Mi computadora se apaga

Hola!

Le escribo el mensaje como enterado Ahorita mismo estoy con Malwarebytes, pero el análisis se ve que va para largo

Cuando este todo, le envió mensaje, gracias

Saludos

De acuerdo, no hay problema, por aquí estaremos.

Saludos.

Hola, se me apagó mientras estaba en el análisis ¿Que puedo hacer?

Ya van dos veces que pasa ): ¿Lo vuelvo a intentar?

Saludos

Accede a Windows desde el modo seguro con RED y ejecuta los procesos desde ese modo de trabajo, para acceder a él sigue estas indicaciones :

Usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

Saludos.

Listo, ya volví a poner el analizador en curso Le notifico cualquier cosa Saludos

1 me gusta

Perfecto… veamos si sigue sin problemas. :+1:

malwarebytes

Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 29/4/20
Hora del análisis: 17:55
Archivo de registro: 8cbf75f6-8a6c-11ea-95a7-b42e990382cc.json

-Información del software-
Versión: 4.1.0.56
Versión de los componentes: 1.0.889
Versión del paquete de actualización: 1.0.23162
Licencia: Prueba

-Información del sistema-
SO: Windows 10 (Build 18362.778)
CPU: x64
Sistema de archivos: NTFS
Usuario: DESKTOP-JA9PJRI\MoreThanMe

-Resumen del análisis-
Tipo de análisis: Análisis personalizado
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 570027
Amenazas detectadas: 0
Amenazas en cuarentena: 0
Tiempo transcurrido: 15 hr, 5 min, 25 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 0
(No hay elementos maliciosos detectados)

Valor del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Secuencia de datos: 0
(No hay elementos maliciosos detectados)

Carpeta: 0
(No hay elementos maliciosos detectados)

Archivo: 0
(No hay elementos maliciosos detectados)

Sector físico: 0
(No hay elementos maliciosos detectados)

WMI: 0
(No hay elementos maliciosos detectados)


(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build:    04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    04-30-2020
# Duration: 00:00:02
# OS:       Windows 10 Pro
# Cleaned:  0
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1405 octets] - [30/04/2020 09:19:23]
AdwCleaner[S01].txt - [1466 octets] - [30/04/2020 09:26:18]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Enterprise x64 
Ran by MoreThanMe (Administrator) on 30/04/2020 at  9:41:50.42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 1 

Successfully deleted: C:\ai_recyclebin (Folder) 



Registry: 0 





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30/04/2020 at  9:44:38.23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 28-04-2020
Ejecutado por MoreThanMe (administrador) sobre DESKTOP-JA9PJRI (Gigabyte Technology Co., Ltd. A320M-S2H) (30-04-2020 09:46:34)
Ejecutado desde C:\Users\TalentPC\Desktop
Perfiles cargados: MoreThanMe (Perfiles disponibles: MoreThanMe)
Platform: Windows 10 Pro Versión 1903 18362.778 (X64) Idioma: Español (México)
Navegador predeterminado: Edge
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\RtkAudUService64.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-1074164132-3260105572-149681692-1001\...\Run: [OneDrive] => C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe [1579368 2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1074164132-3260105572-149681692-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\TalentPC\AppData\Local\Microsoft\Teams\Update.exe [2342544 2020-04-29] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1074164132-3260105572-149681692-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.129\Installer\chrmstp.exe [2020-04-29] (Google LLC -> Google LLC)

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {07C6B8EB-6E81-4BBD-AB68-3D326164C47A} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369352 2020-04-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {181D092F-4C5D-4843-904A-2FBE3D27C06D} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2350176 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {18CCCB09-02AB-47A8-9710-AF4434529C87} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2167712 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {304BFD0D-5628-4A4A-AA5E-D832103526A2} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [150264 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {31EE7268-62C6-4620-982A-396D2BEECA36} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\sdxhelper.exe [150264 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {44EDBBBE-A348-47AB-9F71-0BBC85319AB8} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [2731368 2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {62753FE8-F86F-4666-BDFB-CA7A49856D8D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {722D2CD7-9FDA-4C12-A04F-CF1568DCE6BB} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {7B1DAE90-71AC-4547-9DDB-85E50F57C9A1} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2167712 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {97D60DA8-9660-4714-82FA-2CD2749ED8A6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-04-29] (Google Inc -> Google LLC)
Task: {A4DC09A6-9416-4E71-B6EF-C9827446E4BF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6291864 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07} - System32\Tasks\AdwCleaner_onReboot => C:\Users\TalentPC\Desktop\adwcleaner_8.0.4.exe [8196784 2020-04-29] (Malwarebytes Inc -> Malwarebytes)
Task: {BB8D5B6C-7E8D-4C4C-8510-774AD842F056} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6291864 2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Task: {CA2ECA56-084A-43FB-B8D8-AFAF3D8285DF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2020-04-29] (Google Inc -> Google LLC)
Task: {E41C40F6-4639-4EA0-AAAE-5F159B21C022} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_MoreThanMe => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [5820440 2020-03-12] (Janos Mathe -> H.D.S. Hungary)
Task: {F9B2F2D2-C543-4261-94DE-1563B0FB8DE2} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27369352 2020-04-02] (Microsoft Corporation -> Microsoft Corporation)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254
Tcpip\..\Interfaces\{9039055f-da1f-42dd-a1bc-5af22137efdc}: [DhcpNameServer] 192.168.1.254 192.168.1.254

Internet Explorer:
==================
HKU\S-1-5-21-1074164132-3260105572-149681692-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)

Edge: 
======
Edge Notifications: HKU\S-1-5-21-1074164132-3260105572-149681692-1001 -> hxxps://forospyware.com

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-04-29] (Microsoft Corporation -> Microsoft Corporation)

Chrome: 
=======
CHR Profile: C:\Users\TalentPC\AppData\Local\Google\Chrome\User Data\Default [2020-04-29]
CHR StartupUrls: Default -> "hxxps://www.google.com/"

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11600776 2020-04-02] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files (x86)\Microsoft OneDrive\FileSyncHelper.exe [2142056 2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-04-29] (Malwarebytes Inc -> Malwarebytes)
S3 OneDrive Updater Service; C:\Program Files (x86)\Microsoft OneDrive\OneDriveUpdaterService.exe [2499944 2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
R2 RtkAudioUniversalService; C:\WINDOWS\System32\RtkAudUService64.exe [856288 2019-10-30] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5930136 2020-04-18] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-04-28] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-04-28] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [46040 2019-10-30] (Advanced Micro Devices INC. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [24528 2019-04-18] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [32520 2019-09-17] (Advanced Micro Devices INC. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [138064 2019-06-27] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-04-29] (Malwarebytes Corporation -> Malwarebytes)
S3 LGJoyHidFilter; C:\WINDOWS\system32\drivers\LGJoyHidFilter.sys [57368 2018-10-05] (Logitech Inc -> Logitech Inc.)
S3 LGJoyHidLo; C:\WINDOWS\system32\drivers\LGJoyHidLo.sys [47256 2018-10-05] (Logitech Inc -> Logitech Inc.)
S3 LGJoyXlCore; C:\WINDOWS\system32\drivers\LGJoyXlCore.sys [67736 2018-10-05] (Logitech Inc -> Logitech Inc.)
S3 LGSHidFilt; C:\WINDOWS\System32\drivers\LGSHidFilt.Sys [64280 2018-10-05] (Logitech -> Logitech Inc.)
S3 LGSUsbFilt; C:\WINDOWS\System32\drivers\LGSUsbFilt.Sys [41752 2018-10-05] (Logitech -> Logitech Inc.)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [214496 2020-04-29] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-04-29] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [195432 2020-04-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73368 2020-04-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-04-30] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [125088 2020-04-30] (Malwarebytes Inc -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9952681a7bb1dfac\nvlddmkm.sys [23446968 2020-04-11] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NVSWCFilter; C:\WINDOWS\System32\drivers\nvswcfilter.sys [44984 2020-03-31] (NVIDIA Corporation -> NVIDIA Corporation)
S3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [67456 2020-03-11] (NVIDIA Corporation -> NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1167768 2019-11-20] (Realtek Semiconductor Corp. -> Realtek )
R3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [51776 2020-02-17] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_022a; C:\WINDOWS\System32\drivers\RzDev_022a.sys [52288 2020-02-17] (Razer USA Ltd. -> Razer Inc)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-04-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [391392 2020-04-28] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-04-28] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) ===================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-04-30 09:46 - 2020-04-30 09:47 - 000016642 _____ C:\Users\TalentPC\Desktop\FRST.txt
2020-04-30 09:46 - 2020-04-30 09:47 - 000000000 ____D C:\FRST
2020-04-30 09:44 - 2020-04-30 09:44 - 000000608 _____ C:\Users\TalentPC\Desktop\JRT.txt
2020-04-30 09:42 - 2020-04-30 09:44 - 000000000 ____D C:\Users\TalentPC\AppData\LocalLow\IGDump
2020-04-30 09:28 - 2020-04-30 09:28 - 000073368 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-04-30 09:27 - 2020-04-30 09:27 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-04-30 09:27 - 2020-04-30 09:27 - 000195432 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-04-30 09:27 - 2020-04-30 09:27 - 000125088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-04-30 09:26 - 2020-04-30 09:26 - 000003178 _____ C:\WINDOWS\system32\Tasks\AdwCleaner_onReboot
2020-04-30 09:11 - 2020-04-30 09:19 - 000000000 ____D C:\AdwCleaner
2020-04-29 13:53 - 2020-04-29 18:03 - 000325322 _____ C:\WINDOWS\ntbtlog.txt
2020-04-29 13:53 - 2020-04-29 17:54 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2020-04-29 13:49 - 2020-04-29 13:49 - 000000036 _____ C:\Users\TalentPC\Desktop\Apagar Windows 8-Iniciar a prueba de fallos.bat
2020-04-29 11:26 - 2020-04-29 11:26 - 000000000 ____D C:\Users\TalentPC\AppData\Local\mbam
2020-04-29 11:25 - 2020-04-29 11:25 - 000214496 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-04-29 11:25 - 2020-04-29 11:25 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-04-29 11:25 - 2020-04-29 11:25 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-04-29 11:25 - 2020-04-29 11:25 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-04-29 11:25 - 2020-04-29 11:25 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-04-29 11:25 - 2020-04-29 11:25 - 000000000 ____D C:\Users\TalentPC\AppData\Local\mbamtray
2020-04-29 11:25 - 2020-04-29 11:25 - 000000000 ____D C:\ProgramData\Malwarebytes
2020-04-29 11:19 - 2020-04-29 11:19 - 000000000 ____D C:\Program Files\Malwarebytes
2020-04-29 11:18 - 2020-04-29 11:18 - 000046226 _____ C:\Users\TalentPC\Documents\cc_20200429_111817.reg
2020-04-29 11:11 - 2020-04-29 11:11 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-04-29 11:11 - 2020-04-29 11:11 - 000002898 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-04-29 11:11 - 2020-04-29 11:11 - 000002371 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-29 11:11 - 2020-04-29 11:11 - 000002330 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-29 11:11 - 2020-04-29 11:11 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-04-29 11:11 - 2020-04-29 11:11 - 000000000 ____D C:\Users\TalentPC\AppData\Local\Google
2020-04-29 11:11 - 2020-04-29 11:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2020-04-29 11:11 - 2020-04-29 11:11 - 000000000 ____D C:\Program Files\CCleaner
2020-04-29 11:09 - 2020-04-29 11:54 - 000003558 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-04-29 11:09 - 2020-04-29 11:54 - 000003434 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-04-29 11:09 - 2020-04-29 11:54 - 000000000 ____D C:\Program Files (x86)\Google
2020-04-29 11:08 - 2020-04-29 11:08 - 002283008 _____ (Farbar) C:\Users\TalentPC\Desktop\FRST64.exe
2020-04-29 11:03 - 2020-04-29 11:03 - 001790024 _____ (Malwarebytes) C:\Users\TalentPC\Desktop\JRT.exe
2020-04-29 11:02 - 2020-04-29 11:02 - 008196784 _____ (Malwarebytes) C:\Users\TalentPC\Desktop\adwcleaner_8.0.4.exe
2020-04-29 11:01 - 2020-04-29 11:01 - 001980016 _____ (Malwarebytes) C:\Users\TalentPC\Desktop\MBSetup.exe
2020-04-29 11:00 - 2020-04-29 11:00 - 022267336 _____ (Piriform Software Ltd) C:\Users\TalentPC\Desktop\ccsetup565.exe
2020-04-29 10:11 - 2020-04-29 11:07 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2020-04-29 10:11 - 2020-04-29 10:11 - 000001156 _____ C:\Users\TalentPC\Desktop\Hard Disk Sentinel.lnk
2020-04-29 10:11 - 2020-04-29 10:11 - 000000000 ____D C:\WINDOWS\system32\Tasks\HardDiskSentinel
2020-04-29 10:11 - 2020-04-29 10:11 - 000000000 ____D C:\Users\TalentPC\AppData\Roaming\Hard Disk Sentinel
2020-04-29 10:11 - 2020-04-29 10:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hard Disk Sentinel
2020-04-29 10:03 - 2020-04-29 10:03 - 000002379 _____ C:\Users\TalentPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams.lnk
2020-04-29 10:03 - 2020-04-29 10:03 - 000002371 _____ C:\Users\TalentPC\Desktop\Microsoft Teams.lnk
2020-04-29 10:03 - 2020-04-29 10:03 - 000000000 ____D C:\Users\TalentPC\AppData\Roaming\Microsoft Teams
2020-04-29 10:02 - 2020-04-29 10:03 - 000000000 ____D C:\Users\TalentPC\AppData\Local\SquirrelTemp
2020-04-29 09:35 - 2020-04-29 09:36 - 000000000 ____D C:\Users\TalentPC\Documents\COMPUTADORA
2020-04-29 08:45 - 2020-04-29 08:45 - 000000000 ____D C:\Program Files (x86)\Teams Installer
2020-04-29 08:44 - 2020-04-29 08:44 - 000002538 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Empresarial.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002489 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002470 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002452 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2020-04-29 08:44 - 2020-04-29 08:44 - 000002397 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2020-04-29 08:43 - 2020-04-29 08:43 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2020-04-29 08:16 - 2020-04-29 08:16 - 000000000 ____D C:\Users\TalentPC\AppData\Local\PeerDistRepub
2020-04-29 08:07 - 2020-04-29 08:08 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-04-29 08:07 - 2020-04-29 08:07 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-04-29 07:50 - 2020-04-29 08:44 - 000000000 ____D C:\Program Files\Microsoft Office
2020-04-29 07:50 - 2020-04-29 07:50 - 000000000 ____D C:\Program Files\Microsoft Office 15
2020-04-28 13:41 - 2020-04-28 13:41 - 000000000 ____D C:\Users\TalentPC\AppData\Local\D3DSCache
2020-04-28 12:59 - 2020-04-28 12:59 - 000000000 ___HD C:\OneDriveTemp
2020-04-28 12:58 - 2020-04-29 13:31 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2020-04-28 12:58 - 2020-04-28 12:58 - 000003206 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2020-04-28 12:58 - 2020-04-28 12:58 - 000002246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-04-28 12:58 - 2020-04-28 12:58 - 000000000 ___RD C:\Users\Default\OneDrive
2020-04-28 12:58 - 2020-04-28 12:58 - 000000000 ___RD C:\Users\Default User\OneDrive
2020-04-28 12:58 - 2020-04-28 12:58 - 000000000 ____D C:\Users\TalentPC\AppData\Local\OneDrive
2020-04-28 07:46 - 2020-04-28 07:46 - 000000299 _____ C:\Users\TalentPC\Downloads\Chequear_ Disco_Windows.bat
2020-04-28 07:16 - 2020-04-28 07:16 - 000000000 ____D C:\Users\TalentPC\AppData\Local\NVIDIA
2020-04-28 07:02 - 2020-04-28 07:02 - 000000000 ____D C:\Users\TalentPC\AppData\Local\CEF
2020-04-28 07:01 - 2020-04-28 07:18 - 000000000 ____D C:\Users\TalentPC\AppData\Roaming\.minecraft
2020-04-28 06:59 - 2020-04-28 06:57 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-04-27 23:28 - 2020-04-27 23:28 - 000000000 ____D C:\Users\TalentPC\AppData\Local\Comms
2020-04-27 23:15 - 2020-04-29 11:16 - 000000000 ____D C:\WINDOWS\Panther
2020-04-27 23:13 - 2020-04-28 19:42 - 000000000 ____D C:\Users\TalentPC\AppData\Local\PlaceholderTileLogoFolder
2020-04-27 23:12 - 2020-04-29 13:31 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2020-04-27 23:10 - 2020-04-27 23:35 - 000000000 ____D C:\Users\TalentPC\AppData\Local\Publishers
2020-04-27 23:10 - 2020-04-27 23:10 - 000000000 ____D C:\Users\TalentPC\AppData\Local\MicrosoftEdge
2020-04-27 23:09 - 2020-04-27 23:30 - 000000000 ____D C:\ProgramData\Packages
2020-04-27 23:08 - 2020-04-29 08:51 - 000000000 ____D C:\Users\TalentPC\AppData\Local\Packages
2020-04-27 23:08 - 2020-04-28 07:15 - 000000000 ____D C:\Users\TalentPC\AppData\Local\ConnectedDevicesPlatform
2020-04-27 23:08 - 2020-04-27 23:08 - 000000020 ___SH C:\Users\TalentPC\ntuser.ini
2020-04-27 23:08 - 2020-04-27 23:08 - 000000000 ____D C:\Users\TalentPC\AppData\Roaming\Adobe
2020-04-27 23:08 - 2020-04-27 23:08 - 000000000 ____D C:\Users\TalentPC\AppData\Local\VirtualStore
2020-04-27 23:05 - 2020-04-27 23:08 - 000000000 ____D C:\Windows.old
2020-04-27 23:04 - 2020-04-27 23:08 - 000000000 ____D C:\Program Files (x86)\Razer
2020-04-27 23:04 - 2020-04-27 23:04 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2020-04-27 23:03 - 2020-04-27 23:03 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2020-04-27 23:02 - 2020-04-27 23:02 - 000000000 ____D C:\WINDOWS\Setup
2020-04-27 23:01 - 2020-04-30 09:33 - 000783126 _____ C:\WINDOWS\system32\perfh00A.dat
2020-04-27 23:01 - 2020-04-30 09:33 - 000152596 _____ C:\WINDOWS\system32\perfc00A.dat
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\OCR
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\ProgramData\ssh
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\Program Files\Reference Assemblies
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\Program Files\MSBuild
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2020-04-27 23:01 - 2020-04-27 23:01 - 000000000 ____D C:\Program Files (x86)\MSBuild
2020-04-27 23:01 - 2020-04-27 23:00 - 000346834 _____ C:\WINDOWS\system32\perfi00A.dat
2020-04-27 23:01 - 2020-04-27 23:00 - 000043954 _____ C:\WINDOWS\system32\perfd00A.dat
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\es
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\winrm
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\WCN
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\slmgr
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\es
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\0409
2020-04-27 23:00 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\DigitalLocker
2020-04-27 22:57 - 2020-02-03 15:56 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-04-27 22:57 - 2020-02-03 15:56 - 000179608 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-04-27 22:56 - 2020-04-27 22:53 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2020-04-27 22:56 - 2020-04-27 22:53 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2020-04-27 22:56 - 2020-04-27 22:53 - 000003103 _____ C:\WINDOWS\SysWOW64\mmc.exe.config
2020-04-27 22:56 - 2020-04-27 22:53 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2020-04-27 22:55 - 2020-04-30 09:42 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-04-27 22:55 - 2020-04-29 13:43 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-04-27 22:55 - 2020-04-29 11:25 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-04-27 22:55 - 2020-04-29 11:11 - 000000000 ___RD C:\Program Files (x86)
2020-04-27 22:55 - 2020-04-29 08:44 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-04-27 22:55 - 2020-04-28 18:29 - 000000000 ___HD C:\Program Files\WindowsApps
2020-04-27 22:55 - 2020-04-28 06:58 - 000000000 ____D C:\WINDOWS\appcompat
2020-04-27 22:55 - 2020-04-28 06:58 - 000000000 ____D C:\Program Files\Windows Defender
2020-04-27 22:55 - 2020-04-27 23:28 - 000000000 ____D C:\WINDOWS\ServiceState
2020-04-27 22:55 - 2020-04-27 23:15 - 000000000 ____D C:\WINDOWS\Containers
2020-04-27 22:55 - 2020-04-27 23:13 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-04-27 22:55 - 2020-04-27 23:12 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-04-27 22:55 - 2020-04-27 23:12 - 000000000 ____D C:\WINDOWS\CSC
2020-04-27 22:55 - 2020-04-27 23:08 - 000000000 ____D C:\WINDOWS\system32\spool
2020-04-27 22:55 - 2020-04-27 23:08 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2020-04-27 22:55 - 2020-04-27 23:05 - 000000000 __RHD C:\Users\Public\Libraries
2020-04-27 22:55 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2020-04-27 22:55 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\SystemResources
2020-04-27 22:55 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2020-04-27 22:55 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\system32\MUI
2020-04-27 22:55 - 2020-04-27 23:01 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ___SD C:\WINDOWS\system32\dsc
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\setup
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\system32\Com
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\IME
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\WINDOWS\Help
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\Program Files\Common Files\System
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-04-27 22:55 - 2020-04-27 23:00 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ___SD C:\WINDOWS\system32\UNP
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ___SD C:\WINDOWS\system32\Nui
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\TextInput
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\ti-et
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\ta-lk
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\ta-in
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\si-lk
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\Sgrm
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\osa-Osge-001
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\my-mm
2020-04-27 22:55 - 2020-04-27 22:56 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 __SHD C:\Program Files\Windows Sidebar
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 __RSD C:\WINDOWS\Media
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ___SD C:\WINDOWS\system32\AppV
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ___HD C:\WINDOWS\LanguageOverlayCache
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Web
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\WaaS
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Vss
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\tracing
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\TAPI
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SystemApps
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\winevt
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\ras
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\Keywords
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\IME
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\icsxml
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\ias
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\Hydrogen
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\GroupPolicy
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\ff-Adlm-SN
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\DriverState
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\downlevel
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\DDFs
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\appraiser
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\am-et
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\System
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SKB
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\ShellComponents
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\security
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\schemas
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\SchCache
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Resources
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\rescache
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\RemotePackages
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Registration
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Provisioning
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\PLA
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Performance
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\ModemLogs
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\L2Schemas
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\InputMethod
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\IdentityCRL
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Globalization
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\DiagTrack
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Cursors
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\Branding
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\addins

2da parte


2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\ProgramData\USOShared
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files\Windows Security
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files\Windows Portable Devices
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files\ModifiableWindowsApps
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files\Common Files\Services
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files (x86)\Windows NT
2020-04-27 22:55 - 2020-04-27 22:55 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2020-04-27 22:55 - 2020-04-27 22:53 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2020-04-27 22:55 - 2020-04-27 22:53 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2020-04-27 22:55 - 2020-04-27 22:53 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2020-04-27 22:55 - 2020-04-27 22:53 - 000018903 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2020-04-27 22:55 - 2020-04-27 22:53 - 000017635 _____ C:\WINDOWS\system32\Drivers\etc\services
2020-04-27 22:55 - 2020-04-27 22:53 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2020-04-27 22:55 - 2020-04-27 22:53 - 000003103 _____ C:\WINDOWS\system32\mmc.exe.config
2020-04-27 22:55 - 2020-04-27 22:53 - 000001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2020-04-27 22:55 - 2020-04-27 22:53 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2020-04-27 22:55 - 2020-04-27 22:53 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2020-04-27 22:55 - 2020-04-27 22:53 - 000000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2020-04-27 22:55 - 2020-04-27 22:53 - 000000219 _____ C:\WINDOWS\system.ini
2020-04-27 22:55 - 2020-04-27 22:53 - 000000092 _____ C:\WINDOWS\win.ini
2020-04-27 22:55 - 2020-04-27 22:50 - 000000000 ____D C:\ProgramData\USOPrivate
2020-04-27 22:55 - 2020-04-27 22:47 - 000000000 ____D C:\Program Files\Windows NT
2020-04-27 22:55 - 2020-04-27 22:28 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-04-27 22:55 - 2020-04-27 22:28 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-04-27 22:55 - 2020-04-27 22:16 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2020-04-27 22:54 - 2020-04-30 09:33 - 000000000 ____D C:\WINDOWS\INF
2020-04-27 22:49 - 2020-04-30 09:33 - 001767626 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-04-27 22:47 - 2020-04-29 08:07 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Local\Historial
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Local\Datos de programa
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default\AppData\Local\Archivos temporales de Internet
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Historial
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Datos de programa
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default User\AppData\Local\Archivos temporales de Internet
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\Default User
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Users\All Users
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\ProgramData\Plantillas
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\ProgramData\Menú Inicio
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\ProgramData\Escritorio
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\ProgramData\Documentos
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\ProgramData\Datos de programa
2020-04-27 22:47 - 2020-04-27 22:47 - 000000000 _SHDL C:\Program Files\Archivos comunes
2020-04-27 22:46 - 2020-04-30 09:27 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-04-27 22:46 - 2020-04-28 06:58 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-04-27 22:44 - 2020-04-27 22:44 - 000023054 _____ C:\Users\TalentPC\Desktop\Aplicaciones quitadas.html
2020-04-27 22:39 - 2020-04-30 09:26 - 089391104 _____ C:\WINDOWS\system32\config\SOFTWARE
2020-04-27 22:39 - 2020-04-30 09:26 - 012845056 _____ C:\WINDOWS\system32\config\SYSTEM
2020-04-27 22:39 - 2020-04-30 09:26 - 000786432 _____ C:\WINDOWS\system32\config\DEFAULT
2020-04-27 22:39 - 2020-04-30 09:26 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-04-27 22:39 - 2020-04-30 09:26 - 000131072 _____ C:\WINDOWS\system32\config\SAM
2020-04-27 22:39 - 2020-04-30 09:26 - 000032768 _____ C:\WINDOWS\system32\config\SECURITY
2020-04-27 22:39 - 2020-04-29 08:06 - 000000000 ____D C:\WINDOWS\servicing
2020-04-27 22:39 - 2020-04-27 22:55 - 000000000 ____D C:\WINDOWS\system32\SMI
2020-04-27 22:39 - 2020-04-27 22:47 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-04-27 22:34 - 2020-04-30 09:22 - 000000000 ____D C:\Users\TalentPC
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Reciente
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Plantillas
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Mis documentos
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Menú Inicio
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Impresoras
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Entorno de red
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Documents\Mis vídeos
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Documents\Mis imágenes
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Documents\Mi música
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Datos de programa
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\Configuración local
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\AppData\Local\Historial
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\AppData\Local\Datos de programa
2020-04-27 22:34 - 2020-04-27 22:34 - 000000000 _SHDL C:\Users\TalentPC\AppData\Local\Archivos temporales de Internet
2020-04-27 22:27 - 2020-04-30 09:42 - 000000000 ____D C:\ProgramData\NVIDIA
2020-04-27 22:27 - 2020-04-27 23:08 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-04-27 22:27 - 2020-04-27 22:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2020-04-27 22:27 - 2020-04-27 22:27 - 000000000 ____D C:\ProgramData\Razer
2020-04-27 22:27 - 2020-04-27 22:27 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-04-27 22:27 - 2020-04-27 22:27 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2020-04-27 22:27 - 2020-04-03 16:56 - 005581808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-04-27 22:27 - 2020-04-03 16:56 - 002631664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2020-04-27 22:27 - 2020-04-03 16:55 - 001759032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2020-04-27 22:27 - 2020-04-03 16:55 - 001172464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2020-04-27 22:27 - 2020-04-03 16:55 - 000446264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2020-04-27 22:27 - 2020-04-03 16:55 - 000121144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2020-04-27 22:27 - 2020-04-03 16:55 - 000074736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2020-04-27 22:27 - 2020-04-03 05:08 - 009037867 _____ C:\WINDOWS\system32\nvcoproc.bin
2020-04-27 22:27 - 2020-03-06 22:18 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2020-04-27 22:27 - 2019-06-20 10:15 - 002874368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-04-27 22:25 - 2020-04-27 23:16 - 000000000 ___HD C:\$SysReset
2020-04-27 22:17 - 2020-04-30 09:21 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-04-27 22:17 - 2020-04-29 10:02 - 000438888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-04-27 19:15 - 2020-04-27 19:15 - 000000299 _____ C:\Users\TalentPC\Desktop\Chequear_ Disco_Windows (1).bat
2020-04-27 15:46 - 2020-04-27 16:10 - 000016120 _____ C:\Users\TalentPC\Desktop\BSOD.txt
2020-04-27 15:21 - 2020-04-27 23:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2020-04-27 15:04 - 2020-04-27 15:04 - 001353488 _____ (Microsoft Corporation) C:\Users\TalentPC\Downloads\winsdksetup.exe
2020-04-27 09:45 - 2020-04-27 09:45 - 000000000 ____D C:\Users\TalentPC\source
2020-04-27 09:38 - 2020-04-27 09:45 - 000000000 ____D C:\Users\TalentPC\Documents\Visual Studio 2019
2020-04-27 09:35 - 2020-04-27 09:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.7
2020-04-27 09:13 - 2020-04-27 23:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2019
2020-04-27 08:40 - 2020-04-27 08:40 - 001394488 _____ (Microsoft Corporation) C:\Users\TalentPC\Downloads\vs_Community.exe
2020-04-25 10:42 - 2020-04-25 10:42 - 000000080 ___SH C:\bootTel.dat
2020-04-21 07:40 - 2020-04-27 19:15 - 000000000 ____D C:\Users\TalentPC\Documents\DESCARGAS OPERA
2020-04-18 12:56 - 2020-04-18 12:56 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 022636544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 018027520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 008013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 007756800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 007017472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 005910016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 004611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 003512320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 002951832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSAT.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 002369576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 002188600 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001870408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001659408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001545216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 001495864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001413840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001397576 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 001386296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001264640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 001151816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001077064 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 001013000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 001008128 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000775696 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000686080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000673464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2020-04-18 12:56 - 2020-04-18 12:56 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2020-04-18 12:56 - 2020-04-18 12:56 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000420152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000381440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbadmin.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasrad.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000187392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasrad.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.XamlHost.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.XamlHost.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-04-18 12:56 - 2020-04-18 12:56 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasacct.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-04-18 12:56 - 2020-04-18 12:56 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasacct.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumapi.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumapi.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\iaspolcy.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2010CustomActions.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iaspolcy.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ias.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ias.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-04-18 12:56 - 2020-04-18 12:56 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-04-18 12:55 - 2020-04-18 12:55 - 014818816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 006523048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 004563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 003802624 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 003753472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 003729408 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 003547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 002871608 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 002800128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 002767928 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 002086656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001999960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001945600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001918976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-04-18 12:55 - 2020-04-18 12:55 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001665216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001656904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001646048 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001612800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001603584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001512832 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 001484384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 001477112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001427456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001378528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001368576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001300280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 001261808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001243648 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001136128 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001081856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001011200 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000993280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000974336 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000924672 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000915192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000912896 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000892416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000865280 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000811320 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000785920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000759272 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000747320 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000684560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000673704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000665088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000638480 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000632832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000629760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000628616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000618296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000538160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000515600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000513576 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000491008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000487784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-04-18 12:55 - 2020-04-18 12:55 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000415760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000406480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Enumeration.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\es.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpr.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\es.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000323584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000277864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000268008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000259776 _____ (Microsoft Corporation) C:\WINDOWS\system32\logoncli.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000251704 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000190048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\logoncli.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000185952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000178192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000147696 _____ (Microsoft Corporation) C:\WINDOWS\system32\smss.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000142544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000127280 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000123952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000115120 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000102216 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000089336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\keepaliveprovider.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000066624 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000058880 _____ C:\WINDOWS\system32\runexehelper.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000050544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxssrv.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000033080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hwpolicy.sys
2020-04-18 12:55 - 2020-04-18 12:55 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sbservicetrigger.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wksprtPS.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsunattend.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Custom.ps.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2020-04-18 12:55 - 2020-04-18 12:55 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-04-18 12:55 - 2020-04-18 12:55 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 017790464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 007849216 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 003980800 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 003587384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 003109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 002717184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 002131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 002126144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 002114560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001960448 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001783296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001497600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001263856 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001127424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 001071616 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000879616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000654912 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000524264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000437560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000339304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000297272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000231912 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000193848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000151352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\scmbus.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000089912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.Common.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcProxyStubs.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-04-18 12:54 - 2020-04-18 12:54 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\flpydisk.sys
2020-04-18 12:54 - 2020-04-18 12:54 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Custom.ps.dll
2020-04-18 12:54 - 2020-04-18 12:54 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sfloppy.sys
2020-04-18 12:27 - 2020-04-18 12:27 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-04-18 12:27 - 2020-04-18 12:27 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-04-16 20:06 - 2020-04-11 16:55 - 001729232 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-04-16 20:06 - 2020-04-11 16:55 - 001729232 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-04-16 20:06 - 2020-04-11 16:55 - 001329360 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-04-16 20:06 - 2020-04-11 16:55 - 001329360 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-04-16 20:06 - 2020-04-11 16:55 - 001078992 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-04-16 20:06 - 2020-04-11 16:55 - 001078992 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-04-16 20:06 - 2020-04-11 16:55 - 000937680 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-04-16 20:06 - 2020-04-11 16:55 - 000937680 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-04-16 20:06 - 2020-04-11 16:55 - 000450280 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-04-16 20:06 - 2020-04-11 16:55 - 000346856 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-04-16 20:06 - 2020-04-11 16:54 - 011945872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2020-04-16 20:06 - 2020-04-11 16:54 - 010286480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 017601632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 015158384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 005855856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 005159520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 002074232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001722480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6444587.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001566328 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001483376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6444587.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001481328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001350792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001142200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 001048504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000817080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000811448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000679864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000676448 _____ C:\WINDOWS\system32\nvofapi64.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000655312 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000546744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2020-04-16 20:06 - 2020-04-11 16:53 - 000543160 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2020-04-16 20:06 - 2020-04-11 16:52 - 004927960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-04-16 20:06 - 2020-04-11 16:51 - 004195688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2020-04-16 20:06 - 2020-04-11 10:40 - 001682368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2020-04-16 20:06 - 2020-04-11 10:40 - 000223120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-04-16 20:06 - 2020-04-11 10:40 - 000039824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2020-04-16 20:06 - 2020-04-03 19:21 - 000057237 _____ C:\WINDOWS\system32\nvinfo.pb
2020-04-16 20:06 - 2020-03-11 14:26 - 000067456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2020-04-16 19:28 - 2020-03-31 18:58 - 000044984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvswcfilter.sys
2020-04-08 10:52 - 2020-04-08 10:53 - 000000000 ____D C:\Users\TalentPC\AppData\LocalLow\Adobe
2020-04-08 10:49 - 2020-04-08 10:49 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-04-08 07:41 - 2020-04-08 07:42 - 019271699 _____ C:\Users\TalentPC\Downloads\!                       §bEpax§640k §3[32x].zip
2020-04-03 14:48 - 2020-04-03 14:48 - 000000000 ____D C:\Users\TalentPC\.lunarclient

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-04-30 09:44 - 2019-05-06 19:25 - 000000000 ____D C:\Users\TalentPC\Documents\Tareas Angel
2020-04-30 09:28 - 2019-04-18 04:33 - 000000000 ___RD C:\Users\TalentPC\OneDrive
2020-04-29 11:14 - 2019-07-19 21:30 - 000000000 ____D C:\temp
2020-04-29 08:44 - 2019-04-17 23:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Herramientas de Microsoft Office
2020-04-28 07:29 - 2019-10-11 17:39 - 000000000 ____D C:\Users\TalentPC\Documents\BLC PUNTO MINECRAFT
2020-04-28 07:28 - 2019-05-12 06:27 - 000000000 ___RD C:\Users\TalentPC\Desktop\Dolphin
2020-04-27 23:12 - 2020-02-22 21:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2020-04-27 23:12 - 2019-10-27 11:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
2020-04-27 23:12 - 2019-08-09 07:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2020-04-27 23:12 - 2019-07-19 21:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer Cortex
2020-04-27 23:12 - 2019-06-15 09:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2020-04-27 23:12 - 2019-04-18 13:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2020-04-27 23:11 - 2019-04-18 04:32 - 000001450 ____H C:\Users\TalentPC\Desktop\Microsoft Edge.lnk
2020-04-27 23:08 - 2019-04-18 04:31 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-04-27 23:08 - 2019-04-18 04:31 - 000000000 ___RD C:\Users\TalentPC\3D Objects
2020-04-27 23:05 - 2019-05-04 14:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
2020-04-27 23:05 - 2019-04-18 04:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2020-04-27 22:44 - 2019-06-15 09:43 - 000000000 ____D C:\Users\TalentPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2020-04-20 09:55 - 2019-08-09 07:29 - 000000000 ____D C:\Users\TalentPC\Documents\Lightshot
2020-04-16 09:05 - 2019-04-22 14:56 - 000000000 ____D C:\Users\TalentPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2020-04-15 14:21 - 2019-07-19 21:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2020-04-03 15:44 - 2019-04-28 07:31 - 000000000 ____D C:\AlphaAntiLeak
2020-04-03 14:48 - 2019-04-28 07:31 - 000002055 _____ C:\Users\TalentPC\Desktop\Lunar Client.lnk

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)

==================== Final de FRST.txt ========================
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 28-04-2020
Ejecutado por MoreThanMe (30-04-2020 09:48:36)
Ejecutado desde C:\Users\TalentPC\Desktop
Windows 10 Pro Versión 1903 18362.778 (X64) (2020-04-28 04:08:19)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-1074164132-3260105572-149681692-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1074164132-3260105572-149681692-503 - Limited - Disabled)
Invitado (S-1-5-21-1074164132-3260105572-149681692-501 - Limited - Disabled)
MoreThanMe (S-1-5-21-1074164132-3260105572-149681692-1001 - Administrator - Enabled) => C:\Users\TalentPC
WDAGUtilityAccount (S-1-5-21-1074164132-3260105572-149681692-504 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

CCleaner (HKLM\...\CCleaner) (Version: 5.65 - Piriform)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.129 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Hard Disk Sentinel PRO (HKLM-x32\...\Hard Disk Sentinel_is1) (Version: 5.61 - Janos Mathe)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft Office 365 ProPlus - es-es (HKLM\...\O365ProPlusRetail - es-es) (Version: 16.0.11929.20708 - Microsoft Corporation)
Microsoft OneDrive (HKLM-x32\...\OneDriveSetup.exe) (Version: 19.232.1124.0012 - Microsoft Corporation)
Microsoft Teams (HKU\S-1-5-21-1074164132-3260105572-149681692-1001\...\Teams) (Version: 1.3.00.4461 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20708 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.11929.20708 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0C0A-1000-0000000FF1CE}) (Version: 16.0.11929.20708 - Microsoft Corporation) Hidden
Panel de control de NVIDIA 445.87 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 445.87 - NVIDIA Corporation) Hidden
Teams Machine-Wide Installer (HKLM-x32\...\{731F6BAA-A986-45A4-8936-7C3AAAAA760B}) (Version: 1.3.0.4461 - Microsoft Corporation)

Packages:
=========
Bubble Witch 3 Saga -> C:\Program Files\WindowsApps\king.com.BubbleWitch3Saga_6.8.5.0_x86__kgqvnymyfvs32 [2020-04-27] (king.com)
Candy Crush Friends -> C:\Program Files\WindowsApps\king.com.CandyCrushFriends_1.35.2.0_x86__kgqvnymyfvs32 [2020-04-27] (king.com)
Complemento de motor multimedia para Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-04-28] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2020-04-27] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\microsoft.advertising.xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2020-04-27] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.4030.0_x64__8wekyb3d8bbwe [2020-04-27] (Microsoft Studios) [MS Ad]
Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.14.6005.0_x64__8wekyb3d8bbwe [2020-04-28] (Microsoft Studios)
MSN El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-04-27] (Microsoft Corporation) [MS Ad]
Realtek Audio Control -> C:\Program Files\WindowsApps\RealtekSemiconductorCorp.RealtekAudioControl_1.3.180.0_x64__dt26b99r8h8gj [2020-04-27] (Realtek Semiconductor Corp)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

CustomCLSID: HKU\S-1-5-21-1074164132-3260105572-149681692-1001_Classes\CLSID\{19A6E644-14E6-4A60-B8D7-DD20610A871D}\InprocServer32 -> C:\Users\TalentPC\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20031.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1074164132-3260105572-149681692-1001_Classes\CLSID\{CB965DF1-B8EA-49C7-BDAD-5457FDC1BF92}\InprocServer32 -> C:\Users\TalentPC\AppData\Local\Microsoft\TeamsMeetingAddin\1.0.20031.2\x64\Microsoft.Teams.AddinLoader.dll (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-29] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files (x86)\Microsoft OneDrive\19.232.1124.0012\amd64\FileSyncShell64.dll [2020-04-28] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-04-03] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-04-29] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Lista blanca) ====================

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2020-04-27 22:55 - 2020-04-27 22:53 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKU\S-1-5-21-1074164132-3260105572-149681692-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\TalentPC\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\mario galaxy.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [{D1713635-2A5B-4F35-975E-E06798E93E07}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E44C6689-9217-4D61-974F-97BD433DD035}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{74C732A0-8CAA-4935-BBFA-676D28B6B513}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E121343B-44FD-4B37-B098-A994D19770F9}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{80976F16-B30B-4A60-A910-0A8E830CE90D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AB64CFC0-1253-4363-B6D7-90B5D44B94E0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Puntos de Restauración =========================

29-04-2020 07:55:56 Windows Update
30-04-2020 09:41:52 JRT Pre-Junkware Removal

==================== Dispositivos defectuosos en el Administrador de dispositivos ============


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (04/30/2020 09:47:37 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2064,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (04/30/2020 09:37:27 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4452,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (04/30/2020 09:14:28 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: Los Servicios de cifrado no pudieron inicializar el objeto "System Writer" de la copia de seguridad de VSS.

Details:
Could not query the status of the EventSystem service.

System Error:
Se está cerrando el sistema.
.

Error: (04/29/2020 01:50:31 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al llamar a la rutina CoCreateInstance. HR = 0x8007045b, Se está cerrando el sistema.
.

Error: (04/29/2020 01:50:31 PM) (Source: VSS) (EventID: 13) (User: )
Description: Información del Servicio de instantáneas de volumen: el servidor COM con CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} y el nombre CEventSystem no puede iniciarse. [0x8007045b, Se está cerrando el sistema.
]

Error: (04/29/2020 01:40:31 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (4304,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (04/29/2020 11:57:31 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (3640,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.

Error: (04/29/2020 11:25:19 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11000,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log.


Errores del sistema:
=============
Error: (04/30/2020 09:42:36 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Realtek Audio Universal Service terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 0 milisegundos: Reiniciar el servicio.

Error: (04/30/2020 09:42:33 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio NVIDIA Display Container LS terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 6000 milisegundos: Reiniciar el servicio.

Error: (04/30/2020 09:26:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: El servicio Servicio de antivirus de Windows Defender se cerró con el siguiente error: 
%%2147550931

Error: (04/30/2020 09:26:30 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Servicio Hacer clic y ejecutar de Microsoft Office terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 0 milisegundos: Reiniciar el servicio.

Error: (04/30/2020 09:26:30 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Realtek Audio Universal Service terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 0 milisegundos: Reiniciar el servicio.

Error: (04/30/2020 09:26:30 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio NVIDIA Display Container LS terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 6000 milisegundos: Reiniciar el servicio.

Error: (04/30/2020 09:21:25 AM) (Source: volmgr) (EventID: 161) (User: )
Description: No se pudo crear el archivo de volcado debido a un error durante la creación del volcado.

Error: (04/30/2020 09:21:43 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: El cierre anterior del sistema a las 09:15:12 a. m. del ‎30/‎04/‎2020 resultó inesperado.


Windows Defender:
===================================
Date: 2020-04-29 10:21:26.934
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {1FE97DB7-2CCC-4B4F-83A8-AC297FE7BAFD}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-04-29 09:45:13.620
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {593F66C4-0BE2-41AB-A7FC-4CC541FDCE06}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-04-29 09:25:53.711
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {B2684B5C-427C-4704-9B9B-3CD59B64B310}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-04-29 09:21:11.061
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {0F2FD92D-FE71-41D5-82AC-5EBC9FE07EFB}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-04-29 08:50:02.738
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {52D43CCA-CA8A-4889-87A1-264744F9EB09}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2020-04-29 18:03:57.071
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.313.2582.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor: 
Versión anterior del motor: 1.1.16900.4
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 

Date: 2020-04-29 17:53:50.326
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 
Motivo: La inteligencia de seguridad antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

Date: 2020-04-29 14:03:15.849
Description: 
Antivirus de Windows Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.313.2582.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor: 
Versión anterior del motor: 1.1.16900.4
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 

Date: 2020-04-29 13:53:05.554
Description: 
La característica Protección en tiempo real de Antivirus de Windows Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores 
Motivo: La inteligencia de seguridad antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.

==================== Información de la memoria =========================== 

BIOS: American Megatrends Inc. F24 12/25/2018
Placa base: Gigabyte Technology Co., Ltd. A320M-S2H-CF
Procesador: AMD Ryzen 5 2400G with Radeon Vega Graphics 
Porcentaje de memoria en uso: 36%
RAM física total: 8139.29 MB
RAM física disponible: 5200.49 MB
Virtual total: 10059.29 MB
Virtual disponible: 5955.2 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:930.91 GB) (Free:837.52 GB) NTFS

\\?\Volume{6883a161-13cb-49b9-bfd3-bf560c08617e}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.08 GB) NTFS
\\?\Volume{a56e484e-19c1-4b8c-a323-973cfaadf3c7}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Final de Addition.txt =======================

Ahí están las faltantes :grinning: Saludos cordiales

Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKU\S-1-5-21-1074164132-3260105572-149681692-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.129\Installer\chrmstp.exe [2020-04-29] (Google LLC -> Google LLC)
Task: {B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07} - System32\Tasks\AdwCleaner_onReboot => C:\Users\TalentPC\Desktop\adwcleaner_8.0.4.exe [8196784 2020-04-29] (Malwarebytes Inc -> Malwarebytes)
Task: {E41C40F6-4639-4EA0-AAAE-5F159B21C022} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_MoreThanMe => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [5820440 2020-03-12] (Janos Mathe -> H.D.S. Hungary)
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

Y ahora usa el 2º MÉTODO: de esta Faq de Windows 8(aplicable a Windows 10) :arrow_forward: ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX/Corregir y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.

holaaa, el link para el Delfix no responde ¿Qué podría hacer? saludos

Hola.

Parece que existe algún problema con el enlace de descarga. :face_with_raised_eyebrow:

Por aquí te lo adjunto para que puedas descargarlo :arrow_right: delfix.exe. :+1:

Saludos.

Resultados de la corrección de Farbar Recovery Scan Tool (x64) Versión: 30-04-2020
Ejecutado por MoreThanMe (30-04-2020 14:09:40) Run:1
Ejecutado desde C:\Users\TalentPC\Desktop
Perfiles cargados: MoreThanMe (Perfiles disponibles: MoreThanMe)
Modo de Inicio: Safe Mode (with Networking)
==============================================

fixlist contenido:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
HKU\S-1-5-21-1074164132-3260105572-149681692-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.129\Installer\chrmstp.exe [2020-04-29] (Google LLC -> Google LLC)
Task: {B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07} - System32\Tasks\AdwCleaner_onReboot => C:\Users\TalentPC\Desktop\adwcleaner_8.0.4.exe [8196784 2020-04-29] (Malwarebytes Inc -> Malwarebytes)
Task: {E41C40F6-4639-4EA0-AAAE-5F159B21C022} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_MoreThanMe => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [5820440 2020-03-12] (Janos Mathe -> H.D.S. Hungary)
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: El punto de restauración solamente puede ser creado en modo normal.
Procesos cerrados correctamente.
"HKU\S-1-5-21-1074164132-3260105572-149681692-1001\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Smart Cleaning" => eliminado correctamente
HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} => eliminado correctamente
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07} => no pudo ser eliminado. Acceso Denegado.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07} => no pudo ser eliminado. Acceso Denegado.
C:\WINDOWS\System32\Tasks\AdwCleaner_onReboot => movido correctamente
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdwCleaner_onReboot => no pudo ser eliminado. Acceso Denegado.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E41C40F6-4639-4EA0-AAAE-5F159B21C022} => no pudo ser eliminado. Acceso Denegado.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E41C40F6-4639-4EA0-AAAE-5F159B21C022} => no pudo ser eliminado. Acceso Denegado.
C:\WINDOWS\System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_MoreThanMe => movido correctamente
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HardDiskSentinel\Hard Disk Sentinel_MoreThanMe => no pudo ser eliminado. Acceso Denegado.
C:\Windows\System32\Drivers\etc\hosts => movido correctamente
Hosts restaurado correctamente.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-21-1074164132-3260105572-149681692-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-21-1074164132-3260105572-149681692-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente


========= Final de RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= Final de CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


Adaptador de Ethernet Ethernet:

   Sufijo DNS espec¡fico para la conexi¢n. . : huawei.net
   Direcci¢n IPv6 . . . . . . . . . . : 2806:105e:16:2fd::4
   Direcci¢n IPv6 . . . . . . . . . . : 2806:105e:16:2fd:45d1:516d:4252:57be
   Direcci¢n IPv6 . . . . . . . . . . : fd4c:fb45:f365:5400:45d1:516d:4252:57be
   Direcci¢n IPv6 temporal. . . . . . : 2806:105e:16:2fd:10a:9482:29d1:c906
   Direcci¢n IPv6 temporal. . . . . . : fd4c:fb45:f365:5400:10a:9482:29d1:c906
   V¡nculo: direcci¢n IPv6 local. . . : fe80::45d1:516d:4252:57be%8
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.1.73
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : fe80::1%8
                                       192.168.1.254

========= Final de CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= Final de CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

Unable to connect to BITS - 0x8007043c

========= Final de CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= Final de CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= Final de CMD: =========


========= netsh int ipv4 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


========= netsh int ipv6 reset =========

Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.

 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
 se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 6578176 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8441576 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 739098 B
Edge => 15417328 B
Chrome => 140913 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 4140 B
NetworkService => 5336 B
TalentPC => 15986602 B

RecycleBin => 0 B
EmptyTemp: => 45.1 MB datos temporales eliminados.

================================

Resultado de los archivos programados para mover (Modo de Inicio: Normal) (Fecha y Hora: 30-04-2020 14:11:10)


Resultado de las claves programadas para eliminar después de reiniciar:

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7B6EC65-F8D2-4323-B3A8-AAB3DE7FFA07}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdwCleaner_onReboot" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E41C40F6-4639-4EA0-AAAE-5F159B21C022}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E41C40F6-4639-4EA0-AAAE-5F159B21C022}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HardDiskSentinel\Hard Disk Sentinel_MoreThanMe" => eliminado correctamente

==== Final  Fixlog 14:11:19 ====

Hola.

Bien… y ahora quiero que hagas los pasos que se indican en el siguiente tutorial y específicamente las primeras indicaciones y NO las relativas o especificas de W10 porque en función de la version que tengamos pueden variar los menús.

:arrow_right: Liberar Espacio en Discos y Particiones

Cuando termines de hacer esos pasos REINICIAS el equipo y los reputes, y hazlos en ambas ocasiones desde el modo normal de windows.

Cuando termines, nos comentas como sigue la maquina en relación al problema inicialmente comentado. :thinking:

Saludos.

Hola, por lo mientras se ve un funcionamiento normal. Por ahora no se me a apagado el equipo. Lo estoy probando poniendo vídeos. Si veo un anormalidad en ¿cuánto tiempo usted daría? Le comento Saludos

Mientras estaba viendo un video se reinició otra vez

Ummmm… mal asunto…??

Veamos…si tenemos algo escondido. :roll_eyes:

Descarga y descomprime esta herramienta en tu escritorio :arrow_right: Manual de Malwarebytes Anti-Rootkits Beta, y sigues los pasos que se indican para revisar el equipo :

  • Abre la carpeta Mbar, haces doble clic en el archivo Mbar.exe.
  • En la ventana que saldrá pulsas en Next.
  • Pulsar en Update, y cuando termine en Next.
  • Ahora inicias el análisis pulsando en el botón Scan.
  • Al terminar, si existe infección pulsamos en CleanUp y si no hay infección pulsamos en Exit.

Al terminar busca en la carpeta Mbar, y abres los archivos mbar-log.txt y system-log.txt, nos copias el contenido en la siguiente respuesta y comentas resultados.

Saludos.

Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org

Database version:
  main:    v2020.04.30.10
  rootkit: v2020.04.30.10

Windows 10 x64 NTFS
Internet Explorer 11.778.18362.0
MoreThanMe :: DESKTOP-JA9PJRI [administrator]

30/04/2020 07:32:00 p. m.
mbar-log-2020-04-30 (19-32-00).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 171047
Time elapsed: 13 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

Account is Administrative

Internet Explorer version: 11.778.18362.0

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 3.593000 GHz
Memory total: 8534667264, free: 5265326080

Downloaded database version: v2020.04.30.10
Downloaded database version: v2020.04.30.10
Downloaded database version: v2018.01.20.01
=======================================
Initializing...
Driver version: 4.3.0.15
------------ Kernel report ------------
     04/30/2020 19:31:52
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\ksecdd.sys
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\System32\drivers\FLTMGR.SYS
\SystemRoot\System32\drivers\clipsp.sys
\SystemRoot\System32\drivers\cmimcext.sys
\SystemRoot\System32\drivers\ntosext.sys
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\cng.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\WppRecorder.sys
\SystemRoot\system32\drivers\SleepStudyHelper.sys
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\system32\drivers\mssecflt.sys
\SystemRoot\system32\drivers\SgrmAgent.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\system32\drivers\WindowsTrustedRT.sys
\SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\system32\drivers\CEA.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\System32\drivers\EhStorClass.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\amdpsp.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\drivers\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volume.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iorate.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\drivers\cdrom.sys
\SystemRoot\system32\drivers\filecrypt.sys
\SystemRoot\system32\drivers\tbs.sys
\??\C:\WINDOWS\system32\drivers\BadlionAnticheat.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_307898c750ba9e44\BasicDisplay.sys
\SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_ba2a8de08ea0d469\BasicRender.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afunix.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\drivers\vwififlt.sys
\SystemRoot\System32\drivers\pacer.sys
\SystemRoot\system32\drivers\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\gpuenergydrv.sys
\??\C:\WINDOWS\system32\drivers\mbae64.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\drivers\bam.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\System32\drivers\Vid.sys
\SystemRoot\System32\drivers\winhvr.sys
\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_43ac632006e874bb\CompositeBus.sys
\SystemRoot\System32\drivers\kdnic.sys
\SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_e566af5dd9858a0e\umbus.sys
\SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9952681a7bb1dfac\nvlddmkm.sys
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\System32\drivers\portcls.sys
\SystemRoot\System32\drivers\drmk.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\system32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\rt640x64.sys
\SystemRoot\System32\drivers\AMDPCIDev.sys
\SystemRoot\System32\drivers\amdppm.sys
\SystemRoot\System32\drivers\amdgpio2.sys
\SystemRoot\System32\Drivers\msgpioclx.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\amdgpio3.sys
\SystemRoot\System32\DriverStore\FileRepository\uefi.inf_amd64_4fcaf0fc6eaf7533\UEFI.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_1c567926e5b29133\swenum.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\System32\drivers\USBD.SYS
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\drivers\RzDev_022a.sys
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\drivers\kbdhid.sys
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\System32\Drivers\mshidkmdf.sys
\SystemRoot\System32\drivers\RzCommon.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\drivers\dump_storahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\win32kfull.sys
\SystemRoot\System32\win32kbase.sys
\SystemRoot\System32\drivers\dxgmms2.sys
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\wcifs.sys
\SystemRoot\system32\drivers\cldflt.sys
\SystemRoot\system32\drivers\storqosflt.sys
\SystemRoot\System32\Drivers\MbamChameleon.sys
\SystemRoot\system32\drivers\mslldp.sys
\SystemRoot\system32\drivers\rspndr.sys
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\lltdio.sys
\SystemRoot\system32\drivers\winquic.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\drivers\mmcss.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\drivers\rassstp.sys
\SystemRoot\System32\DRIVERS\NDProxy.sys
\SystemRoot\System32\drivers\AgileVpn.sys
\SystemRoot\System32\drivers\rasl2tp.sys
\SystemRoot\System32\drivers\raspptp.sys
\SystemRoot\System32\DRIVERS\raspppoe.sys
\SystemRoot\System32\DRIVERS\ndistapi.sys
\SystemRoot\System32\drivers\ndiswan.sys
\SystemRoot\System32\Drivers\mbamswissarmy.sys
\SystemRoot\system32\DRIVERS\mwac.sys
\SystemRoot\system32\DRIVERS\farflt.sys
\??\C:\WINDOWS\system32\DRIVERS\mbam.sys
\SystemRoot\System32\drivers\condrv.sys
\??\C:\WINDOWS\system32\drivers\27EEA431.sys
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2020.04.30.10
  rootkit: v2020.04.30.10

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffcd8fee947060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffcd8fee7108d0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffcd8fee947060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xffffcd8fee576060, DeviceName: \Device\0000002c\, DriverName: \Driver\storahci\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 0

GPT Protective MBR Partition information:

    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

GPT Partition information:

    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 1879738401
    GPT Header CurrentLba = 1 BackupLba 1953525167
    GPT Header FirstUsableLba 34  LastUsableLba 1953525134
    GPT Header Guid d5a11cab-8efa-4017-88e1-5bfd80add357
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128

    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 1879738401
    Backup GPT header CurrentLba = 1953525167 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 1953525134
    Backup GPT header Guid d5a11cab-8efa-4017-88e1-5bfd80add357
    Backup GPT header Contains 128 partition entries starting at LBA 1953525135
    Backup GPT header Partition entry size = 128

    Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 6883a161-13cb-49b9-bfd3-bf56c8617e
    FirstLBA 2048  Last LBA 1023999
    Attributes 1
    Partition Name                 Basic data partition

    Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
    Partition ID a56e484e-19c1-4b8c-a323-973cfaadf3c7
    FirstLBA 1024000  Last LBA 1226751
    Attributes 0
    Partition Name                 EFI system partition

    GPT Partition 1 is bootable
    Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID 13ca642-2760-42e9-a0da-e093a2ecb1ac
    FirstLBA 1226752  Last LBA 1259519
    Attributes 0
    Partition Name         Microsoft reserved partition

    Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID 3412e8f5-221a-4d36-b5b8-65295aab64d6
    FirstLBA 1259520  Last LBA 1953523711
    Attributes 0
    Partition Name                 Basic data partition

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
File "C:\Windows\System32\KERNELBASE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\psapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\user32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\win32u.dll" is sparse (flags = 32768)
File "C:\Windows\System32\gdi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\GDI32FULL.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MSVCP_WIN.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\ucrtbase.dll" is sparse (flags = 32768)
File "C:\Windows\System32\advapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msvcrt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sechost.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rpcrt4.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sspicli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CRYPTBASE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BCRYPTPRIMITIVES.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\imm32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\shell32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cfgmgr32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SHCore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\combase.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STORAGE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\profapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\powrprof.dll" is sparse (flags = 32768)
File "C:\Windows\System32\umpdc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\shlwapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\KERNEL.APPCORE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\cryptsp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ole32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wintrust.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msasn1.dll" is sparse (flags = 32768)
File "C:\Windows\System32\crypt32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\version.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wininet.dll" is sparse (flags = 32768)
File "C:\Windows\System32\imagehlp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\netapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\userenv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mpr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\IPHLPAPI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\netutils.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ws2_32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\comdlg32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\oleaut32.dll" is sparse (flags = 32768)
File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.18362.778_none_71d70b7d5ae4146f\comctl32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winmm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winspool.drv" is sparse (flags = 32768)
File "C:\Windows\System32\bcrypt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINMMBASE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\propsys.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sfc_os.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rsaenh.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wkscli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\uxtheme.dll" is sparse (flags = 32768)
File "C:\Windows\System32\iertutil.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winhttp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mswsock.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winnsi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nsi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\urlmon.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dnsapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rasadhlp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FWPUCLNT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\msctf.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dhcpcsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ntmarta.dll" is sparse (flags = 32768)
File "C:\Windows\System32\fltLib.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TEXTINPUTFRAMEWORK.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\COREUICOMPONENTS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WinTypes.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wtsapi32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\winsta.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mssprxy.dll" is sparse (flags = 32768)
File "C:\Windows\System32\coml2.dll" is sparse (flags = 32768)
File "C:\Windows\System32\linkinfo.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ntshrui.dll" is sparse (flags = 32768)
File "C:\Windows\System32\srvcli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\smss.exe" is sparse (flags = 32768)
File "C:\Windows\System32\csrss.exe" is sparse (flags = 32768)
File "C:\Windows\System32\wininit.exe" is sparse (flags = 32768)
File "C:\Windows\System32\services.exe" is sparse (flags = 32768)
File "C:\Windows\System32\lsass.exe" is sparse (flags = 32768)
File "C:\Windows\System32\winlogon.exe" is sparse (flags = 32768)
File "C:\Windows\System32\svchost.exe" is sparse (flags = 32768)
File "C:\Windows\System32\FONTDRVHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\dwm.exe" is sparse (flags = 32768)
File "C:\Windows\System32\spoolsv.exe" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\WmiPrvSE.exe" is sparse (flags = 32768)
File "C:\Windows\System32\dllhost.exe" is sparse (flags = 32768)
File "C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.778_none_2e73ee38278978be\comctl32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wsock32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\setupapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\newdev.dll" is sparse (flags = 32768)
File "C:\Windows\System32\devrtl.dll" is sparse (flags = 32768)
File "C:\Windows\System32\hhctrl.ocx" is sparse (flags = 32768)
File "C:\Windows\System32\idndl.dll" is sparse (flags = 32768)
File "C:\Windows\System32\normaliz.dll" is sparse (flags = 32768)
File "C:\Windows\System32\perfdisk.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wmiclnt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\devobj.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\wbemprox.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbemcomn.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\wbemsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\fastprox.dll" is sparse (flags = 32768)
File "C:\Windows\System32\riched32.dll" is sparse (flags = 32768)
File "C:\Windows\System32\riched20.dll" is sparse (flags = 32768)
File "C:\Windows\System32\usp10.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msls31.dll" is sparse (flags = 32768)
File "C:\Windows\System32\d3d11.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dcomp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dxgi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DXCore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TWINAPI.APPCORE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\rmclient.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TASKHOSTW.EXE" is sparse (flags = 32768)
File "C:\Windows\explorer.exe" is sparse (flags = 32768)
File "C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\STARTMENUEXPERIENCEHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SEARCHINDEXER.EXE" is sparse (flags = 32768)
File "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" is sparse (flags = 32768)
File "C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MICROSOFTEDGE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SEARCHPROTOCOLHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\BROWSER_BROKER.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SETTINGSYNCHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SECURITYHEALTHSYSTRAY.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\SECURITYHEALTHSERVICE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\secur32.dll" is sparse (flags = 32768)
File "C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.778_none_5f5ee11d821bf28c\GdiPlus.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dwmapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wer.dll" is sparse (flags = 32768)
File "C:\Windows\System32\xmllite.dll" is sparse (flags = 32768)
File "C:\Windows\System32\credui.dll" is sparse (flags = 32768)
File "C:\Windows\System32\Faultrep.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dbghelp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ncrypt.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ntasn1.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dbgcore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wscapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mlang.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ONECOREUAPCOMMONPROXYSTUB.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\APPXDEPLOYMENTCLIENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\FIREWALLAPI.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\fwbase.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msxml6.dll" is sparse (flags = 32768)
File "C:\Windows\System32\taskschd.dll" is sparse (flags = 32768)
File "C:\Windows\System32\Wpc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wlidprov.dll" is sparse (flags = 32768)
File "C:\Windows\System32\samcli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.SERVICES.TARGETEDCONTENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\STRUCTUREDQUERY.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.STORAGE.SEARCH.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DHCPCSVC6.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dpapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\webio.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWSCODECS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\schannel.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MSKEYPROTECT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\NCRYPTSSLP.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\cryptnet.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dsreg.dll" is sparse (flags = 32768)
File "C:\Windows\System32\MSVCP110_WIN.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\netprofm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\npmproxy.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sxs.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dusmapi.dll" is sparse (flags = 32768)
File "C:\Windows\ImmersiveControlPanel\SYSTEMSETTINGS.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\audiodg.exe" is sparse (flags = 32768)
File "C:\Windows\System32\POLICYMANAGER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\EXPLORERFRAME.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\APPRESOLVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\BCP47LANGS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\slc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sppc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ONECORECOMMONPROXYSTUB.DLL" is sparse (flags = 32768)
File "C:\Windows\SysWOW64\cmd.exe" is sparse (flags = 32768)
File "C:\Windows\System32\cmdext.dll" is sparse (flags = 32768)
File "C:\Windows\System32\conhost.exe" is sparse (flags = 32768)
File "C:\Windows\System32\SEARCHFILTERHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\userinit.exe" is sparse (flags = 32768)
File "C:\Windows\System32\scecli.dll" is sparse (flags = 32768)
File "C:\Windows\System32\msv1_0.dll" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mup.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\CmBatt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\appid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\AcpiDev.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\1394ohci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\amdk8.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpipagr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\afd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\flpydisk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mspclock.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\asyncmac.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpiex.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\isapnp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\acpitime.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\stornvme.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Ucx01000.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Acx01000.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mrxsmb20.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mpsdrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidi2c.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\afunix.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sdstor.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ahcache.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\amdppm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\IPMIDrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\APPLOCKERFLTR.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pciide.sys" is sparse (flags = 32768)
File "C:\Windows\System32\APPVCLIENT.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\AppVStrm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\AppvVfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\APPVVEMGR.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wcifs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\srv2.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\atapi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fdc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bindflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bowser.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\storufs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BthA2dp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bthenum.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HYPERVIDEO.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\portcfg.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BthMini.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bthport.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BTHUSB.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\bttflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\BUTTONCONVERTER.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cng.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\csc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cdfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\clfs.sys" is sparse (flags = 32768)
File "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSVCHOST.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cdrom.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\cldflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\condrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\dfsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\disk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mssecflt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\DiagSvcs\DIAGNOSTICSHUB.STANDARDCOLLECTOR.SERVICE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\dmvsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\drmkaud.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\serial.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\dxgkrnl.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tcpip.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\EHSTORCLASS.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\EHSTORTCGDRV.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\errdev.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fileinfo.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vmstorfl.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\FILETRACE.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fltMgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\monitor.sys" is sparse (flags = 32768)
File "C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PRESENTATIONFONTCACHE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\FSDEPENDS.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\STORQOSFLT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\fvevol.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndisuio.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MSGPIOCLX.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rasl2tp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mrxsmb.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HdAudio.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hdaudbus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidbatt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HIDINTERRUPT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tsusbhub.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidspi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hidusb.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\http.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\HVSERVICE.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hwpolicy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\hyperkbd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndproxy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\i8042prt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\intelide.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\intelpep.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vdrvroot.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\intelppm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\msiscsi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\kbdclass.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\kbdhid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ksecdd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ksecpkg.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ksthunk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\luafv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\msisadrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mstee.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MbbCx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mmcss.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mskssrv.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wimmount.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mrxdav.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mspqm.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mouclass.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mouhid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mountmgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\VSSVC.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MSHIDKMDF.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\mssmbios.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\MTConfig.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\nwifi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\netbios.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\netvsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndis.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NDISIMPLATFORM.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tunnel.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndistapi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NDISVIRTUALBUS.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ndiswan.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NETADAPTERCX.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\netbt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\NPSVCTRIG.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\nsiproxy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\Spectrum.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\parport.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\partmgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pcw.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pdc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\pcmcia.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\PEAuth.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\RDPVIDEOMINIPORT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\raspptp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\processr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ramdisk.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rasacd.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\agilevpn.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\raspppoe.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rassstp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rdbss.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\rdpdr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wacompen.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sbp2port.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sdbus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SerCx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SpbCx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\serenum.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SerCx2.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sermouse.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\sfloppy.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\SPACEPORT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\sppsvc.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\srvnet.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\storahci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\storvsc.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tdx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\tpm.sys" is sparse (flags = 32768)
File "C:\Windows\servicing\TRUSTEDINSTALLER.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\uaspstor.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Udecx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\udfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\AGENTSERVICE.EXE" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\umpass.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBAUDIO.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBAUDIO2.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbccgp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBXHCI.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbuhci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbohci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbehci.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbhub.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBHUB3.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\usbser.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\USBSTOR.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\vds.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\VERIFIEREXT.SYS" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vhdmp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Vid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vhf.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vmbus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\VMBusHID.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volmgr.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volmgrx.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volsnap.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\volume.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vsmraid.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vwifibus.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\vwififlt.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wanarp.sys" is sparse (flags = 32768)
File "C:\Windows\System32\wbengine.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\Wdf01000.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\WdiWiFi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wfplwfs.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\winnat.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\winquic.sys" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\wmiacpi.sys" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\WmiApSrv.exe" is sparse (flags = 32768)
File "C:\Windows\System32\drivers\ws2ifsl.sys" is sparse (flags = 32768)
File "C:\Windows\System32\umpnpmgr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\AarSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rpcss.dll" is sparse (flags = 32768)
File "C:\Windows\System32\appinfo.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DISPBROKER.DESKTOP.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MICROSOFT.BLUETOOTH.USERSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\ASSIGNEDACCESSMANAGERSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\psmsrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\AUDIOENDPOINTBUILDER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\APPXDEPLOYMENTSERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\audiosrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wwansvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wlidsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wlansvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wcncsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wevtsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\AxInstSv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\RpcEpMap.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CDPUSERSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dssvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\bdesvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\BFE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\netman.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cdpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\cscsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\umpo.dll" is sparse (flags = 32768)
File "C:\Windows\System32\qmgr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CBDHSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ClipSVC.dll" is sparse (flags = 32768)
File "C:\Windows\System32\BTAGSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\profsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\pnrpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\CAPABILITYACCESSMANAGER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\TETHERINGSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\cryptsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DEFRAGSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DEVICEACCESS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DEVICESFLOWBROKER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\DEVQUERYBROKER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dhcpcore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DiagSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dot3svc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\dusmsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\DIAGTRACK.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MICROSOFT.GRAPHICS.DISPLAY.DISPLAYENHANCEMENTSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.INTERNAL.MANAGEMENT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\dnsrslvr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WERCPLSUPPORT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\eapsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\efssvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FntCache.dll" is sparse (flags = 32768)
File "C:\Windows\System32\es.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sdrsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\srvsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FRAMESERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\upnphost.dll" is sparse (flags = 32768)
File "C:\Windows\System32\gpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\smphost.dll" is sparse (flags = 32768)
File "C:\Windows\System32\hidserv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\HVHOSTSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\IKEEXT.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\INSTALLSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\iphlpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\keyiso.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wscsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WsmSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wersvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wcmsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wkssvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\lmhsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ipnathlp.dll" is sparse (flags = 32768)
File "C:\Windows\System32\lsm.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WORKFOLDERSSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\MPSSVC.dll" is sparse (flags = 32768)
File "C:\Windows\System32\iscsiexe.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nsisvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\nlasvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ngcsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\NcaSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\NCBSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\netlogon.dll" is sparse (flags = 32768)
File "C:\Windows\System32\NETPROFMSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\NETSETUPSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\NGCCTNRSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\pcasvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\p2psvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\IPSECSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\rasauto.dll" is sparse (flags = 32768)
File "C:\Windows\System32\rasmans.dll" is sparse (flags = 32768)
File "C:\Windows\System32\mprdim.dll" is sparse (flags = 32768)
File "C:\Windows\System32\RDXSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\RMapi.dll" is sparse (flags = 32768)
File "C:\Windows\System32\schedsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SessEnv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SHAREDREALITYSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\SMSROUTERSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\StorSvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sstpsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ssdpsrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wiaservc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\svsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\swprv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\sysmain.dll" is sparse (flags = 32768)
File "C:\Windows\System32\SYSTEMEVENTSBROKERSERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\termsrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\tapisrv.dll" is sparse (flags = 32768)
File "C:\Windows\System32\TIMEBROKERSERVER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\TOKENBROKER.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\TZAUTOUPDATE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\Unistore.dll" is sparse (flags = 32768)
File "C:\Windows\System32\usermgr.dll" is sparse (flags = 32768)
File "C:\Windows\System32\usosvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\w32time.dll" is sparse (flags = 32768)
File "C:\Windows\System32\WAASMEDICSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wiarpc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\wbem\WMIsvc.dll" is sparse (flags = 32768)
File "C:\Windows\System32\FLIGHTSETTINGS.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WINDOWS.MANAGEMENT.SERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WPCDESKTOPMONSVC.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WPDBUSENUM.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\WPNSERVICE.DLL" is sparse (flags = 32768)
File "C:\Windows\System32\wuaueng.dll" is sparse (flags = 32768)
File "C:\Windows\System32\ie4uinit.exe" is sparse (flags = 32768)
File "C:\Windows\System32\rundll32.exe" is sparse (flags = 32768)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished

Le envió los archivos

Saludos!!