01:06:17.254   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\Styles\ on reboot
2021-04-12 01:06:17.254   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\
2021-04-12 01:06:17.254   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\, reason:((error=145))
2021-04-12 01:06:17.254   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\ on reboot
2021-04-12 01:06:17.269   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\
2021-04-12 01:06:17.269   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\
2021-04-12 01:06:17.269   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\, reason:((error=145))
2021-04-12 01:06:17.269   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls.2\ on reboot
2021-04-12 01:06:17.269   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\
2021-04-12 01:06:17.269   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\
2021-04-12 01:06:17.269   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\
2021-04-12 01:06:17.269   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\, reason:((error=145))
2021-04-12 01:06:17.269   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\images\ on reboot
2021-04-12 01:06:17.269   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\
2021-04-12 01:06:17.285   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\
2021-04-12 01:06:17.285   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\, reason:((error=145))
2021-04-12 01:06:17.285   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\qml\ on reboot
2021-04-12 01:06:17.285   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\
2021-04-12 01:06:17.285   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\, reason:((error=145))
2021-04-12 01:06:17.285   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\ on reboot
2021-04-12 01:06:17.285   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\
2021-04-12 01:06:17.285   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\
2021-04-12 01:06:17.285   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\
2021-04-12 01:06:17.285   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\, reason:((error=145))
2021-04-12 01:06:17.285   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\Private\ on reboot
2021-04-12 01:06:17.285   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\
2021-04-12 01:06:17.285   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\, reason:((error=145))
2021-04-12 01:06:17.285   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Extras\ on reboot
2021-04-12 01:06:17.285   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\
2021-04-12 01:06:17.285   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\
2021-04-12 01:06:17.285   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\, reason:((error=145))
2021-04-12 01:06:17.285   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Templates.2\ on reboot
2021-04-12 01:06:17.285   Trying to delete path C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\
2021-04-12 01:06:17.300   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\
2021-04-12 01:06:17.300   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\, reason:((error=145))
2021-04-12 01:06:17.300   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\XmlListModel\ on reboot
2021-04-12 01:06:17.300   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\
2021-04-12 01:06:17.300   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\, reason:((error=145))
2021-04-12 01:06:17.300   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\ on reboot
2021-04-12 01:06:17.300   Trying to delete file or folder: C:\Program Files\Malwarebytes\Anti-Malware\
2021-04-12 01:06:17.300   Failed to delete C:\Program Files\Malwarebytes\Anti-Malware\, reason:((error=145))
2021-04-12 01:06:17.300   Trying to delete file or folder C:\Program Files\Malwarebytes\Anti-Malware\ on reboot
2021-04-12 01:06:36.529   --------END OF LOG FILE ----------

El programa preguntó si queria instalar el Malwarebytes 3x, elegí no hacerlo ya que tengo entendido que esa es una version desactualizada.

En cuanto al IFS, al analizar me salta este mensaje de error:

IFS

Despues del mensaje el programa se cierra automaticamente. Saludos

Hola, buenas @ManU

Respecto MB-Clean.exe >> OK. Perfecto.

Sí, correcto. Esta desactualizada dicha versión. De todas eso que dices: ¿Te lo decía el propio MB-Clean.exe?

Vaya :-1:

OK.

:one: Desactivas tu antivirus :arrow_forward: Como deshabilitar temporalmente un antivirus y cualquier programa de seguridad que tengas activado.

LO DESCARGAS EN TU ESCRITORIO MUY IMPORTANTE (y no en otro sitio).

Descargas Farbar Recovery Scan Tool MUY IMPORTANTE >> seleccionas la versión adecuada para la arquitectura correspondiente de tu Ordenador (32 o 64bits). :arrow_forward: ¿Cómo saber si mi Windows es de 32 o 64 bits.?

:warning: Una vez descargado FRST, desconectas tu equipo de completamente de Internet (apagas el router) >> Super Importante. Acto seguido, cierras también cualquier otro programa que tengas abierto.

:two: Farbar Recovery Scan Tool

  1. Ejecutas el FRST.exe (Si utilizas Windows Vista/7/8 o 10, presionas click derecho y seleccionas Ejecutar como Administrador).

  2. Aparecerá una ventana con un mensaje de Disclaimer/Responsabilidad, presionas sobre Si o Yes.

  3. En la ventana principal del programa presionas sobre Analizar/Scan y esperas a que finalice el análisis.

  4. Aparecerán dos logs/reportes que serán: Frst.txt y Addition.txt, estos quedarán guardados en el escritorio.

:three: Activas de nuevo tu antivirus y cualquier programa de seguridad que tengas activado. También conectas nuevamente tu equipo a Internet.

:four: PRÓXIMA RESPUESTA

Pegas los reportes de FRST y Addition.txt. Debes de poner ambos reportes todos enteros con absolutamente todo su contenido. Deberás de realizar varios mensajes si recibes un mensaje de error/advertencia indicando que es muy largo dicho reporte que formará el mensaje (más de 50.000 carácteres aprox.).

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

:warning: Muy Importante :warning: Coloca los diferentes reportes que te he pedido como se muestra en la siguiente imagen:

Salu2.

Hola,

Si, al terminar la desinstalacion me puso ese mensaje.

Aqui estan los reportes:

FRST.txt:

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x86) Versión: 11-04-2021
Ejecutado por Compaq (administrador) sobre COMPAQ-PC (Hewlett-Packard Compaq Presario CQ50 Notebook PC) (13-04-2021 04:11:09)
Ejecutado desde C:\Users\Compaq\Desktop
Perfiles cargados: Compaq
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Idioma: Español (España, internacional)
Navegador predeterminado: Chrome
Modo de Inicio: Normal

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

() [Archivo no firmado] C:\Program Files\CCleaner\CCleaner.exe
() [Archivo no firmado] C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
() [Archivo no firmado] C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
() [Archivo no firmado] C:\Program Files\Windows Media Player\wmpnetwk.exe
() [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\MEGAsync.exe
() [Archivo no firmado] C:\Windows\explorer.exe
() [Archivo no firmado] C:\Windows\System32\nvvsvc.exe <2>
() [Archivo no firmado] C:\Windows\System32\SearchIndexer.exe
() [Archivo no firmado] C:\Windows\System32\sppsvc.exe
() [Archivo no firmado] C:\Windows\System32\VSSVC.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
(Google LLC -> Google LLC) C:\Program Files\Google\Update\1.3.36.72\GoogleCrashHandler.exe
(Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\lsm.exe
(Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\spoolsv.exe
(Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\taskeng.exe
(Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\taskhost.exe <2>
(Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\wbem\WmiPrvSE.exe <2>
(Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\winlogon.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe [26624 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Winlogon: [Shell] C:\Windows\explorer.exe [2616320 2010-11-20] () [Archivo no firmado]
HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1174016 2010-11-20] () [Archivo no firmado]
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [93696 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1174016 2010-11-20] () [Archivo no firmado]
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [93696 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
HKU\S-1-5-21-2564166442-1154501177-2247460648-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] () [Archivo no firmado]
HKLM\...\Providers\LanMan Print Services: C:\Windows\system32\win32spl.dll [492032 2010-11-20] () [Archivo no firmado]
HKLM\...\Windows NT x86\Print Processors\winprint: C:\Windows\System32\spool\prtprocs\W32X86\winprint.dll [30208 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Print\Monitors\Local Port: C:\Windows\system32\localspl.dll [768512 2010-11-20] () [Archivo no firmado]
HKLM\...\Print\Monitors\Standard TCP/IP Port: C:\Windows\system32\tcpmon.dll [148992 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Print\Monitors\USB Monitor: C:\Windows\system32\usbmon.dll [34304 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Print\Monitors\WSD Port: C:\Windows\system32\WSDMon.dll [185344 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] -> C:\Program Files\Windows Mail\WinMail.exe [2009-07-13] () [Archivo no firmado]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\89.0.4389.114\Installer\chrmstp.exe [2021-04-01] () [Archivo no firmado]
HKLM\Software\...\Authentication\Credential Providers: [{25CBB996-92ED-457e-B28C-4774084BD562}] -> C:\Windows\system32\authui.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Authentication\Credential Providers: [{3dd6bec0-8193-4ffe-ae25-e08e39ea4063}] -> C:\Windows\system32\authui.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Authentication\Credential Providers: [{6f45dc1e-5384-457a-bc13-2cd81b0d28ed}] -> C:\Windows\system32\authui.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Authentication\Credential Provider Filters: [{DDC0EED2-ADBE-40b6-A217-EDE16A79A0DE}] -> C:\Windows\system32\authui.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{0E28E245-9368-4853-AD84-6DA3BA35BB75}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{17D89FEC-5C44-4972-B12D-241CAEF74509}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{1A6364EB-776B-4120-ADE1-B63A406A76B5}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{5794DAFD-BE60-433f-88A2-1A31939AC01F}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{6232C319-91AC-4931-9385-E70C2B099F0E}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{7150F9BF-48AD-4da4-A49C-29EF4A8369BA}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{728EE579-943C-4519-9EF7-AB56765798ED}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{74EE6C03-5363-4554-B161-627540339CAB}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{91FBB303-0CD5-4055-BF42-E512A681B325}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{A3F3E39B-5D83-4940-B954-28315B82F0A8}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{AADCED64-746C-4633-A97C-D61349046527}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{B087BE9D-ED37-454f-AF9C-04291E351182}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{E4F48E54-F38D-4884-BFB9-D4D2E5729C18}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{E5094040-C46C-4115-B030-04FB2E545B00}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{E62688F0-25FD-4c90-BFF5-F508B9D2E31F}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
HKLM\Software\...\Winlogon\GPExtensions: [{F9C77450-3A41-477E-9310-9ACD617BD9E3}] -> C:\Windows\system32\gpprefcl.dll [2010-11-20] () [Archivo no firmado]
Startup: C:\Users\Compaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2021-02-26]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Compaq\AppData\Local\MEGAsync\MEGAsync.exe () [Archivo no firmado]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {005562C2-0D59-44CE-A90C-3A1E547AE482} - System32\Tasks\{128EA561-FD5D-4374-9291-1D03B1367650} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {071D41B6-8806-4EB0-B661-6CB67BE6E86E} - System32\Tasks\Microsoft\Windows\Diagnosis\Scheduled => {c1f85ef8-bcc2-4606-bb39-70c523715eb3} C:\Windows\System32\sdiagschd.dll [45056 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {0B868266-BDD9-4E3D-994D-314F2F87EB56} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] () [Archivo no firmado]
Task: {113EE6A9-8252-4FC0-A808-F8BDF5152636} - System32\Tasks\{D83C7160-6527-4C94-AB28-C4BF3E39F690} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {18812853-2BB2-4E2A-A44E-5188087FD45B} - System32\Tasks\{0159B6AC-B769-4762-95EB-FBE5CF9298BA} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {1B73CCB5-700C-4551-8F8D-5B24A0C8E513} - System32\Tasks\{E51C5BC4-FFB2-432B-937A-446362325A61} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\GAME\Empires2.exe
Task: {1ED2A39D-8F7E-4A93-A367-95572ED379FA} - System32\Tasks\{8CC2D41B-A8C1-4E0F-BB2A-EBBED8A08648} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {24FA84A0-E087-48EC-BC51-2B9C4C815D78} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40b4-8963-D3C761B18371} C:\Windows\System32\perftrack.dll [578048 2009-07-13] () [Archivo no firmado]
Task: {2BD05BA6-988D-4BD3-A9CD-9A39F80AF524} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector => {190BA3F6-0205-4f46-B589-95C6822899D2} C:\Windows\System32\memdiag.dll [15872 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {2C59ECAF-3A27-4640-9F4B-519B05BDD70F} - System32\Tasks\Microsoft\Windows\MUI\LPRemove => C:\Windows\system32\lpremove.exe [61952 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Task: {2D350632-6B1E-4028-9CB0-415643D462BF} - System32\Tasks\{DBF1DDE3-8D89-4178-9D74-CA7796EBB490} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {39E24656-8EDC-4D1E-8084-9FD6715AE205} - System32\Tasks\{AFDB173F-F90C-4010-8E70-0926A15EAD4C} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {4040E761-8758-4007-B2FE-142B24BF4B16} - System32\Tasks\Microsoft\Windows\Ras\MobilityManager => {c463a0fc-794f-4fdf-9201-01938ceacafa} C:\Windows\system32\rasmbmgr.dll [45056 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {4C7ABC85-FE40-4DF3-B340-4256A8EDA3C6} - System32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {5B184694-64C3-4633-94C5-945B3FA561D6} - System32\Tasks\Microsoft\Windows\WindowsBackup\ConfigNotification => C:\Windows\System32\sdclt.exe [1131008 2010-11-20] () [Archivo no firmado]
Task: {611FCC7E-2BE6-4FE6-82E9-C9FF46DFD8C5} - System32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {62CEFE5C-EDC8-4438-BFB8-D9AE7F0D48EC} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [157184 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {6375CC1C-D975-48D2-9CD5-63DB19B10D4A} - System32\Tasks\Microsoft\Windows\WDI\ResolutionHost => {900be39d-6be8-461a-bc4d-b0fa71f5ecb1} C:\Windows\System32\wdi.dll [76288 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {64DA3287-8A12-4FBC-B712-C4D1C652D7CD} - System32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {6EF9FD15-C349-4133-B166-915EC96EE15A} - System32\Tasks\{DAB034BB-7842-4268-A78A-6A9BBE1080A4} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {73259F86-29D6-42FF-B1E7-634F6E40D4F8} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\UserTask-Roam => {58fb76b9-ac85-4e55-ac04-427593b1d060} C:\Windows\system32\dimsjob.dll [33792 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {7BEBF731-9230-4028-995F-40490DCB830C} - System32\Tasks\{A2D09495-2796-46E3-99A1-97D79064D88E} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\GAME\Empires2.exe
Task: {7D3C7871-A917-4EF0-82E8-5F0A96423051} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => C:\Windows\system32\BthUdTask.exe [35328 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {8216A799-EBD8-4DCD-A6A8-B86E4DC96DAC} - System32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {86F80BCB-515D-4F37-B8EF-5FFE87A757D3} - System32\Tasks\{B57F43F2-575C-4A4B-BC76-FC3FCE021DBE} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {8905ECD8-016F-4DC2-90E6-A5F1FA6A841A} - System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated) => {CF2CF428-325B-48D3-8CA8-7633E36E5A32} C:\Windows\system32\msdrm.dll [341504 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Task: {8C193216-B3A6-4026-A5EE-630CB7B121F0} - System32\Tasks\{22FA84A6-D016-4465-A729-338F2A2DF579} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\GAME\Empires2.exe
Task: {9A230BC2-05F9-4646-B5D3-755E69EDD66A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [155592 2021-02-03] (Google LLC -> Google LLC)
Task: {9B17E06E-479A-4F2A-851E-4207D2BB145A} - System32\Tasks\{7311AFC6-BA20-43A8-B01A-11D7241AE240} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {9B75C702-EA13-406A-BADB-6C588EE4375B} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\SystemTask => {58fb76b9-ac85-4e55-ac04-427593b1d060} C:\Windows\system32\dimsjob.dll [33792 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {9E90588B-E6A2-4B5D-98A1-1583C548802E} - System32\Tasks\{2F3A0085-F1BB-42CB-81FB-1C9FADCEC589} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {9EFACBE6-A797-4905-A0C6-014CD3000DBB} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask => {e7ed314f-2816-4c26-aeb5-54a34d02404c} C:\Windows\System32\kernelceip.dll [15872 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {9F54B95F-5096-4803-AE61-E9B3AC5B616D} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector => {190BA3F6-0205-4f46-B589-95C6822899D2} C:\Windows\System32\memdiag.dll [15872 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {A1CFA52F-06F2-418D-ADDB-CD6456D66F43} - System32\Tasks\Microsoft\Windows\RAC\RacTask => {42060D27-CA53-41f5-96E4-B1E8169308A6} C:\Windows\system32\RacEngn.dll [1115136 2010-11-20] () [Archivo no firmado]
Task: {A2CFB6F3-B3AE-4971-8E29-C415BE22D2E5} - System32\Tasks\Microsoft\Windows\Maintenance\WinSAT => {A9A33436-678B-4C9C-A211-7CC38785E79D} C:\Windows\system32\WinSATAPI.dll [335872 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Task: {A316E645-1C56-45A6-BD6A-7DCA79778090} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip => {c27f6b1d-fe0b-45e4-9257-38799fa69bc8} C:\Windows\System32\usbceip.dll [23552 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {A358656C-8390-4C8F-A11D-9A19129699D1} - System32\Tasks\Microsoft\Windows\Offline Files\Logon Synchronization => {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8} C:\Windows\System32\cscui.dll [418816 2010-11-20] () [Archivo no firmado]
Task: {A586D420-D1CB-49EA-AFD7-9CABB92D60CE} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe [226304 2010-11-20] (Microsoft Windows -> Microsoft Corporation) [Archivo no firmado]
Task: {A6394592-54CE-4E93-8D64-1A068F462632} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator => C:\Windows\System32\wsqmcons.exe [254976 2010-11-20] () [Archivo no firmado]
Task: {AB046733-5A8A-4C7A-8325-640568641974} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe [226304 2010-11-20] () [Archivo no firmado]
Task: {AB771A9F-FB0F-4FA1-8B5F-48186615901E} - System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader => {B210D694-C8DF-490d-9576-9E20CDBC20BD} C:\Windows\System32\mscms.dll [481792 2010-11-20] () [Archivo no firmado]
Task: {ABB61418-CEA3-4252-933E-5882E09888DE} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe [226304 2010-11-20] () [Archivo no firmado]
Task: {B21AEC8E-10B9-4306-A5F3-71A025CFED27} - System32\Tasks\{ED991389-BE4B-4AF7-B7CC-B0D1832835A5} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {B84DF9A1-7B83-43D0-8064-2A6EE64E8755} - System32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king"
Task: {BBA67AD0-4BA0-4B44-827B-FF419B70C057} - System32\Tasks\Microsoft\Windows\Multimedia\SystemSoundsService => {2DEA658F-54C1-4227-AF9B-260AB5FC3543} C:\Windows\System32\PlaySndSrv.dll [77312 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {BE1CE895-EB89-409C-BA22-400C9124ECD4} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe [226304 2010-11-20] () [Archivo no firmado]
Task: {C1287D5E-98C0-4EC6-B01E-FCF3DFF8B72B} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline => C:\Windows\system32\schtasks.exe [179712 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Task: {C4DE033A-ACBA-4C18-BDF8-0A2376F8A8DD} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe [226304 2010-11-20] () [Archivo no firmado]
Task: {C8875130-EE87-4D0B-A80F-C19F7CD84723} - System32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {CFA16B5A-F3C2-4F85-8DB2-2FA92D7AAA71} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask => C:\Windows\system32\Wat\WatAdminSvc.exe [1343400 2007-09-01] () [Archivo no firmado]
Task: {D1757C1D-4725-4D89-8029-CD0152E544D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [155592 2021-02-03] (Google LLC -> Google LLC)
Task: {D1CE5A1D-BD07-4CBE-8D10-110128F34D07} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-03-05] () [Archivo no firmado]
Task: {D21F6024-191F-4454-BBBC-09A650DA2549} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => C:\Windows\system32\aitagent.exe [119808 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Task: {D8BB5B7F-D0CA-4F67-A3D7-73E1D05F63DA} - System32\Tasks\Microsoft\Windows\Registry\RegIdleBackup => {ca767aa8-9157-4604-b64b-40747123d5f2} C:\Windows\System32\regidle.dll [13312 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {DE695A84-0462-4060-B25A-A3BAB91DD8A7} - System32\Tasks\{1DE68BB0-6FE7-44DA-BB6A-68934AA62C4F} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {DE8BAE53-2809-4F75-85EF-427D364B9B2C} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\UserTask => {58fb76b9-ac85-4e55-ac04-427593b1d060} C:\Windows\system32\dimsjob.dll [33792 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {DEA0D9DA-DDC3-425D-B110-6BD57CF6A5B8} - System32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors\aocsetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors"
Task: {DF0473CA-5396-44C4-8EA5-2ADC048F7812} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe [186368 2010-11-20] (Microsoft Windows -> Microsoft Corporation) [Archivo no firmado]
Task: {DFB6E67E-50D7-4765-81DC-FC8B4D8D32C9} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe [226304 2010-11-20] () [Archivo no firmado]
Task: {E6ACC982-AAA4-4DE0-B2F8-77F4479089DF} - System32\Tasks\{756D26E0-70EA-4E44-8D9E-4449B9D7E062} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {E6F3A527-8B0B-43FA-94EB-584032761924} - System32\Tasks\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual) => {BF5CB148-7C77-4d8a-A53E-D81C70CF743C} C:\Windows\system32\msdrm.dll [341504 2010-11-20] () [Archivo no firmado]
Task: {EA1FF304-EBFF-4D5F-8E1D-89078DA5BA3C} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe [186368 2010-11-20] () [Archivo no firmado]
Task: {EB06C55E-228A-48A7-BAEC-2C0EB28CB2F7} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-2564166442-1154501177-2247460648-1000 => C:\Users\Compaq\AppData\Local\MEGAsync\MEGAupdater.exe [1303800 2021-01-27] () [Archivo no firmado]
Task: {EBAB487D-830A-4276-A68B-0A1A3CC293A1} - System32\Tasks\{0D869573-A125-4AA8-815A-F62F1F629C64} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] () [Archivo no firmado]
Task: {F0484C32-58F7-49B2-8B62-052EF612C331} - System32\Tasks\{022CCAA3-CAC9-487A-BEDF-F482E735A9F2} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {F126990D-89BA-49F1-A1B6-C62DF84F3E81} - System32\Tasks\Microsoft\Windows\Offline Files\Background Synchronization => {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8} C:\Windows\System32\cscui.dll [418816 2010-11-20] () [Archivo no firmado]
Task: {F1369A11-E983-4458-B390-712EFA1CBA44} - System32\Tasks\Microsoft\Windows\TextServicesFramework\MsCtfMonitor => {01575cfe-9a55-4003-a5e1-f38d1ebdcbe1} C:\Windows\system32\MsCtfMonitor.dll [19968 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Task: {F2B3399D-06B0-4741-8C12-F99FDD18EBF7} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe [186368 2010-11-20] () [Archivo no firmado]
Task: {FC537326-8A46-4C8C-8376-8401BD1A9A57} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [1131008 2010-11-20] () [Archivo no firmado]
Task: {FFB8486A-9861-4B82-BE38-C7F8FB1B6605} - System32\Tasks\Microsoft\Windows\Task Manager\Interactive => {855fec53-d2e4-4999-9e87-3414e9cf0ff4} C:\Windows\system32\wdc.dll [1227776 2010-11-20] () [Archivo no firmado]

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)


==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Winsock: Catalog5 01 C:\Windows\system32\NLAapi.dll [52224 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [52224 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog5 05 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog5 06 C:\Windows\system32\winrnr.dll [20992 2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 01 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 02 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 03 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 04 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 05 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 06 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 07 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 08 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 09 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 10 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 11 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 12 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 13 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 14 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 15 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 16 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 17 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 18 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 19 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 20 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 21 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Winsock: Catalog9 22 C:\Windows\system32\mswsock.dll [232448 2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{78428608-F443-4A57-ACB5-18C3587CF969}: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF DefaultProfile: zm3xbplb.default
FF ProfilePath: C:\Users\Compaq\AppData\Roaming\Mozilla\Firefox\Profiles\zm3xbplb.default [2021-02-01]
FF ProfilePath: C:\Users\Compaq\AppData\Roaming\Mozilla\Firefox\Profiles\a0u3nkns.default-release [2021-04-13]
FF NetworkProxy: Mozilla\Firefox\Profiles\a0u3nkns.default-release -> type", 4
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] () [Archivo no firmado]

Chrome: 
=======
CHR Profile: C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default [2021-04-13]
CHR DefaultSearchURL: Default -> hxxps://ow2.res.office365.com/assets/mail/pwa/v1/pngs/Outlook.48x48x32.png
CHR Extension: (Presentaciones) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-10-04]
CHR Extension: (Documentos) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-10-04]
CHR Extension: (Google Drive) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-10-04]
CHR Extension: (Outlook) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\eigpmdhekjlgjgcppnanaanbdmnlnagl [2020-10-15]
CHR Extension: (Hojas de cálculo) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-10-04]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-16]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-03]
CHR Extension: (Gmail) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-16]

Addition.txt:

Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x86) Versión: 11-04-2021
Ejecutado por Compaq (13-04-2021 04:08:36)
Ejecutado desde C:\Users\Compaq\Desktop
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) (2007-09-01 04:15:42)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-2564166442-1154501177-2247460648-500 - Administrator - Disabled)
Compaq (S-1-5-21-2564166442-1154501177-2247460648-1000 - Administrator - Enabled) => C:\Users\Compaq
Invitado (S-1-5-21-2564166442-1154501177-2247460648-501 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Actualización de NVIDIA 17.12.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 17.12.8 - NVIDIA Corporation)
Adobe Reader XI (11.0.20) - Español (HKLM\...\{AC76BA86-7AD7-1034-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
Big City Adventure - San Francisco en Español (HKLM\...\Big City Adventure - San Francisco en Español) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.77 - Piriform)
Counter-Strike 1.6 (HKLM\...\Counter-Strike 1.6_is1) (Version: Counter-Strike 1.6 No Steam - KingSOFT DVD)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0190 - Disc Soft Ltd)
Freeciv 2.6.3 (GTK+3 client) (HKLM\...\Freeciv-2.6.3-gtk3) (Version:  - )
Google Chrome (HKLM\...\Google Chrome) (Version: 89.0.4389.114 - Google LLC)
Half-Life (HKLM\...\Half-Life_is1) (Version: Half-Life - No Steam - KingSOFT DVD)
Malwarebytes version 4.3.0.98 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.3.0.98 - Malwarebytes)
MEGAsync (HKLM\...\MEGAsync) (Version:  - Mega Limited)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 85.0.2 (x86 es-ES) (HKLM\...\Mozilla Firefox 85.0.2 (x86 es-ES)) (Version: 85.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 85.0 - Mozilla)
Need for Speed Underground 2 (HKLM\...\{909F8EBC-EC7F-48FF-0085-475D818F0F31}) (Version:  - )
Need for Speed™ Most Wanted Black Edition (HKLM\...\{ADE91A13-434D-4229-00BC-182BAD607303}) (Version:  - )
NVIDIA Controlador de gráficos 341.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation)
Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN (HKLM\...\Microsoft .NET Framework 4 Client Profile ESN Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Paquete de idioma de Microsoft .NET Framework 4 Extended ESN (HKLM\...\Microsoft .NET Framework 4 Extended ESN Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.12 - VideoLAN)
Voobly Game Data (HKLM\...\Voobly_is1) (Version: Voobly Game Datas - Voobly)
WinRAR 6.00 (32-bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)
Zuma Deluxe RN Version 1.0 (HKLM\...\Zuma Deluxe_is1) (Version:  - PopCap Games, Inc)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) [Archivo no firmado]
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2015-02-03] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) [Archivo no firmado]

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [VIDC.IV41] => C:\Windows\system32\IR41_32.AX [839680 2009-07-13] (Intel Corporation)

==================== Accesos directos & WMI ========================

(Las entradas pueden ser listadas para ser restauradas o eliminadas.)

Shortcut: C:\Users\Compaq\Desktop\MIO\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ningún archivo)
Shortcut: C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ningún archivo)
ShortcutWithArgument: C:\Users\Compaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Outlook.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=eigpmdhekjlgjgcppnanaanbdmnlnagl

==================== Módulos cargados (Lista blanca) =============

2010-01-09 21:07 - 2010-01-09 21:07 - 001488144 _____ () [Archivo no firmado] C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPOBJS.DLL
2007-08-31 23:51 - 2015-02-03 21:36 - 003956936 _____ () [Archivo no firmado] C:\Program Files\NVIDIA Corporation\Display\NvUI.dll
2007-08-31 23:51 - 2015-02-03 21:36 - 004602184 _____ () [Archivo no firmado] C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
2007-08-31 23:51 - 2015-02-03 21:36 - 001016136 _____ () [Archivo no firmado] C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll
2007-08-31 23:51 - 2015-02-03 21:36 - 001264784 _____ () [Archivo no firmado] C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll
2009-07-13 19:07 - 2009-07-13 20:45 - 000680960 _____ () [Archivo no firmado] c:\program files\windows defender\mpsvc.dll
2007-08-31 23:40 - 2020-12-01 13:31 - 000493104 _____ () [Archivo no firmado] C:\Program Files\WinRAR\rarext.dll
2020-07-21 18:46 - 2020-07-21 18:46 - 013053440 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\avcodec-58.dll
2020-07-21 18:46 - 2020-07-21 18:46 - 002290176 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\avformat-58.dll
2020-07-21 18:46 - 2020-07-21 18:46 - 000521728 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\avutil-56.dll
2020-07-21 18:30 - 2020-07-21 18:30 - 000065024 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\cares.dll
2020-03-31 10:40 - 2020-03-31 10:40 - 000420472 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\imageformats\qwebp.dll
2020-07-21 18:21 - 2020-07-21 18:21 - 002444288 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\libcrypto-1_1.dll
2020-07-21 18:21 - 2020-07-21 18:21 - 000504320 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\libssl-1_1.dll
2019-01-10 19:01 - 2019-01-10 19:01 - 000449280 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\MSVCP140.dll
2020-03-31 00:57 - 2020-03-31 00:57 - 001211000 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\platforms\qwindows.dll
2020-04-27 22:34 - 2020-04-27 22:34 - 005118072 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\Qt5Core.dll
2020-03-31 00:56 - 2020-03-31 00:56 - 005391480 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\Qt5Gui.dll
2020-03-31 00:56 - 2020-03-31 00:56 - 001053304 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\Qt5Network.dll
2020-03-31 00:56 - 2020-03-31 00:56 - 004543096 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\Qt5Widgets.dll
2021-01-27 20:15 - 2021-01-27 20:15 - 000620280 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll
2020-07-21 18:46 - 2020-07-21 18:46 - 000145408 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\swresample-3.dll
2020-07-21 18:46 - 2020-07-21 18:46 - 000570880 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\swscale-5.dll
2015-07-09 05:03 - 2015-07-09 05:03 - 000900288 _____ () [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\ucrtbase.DLL
2010-03-18 13:16 - 2010-03-18 13:16 - 000413008 _____ () [Archivo no firmado] C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000744448 _____ () [Archivo no firmado] C:\Windows\System32\Actioncenter.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 001792000 _____ () [Archivo no firmado] C:\Windows\system32\authui.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000740864 _____ () [Archivo no firmado] C:\Windows\system32\BatMeter.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000494592 _____ () [Archivo no firmado] c:\windows\system32\bfe.dll
2021-03-21 09:08 - 2010-11-20 04:16 - 000692736 _____ () [Archivo no firmado] C:\Windows\System32\bthprops.cpl
2021-03-21 09:08 - 2010-11-20 04:18 - 001003520 _____ () [Archivo no firmado] C:\Windows\system32\CRYPTUI.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000418816 _____ () [Archivo no firmado] C:\Windows\System32\cscui.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 001828352 _____ () [Archivo no firmado] C:\Windows\system32\d3d9.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000854016 _____ () [Archivo no firmado] c:\windows\system32\dbghelp.dll
2009-07-13 19:36 - 2009-07-13 20:45 - 000986624 _____ () [Archivo no firmado] C:\Windows\system32\drmv2clt.dll
2009-07-13 18:58 - 2009-07-13 20:45 - 000717824 _____ () [Archivo no firmado] C:\Windows\system32\DUI70.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 001371136 _____ () [Archivo no firmado] C:\Windows\system32\dwmcore.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 001076736 _____ () [Archivo no firmado] C:\Windows\system32\dwrite.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000508416 _____ () [Archivo no firmado] C:\Windows\system32\dxgi.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000399872 _____ () [Archivo no firmado] C:\Windows\system32\dxp.dll
2009-07-13 18:45 - 2009-07-13 20:45 - 000551424 _____ () [Archivo no firmado] C:\Windows\system32\ElsLad.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 001698816 _____ () [Archivo no firmado] c:\windows\system32\ESENT.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 001493504 _____ () [Archivo no firmado] C:\Windows\system32\EXPLORERFRAME.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000804864 _____ () [Archivo no firmado] c:\windows\system32\fntcache.dll
2009-07-13 19:45 - 2009-07-13 20:35 - 000925184 _____ () [Archivo no firmado] C:\Windows\system32\FXSRESM.DLL
2009-07-13 19:44 - 2009-07-13 20:45 - 000848384 _____ () [Archivo no firmado] C:\Windows\system32\fxsst.dll
2021-03-21 09:07 - 2010-11-20 04:19 - 000593408 _____ () [Archivo no firmado] c:\windows\system32\gpsvc.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 010990080 _____ () [Archivo no firmado] C:\Windows\System32\ieframe.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000499712 _____ () [Archivo no firmado] c:\windows\system32\iphlpsvc.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000768512 _____ () [Archivo no firmado] C:\Windows\System32\localspl.dll
2021-03-21 09:07 - 2010-11-20 04:19 - 003207680 _____ () [Archivo no firmado] C:\Windows\System32\mf.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000566272 _____ () [Archivo no firmado] c:\windows\system32\mpssvc.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000481792 _____ () [Archivo no firmado] C:\Windows\system32\mscms.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000592384 _____ () [Archivo no firmado] C:\Windows\system32\MsftEdit.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 002341376 _____ () [Archivo no firmado] C:\Windows\system32\msi.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 001401344 _____ () [Archivo no firmado] C:\Windows\system32\MSSRCH.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 001236992 _____ () [Archivo no firmado] C:\Windows\System32\msxml3.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 001390080 _____ () [Archivo no firmado] C:\Windows\System32\msxml6.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000801280 _____ () [Archivo no firmado] C:\Windows\System32\NaturalLanguage6.dll
2021-03-21 09:07 - 2010-11-20 04:20 - 002494464 _____ () [Archivo no firmado] C:\Windows\System32\netshell.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 001661440 _____ () [Archivo no firmado] C:\Windows\system32\NetworkExplorer.dll
2009-07-13 19:43 - 2009-07-13 20:46 - 010240512 _____ () [Archivo no firmado] C:\Windows\System32\NLSData000a.dll
2009-07-13 19:43 - 2009-07-13 20:38 - 009892864 _____ () [Archivo no firmado] C:\Windows\System32\NLSLexicons000a.dll
2007-08-31 23:46 - 2015-02-03 23:05 - 002824176 _____ () [Archivo no firmado] C:\Windows\system32\nvapi.dll
2007-08-31 23:51 - 2015-02-03 21:36 - 003060936 _____ () [Archivo no firmado] C:\Windows\system32\NVSVC.DLL
2007-08-31 23:51 - 2015-02-03 21:35 - 002553032 _____ () [Archivo no firmado] C:\Windows\system32\NVSVCR.DLL
2007-08-31 23:47 - 2015-02-03 23:05 - 016128576 _____ () [Archivo no firmado] C:\Windows\system32\nvwgf2um.dll
2009-07-13 18:51 - 2009-07-13 20:46 - 000578048 _____ () [Archivo no firmado] C:\Windows\system32\perftrack.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 001750528 _____ () [Archivo no firmado] C:\Windows\System32\pnidui.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000547840 _____ () [Archivo no firmado] C:\Windows\system32\PortableDeviceApi.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000441856 _____ () [Archivo no firmado] C:\Windows\System32\powercpl.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000395264 _____ () [Archivo no firmado] C:\Windows\system32\prnfldr.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000585728 _____ () [Archivo no firmado] c:\windows\system32\qmgr.dll
2009-07-13 19:25 - 2009-07-13 20:46 - 000772608 _____ () [Archivo no firmado] C:\Windows\System32\RASDLG.dll
2009-07-13 19:25 - 2009-07-13 20:46 - 000845824 _____ () [Archivo no firmado] C:\Windows\system32\RasMM.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000750592 _____ () [Archivo no firmado] c:\windows\system32\schedsvc.dll
2009-07-13 19:06 - 2009-07-13 20:46 - 001111552 _____ () [Archivo no firmado] C:\Windows\system32\sppcext.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000974336 _____ () [Archivo no firmado] C:\Windows\system32\sppobjs.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000412160 _____ () [Archivo no firmado] C:\Windows\system32\sppwinob.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 002146304 _____ () [Archivo no firmado] C:\Windows\System32\SyncCenter.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 001159168 _____ () [Archivo no firmado] c:\windows\system32\sysmain.dll
2009-07-13 18:50 - 2009-07-13 20:46 - 000606720 _____ () [Archivo no firmado] C:\Windows\System32\tdh.dll
2021-03-21 09:08 - 2010-11-20 04:16 - 000478720 _____ () [Archivo no firmado] C:\Windows\system32\timedate.cpl
2021-03-21 09:08 - 2010-11-20 04:21 - 001548288 _____ () [Archivo no firmado] C:\Windows\system32\TQUERY.DLL
2021-03-21 09:08 - 2010-11-20 04:21 - 000638976 _____ () [Archivo no firmado] C:\Windows\system32\van.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 001128448 _____ () [Archivo no firmado] C:\Windows\system32\VSSAPI.DLL
2021-03-21 09:07 - 2010-11-20 04:21 - 000780288 _____ () [Archivo no firmado] C:\Windows\system32\wbem\wbemcore.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000517120 _____ () [Archivo no firmado] C:\Windows\system32\wbem\wmiprvsd.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000782336 _____ () [Archivo no firmado] C:\Windows\system32\webservices.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 001063936 _____ () [Archivo no firmado] C:\Windows\System32\werconcpl.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 001086976 _____ () [Archivo no firmado] c:\windows\system32\wevtsvc.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000463360 _____ () [Archivo no firmado] c:\windows\system32\wiaservc.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000492032 _____ () [Archivo no firmado] C:\Windows\System32\win32spl.dll
2009-07-13 19:25 - 2009-07-13 20:46 - 000748544 _____ () [Archivo no firmado] C:\Windows\system32\WlanMM.dll
2009-07-13 19:22 - 2009-07-13 20:46 - 000829440 _____ () [Archivo no firmado] c:\windows\system32\wlansvc.dll
2009-07-13 19:37 - 2009-07-13 20:46 - 001202176 _____ () [Archivo no firmado] C:\Windows\system32\WMALFXGFXDSP.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000507392 _____ () [Archivo no firmado] C:\Windows\system32\wmdrmdev.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 011410432 _____ () [Archivo no firmado] C:\Windows\system32\wmp.dll
2021-03-21 09:08 - 2010-11-20 04:08 - 012625408 _____ () [Archivo no firmado] C:\Windows\system32\wmploc.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 002311168 _____ () [Archivo no firmado] C:\Windows\system32\wpdshext.dll
2009-07-13 19:01 - 2009-07-13 20:44 - 001140736 _____ () [Archivo no firmado] C:\Windows\System32\wscui.cpl
2021-03-21 09:08 - 2010-11-20 04:21 - 000458752 _____ () [Archivo no firmado] C:\Windows\system32\wsdapi.dll
2020-10-04 17:59 - 2012-06-02 17:49 - 001933848 _____ () [Archivo no firmado] c:\windows\system32\wuaueng.dll
2009-07-13 19:26 - 2009-07-13 20:46 - 000674304 _____ () [Archivo no firmado] C:\Windows\system32\WWanMM.dll
2021-03-21 09:08 - 2010-11-04 17:58 - 000632656 _____ () [Archivo no firmado] C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80.dll
2021-03-21 09:08 - 2010-11-04 17:53 - 000653136 _____ () [Archivo no firmado] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742\MSVCR90.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000530432 _____ () [Archivo no firmado] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll
2009-07-13 19:07 - 2009-07-13 20:45 - 000392704 _____ (Microsoft Corporation) [Archivo no firmado] c:\program files\windows defender\MpClient.dll
2009-07-13 19:07 - 2009-07-13 20:45 - 000153088 _____ (Microsoft Corporation) [Archivo no firmado] c:\program files\windows defender\mprtp.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000045568 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\acppage.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000309760 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\actxprxy.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000640512 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\ADVAPI32.dll
2009-07-13 18:42 - 2009-07-13 20:44 - 000062464 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\aelupsvc.dll
2009-07-13 18:50 - 2009-07-13 20:44 - 000062464 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\AEPIC.dll
2009-07-13 19:09 - 2009-07-13 20:44 - 000046592 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\AltTab.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000295936 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\apphelp.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000047104 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\appinfo.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000195584 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\audioses.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000473600 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\audiosrv.dll
2009-07-13 18:59 - 2009-07-13 20:44 - 000039936 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\bitsigd.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000019456 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\bitsperf.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000102400 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\browser.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000073216 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\Cabinet.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000145920 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\CFGMGR32.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000230912 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\CLUSAPI.DLL
2009-07-13 19:02 - 2009-07-13 20:45 - 000012288 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\cngaudit.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000485888 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\COMDLG32.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000017408 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\credssp.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 001154048 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\CRYPT32.dll
2009-07-13 19:02 - 2009-07-13 20:45 - 000103424 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\cryptnet.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000136192 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\cryptsvc.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000034816 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\CSCAPI.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000023040 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\CSCDLL.dll
2009-07-13 18:57 - 2009-07-13 20:45 - 000161792 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\d3d10_1.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000219136 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\d3d10_1core.dll
2009-07-13 18:57 - 2009-07-13 20:45 - 000011264 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\d3d8thk.dll
2009-07-13 19:33 - 2009-07-13 20:45 - 000066560 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\devenum.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000254464 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\dhcpcore.dll
2009-07-13 19:07 - 2009-07-13 20:45 - 000033792 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\dimsjob.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000270336 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\DNSAPI.dll
2009-07-13 19:26 - 2009-07-13 20:45 - 000006656 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\dnsext.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000132608 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\dnsrslvr.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000144384 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\dps.dll
2009-07-13 18:56 - 2009-07-13 20:45 - 000181248 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\DUser.dll
2009-07-13 18:54 - 2009-07-13 20:45 - 000067072 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\dwmapi.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000097280 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\dwmredir.dll
2009-07-13 19:26 - 2009-07-13 20:45 - 000183296 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\eappcfg.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000222208 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\eapphost.dll
2009-07-13 19:26 - 2009-07-13 20:45 - 000056320 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\eappprxy.dll
2009-07-13 19:26 - 2009-07-13 20:45 - 000098304 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\eapsvc.dll
2009-07-13 19:03 - 2009-07-13 20:45 - 000040448 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\efslsaext.dll
2021-03-21 09:07 - 2010-11-20 04:18 - 000128512 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\EhStorAPI.dll
2009-07-13 19:15 - 2009-07-13 20:45 - 000189952 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\EhStorShell.dll
2009-07-13 18:45 - 2009-07-13 20:45 - 000038912 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\elscore.dll
2009-07-13 19:14 - 2009-07-13 20:45 - 000271360 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\ES.DLL
2009-07-13 18:52 - 2009-07-13 20:45 - 000012800 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\fdphost.dll
2009-07-13 18:52 - 2009-07-13 20:45 - 000041984 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\fdPnp.dll
2009-07-13 18:52 - 2009-07-13 20:45 - 000027136 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\fdproxy.dll
2009-07-13 18:52 - 2009-07-13 20:45 - 000028160 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\fdrespub.dll
2009-07-13 18:52 - 2009-07-13 20:45 - 000076800 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\fdssdp.dll
2009-07-13 18:52 - 2009-07-13 20:45 - 000107008 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\fdwsd.dll
2009-07-13 18:44 - 2009-07-13 20:45 - 000014848 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\FLTLIB.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 000206336 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\framedynos.dll
2009-07-13 18:52 - 2009-07-13 20:45 - 000167424 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\FunDisc.dll
2021-03-21 09:07 - 2010-11-20 04:19 - 000216576 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\fwpuclnt.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 002576384 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\gameux.dll
2009-07-13 19:10 - 2009-07-13 20:45 - 000026112 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\hcproviders.dll
2021-03-21 09:07 - 2010-11-20 04:19 - 000312832 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\hgcpl.dll
2009-07-13 19:21 - 2009-07-13 20:45 - 000022016 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\HID.DLL
2009-07-13 19:23 - 2009-07-13 20:45 - 000288256 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\hnetcfg.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000034816 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\HTTPAPI.dll
2009-07-13 18:55 - 2009-07-13 20:45 - 000009728 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\IconCodecService.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 002064384 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\iertutil.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000155136 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\imagehlp.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000392192 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\imapi2.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000118272 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\IMM32.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 000103936 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\IPHLPAPI.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 000541696 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\kerberos.DLL
2009-07-13 19:02 - 2009-07-13 20:45 - 000019456 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\keyiso.dll
2009-07-13 19:33 - 2009-07-13 20:45 - 000004608 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\ksuser.dll
2009-07-13 19:21 - 2009-07-13 20:45 - 000057344 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\l2gpstore.dll
2009-07-13 19:09 - 2009-07-13 20:45 - 000022016 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\LINKINFO.dll
2009-07-13 19:23 - 2009-07-13 20:45 - 000018432 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\lmhsvc.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000127488 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\logoncli.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 001038848 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\lsasrv.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000076800 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\MAPI32.dll
2009-07-13 19:33 - 2009-07-13 20:45 - 000016896 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\midimap.dll
2009-07-13 19:10 - 2009-07-13 20:45 - 000177664 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\MLANG.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000213504 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\MMDevAPI.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 000158720 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\MPRAPI.dll
2009-07-13 19:33 - 2009-07-13 20:45 - 000072192 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\MSACM32.dll
2009-07-13 19:33 - 2009-07-13 20:44 - 000020992 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\msacm32.drv
2021-03-21 09:08 - 2010-11-20 04:19 - 000034304 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\MSASN1.dll
2009-07-13 18:56 - 2009-07-13 20:45 - 000019968 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\MsCtfMonitor.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000030720 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\msdmo.dll
2009-07-13 19:09 - 2009-07-13 20:45 - 000007680 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\Msidle.dll
2009-07-13 18:55 - 2009-07-13 20:45 - 000004608 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\MSIMG32.dll
2009-07-13 18:56 - 2009-07-13 20:45 - 000157184 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\msls31.dll
2009-07-13 19:03 - 2009-07-13 20:37 - 000002048 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\msprivs.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 000209920 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\mstask.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000167936 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\msutb.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000257024 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\msv1_0.DLL
2021-03-21 09:08 - 2010-11-20 04:19 - 000232448 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\mswsock.dll
2009-07-13 19:24 - 2009-07-13 20:46 - 000052224 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\napinsp.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000078848 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\NCI.dll
2009-07-13 19:00 - 2009-07-13 20:46 - 000049152 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\NCObjAPI.DLL
2021-03-21 09:08 - 2010-11-20 04:20 - 000152064 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\ncsi.dll
2009-07-13 19:22 - 2009-07-13 20:46 - 000041984 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\ndiscapCfg.dll
2009-07-13 19:04 - 2009-07-13 20:46 - 000093696 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\negoexts.DLL
2021-03-21 09:08 - 2010-11-20 04:20 - 000056832 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\NETAPI32.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000406528 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\netcfgx.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000161792 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\netjoin.dll
2021-03-21 09:07 - 2010-11-20 04:20 - 000563712 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\netlogon.DLL
2009-07-13 19:22 - 2009-07-13 20:46 - 000280576 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\netman.dll
2009-07-13 19:26 - 2009-07-13 20:46 - 000360448 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\netprofm.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000022528 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\netutils.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000052224 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\nlaapi.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000242688 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\nlasvc.dll
2009-07-13 18:45 - 2009-07-13 20:39 - 000002048 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\Normaliz.dll
2009-07-13 19:26 - 2009-07-13 20:46 - 000016896 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\npmproxy.dll
2021-03-21 09:07 - 2010-11-20 04:20 - 000011776 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\nrpsrv.DLL
2009-07-13 18:42 - 2009-07-13 20:46 - 000019456 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\nsisvc.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000442880 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\ntshrui.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 001414144 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\ole32.dll
2009-07-13 18:56 - 2009-07-13 20:46 - 000233472 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\OLEACC.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000571904 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\OLEAUT32.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000199168 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\OneX.DLL
2009-07-13 18:50 - 2009-07-13 20:46 - 000154624 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\pcasvc.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000236544 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\pdh.dll
2009-07-13 19:04 - 2009-07-13 20:46 - 000186880 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\pku2u.DLL
2009-07-13 19:33 - 2009-07-13 20:46 - 000077312 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\PlaySndSrv.dll
2009-07-13 18:50 - 2009-07-13 20:46 - 000010752 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\pnpts.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000032768 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\PrintIsolationProxy.dll
2021-03-21 09:07 - 2010-11-20 04:20 - 000164352 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\profsvc.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000988160 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\PROPSYS.dll
2021-03-21 09:08 - 2010-11-20 04:20 - 000171520 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\QAgent.dll
2009-07-13 18:59 - 2009-07-13 20:46 - 000021504 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\qmgrprxy.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000080896 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\QUtil.dll
2009-07-13 18:50 - 2009-07-13 20:46 - 000085504 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\radardt.dll
2009-07-13 18:50 - 2009-07-13 20:46 - 000062976 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\radarrs.dll
2009-07-13 19:24 - 2009-07-13 20:46 - 000011776 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\rasadhlp.dll
2009-07-13 19:24 - 2009-07-13 20:46 - 000081408 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\rascfg.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000071168 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\RESUTILS.DLL
2009-07-13 18:42 - 2009-07-13 20:46 - 000043520 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\rpcepmap.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000046080 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\RpcRtRemote.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000376832 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\rpcss.dll
2009-07-13 18:52 - 2009-07-13 20:46 - 000152064 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\RstrtMgr.DLL
2021-03-21 09:08 - 2010-11-20 04:21 - 000037376 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\rtutils.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000051200 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\samcli.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000551424 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SAMSRV.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000175616 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\scecli.DLL
2021-03-21 09:08 - 2010-11-20 04:21 - 000307712 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SCESRV.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000224256 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\schannel.DLL
2009-07-13 19:12 - 2009-07-13 20:46 - 000173568 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\scrobj.dll
2009-07-13 19:12 - 2009-07-13 20:46 - 000163840 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\scrrun.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000646144 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SearchFolder.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000022016 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\secur32.dll
2009-07-13 18:51 - 2009-07-13 20:46 - 000049664 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\sens.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 001667584 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SETUPAPI.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000179712 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\shdocvw.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 012872192 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SHELL32.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000350208 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SHLWAPI.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000328192 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\shsvcs.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000014336 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\slwga.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000220160 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SndVolSSO.DLL
2009-07-13 19:25 - 2009-07-13 20:46 - 000022528 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\snmpapi.dll
2009-07-13 18:46 - 2009-07-13 20:46 - 000081920 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SPFILEQ.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000030208 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\spool\PRTPROCS\W32X86\winprint.dll
2009-07-13 19:48 - 2009-07-13 20:46 - 000045056 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\SPOOLSS.DLL
2021-03-21 09:08 - 2010-11-20 04:20 - 000121344 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\sppc.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000193536 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\sppcomapi.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000053760 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\sppuinotify.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000090112 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\srvcli.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000168960 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\srvsvc.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000009728 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SSCORE.DLL
2009-07-13 19:25 - 2009-07-13 20:46 - 000039936 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SSDPAPI.dll
2009-07-13 19:25 - 2009-07-13 20:46 - 000162816 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\ssdpsrv.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000100352 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SSPICLI.DLL
2021-03-21 09:08 - 2010-11-20 04:21 - 000015872 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SspiSrv.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000228352 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\stobject.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000363520 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\StructuredQuery.dll
2009-07-13 18:53 - 2009-07-13 20:46 - 000313856 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\swprv.dll
2009-07-13 19:09 - 2009-07-13 20:46 - 000078336 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\SYNCENG.dll
2009-07-13 19:37 - 2009-07-13 20:46 - 000055296 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\Syncreg.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000159232 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\syncui.dll
2009-07-13 19:49 - 2009-07-13 20:46 - 000192000 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\TAPI32.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000305152 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\taskcomp.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000505856 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\taskschd.dll
2009-07-13 18:42 - 2009-07-13 20:46 - 000012288 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\tbs.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000181760 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\tcpipcfg.dll
2009-07-13 19:48 - 2009-07-13 20:46 - 000148992 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\tcpmon.dll
2009-07-13 19:09 - 2009-07-13 20:46 - 000037376 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\themeservice.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000082944 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\thumbcache.dll
2009-07-13 19:14 - 2009-07-13 20:46 - 000077312 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\trkwks.dll
2009-07-13 18:59 - 2009-07-13 20:46 - 000013312 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\tschannel.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000065024 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\tspkg.DLL
2021-03-21 09:08 - 2010-11-20 04:21 - 000146432 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\twext.dll
2009-07-13 18:49 - 2009-07-13 20:46 - 000170496 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\UBPM.dll
2009-07-13 18:58 - 2009-07-13 20:46 - 000099328 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\UIAnimation.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000050688 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\umb.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000293376 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\umpnpmgr.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000119808 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\umpo.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000206848 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\upnp.dll
2009-07-13 19:25 - 2009-07-13 20:46 - 000266752 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\upnphost.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 001229824 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\urlmon.dll
2009-07-13 19:48 - 2009-07-13 20:46 - 000034304 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\usbmon.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000081920 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\USERENV.dll
2009-07-13 18:54 - 2009-07-13 20:46 - 000029696 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\uxsms.dll
2009-07-13 18:45 - 2009-07-13 20:46 - 000017408 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\VirtDisk.dll
2009-07-13 18:53 - 2009-07-13 20:46 - 000026112 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\vss_ps.dll
2009-07-13 18:53 - 2009-07-13 20:46 - 000056320 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\VssTrace.DLL
2009-07-13 19:00 - 2009-07-13 20:46 - 000056832 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wbem\ncprov.dll
2009-07-13 19:01 - 2009-07-13 20:46 - 000187392 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wbem\wbemdisp.dll
2009-07-13 19:00 - 2009-07-13 20:46 - 000342528 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wbem\wbemess.dll
2009-07-13 19:00 - 2009-07-13 20:46 - 000047616 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wbem\wbemsvc.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000131072 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wbem\wmidcprv.dll
2009-07-13 18:49 - 2009-07-13 20:46 - 000090112 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wbem\WmiPerfClass.dll
2009-07-13 19:00 - 2009-07-13 20:46 - 000168960 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\wbem\wmisvc.dll
2009-07-13 18:49 - 2009-07-13 20:46 - 000076288 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\wdi.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000031744 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wdiasqmmodule.dll
2009-07-13 19:04 - 2009-07-13 20:46 - 000171520 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wdigest.DLL
2021-03-21 09:08 - 2010-11-20 04:16 - 000172032 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wdmaud.drv
2021-03-21 09:08 - 2010-11-20 04:21 - 000314880 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\webio.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000381440 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\wer.dll
2009-07-13 18:57 - 2009-07-13 20:46 - 000061440 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\wercplsupport.dll
2009-07-13 19:22 - 2009-07-13 20:46 - 000018944 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wfapigp.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000033280 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wiarpc.dll
2009-07-13 19:44 - 2009-07-13 20:46 - 000012800 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wiatrace.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 001010688 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WindowsCodecs.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000351232 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WINHTTP.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000980992 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WININET.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000194048 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WINMM.dll
2009-07-13 19:07 - 2009-07-13 20:46 - 000020992 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\winrnr.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000335872 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WinSATAPI.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000134656 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\WinSCard.dll
2021-03-21 09:08 - 2010-11-20 04:16 - 000320000 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\WINSPOOL.DRV
2021-03-21 09:07 - 2010-11-20 04:21 - 000156672 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WINSTA.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000172032 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WINTRUST.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000047104 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wkscli.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000084480 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\wkssvc.dll
2009-07-13 19:21 - 2009-07-13 20:46 - 000081408 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\Wlanapi.dll
2009-07-13 19:21 - 2009-07-13 20:46 - 000084480 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wlanhlp.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000428032 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\WLANMSM.DLL
2009-07-13 19:21 - 2009-07-13 20:46 - 000392192 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\WLANSEC.dll
2009-07-13 19:21 - 2009-07-13 20:46 - 000008192 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\wlanutil.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000269824 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WLDAP32.dll
2009-07-13 19:21 - 2009-07-13 20:46 - 000118784 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\wlgpclnt.dll
2009-07-13 19:06 - 2009-07-13 20:46 - 000008704 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wls0wndh.dll
2009-07-13 19:49 - 2009-07-13 20:41 - 000005120 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\WMI.dll
2009-07-13 19:06 - 2009-07-13 20:46 - 000011264 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WMsgAPI.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000206848 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WS2_32.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000051712 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\WSCAPI.dll
2009-07-13 19:01 - 2009-07-13 20:46 - 000095744 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\wscinterop.dll
2021-03-21 09:07 - 2010-11-20 04:21 - 000021504 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WSDCHNGR.DLL
2009-07-13 19:48 - 2009-07-13 20:46 - 000185344 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\WSDMon.dll
2009-07-13 19:23 - 2009-07-13 20:46 - 000013824 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\wshqos.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000051712 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\System32\wsnmp32.dll
2009-07-13 19:25 - 2009-07-13 20:46 - 000015360 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WSOCK32.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000040448 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\WTSAPI32.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000162304 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\WUDFPlatform.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000067584 _____ (Microsoft Corporation) [Archivo no firmado] c:\windows\system32\wudfsvc.dll
2009-07-13 19:26 - 2009-07-13 20:46 - 000284672 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wwanapi.dll
2009-07-13 19:26 - 2009-07-13 20:46 - 000027648 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\wwapi.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000327680 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\system32\zipfldr.dll
2021-03-21 09:08 - 2010-11-20 03:55 - 001680896 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\COMCTL32.dll
2021-03-21 09:08 - 2010-11-20 03:55 - 001624576 _____ (Microsoft Corporation) [Archivo no firmado] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
2021-03-21 09:08 - 2010-11-20 04:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.DLL
2009-07-13 18:41 - 2009-07-13 20:45 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\CSRSRV.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000304640 _____ (Microsoft Corporation) C:\Windows\system32\GDI32.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000857600 _____ (Microsoft Corporation) C:\Windows\SYSTEM32\kernel32.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\KERNELBASE.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000653312 _____ (Microsoft Corporation) C:\Windows\system32\RPCRT4.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000380416 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000811520 _____ (Microsoft Corporation) C:\Windows\system32\USER32.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000626176 _____ (Microsoft Corporation) C:\Windows\system32\USP10.dll
2021-03-21 09:08 - 2010-11-20 04:21 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.DLL
2009-07-13 18:41 - 2009-07-13 20:45 - 000020480 _____ (Microsoft Windows -> Microsoft Corporation) [Archivo no firmado] c:\windows\system32\ktmw32.dll
2020-07-21 18:32 - 2020-07-21 18:32 - 000295936 _____ (The curl library, hxxps://curl.haxx.se/) [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\libcurl.dll
2021-03-21 09:08 - 2010-11-20 04:19 - 000093696 _____ (Windows (R) Codename Longhorn DDK provider) [Archivo no firmado] C:\Windows\system32\fms.dll

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\32800591.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\32800591.sys => ""="Driver"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer (Versión 8) (Lista blanca) ==========

HKU\S-1-5-21-2564166442-1154501177-2247460648-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.msn.com/es-ve/?ocid=iehp
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] () [Archivo no firmado]
Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2010-11-20] () [Archivo no firmado]
Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll [2010-11-20] () [Archivo no firmado]
Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2010-11-20] () [Archivo no firmado]
Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2010-11-20] () [Archivo no firmado]
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll [2010-11-20] () [Archivo no firmado]
Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll [2009-05-23] () [Archivo no firmado]
Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2009-07-13] (Microsoft Corporation) [Archivo no firmado]
Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2010-11-20] () [Archivo no firmado]
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll [2010-11-20] () [Archivo no firmado]
Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2010-11-20] () [Archivo no firmado]
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) [Archivo no firmado]

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2021-02-02 23:04 - 2021-04-07 18:30 - 000000983 _____ C:\Windows\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKU\S-1-5-21-2564166442-1154501177-2247460648-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Compaq\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: DAEMON Tools Lite Automount => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
MSCONFIG\startupreg: Voobly => "C:\Program Files\Voobly\voobly.exe" --startup

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [TCP Query User{8CD26569-87FA-47C0-80E2-D5E45AC96B15}C:\program files\microsoft games\age of empires ii\empires2.exe] => (Allow) C:\program files\microsoft games\age of empires ii\empires2.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{D998B48E-004B-44A8-A6FF-01C26BCA7163}C:\program files\microsoft games\age of empires ii\empires2.exe] => (Allow) C:\program files\microsoft games\age of empires ii\empires2.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{AE9693B1-5E0B-4D6B-A968-C8B6FF7FAB14}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{DC7704C6-148A-4BD0-B6B2-D3BE4693F85D}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{65F9EFEC-1FC5-45B9-BB8D-F64BBB0D42D0}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{1C1304FB-DF73-4240-97A6-B4CDAB12F0C1}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{1838A184-D235-4F28-9806-E1558B7765CE}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{AC945FC5-049F-4CF9-A260-9E64C68FE963}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{3FA4DB93-BF3C-47B4-A74D-CA2B6CCB0071}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [UDP Query User{30C8772A-61D5-4316-88B2-54B965E14BE7}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [TCP Query User{4CC594B4-994A-4F99-81FA-C102E327671F}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [UDP Query User{C216244A-10D5-43CF-8C21-B8B7D48B3FBA}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [{F5A5BD9A-6B9D-494C-A9AB-14C409286E09}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe () [Archivo no firmado]
FirewallRules: [{DC50C8A4-7200-4BBD-88AF-693B895FD208}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe () [Archivo no firmado]
FirewallRules: [{10530CC6-56A9-4CFD-ADAE-12B6B35D9A66}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{D7A5216F-A159-40FE-B12B-79E7884B0F20}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{E27EFDBA-AF88-45AE-AB36-E51D19E1528C}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{CD55D127-1D97-4011-B3E4-692E9D17BED1}C:\program files\counter-strike 1.6\hl.exe] => (Allow) C:\program files\counter-strike 1.6\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [UDP Query User{B8FD7C99-1F56-48F7-B36C-B31FA7E9BEEF}C:\program files\counter-strike 1.6\hl.exe] => (Allow) C:\program files\counter-strike 1.6\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [TCP Query User{EE17AEA0-458D-441D-8087-6DC0BF4FDF97}C:\program files\voobly\voobly.exe] => (Allow) C:\program files\voobly\voobly.exe (Voobly) [Archivo no firmado]
FirewallRules: [UDP Query User{1BF2B6C1-A965-42FD-9C3A-96EB5E952E97}C:\program files\voobly\voobly.exe] => (Allow) C:\program files\voobly\voobly.exe (Voobly) [Archivo no firmado]
FirewallRules: [TCP Query User{3383C12A-E1E5-4392-B416-7726202A7457}C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe] => (Allow) C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{2B61AFF9-4CF3-469F-A5B2-B3E9226BF47C}C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe] => (Allow) C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{612F22CA-3303-47D9-A0F5-7E3FF34B2B65}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{4D42DBB5-DB95-402D-BE07-2908BD130DAB}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{FEB395BE-1609-4E16-86F8-3A1ABF57A3D6}C:\program files\ea games\need for speed underground 2\speed2.exe] => (Block) C:\program files\ea games\need for speed underground 2\speed2.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{DC777137-DE87-4390-9C06-C9A3F1AF5F36}C:\program files\ea games\need for speed underground 2\speed2.exe] => (Block) C:\program files\ea games\need for speed underground 2\speed2.exe () [Archivo no firmado]
FirewallRules: [{78C83FCA-4BFD-4F11-B51E-8F6AA10F8077}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{7D219220-B3DD-4F5B-93D3-C378FE32546E}C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe] => (Allow) C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{77325613-A62E-4F64-800F-AAF88230FFE1}C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe] => (Allow) C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe () [Archivo no firmado]

==================== Puntos de Restauración =========================

12-04-2021 02:39:46 Punto de control programado

==================== Dispositivos defectuosos en el Administrador de dispositivos ============


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (04/13/2021 03:48:40 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:48:40 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:48:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:46:11 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:46:11 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:46:11 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:46:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/13/2021 03:46:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.


Errores del sistema:
=============
Error: (04/12/2021 04:17:49 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 40

Error: (04/12/2021 01:53:33 AM) (Source: volsnap) (EventID: 36) (User: )
Description: Se anularon las instantáneas del volumen C: porque el almacenamiento de instantáneas no pudo crecer debido a un límite impuesto por el usuario.

Error: (04/12/2021 12:56:43 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 40

Error: (04/12/2021 12:56:41 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 70

Error: (04/12/2021 12:56:41 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 70

Error: (04/12/2021 12:56:37 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 40

Error: (04/12/2021 12:56:36 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 70

Error: (04/12/2021 12:56:35 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: 70


==================== Información de la memoria =========================== 

BIOS: Hewlett-Packard F.54 08/18/2009
Placa base: Wistron 360A
Procesador: AMD Athlon Dual-Core QL-65
Porcentaje de memoria en uso: 98%
RAM física total: 1406.43 MB
RAM física disponible: 23.73 MB
Virtual total: 2812.85 MB
Virtual disponible: 306.44 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:297.99 GB) (Free:226.38 GB) NTFS

\\?\Volume{5fbd3783-5845-11dc-95a5-806e6f6e6963}\ (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 000852C1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)

==================== Final  Addition.txt =======================

Saludos.

Hola, buenas @ManU disculpa que haya tardado en responder.

Pon de nuevo el reporte de FRST.txt ya que falta un trozo pues está incompleto y se acaba en la parte del chrome:

Chrome: 
=======
CHR Profile: C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default [2021-04-13]
CHR DefaultSearchURL: Default -> hxxps://ow2.res.office365.com/assets/mail/pwa/v1/pngs/Outlook.48x48x32.png
CHR Extension: (Presentaciones) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-10-04]
CHR Extension: (Documentos) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-10-04]
CHR Extension: (Google Drive) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-10-04]
CHR Extension: (Outlook) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\eigpmdhekjlgjgcppnanaanbdmnlnagl [2020-10-15]
CHR Extension: (Hojas de cálculo) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-10-04]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-03-16]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-03]
CHR Extension: (Gmail) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-03-16]

Y ese debería de seguir hasta que vieses una línea que indica el final del FRST.txt como esta:

==================== Final de FRST.txt ========================

Salu2.

Hola,

El reporte termina en esa linea de chrome, significa que el analisis no se completó?

Debo hacer el analisis de nuevo?, Saludos.

Hola @ManU

Correcto. Por el motivo que sea no se completó el reporte o algo sucedió y no se finalizó el FRST.txt lo extraño es que el de Addition.txt sí que es correcto.

¿Desactivaste temporalmente el antivirus? Es decir en tu caso el Windows Defender.

Sí, repítelo y trae de nuevos ambos reportes de todas formas (FRST.txt y Addition.txt).

Salu2.

Hola,

Al intentar desactivar Windows Defender me dice que debo actualizar las definiciones y no me deja acceder a herramientas para desactivarlo:

Supuse que al actualizar las definiciones me permitiría usar las herramientas, pero después de un rato de buscar actualizaciones me salta este error:

En el centro de actividades me dice que no tengo ningún antivirus activado, asi que no estoy seguro de si Windows Defender esta activado o no. Saludos.

OK @ManU

Inicia de nuevo el equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows. Si no funcionasen los métodos que se explican en el anterior post, prueba estos otros. Más concretamente, primero el 3 (Seleccionando Red en lugar de Mínimo) y si no el 2 (también Red).

Una vez iniciado en este modo, lanzas de nuevo el FRST y traes ambos reportes.

Salu2.

Hola, disculpa por tardar tanto, estuve un poco ocupado esta semana; aquí están los reportes de FRST:

FRST.txt:

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x86) Versión: 11-04-2021
Ejecutado por Compaq (administrador) sobre COMPAQ-PC (Hewlett-Packard Compaq Presario CQ50 Notebook PC) (26-04-2021 01:47:37)
Ejecutado desde C:\Users\Compaq\Desktop
Perfiles cargados: Compaq
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) Idioma: Español (España, internacional)
Navegador predeterminado: Chrome
Modo de Inicio: Safe Mode (with Networking)

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)


==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKU\S-1-5-21-2564166442-1154501177-2247460648-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\90.0.4430.85\Installer\chrmstp.exe [2021-04-22] (Google LLC -> Google LLC)
Startup: C:\Users\Compaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2021-02-26]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Compaq\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited) [Archivo no firmado]
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {005562C2-0D59-44CE-A90C-3A1E547AE482} - System32\Tasks\{128EA561-FD5D-4374-9291-1D03B1367650} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {0B868266-BDD9-4E3D-994D-314F2F87EB56} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [27168840 2021-03-05] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {113EE6A9-8252-4FC0-A808-F8BDF5152636} - System32\Tasks\{D83C7160-6527-4C94-AB28-C4BF3E39F690} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {18812853-2BB2-4E2A-A44E-5188087FD45B} - System32\Tasks\{0159B6AC-B769-4762-95EB-FBE5CF9298BA} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {1B73CCB5-700C-4551-8F8D-5B24A0C8E513} - System32\Tasks\{E51C5BC4-FFB2-432B-937A-446362325A61} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\GAME\Empires2.exe
Task: {1ED2A39D-8F7E-4A93-A367-95572ED379FA} - System32\Tasks\{8CC2D41B-A8C1-4E0F-BB2A-EBBED8A08648} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {2D350632-6B1E-4028-9CB0-415643D462BF} - System32\Tasks\{DBF1DDE3-8D89-4178-9D74-CA7796EBB490} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {39E24656-8EDC-4D1E-8084-9FD6715AE205} - System32\Tasks\{AFDB173F-F90C-4010-8E70-0926A15EAD4C} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {4C7ABC85-FE40-4DF3-B340-4256A8EDA3C6} - System32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {611FCC7E-2BE6-4FE6-82E9-C9FF46DFD8C5} - System32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {64DA3287-8A12-4FBC-B712-C4D1C652D7CD} - System32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {6EF9FD15-C349-4133-B166-915EC96EE15A} - System32\Tasks\{DAB034BB-7842-4268-A78A-6A9BBE1080A4} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {7BEBF731-9230-4028-995F-40490DCB830C} - System32\Tasks\{A2D09495-2796-46E3-99A1-97D79064D88E} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\GAME\Empires2.exe
Task: {8216A799-EBD8-4DCD-A6A8-B86E4DC96DAC} - System32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {86F80BCB-515D-4F37-B8EF-5FFE87A757D3} - System32\Tasks\{B57F43F2-575C-4A4B-BC76-FC3FCE021DBE} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {8C193216-B3A6-4026-A5EE-630CB7B121F0} - System32\Tasks\{22FA84A6-D016-4465-A729-338F2A2DF579} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\GAME\Empires2.exe
Task: {9A230BC2-05F9-4646-B5D3-755E69EDD66A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [155592 2021-02-03] (Google LLC -> Google LLC)
Task: {9B17E06E-479A-4F2A-851E-4207D2BB145A} - System32\Tasks\{7311AFC6-BA20-43A8-B01A-11D7241AE240} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {9E90588B-E6A2-4B5D-98A1-1583C548802E} - System32\Tasks\{2F3A0085-F1BB-42CB-81FB-1C9FADCEC589} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe
Task: {B21AEC8E-10B9-4306-A5F3-71A025CFED27} - System32\Tasks\{ED991389-BE4B-4AF7-B7CC-B0D1832835A5} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {B84DF9A1-7B83-43D0-8064-2A6EE64E8755} - System32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king"
Task: {C8875130-EE87-4D0B-A80F-C19F7CD84723} - System32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {D1757C1D-4725-4D89-8029-CD0152E544D2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [155592 2021-02-03] (Google LLC -> Google LLC)
Task: {D1CE5A1D-BD07-4CBE-8D10-110128F34D07} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-03-05] (Piriform Software Ltd -> Piriform)
Task: {DE695A84-0462-4060-B25A-A3BAB91DD8A7} - System32\Tasks\{1DE68BB0-6FE7-44DA-BB6A-68934AA62C4F} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {DEA0D9DA-DDC3-425D-B110-6BD57CF6A5B8} - System32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors\aocsetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors"
Task: {E6ACC982-AAA4-4DE0-B2F8-77F4479089DF} - System32\Tasks\{756D26E0-70EA-4E44-8D9E-4449B9D7E062} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {EB06C55E-228A-48A7-BAEC-2C0EB28CB2F7} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-2564166442-1154501177-2247460648-1000 => C:\Users\Compaq\AppData\Local\MEGAsync\MEGAupdater.exe [1303800 2021-01-27] (Mega Limited -> Mega Limited) [Archivo no firmado]
Task: {EBAB487D-830A-4276-A68B-0A1A3CC293A1} - System32\Tasks\{0D869573-A125-4AA8-815A-F62F1F629C64} => C:\Program Files\Microsoft Games\Age of Empires II\Age2_X1\age2_x1.Exe [3145728 2019-05-12] (Microsoft Corporation) [Archivo no firmado]
Task: {F0484C32-58F7-49B2-8B62-052EF612C331} - System32\Tasks\{022CCAA3-CAC9-487A-BEDF-F482E735A9F2} => C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)


==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{78428608-F443-4A57-ACB5-18C3587CF969}: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF DefaultProfile: zm3xbplb.default
FF ProfilePath: C:\Users\Compaq\AppData\Roaming\Mozilla\Firefox\Profiles\zm3xbplb.default [2021-02-01]
FF ProfilePath: C:\Users\Compaq\AppData\Roaming\Mozilla\Firefox\Profiles\a0u3nkns.default-release [2021-04-25]
FF NetworkProxy: Mozilla\Firefox\Profiles\a0u3nkns.default-release -> type", 4
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems, Incorporated -> Adobe Systems Inc.) [Archivo no firmado]

Chrome: 
=======
CHR Profile: C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default [2021-04-26]
CHR DefaultSearchURL: Default -> hxxps://ow2.res.office365.com/assets/mail/pwa/v1/pngs/Outlook.48x48x32.png
CHR Extension: (Presentaciones) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2020-10-04]
CHR Extension: (Documentos) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2020-10-04]
CHR Extension: (Google Drive) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2020-10-24]
CHR Extension: (YouTube) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2020-10-04]
CHR Extension: (Outlook) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\eigpmdhekjlgjgcppnanaanbdmnlnagl [2020-10-15]
CHR Extension: (Hojas de cálculo) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2020-10-04]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2021-04-16]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-02-03]
CHR Extension: (Gmail) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2020-10-24]
CHR Extension: (Chrome Media Router) - C:\Users\Compaq\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2021-04-24]

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1138368 2016-05-30] (Disc Soft Ltd -> Disc Soft Ltd) [Archivo no firmado]
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Windows -> Microsoft Corporation)

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R3 athr; C:\Windows\System32\DRIVERS\athr.sys [1096704 2009-07-13] (Microsoft Windows -> Atheros Communications, Inc.)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [26168 2021-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [40504 2021-02-02] (Disc Soft Ltd -> Disc Soft Ltd)
R3 nvsmu; C:\Windows\System32\DRIVERS\nvsmu.sys [18944 2010-03-22] (Microsoft Windows Hardware Compatibility Publisher -> NVIDIA Corporation)
R3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [283864 2014-12-08] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation)
S3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL3.SYS [207360 2009-07-13] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV3.SYS [980992 2009-07-13] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT3.SYS [661504 2009-07-13] (Microsoft Windows -> Conexant Systems, Inc.)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) (Lista blanca) =========

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2021-04-26 01:47 - 2021-04-26 01:48 - 000013300 _____ C:\Users\Compaq\Desktop\FRST.txt
2021-04-26 01:46 - 2021-04-26 01:46 - 000065302 _____ C:\Windows\ntbtlog.txt
2021-04-26 01:02 - 2021-04-26 01:03 - 000000000 ____D C:\Users\Compaq\Downloads\Explicaciones
2021-04-26 01:01 - 2021-04-26 01:01 - 001226461 _____ C:\Users\Compaq\Downloads\Clases. Primera y Segunda Ley de Newton.pdf
2021-04-26 00:55 - 2021-04-26 00:58 - 000001201 _____ C:\Users\Compaq\Desktop\Ejercicios Fisica.txt
2021-04-25 22:51 - 2021-04-25 22:52 - 000903763 _____ C:\Users\Compaq\Downloads\Clases. Tercera Ley de Newton.pdf
2021-04-25 19:53 - 2021-04-26 00:35 - 000000674 _____ C:\Users\Compaq\Desktop\Formulas de la 1ra y 2da Ley de Newton.txt
2021-04-25 19:25 - 2021-04-25 19:25 - 000000214 _____ C:\Users\Compaq\Desktop\Tabla Unidades de Fuerza.txt
2021-04-17 01:50 - 2021-04-17 01:50 - 000013065 _____ C:\Users\Compaq\Desktop\Windows Defender - Acceso directo.lnk
2021-04-13 04:03 - 2021-04-26 01:47 - 000000000 ____D C:\FRST
2021-04-12 19:28 - 2021-04-12 19:29 - 002010624 _____ (Farbar) C:\Users\Compaq\Desktop\FRST.exe
2021-04-12 01:21 - 2021-04-12 02:09 - 000000000 ____D C:\FSTool
2021-04-10 14:30 - 2021-04-10 15:26 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\ZHP
2021-04-10 14:30 - 2021-04-10 14:30 - 000000000 ____D C:\Users\Compaq\AppData\Local\ZHP
2021-04-09 14:23 - 2021-04-09 14:26 - 000000000 ____D C:\Users\Compaq\Desktop\MIO
2021-04-07 12:39 - 2021-04-07 18:30 - 000000000 ____D C:\Users\Compaq\Doctor Web
2021-04-07 00:05 - 2021-04-07 02:48 - 243542488 ____H C:\Users\Compaq\Desktop\mo1axva7.exe
2021-04-06 14:22 - 2021-04-06 14:24 - 000000000 ____D C:\Users\Compaq\Downloads\NFSU Mods
2021-04-06 11:07 - 2021-04-06 13:32 - 000000000 ____D C:\KVRT2020_Data
2021-04-03 20:54 - 2021-04-03 20:54 - 000001850 _____ C:\Users\Compaq\AppData\Local\recently-used.xbel
2021-04-03 02:15 - 2021-04-03 02:15 - 000000000 ____D C:\Users\Compaq\AppData\Local\ESET
2021-04-02 16:47 - 2021-04-02 18:05 - 001605632 _____ C:\Users\Compaq\Downloads\KVRT.exe.part
2021-03-31 15:00 - 2021-04-18 00:56 - 000000000 ____D C:\Users\Compaq\Desktop\Programas
2021-03-30 21:31 - 2021-03-30 21:38 - 000508516 _____ C:\TDSSKiller.3.1.0.28_30.03.2021_21.31.22_log.txt
2021-03-30 21:29 - 2021-03-30 21:29 - 000004572 _____ C:\TDSSKiller.3.1.0.28_30.03.2021_21.29.24_log.txt
2021-03-30 20:46 - 2021-03-30 20:46 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\624735FF.sys
2021-03-28 20:12 - 2021-03-28 20:12 - 000001342 _____ C:\Users\Compaq\Documents\cc_20210328_201203.reg
2021-03-28 20:12 - 2021-03-28 20:12 - 000000176 _____ C:\Users\Compaq\Documents\cc_20210328_201225.reg
2021-03-28 20:10 - 2021-03-28 20:11 - 000053748 _____ C:\Users\Compaq\Documents\cc_20210328_200949.reg
2021-03-28 20:01 - 2021-04-25 14:29 - 000004128 _____ C:\Windows\system32\Tasks\CCleaner Update
2021-03-28 20:01 - 2021-03-28 20:01 - 000002812 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC
2021-03-28 20:01 - 2021-03-28 20:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2021-03-28 17:33 - 2021-04-25 20:01 - 000000000 ____D C:\Program Files\CCleaner
2021-03-28 01:50 - 2021-03-28 01:50 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\65675A01.sys
2021-03-28 01:43 - 2021-03-30 20:59 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2021-03-28 01:32 - 2021-03-28 01:32 - 000000261 _____ C:\DelFix.txt
2021-03-27 20:11 - 2021-03-27 20:11 - 000002972 _____ C:\Windows\system32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579}
2021-03-27 20:11 - 2021-03-27 20:11 - 000002972 _____ C:\Windows\system32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435}
2021-03-27 18:45 - 2021-03-27 18:45 - 000042261 _____ C:\Users\Compaq\Downloads\GMP Brakes.rar
2021-03-27 18:39 - 2021-03-27 18:39 - 000000000 ____D C:\Users\Compaq\Downloads\Skyline R32 NFSU2
2021-03-27 18:30 - 2021-03-27 18:34 - 001233941 _____ C:\Users\Compaq\Downloads\Skyline R32 NFSU2.rar
2021-03-27 13:30 - 2021-03-31 14:53 - 000000000 ____D C:\Users\Compaq\Documents\Juegos

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2021-04-26 01:39 - 2007-09-23 21:18 - 000003986 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{1C3F95CA-9683-4770-8320-FFE10D71C5E1}
2021-04-26 01:26 - 2009-07-14 00:04 - 000024512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-04-26 01:26 - 2009-07-14 00:04 - 000024512 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-04-26 01:11 - 2021-02-02 02:26 - 000000000 ___RD C:\Users\Compaq\Documents\MEGA
2021-04-26 01:04 - 2021-03-19 17:39 - 000000000 ____D C:\Users\Compaq\Downloads\Imagenes
2021-04-26 01:04 - 2021-02-04 14:40 - 000000000 ____D C:\Users\Compaq\Downloads\Programas
2021-04-25 14:26 - 2009-07-14 00:23 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-04-25 01:00 - 2021-03-19 16:15 - 000000000 ____D C:\Users\Compaq\AppData\Local\ElevatedDiagnostics
2021-04-24 01:36 - 2007-09-01 00:20 - 000000000 ____D C:\Users\Compaq\Desktop\Juegos
2021-04-23 20:01 - 2021-02-02 11:49 - 000000000 ____D C:\Users\Compaq\Documents\MEGAsync Downloads
2021-04-23 19:59 - 2021-03-23 02:34 - 000000000 ____D C:\Users\Compaq\AppData\Local\CrashDumps
2021-04-23 14:23 - 2009-07-13 22:07 - 000000000 ____D C:\Windows\inf
2021-04-22 23:53 - 2021-02-03 16:23 - 000000000 ____D C:\Users\Compaq\Desktop\Clases
2021-04-22 22:20 - 2021-02-03 14:41 - 000002168 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2021-04-22 21:14 - 2021-03-20 19:20 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\vlc
2021-04-21 02:38 - 2021-02-03 14:23 - 000003458 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2021-04-21 02:38 - 2021-02-03 14:23 - 000003330 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2021-04-17 18:54 - 2021-02-01 18:19 - 000000000 ____D C:\Users\Compaq\AppData\LocalLow\Mozilla
2021-04-09 14:24 - 2009-07-14 04:18 - 000744986 _____ C:\Windows\system32\perfh00A.dat
2021-04-09 14:24 - 2009-07-14 04:18 - 000157454 _____ C:\Windows\system32\perfc00A.dat
2021-04-09 14:24 - 2007-08-31 23:50 - 001669262 _____ C:\Windows\system32\PerfStringBackup.INI
2021-04-08 22:56 - 2021-03-17 23:17 - 000000000 ____D C:\Users\Compaq\Documents\Musica
2021-04-08 22:37 - 2021-02-02 02:43 - 000000000 ___HD C:\Users\Compaq\Documents\Academy School Simulator
2021-04-08 18:18 - 2009-07-13 22:07 - 000000000 ____D C:\Windows\system32\NDF
2021-04-08 15:20 - 2021-02-17 23:06 - 000000000 ____D C:\Program Files\Counter-Strike 1.6
2021-04-08 13:52 - 2007-08-31 23:45 - 000000000 ____D C:\Users\Compaq
2021-04-07 18:33 - 2007-08-31 23:40 - 000000000 ____D C:\Users\Compaq\Documents\RemoveWAT 2.2.6
2021-04-06 12:54 - 2007-08-31 23:40 - 000000000 ____D C:\Users\Compaq\Documents\dpr
2021-04-03 20:54 - 2021-02-25 12:58 - 000000000 ____D C:\Users\Compaq\AppData\Local\gtk-3.0
2021-04-03 20:30 - 2021-02-25 12:46 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\.freeciv
2021-04-01 17:39 - 2021-02-02 12:39 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\DAEMON Tools Lite
2021-04-01 11:58 - 2021-02-07 11:42 - 000003012 _____ C:\Windows\system32\Tasks\{756D26E0-70EA-4E44-8D9E-4449B9D7E062}
2021-04-01 11:58 - 2021-02-07 11:42 - 000003012 _____ C:\Windows\system32\Tasks\{1DE68BB0-6FE7-44DA-BB6A-68934AA62C4F}
2021-04-01 11:58 - 2021-02-07 11:41 - 000003012 _____ C:\Windows\system32\Tasks\{8CC2D41B-A8C1-4E0F-BB2A-EBBED8A08648}
2021-04-01 11:58 - 2021-02-07 11:37 - 000003012 _____ C:\Windows\system32\Tasks\{7311AFC6-BA20-43A8-B01A-11D7241AE240}
2021-04-01 11:58 - 2021-02-07 11:37 - 000003012 _____ C:\Windows\system32\Tasks\{128EA561-FD5D-4374-9291-1D03B1367650}
2021-04-01 11:58 - 2021-02-07 11:37 - 000003012 _____ C:\Windows\system32\Tasks\{0D869573-A125-4AA8-815A-F62F1F629C64}
2021-04-01 11:58 - 2021-02-07 11:36 - 000003012 _____ C:\Windows\system32\Tasks\{ED991389-BE4B-4AF7-B7CC-B0D1832835A5}
2021-04-01 11:58 - 2021-01-27 15:34 - 000003000 _____ C:\Windows\system32\Tasks\{A2D09495-2796-46E3-99A1-97D79064D88E}
2021-04-01 11:58 - 2021-01-27 15:34 - 000003000 _____ C:\Windows\system32\Tasks\{22FA84A6-D016-4465-A729-338F2A2DF579}
2021-04-01 11:58 - 2021-01-27 15:29 - 000002998 _____ C:\Windows\system32\Tasks\{0159B6AC-B769-4762-95EB-FBE5CF9298BA}
2021-04-01 11:58 - 2021-01-27 15:25 - 000003234 _____ C:\Windows\system32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557}
2021-04-01 11:58 - 2021-01-27 15:13 - 000002998 _____ C:\Windows\system32\Tasks\{2F3A0085-F1BB-42CB-81FB-1C9FADCEC589}
2021-04-01 11:58 - 2021-01-27 15:13 - 000002998 _____ C:\Windows\system32\Tasks\{022CCAA3-CAC9-487A-BEDF-F482E735A9F2}
2021-04-01 11:57 - 2021-02-07 11:42 - 000003012 _____ C:\Windows\system32\Tasks\{DBF1DDE3-8D89-4178-9D74-CA7796EBB490}
2021-04-01 11:57 - 2021-02-07 11:42 - 000003012 _____ C:\Windows\system32\Tasks\{D83C7160-6527-4C94-AB28-C4BF3E39F690}
2021-04-01 11:57 - 2021-02-07 11:38 - 000003012 _____ C:\Windows\system32\Tasks\{DAB034BB-7842-4268-A78A-6A9BBE1080A4}
2021-04-01 11:57 - 2021-02-07 11:37 - 000003012 _____ C:\Windows\system32\Tasks\{B57F43F2-575C-4A4B-BC76-FC3FCE021DBE}
2021-04-01 11:57 - 2021-01-27 15:38 - 000003258 _____ C:\Windows\system32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638}
2021-04-01 11:57 - 2021-01-27 15:34 - 000003000 _____ C:\Windows\system32\Tasks\{E51C5BC4-FFB2-432B-937A-446362325A61}
2021-04-01 11:57 - 2021-01-27 15:13 - 000002998 _____ C:\Windows\system32\Tasks\{AFDB173F-F90C-4010-8E70-0926A15EAD4C}
2021-03-31 21:06 - 2020-10-06 00:18 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\Avast Software
2021-03-30 21:10 - 2021-02-01 18:19 - 000000000 ____D C:\Program Files\Mozilla Firefox
2021-03-28 20:03 - 2020-10-05 02:11 - 000000000 ____D C:\Windows\Minidump
2021-03-28 20:03 - 2009-07-13 22:07 - 000000000 ____D C:\Windows\ModemLogs
2021-03-28 20:03 - 2007-08-31 18:39 - 000000000 ____D C:\Windows\Panther

==================== Archivos en la raíz de algunos directorios ========

2021-02-02 12:41 - 2021-02-02 12:41 - 000295074 _____ () C:\Users\Compaq\AppData\Roaming\gmi_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
2021-04-03 20:54 - 2021-04-03 20:54 - 000001850 _____ () C:\Users\Compaq\AppData\Local\recently-used.xbel

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)


LastRegBack: 2021-04-22 09:04
==================== Final de FRST.txt ========================

Addition.txt:

Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x86) Versión: 11-04-2021
Ejecutado por Compaq (26-04-2021 01:49:13)
Ejecutado desde C:\Users\Compaq\Desktop
Microsoft Windows 7 Ultimate  Service Pack 1 (X86) (2007-09-01 04:15:42)
Modo de Inicio: Safe Mode (with Networking)
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-2564166442-1154501177-2247460648-500 - Administrator - Disabled)
Compaq (S-1-5-21-2564166442-1154501177-2247460648-1000 - Administrator - Enabled) => C:\Users\Compaq
Invitado (S-1-5-21-2564166442-1154501177-2247460648-501 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Actualización de NVIDIA 17.12.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 17.12.8 - NVIDIA Corporation)
Adobe Reader XI (11.0.20) - Español (HKLM\...\{AC76BA86-7AD7-1034-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
Big City Adventure - San Francisco en Español (HKLM\...\Big City Adventure - San Francisco en Español) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.77 - Piriform)
Counter-Strike 1.6 (HKLM\...\Counter-Strike 1.6_is1) (Version: Counter-Strike 1.6 No Steam - KingSOFT DVD)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.4.0.0190 - Disc Soft Ltd)
Freeciv 2.6.3 (GTK+3 client) (HKLM\...\Freeciv-2.6.3-gtk3) (Version:  - )
Google Chrome (HKLM\...\Google Chrome) (Version: 90.0.4430.85 - Google LLC)
Half-Life (HKLM\...\Half-Life_is1) (Version: Half-Life - No Steam - KingSOFT DVD)
Malwarebytes version 4.3.0.98 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.3.0.98 - Malwarebytes)
MEGAsync (HKLM\...\MEGAsync) (Version:  - Mega Limited)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 85.0.2 (x86 es-ES) (HKLM\...\Mozilla Firefox 85.0.2 (x86 es-ES)) (Version: 85.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 85.0 - Mozilla)
Need for Speed Underground 2 (HKLM\...\{909F8EBC-EC7F-48FF-0085-475D818F0F31}) (Version:  - )
Need for Speed™ Most Wanted Black Edition (HKLM\...\{ADE91A13-434D-4229-00BC-182BAD607303}) (Version:  - )
NVIDIA Controlador de gráficos 341.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation)
Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN (HKLM\...\Microsoft .NET Framework 4 Client Profile ESN Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Paquete de idioma de Microsoft .NET Framework 4 Extended ESN (HKLM\...\Microsoft .NET Framework 4 Extended ESN Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.12 - VideoLAN)
Voobly Game Data (HKLM\...\Voobly_is1) (Version: Voobly Game Datas - Voobly)
WinRAR 6.00 (32-bit) (HKLM\...\WinRAR archiver) (Version: 6.00.0 - win.rar GmbH)
Zuma Deluxe RN Version 1.0 (HKLM\...\Zuma Deluxe_is1) (Version:  - PopCap Games, Inc)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) [Archivo no firmado]
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll [2021-01-27] (Mega Limited -> ) [Archivo no firmado]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2015-02-03] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers6: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-12-01] (win.rar GmbH -> Alexander Roshal) [Archivo no firmado]

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [VIDC.IV41] => C:\Windows\system32\IR41_32.AX [839680 2009-07-13] (Microsoft Windows -> Intel Corporation)

==================== Accesos directos & WMI ========================

(Las entradas pueden ser listadas para ser restauradas o eliminadas.)

Shortcut: C:\Users\Compaq\Desktop\MIO\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ningún archivo)
Shortcut: C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ningún archivo)
ShortcutWithArgument: C:\Users\Compaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Outlook.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) ->  --profile-directory=Default --app-id=eigpmdhekjlgjgcppnanaanbdmnlnagl

==================== Módulos cargados (Lista blanca) =============

2021-01-27 20:15 - 2021-01-27 20:15 - 000620280 _____ (Mega Limited -> ) [Archivo no firmado] C:\Users\Compaq\AppData\Local\MEGAsync\ShellExtX32.dll
2007-08-31 23:40 - 2020-12-01 13:31 - 000493104 _____ (win.rar GmbH -> Alexander Roshal) [Archivo no firmado] C:\Program Files\WinRAR\rarext.dll

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\32800591.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\32800591.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer (Versión 8) (Lista blanca) ==========

HKU\S-1-5-21-2564166442-1154501177-2247460648-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxps://www.msn.com/es-ve/?ocid=iehp
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2021-02-02 23:04 - 2021-04-07 18:30 - 000000983 _____ C:\Windows\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKU\S-1-5-21-2564166442-1154501177-2247460648-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: DAEMON Tools Lite Automount => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
MSCONFIG\startupreg: Voobly => "C:\Program Files\Voobly\voobly.exe" --startup

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [TCP Query User{8CD26569-87FA-47C0-80E2-D5E45AC96B15}C:\program files\microsoft games\age of empires ii\empires2.exe] => (Allow) C:\program files\microsoft games\age of empires ii\empires2.exe (Microsoft Corporation) [Archivo no firmado]
FirewallRules: [UDP Query User{D998B48E-004B-44A8-A6FF-01C26BCA7163}C:\program files\microsoft games\age of empires ii\empires2.exe] => (Allow) C:\program files\microsoft games\age of empires ii\empires2.exe (Microsoft Corporation) [Archivo no firmado]
FirewallRules: [TCP Query User{AE9693B1-5E0B-4D6B-A968-C8B6FF7FAB14}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe (Microsoft Corporation) [Archivo no firmado]
FirewallRules: [UDP Query User{DC7704C6-148A-4BD0-B6B2-D3BE4693F85D}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe (Microsoft Corporation) [Archivo no firmado]
FirewallRules: [TCP Query User{65F9EFEC-1FC5-45B9-BB8D-F64BBB0D42D0}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{1C1304FB-DF73-4240-97A6-B4CDAB12F0C1}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{1838A184-D235-4F28-9806-E1558B7765CE}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe (Microsoft Corporation) [Archivo no firmado]
FirewallRules: [UDP Query User{AC945FC5-049F-4CF9-A260-9E64C68FE963}C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe] => (Allow) C:\program files\microsoft games\age of empires ii\age2_x1\age2_x1.exe (Microsoft Corporation) [Archivo no firmado]
FirewallRules: [TCP Query User{3FA4DB93-BF3C-47B4-A74D-CA2B6CCB0071}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [UDP Query User{30C8772A-61D5-4316-88B2-54B965E14BE7}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [TCP Query User{4CC594B4-994A-4F99-81FA-C102E327671F}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [UDP Query User{C216244A-10D5-43CF-8C21-B8B7D48B3FBA}C:\program files\valve\half-life\hl.exe] => (Allow) C:\program files\valve\half-life\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [{F5A5BD9A-6B9D-494C-A9AB-14C409286E09}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{DC50C8A4-7200-4BBD-88AF-693B895FD208}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{10530CC6-56A9-4CFD-ADAE-12B6B35D9A66}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{D7A5216F-A159-40FE-B12B-79E7884B0F20}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{E27EFDBA-AF88-45AE-AB36-E51D19E1528C}C:\windows\system32\dplaysvr.exe] => (Allow) C:\windows\system32\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{CD55D127-1D97-4011-B3E4-692E9D17BED1}C:\program files\counter-strike 1.6\hl.exe] => (Allow) C:\program files\counter-strike 1.6\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [UDP Query User{B8FD7C99-1F56-48F7-B36C-B31FA7E9BEEF}C:\program files\counter-strike 1.6\hl.exe] => (Allow) C:\program files\counter-strike 1.6\hl.exe (Valve) [Archivo no firmado]
FirewallRules: [TCP Query User{EE17AEA0-458D-441D-8087-6DC0BF4FDF97}C:\program files\voobly\voobly.exe] => (Allow) C:\program files\voobly\voobly.exe (Voobly) [Archivo no firmado]
FirewallRules: [UDP Query User{1BF2B6C1-A965-42FD-9C3A-96EB5E952E97}C:\program files\voobly\voobly.exe] => (Allow) C:\program files\voobly\voobly.exe (Voobly) [Archivo no firmado]
FirewallRules: [TCP Query User{3383C12A-E1E5-4392-B416-7726202A7457}C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe] => (Allow) C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{2B61AFF9-4CF3-469F-A5B2-B3E9226BF47C}C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe] => (Allow) C:\program files\EA GAMES\need for speed most wanted black edition\speed.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{612F22CA-3303-47D9-A0F5-7E3FF34B2B65}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{4D42DBB5-DB95-402D-BE07-2908BD130DAB}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [TCP Query User{FEB395BE-1609-4E16-86F8-3A1ABF57A3D6}C:\program files\ea games\need for speed underground 2\speed2.exe] => (Block) C:\program files\ea games\need for speed underground 2\speed2.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{DC777137-DE87-4390-9C06-C9A3F1AF5F36}C:\program files\ea games\need for speed underground 2\speed2.exe] => (Block) C:\program files\ea games\need for speed underground 2\speed2.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{7D219220-B3DD-4F5B-93D3-C378FE32546E}C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe] => (Allow) C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{77325613-A62E-4F64-800F-AAF88230FFE1}C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe] => (Allow) C:\users\compaq\desktop\juegos\zumbiblocks\zumbiblocks\zumbiblocks.exe () [Archivo no firmado]
FirewallRules: [{A42AC250-9DA0-4660-8CE6-031DC7D4DFCB}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Puntos de Restauración =========================

12-04-2021 02:39:46 Punto de control programado
19-04-2021 12:54:25 Punto de control programado

==================== Dispositivos defectuosos en el Administrador de dispositivos ============

Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (04/26/2021 01:48:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:48:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:48:03 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:47:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:47:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:47:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:47:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.

Error: (04/26/2021 01:47:56 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Error en la extracción de la lista raíz de terceros del archivo .CAB actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> con el error: Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza.
.


Errores del sistema:
=============
Error: (04/26/2021 01:47:57 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1084" al intentar iniciar el servicio VSS con argumentos "" para ejecutar el servidor:
{E579AB5F-1CC4-44B4-BED9-DE0991FF0623}

Error: (04/26/2021 01:46:48 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (04/26/2021 01:46:48 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1084" al intentar iniciar el servicio WSearch con argumentos "" para ejecutar el servidor:
{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (04/26/2021 01:46:46 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1084" al intentar iniciar el servicio EventSystem con argumentos "" para ejecutar el servidor:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (04/26/2021 01:46:37 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1084" al intentar iniciar el servicio ShellHWDetection con argumentos "" para ejecutar el servidor:
{DD522ACC-F821-461A-A407-50B198B896DC}

Error: (04/26/2021 01:46:30 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
discache
spldr
Wanarpv6

Error: (04/26/2021 01:46:25 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: El cierre anterior del sistema a las 01:44:19 a.m. del ‎26/‎04/‎2021 resultó inesperado.

Error: (04/25/2021 03:30:22 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 70.


Windows Defender:
================
Date: 2021-04-17 03:45:49.539
Description: 
Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma:1.335.1022.0
Versión de firma anterior:
Origen de actualización:Usuario
Tipo de firma:AntiSpyware
Tipo de actualización:Completa
Usuario:Compaq-PC\Compaq
Versión de motor actual:1.1.18000.5
Versión de motor anterior:
Código de error:0x800b0109
Descripción de error:Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza. 

Date: 2021-04-17 03:45:49.538
Description: 
Windows Defender encontró un error al intentar actualizar el motor.
Nueva versión de motor:1.1.18000.5
Versión de motor anterior:
Origen de actualización:Usuario
Usuario:Compaq-PC\Compaq
Código de error:0x800b0109
Descripción de error:Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza. 

Date: 2021-04-17 01:48:32.435
Description: 
Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma:1.335.1022.0
Versión de firma anterior:
Origen de actualización:Usuario
Tipo de firma:AntiSpyware
Tipo de actualización:Completa
Usuario:Compaq-PC\Compaq
Versión de motor actual:1.1.18000.5
Versión de motor anterior:
Código de error:0x800b0109
Descripción de error:Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza. 

Date: 2021-04-17 01:48:32.435
Description: 
Windows Defender encontró un error al intentar actualizar el motor.
Nueva versión de motor:1.1.18000.5
Versión de motor anterior:
Origen de actualización:Usuario
Usuario:Compaq-PC\Compaq
Código de error:0x800b0109
Descripción de error:Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza. 

Date: 2021-04-17 01:48:30.594
Description: 
Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma:1.335.1022.0
Versión de firma anterior:
Origen de actualización:Usuario
Tipo de firma:AntiSpyware
Tipo de actualización:Completa
Usuario:Compaq-PC\Compaq
Versión de motor actual:1.1.18000.5
Versión de motor anterior:
Código de error:0x800b0109
Descripción de error:Se procesó correctamente una cadena de certificados, pero termina en un certificado de raíz no compatible con el proveedor de confianza. 

==================== Información de la memoria =========================== 

BIOS: Hewlett-Packard F.54 08/18/2009
Placa base: Wistron 360A
Procesador: AMD Athlon Dual-Core QL-65
Porcentaje de memoria en uso: 95%
RAM física total: 1406.43 MB
RAM física disponible: 63.45 MB
Virtual total: 2812.85 MB
Virtual disponible: 1491.78 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:297.99 GB) (Free:223.04 GB) NTFS

\\?\Volume{5fbd3783-5845-11dc-95a5-806e6f6e6963}\ (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 298.1 GB) (Disk ID: 000852C1)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)

==================== Final  Addition.txt =======================

Saludos!

Hola, buenas @ManU

:zero: PREGUNTAS

¿De todos los videojuegos que tienes hay alguno pirata :pirate_flag: (crackeado)? Si es así… dime todos los que sean :pirate_flag:

:one: DESINSTALACIÓN

Para los programas en que te diga: los quitas. Hazlo así:

Desinstalalos con Revo Uninstaller en su Modo Avanzado. Para ello sigues su manual la parte de desinstalación de programas.

Quitas el programa que encuentre Revo con el nombre: Malwarebytes version 4.3.0.98 o algo parecido (si ves cualquier programa allí que ponga Malwarebytes, pues lo desinstalas con el Revo de esta forma). Pues por lo que veo en los reportes aún tienes instalada o tienes restos de Malwarebytes version 4.3.0.98. En caso de no encontrar Malwarebytes con el Revo, pues sigues con los siguientes pasos.

:two: Ahora debes de hacer una COPIA DE SEGURIDAD DEL REGISTRO, para ello:

  • Reinicias el ordenador en Modo Normal.

  • Descargas DelFix en tu escritorio.

  • Doble clic para ejecutarlo. (Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona - Ejecutar como Administrador)

  • Marcas solamente la casilla de Create registry backup, el resto te aseguras de que no estén seleccionadas.

  • Presionas en Run.

Se abrirá el informe (DelFix.txt), puedes cerrarlo. Pero lo guardas por si en el futuro te lo pido/hace falta.

Seguidamente, CIERRAS TODOS LOS PROGRAMAS, vas a Inicio >> Ejecutar y escribes Notepad.exe

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN
Task: {4C7ABC85-FE40-4DF3-B340-4256A8EDA3C6} - System32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {611FCC7E-2BE6-4FE6-82E9-C9FF46DFD8C5} - System32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {64DA3287-8A12-4FBC-B712-C4D1C652D7CD} - System32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {8216A799-EBD8-4DCD-A6A8-B86E4DC96DAC} - System32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {B84DF9A1-7B83-43D0-8064-2A6EE64E8755} - System32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king"
Task: {C8875130-EE87-4D0B-A80F-C19F7CD84723} - System32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {DEA0D9DA-DDC3-425D-B110-6BD57CF6A5B8} - System32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors\aocsetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors"
C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems, Incorporated -> Adobe Systems Inc.) [Archivo no firmado]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2021-03-30 20:46 - 2021-03-30 20:46 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\624735FF.sys
2021-03-28 01:50 - 2021-03-28 01:50 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\65675A01.sys
2021-03-28 01:43 - 2021-03-30 20:59 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2021-03-27 20:11 - 2021-03-27 20:11 - 000002972 _____ C:\Windows\system32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579}
2021-03-27 20:11 - 2021-03-27 20:11 - 000002972 _____ C:\Windows\system32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435}
2021-04-07 18:33 - 2007-08-31 23:40 - 000000000 ____D C:\Users\Compaq\Documents\RemoveWAT 2.2.6
2021-04-01 11:58 - 2021-01-27 15:25 - 000003234 _____ C:\Windows\system32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557}
2021-04-01 11:57 - 2021-01-27 15:38 - 000003258 _____ C:\Windows\system32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638}
2021-03-31 21:06 - 2020-10-06 00:18 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\Avast Software
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
Shortcut: C:\Users\Compaq\Desktop\MIO\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ningún archivo)
Shortcut: C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ningún archivo)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
File: C:\Users\Compaq\Desktop\mo1axva7.exe
VirusTotal: C:\Users\Compaq\Desktop\mo1axva7.exe
Folder: C:\Users\Compaq\Desktop\MIO
Folder: C:\Users\Compaq\Downloads\NFSU Mods
File: C:\Users\Compaq\AppData\Roaming\gmi_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
VirusTotal: C:\Users\Compaq\AppData\Roaming\gmi_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
File: C:\Users\Compaq\AppData\Local\recently-used.xbel
VirusTotal: C:\Users\Compaq\AppData\Local\recently-used.xbel
Folder: C:\Users\Compaq\Documents\dpr
File: C:\Users\Compaq\Downloads\GMP Brakes.rar
VirusTotal: C:\Users\Compaq\Downloads\GMP Brakes.rar
File: C:\Users\Compaq\Downloads\Skyline R32 NFSU2.rar
VirusTotal: C:\Users\Compaq\Downloads\Skyline R32 NFSU2.rar
Folder: C:\Users\Compaq\Downloads\Skyline R32 NFSU2

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END

Lo guardas con el nombre de FIXLIST.TXT en tu escritorio (MUY IMPORTANTE). Pues en caso contrario no funcionará el SCRIPT, ambos ficheros (FRST.exe y FIXLIST.TXT ) y deben de estar en la ubicación del ESCRITORIO.

:warning: El anterior Script de reparación es personalizado para la máquina en concreto para la cual se fabricó y está hecho específicamente por un miembro del Staff. Si se tiene un problema parecido, por favor abra su propio tema para recibir ayuda personalizada y específica. Utilizar Scripts de otros Sistemas puede causar daños graves en su ordenador.

Finalmente (OJO, en MODO NORMAL):

  1. Ejecutas nuevamente FRST.exe (Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona - Ejecutar como Administrador).

  2. Presionas sobre Fix/Corregir y esperas a que finalice el proceso. No hagas nada con el PC mientras este realizando dichas reparaciones, incluso si parece ser que se ha quedado colgado. No lo toques y esperas.

  3. Cunado finalice, en el ESCRITORIO se creará el fichero FIXLOG.TXT lo traes en tu próxima respuesta.

  4. Reinicias el ordenador en Modo Normal compruebas durante un rato el funcionamiento de este y comentas como sigue el problema inicialmente planteado.

:warning: Muy Importante :warning: Coloca el reporte que te he pedido como se muestra en la siguiente imagen:

Salu2.

Hola,

Casi todos son piratas la verdad, he crackeado 2:

  • Age Of Empires II (Pirata)
  • Big City Adventures: San Francisco (Pirata)
  • Counter Strike 1.6 (Pirata)
  • DeSmuMe (Emulador de la Nintendo DS)
  • Adobe Flash Player 18.0 (No se si cuenta como juego)
  • Freeciv (Gratis, lo descargue desde su pagina oficial)
  • GTA San Andreas (Pirata)
  • Half - Life (Pirata)
  • NFS Hot Pursuit 2 (Pirata)
  • NFS Most Wanted Black Edition (Crackeado)
  • NFS Underground 2 (Crackeado)
  • NFS Underground (Pirata)
  • Papers, Please (Pirata)
  • Plantas Vs Zombies (Pirata)
  • Snes9x (Emulador de la SNES)
  • The Conquerors (Pirata)
  • The Escapists (Pirata)
  • Zuma Deluxe (Pirata)
  • ZumbiBlocks (Alpha gratuita)

Malwarebytes aparecía en la lista, así que lo desinstalé según el manual.

Fixlog.txt:

Resultados de la corrección de Farbar Recovery Scan Tool (x86) Versión: 11-04-2021
Ejecutado por Compaq (28-04-2021 01:01:04) Run:1
Ejecutado desde C:\Users\Compaq\Desktop
Perfiles cargados: Compaq
Modo de Inicio: Normal

==============================================

fixlist contenido:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricci�n <==== ATENCI�N
Task: {4C7ABC85-FE40-4DF3-B340-4256A8EDA3C6} - System32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {611FCC7E-2BE6-4FE6-82E9-C9FF46DFD8C5} - System32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {64DA3287-8A12-4FBC-B712-C4D1C652D7CD} - System32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {8216A799-EBD8-4DCD-A6A8-B86E4DC96DAC} - System32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {B84DF9A1-7B83-43D0-8064-2A6EE64E8755} - System32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king\aoesetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\01 age king"
Task: {C8875130-EE87-4D0B-A80F-C19F7CD84723} - System32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059} => C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Task: {DEA0D9DA-DDC3-425D-B110-6BD57CF6A5B8} - System32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638} => C:\Windows\system32\pcalua.exe -a "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors\aocsetup.exe.EXE" -d "C:\Users\Compaq\Desktop\AGE 2 FULL\02 age Conquerors"
C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes
FF Plugin: @microsoft.com/GENUINE -> disabled [Ning�n archivo]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems, Incorporated -> Adobe Systems Inc.) [Archivo no firmado]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
2021-03-30 20:46 - 2021-03-30 20:46 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\624735FF.sys
2021-03-28 01:50 - 2021-03-28 01:50 - 000222648 _____ (Malwarebytes) C:\Windows\system32\Drivers\65675A01.sys
2021-03-28 01:43 - 2021-03-30 20:59 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2021-03-27 20:11 - 2021-03-27 20:11 - 000002972 _____ C:\Windows\system32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579}
2021-03-27 20:11 - 2021-03-27 20:11 - 000002972 _____ C:\Windows\system32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059}
2021-03-27 20:10 - 2021-03-27 20:10 - 000002972 _____ C:\Windows\system32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435}
2021-04-07 18:33 - 2007-08-31 23:40 - 000000000 ____D C:\Users\Compaq\Documents\RemoveWAT 2.2.6
2021-04-01 11:58 - 2021-01-27 15:25 - 000003234 _____ C:\Windows\system32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557}
2021-04-01 11:57 - 2021-01-27 15:38 - 000003258 _____ C:\Windows\system32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638}
2021-03-31 21:06 - 2020-10-06 00:18 - 000000000 ____D C:\Users\Compaq\AppData\Roaming\Avast Software
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ning�n archivo
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ning�n archivo
Shortcut: C:\Users\Compaq\Desktop\MIO\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ning�n archivo)
Shortcut: C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk -> C:\Program Files\Microsoft Games\Age of Empires II\age2_x1\agefix.bat (Ning�n archivo)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
File: C:\Users\Compaq\Desktop\mo1axva7.exe
VirusTotal: C:\Users\Compaq\Desktop\mo1axva7.exe
Folder: C:\Users\Compaq\Desktop\MIO
Folder: C:\Users\Compaq\Downloads\NFSU Mods
File: C:\Users\Compaq\AppData\Roaming\gmi_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
VirusTotal: C:\Users\Compaq\AppData\Roaming\gmi_1N1I1F1S1T1I0M1F1Q2Y1I1P1B0C1F1Q1P.txt
File: C:\Users\Compaq\AppData\Local\recently-used.xbel
VirusTotal: C:\Users\Compaq\AppData\Local\recently-used.xbel
Folder: C:\Users\Compaq\Documents\dpr
File: C:\Users\Compaq\Downloads\GMP Brakes.rar
VirusTotal: C:\Users\Compaq\Downloads\GMP Brakes.rar
File: C:\Users\Compaq\Downloads\Skyline R32 NFSU2.rar
VirusTotal: C:\Users\Compaq\Downloads\Skyline R32 NFSU2.rar
Folder: C:\Users\Compaq\Downloads\Skyline R32 NFSU2

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
*****************

El punto de restauración fue creado correctamente.
Procesos cerrados correctamente.
HKLM\SOFTWARE\Policies\Mozilla => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4C7ABC85-FE40-4DF3-B340-4256A8EDA3C6}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C7ABC85-FE40-4DF3-B340-4256A8EDA3C6}" => eliminado correctamente
C:\Windows\System32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FDD08436-66A3-4A89-AF72-BA2B732D2579}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{611FCC7E-2BE6-4FE6-82E9-C9FF46DFD8C5}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{611FCC7E-2BE6-4FE6-82E9-C9FF46DFD8C5}" => eliminado correctamente
C:\Windows\System32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CD345DAA-7035-4F59-864B-A0513F4D324D}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{64DA3287-8A12-4FBC-B712-C4D1C652D7CD}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{64DA3287-8A12-4FBC-B712-C4D1C652D7CD}" => eliminado correctamente
C:\Windows\System32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0796BA5E-6EEB-4D9D-9EF5-94A970364435}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8216A799-EBD8-4DCD-A6A8-B86E4DC96DAC}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8216A799-EBD8-4DCD-A6A8-B86E4DC96DAC}" => eliminado correctamente
C:\Windows\System32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DFB11A7F-BE40-4877-8228-F545859A8AAD}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B84DF9A1-7B83-43D0-8064-2A6EE64E8755}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B84DF9A1-7B83-43D0-8064-2A6EE64E8755}" => eliminado correctamente
C:\Windows\System32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B3BBA59-461D-49A6-8975-6126C5668557}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C8875130-EE87-4D0B-A80F-C19F7CD84723}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8875130-EE87-4D0B-A80F-C19F7CD84723}" => eliminado correctamente
C:\Windows\System32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AF5C402B-B4CB-4EB1-AD0F-B52490852059}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DEA0D9DA-DDC3-425D-B110-6BD57CF6A5B8}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DEA0D9DA-DDC3-425D-B110-6BD57CF6A5B8}" => eliminado correctamente
C:\Windows\System32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DE339366-2D63-4F39-841D-248167EF0638}" => eliminado correctamente
"C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe" => no encontrado
C:\Program Files\Malwarebytes => movido correctamente
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => eliminado correctamente
HKLM\Software\MozillaPlugins\Adobe Reader => eliminado correctamente
HKLM\System\CurrentControlSet\Services\Synth3dVsc => eliminado correctamente
Synth3dVsc => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\tsusbhub => eliminado correctamente
tsusbhub => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\VGPU => eliminado correctamente
VGPU => servicio eliminado correctamente
C:\Windows\system32\Drivers\624735FF.sys => movido correctamente
C:\Windows\system32\Drivers\65675A01.sys => movido correctamente
C:\ProgramData\Malwarebytes' Anti-Malware (portable) => movido correctamente
"C:\Windows\system32\Tasks\{FDD08436-66A3-4A89-AF72-BA2B732D2579}" => no encontrado
"C:\Windows\system32\Tasks\{CD345DAA-7035-4F59-864B-A0513F4D324D}" => no encontrado
"C:\Windows\system32\Tasks\{DFB11A7F-BE40-4877-8228-F545859A8AAD}" => no encontrado
"C:\Windows\system32\Tasks\{AF5C402B-B4CB-4EB1-AD0F-B52490852059}" => no encontrado
"C:\Windows\system32\Tasks\{0796BA5E-6EEB-4D9D-9EF5-94A970364435}" => no encontrado
C:\Users\Compaq\Documents\RemoveWAT 2.2.6 => movido correctamente
"C:\Windows\system32\Tasks\{5B3BBA59-461D-49A6-8975-6126C5668557}" => no encontrado
"C:\Windows\system32\Tasks\{DE339366-2D63-4F39-841D-248167EF0638}" => no encontrado
C:\Users\Compaq\AppData\Roaming\Avast Software => movido correctamente
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\MBAMShlExt => eliminado correctamente
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\MBAMShlExt => eliminado correctamente
C:\Users\Compaq\Desktop\MIO\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk => movido correctamente
C:\Users\Compaq\Desktop\Juegos\AGE 2 FULL\02 age Conquerors\GAME\AGE2_X1\agefixed.lnk => movido correctamente

========================= File: C:\Users\Compaq\Desktop\mo1axva7.exe ========================

C:\Users\Compaq\Desktop\mo1axva7.exe
El archivo está firmado digitalmente
MD5: E3506C55E4AA6B7A640284A650432CD2
Fecha de creación y modificación: 2021-04-07 00:05 - 2021-04-07 02:48
Tamaño: 243542488
Atributos: ---AH
Nombre de la compañía: Doctor Web Ltd. -> 
Interno Nombre: 
Original Nombre: 
Producto: 
Descripción: 
Archivo Versión: 
Producto Versión: 
Copyright: 
VirusTotal: 0

====== Final de File: ======

Lo reinicié y todo se ve normal.

¿Instalo Malwarebytes y veo si funciona?, Saludos.