Necesito eliminar un virus .paas que contamino todos mis archivos y desactivo mi Windows defender

REPORTE TDSKILLER 3

13:57:55.0688 0x1ce0  [ 82B656712713424A707F1E127C68E02F, 69FBB0692C37DA498014CC6CDC609E612A3207A17B280EDE5C02248571F91F11 ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
13:57:55.0703 0x1ce0  mvumis - ok
13:57:55.0766 0x1ce0  [ E86983528B16F54AFDD2883280791420, 350509D6AC369D1FFF1E6DBC901A1C94BA5EE970802D1844C4FFBA4472BE5103 ] NativeWifiP     C:\WINDOWS\system32\DRIVERS\nwifi.sys
13:57:55.0844 0x1ce0  NativeWifiP - ok
13:57:55.0891 0x1ce0  [ 1E641165EADCE9085810CCD4E1AAF443, 9C7EC8118B3550829215665F2C7D537E691BA6035432CC36834039D8D64D8A60 ] NaturalAuthentication C:\WINDOWS\System32\NaturalAuth.dll
13:57:55.0922 0x1ce0  NaturalAuthentication - ok
13:57:56.0000 0x1ce0  [ D47A20839608B8213065D7AFC8C42195, 7B0187BE9705ED2F925616C13B3744BAC0A9C96B21BE503D96BC9EE7EE125B33 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
13:57:56.0110 0x1ce0  NcaSvc - ok
13:57:56.0172 0x1ce0  [ ECD81E3CD27CCC5945A15377CE194E07, 51B060250DF29BA189307554A05E97A951007330CD015837A32B7A67D3C15C77 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
13:57:56.0219 0x1ce0  NcbService - ok
13:57:56.0266 0x1ce0  [ 8C938E851CDF2CE30BBEA14555B61820, F853F526C811893BD40B1124BAEC543099381E7BF091729B6A6665DF3CE10B94 ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
13:57:56.0328 0x1ce0  NcdAutoSetup - ok
13:57:56.0360 0x1ce0  [ D62777BD13AC73F8FB20039B701D5292, E3708D62DEA31BA03D7CE7EEF6A270DA2B3556559140B556F5AB4EA289F921E2 ] ndfltr          C:\WINDOWS\System32\drivers\ndfltr.sys
13:57:56.0375 0x1ce0  ndfltr - ok
13:57:56.0438 0x1ce0  [ D8DB3D35B9817928F7F0B188AE2BAC67, 6CD03349309B33029C35E1EB90665398EA5D8D9A2D62BBCCF6BCF879F5E02C08 ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
13:57:56.0532 0x1ce0  NDIS - ok
13:57:56.0563 0x1ce0  [ 6BEC0929C7A7BF2A7C44F585ECC7DAEB, 5F6395268CBD26A4B90960479040C114B2C8A3F24C188C2D5F62D6AB43A637D1 ] NdisCap         C:\WINDOWS\system32\drivers\ndiscap.sys
13:57:56.0610 0x1ce0  NdisCap - ok
13:57:56.0641 0x1ce0  [ FF4D48CB9B1FA642E9DE8C4EAF05C980, A8C470C3429D693678F16CE47BD104B8F1E8870600C54F81058951D4A0C8A125 ] NdisImPlatform  C:\WINDOWS\system32\drivers\NdisImPlatform.sys
13:57:56.0688 0x1ce0  NdisImPlatform - ok
13:57:56.0735 0x1ce0  [ 8F6BC1F9E7331F564367456649CD3C84, 58FDA9DC5748D4F102F6B9BC6EEED687244ED74B32D584119750BF964ECD807E ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
13:57:56.0782 0x1ce0  NdisTapi - ok
13:57:56.0860 0x1ce0  [ 09BD40437780ED584D06519373ACEDC7, 3D7685D3960382FB102E225634D54A2370DA53DEB89CAE4765AD00C9AFE030B7 ] Ndisuio         C:\WINDOWS\system32\drivers\ndisuio.sys
13:57:56.0891 0x1ce0  Ndisuio - ok
13:57:56.0922 0x1ce0  [ 31AE9050FF9D6CBE1BC2A7EA5F98D6A3, 2960AF22637EDA95DF6ED154278B23AC157AF2DE6F342DA7D8083E4F7F70730F ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
13:57:56.0953 0x1ce0  NdisVirtualBus - ok
13:57:56.0985 0x1ce0  [ E48770FA7691847311752AE892FCC6B4, 2666A2E880BCD839D9F0D51F21CFA12FDB13FE75061D47DE1974F0A67B6BF611 ] NdisWan         C:\WINDOWS\System32\drivers\ndiswan.sys
13:57:57.0032 0x1ce0  NdisWan - ok
13:57:57.0047 0x1ce0  [ E48770FA7691847311752AE892FCC6B4, 2666A2E880BCD839D9F0D51F21CFA12FDB13FE75061D47DE1974F0A67B6BF611 ] ndiswanlegacy   C:\WINDOWS\system32\DRIVERS\ndiswan.sys
13:57:57.0094 0x1ce0  ndiswanlegacy - ok
13:57:57.0407 0x1ce0  [ 33CDAEDC7CBE8339A8324CEC2461BFB4, DAAEACDB4506D2BDDED61957D92FB4983E11D9CE6E7B25119B4CBFB431C945F4 ] NDKPing         C:\WINDOWS\system32\drivers\NDKPing.sys
13:57:57.0438 0x1ce0  NDKPing - ok
13:57:57.0453 0x1ce0  [ EBB9D06E3C9F01FE299E9508D5B19BEB, 502AE6F59243354366ABE8DDB1F26BA79C5A08E56F9369525678CC072CF65486 ] ndproxy         C:\WINDOWS\system32\DRIVERS\NDProxy.sys
13:57:57.0500 0x1ce0  ndproxy - ok
13:57:57.0563 0x1ce0  [ 77621E74FD79B267071A0D12C643A48A, 8228B7D1237A0FFABCCC150B299EA494C8F0CB4CCB51AB0DBFF08CBAA9EFC4BB ] Ndu             C:\WINDOWS\system32\drivers\Ndu.sys
13:57:57.0594 0x1ce0  Ndu - ok
13:57:57.0625 0x1ce0  [ EA21A1CC5482642E9A8850E88DB24039, A7FEA3ADDF86904F83602638B05562197BCB7094AE289C4C5E4802020BBA1576 ] NetAdapterCx    C:\WINDOWS\system32\drivers\NetAdapterCx.sys
13:57:57.0657 0x1ce0  NetAdapterCx - ok
13:57:57.0703 0x1ce0  [ 4687FAC962855BDB1896C02334E95D54, E7F7F30D9513FDD2236FCFD5549DCD93101562BA1117213EA4DF32B70BB48A73 ] NetBIOS         C:\WINDOWS\system32\drivers\netbios.sys
13:57:57.0703 0x1ce0  NetBIOS - ok
13:57:57.0766 0x1ce0  [ 49F7DE6F689C47B64A2C2D46CD98E327, 679A89E9078D5865C52FCAE3A86D5AD252BF22B819901303F186D55EC976E1CD ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
13:57:57.0813 0x1ce0  NetBT - ok
13:57:57.0844 0x1ce0  [ 15A556DEF233F112D127025AB51AC2D3, 362AB9743FF5D0F95831306A780FC3E418990F535013C80212DD85CB88EF7427 ] Netlogon        C:\WINDOWS\system32\lsass.exe
13:57:57.0860 0x1ce0  Netlogon - ok
13:57:57.0907 0x1ce0  [ 62D46DA273CB543BB1671FE708A280CA, 4AB8B86B076320DE116F42DACC83DC95C635CB32392F3EBBE0FC64F22E7BF70A ] Netman          C:\WINDOWS\System32\netman.dll
13:57:57.0938 0x1ce0  Netman - ok
13:57:58.0000 0x1ce0  [ A510EE633987CE98E6389E5D8F3DF91D, CA78A64A86D8875DEB9C9E8E7CA8A6E36A7BDE222698F187BAEEEB5A023DE0DD ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
13:57:58.0110 0x1ce0  netprofm - ok
13:57:58.0203 0x1ce0  [ A3F8BF8193D36C4C8CEF20AFF28411E9, E6C6321820AFB4D3ABF2DAF894EFE0E8FC308F5DE6F9FE2FFE56F89A319C8C0E ] netr28x         C:\WINDOWS\System32\drivers\netr28x.sys
13:57:58.0375 0x1ce0  netr28x - ok
13:57:58.0422 0x1ce0  [ 4CEFFE7F3483FFC5D50CAB27818A7C3B, D45037ADD9AF6C488AC0A11356367EC684BF36E6A48625247B9BECCB4AF29C24 ] NetSetupSvc     C:\WINDOWS\System32\NetSetupSvc.dll
13:57:58.0485 0x1ce0  NetSetupSvc - ok
13:57:58.0610 0x1ce0  [ B9D455C60292DF5FCB064834CA5802AA, 75DCE4E5FA08CCEAF4D3D30FE8E26903FCDD14CC852E820F63B40F374C706DBD ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:57:58.0625 0x1ce0  NetTcpPortSharing - ok
13:57:58.0672 0x1ce0  [ 759A278622CC8EA153A4CDD11F1406F2, F0F911B8C8EB24F2A8FF68D9092A37076E840504EB594E01D5BD7C5457494BE5 ] netvsc          C:\WINDOWS\System32\drivers\netvsc.sys
13:57:58.0703 0x1ce0  netvsc - ok
13:57:58.0766 0x1ce0  [ 393E333035EBA76AA01B62DAFE29310A, 3AADF924FD9729B040D4063E2721E465EF385944F8BE60A3A9DCB0CAC2B7188C ] NgcCtnrSvc      C:\WINDOWS\System32\NgcCtnrSvc.dll
13:57:58.0828 0x1ce0  NgcCtnrSvc - ok
13:57:58.0860 0x1ce0  [ B52F2A6D1756DB934ACE03F61B418B15, C21BBD70CFA83F796949A6C43DFDCA77501C621044FDD1ADED5F59A9CACD1D58 ] NgcSvc          C:\WINDOWS\system32\ngcsvc.dll
13:57:58.0938 0x1ce0  NgcSvc - ok
13:57:59.0000 0x1ce0  [ 0B541C7B0B371CD20EA7984968816692, 6CF5910DBA069FF425D6AED94FE2CED5FA2B34F2AF806694E556D8D424497328 ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
13:57:59.0047 0x1ce0  NlaSvc - ok
13:57:59.0094 0x1ce0  [ 6E9CB02C4FB90AC76B11D01D5D5EB934, C3168A7240D56300CC8C4C72508A8249D36AAB630429A0B26D742192FB6F0D35 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
13:57:59.0110 0x1ce0  Npfs - ok
13:57:59.0125 0x1ce0  [ B2B57F620C085F2EA764BDF79AF7BE30, CA3657D9365D34FFECF6B5DE8E5905A2491756B1CC227D9AB8762B09111E9860 ] npsvctrig       C:\WINDOWS\System32\drivers\npsvctrig.sys
13:57:59.0156 0x1ce0  npsvctrig - ok
13:57:59.0203 0x1ce0  [ 0FA6DD9E38FF747C54FF5AE05F304327, 85449DBDBD24D72E0BAD82C81306F5AEC18F7CF23631BCFC09E8AEE4C7C646BE ] nsi             C:\WINDOWS\system32\nsisvc.dll
13:57:59.0250 0x1ce0  nsi - ok
13:57:59.0250 0x1ce0  [ 099D027B23831D009DEB40031795A915, 4E6E391847B90C796BC7B208614F66F48BD0A6CE253295DC24DFA47E9D214151 ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
13:57:59.0297 0x1ce0  nsiproxy - ok
13:57:59.0422 0x1ce0  [ 71D1E60F1CA832751584F2DA6B207702, 8DBE4D7931B869F587F13B6A92EBEF3CE1AFE6D4EFC9FF8DA845EA1745FC51CA ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
13:57:59.0547 0x1ce0  Ntfs - ok
13:57:59.0594 0x1ce0  [ 2CB7C3B739D8D34B9249F7DC6C8B5C1A, 318DD3D989EBED3F29A4C3F6FA819F060BE9C14C549B7DAD8ECA2B73C7932722 ] Null            C:\WINDOWS\system32\drivers\Null.sys
13:57:59.0625 0x1ce0  Null - ok
13:57:59.0656 0x1ce0  [ BEB8637D4B098B286B8B4F46E88A57AD, C0515F0F429A3B60AEC5F9F2AEDCF387CF941D306A21C9BCB56571C83560C6C1 ] nvdimm          C:\WINDOWS\system32\drivers\nvdimm.sys
13:57:59.0672 0x1ce0  nvdimm - ok
13:57:59.0688 0x1ce0  [ 5281A4F23E594AE6EDE1E38B1F8518E0, 628927EB91C6A323CA67B97EF743775B68D30599A0F0593BC3B5C0BA6C5AB82C ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
13:57:59.0703 0x1ce0  nvraid - ok
13:57:59.0735 0x1ce0  [ A11D15751217EEB734033BB5A929B1CD, F07CD88B7939C53DF83E93D40FB5AB115946393AFBE8DBA75FEE7247BF3063A9 ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
13:57:59.0766 0x1ce0  nvstor - ok
13:57:59.0828 0x1ce0  [ 8BBF06E5B2A4E5A1A74230003F6AAAA7, CE1B45DC50B6D82D85DAE5EEED4EA2A7D3E5AFAB24957437679CB366B6BE33C4 ] OneSyncSvc      C:\WINDOWS\System32\APHostService.dll
13:57:59.0906 0x1ce0  OneSyncSvc - ok
13:58:00.0125 0x1ce0  [ 2B8E4C792BED0E5882702720BC528AE5, 6D7CB027BC6014CB268C49B46049CDFF3BA94D07102A65BD053335A28E83D125 ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:58:00.0141 0x1ce0  ose - ok
13:58:00.0203 0x1ce0  [ F8CE0B4F1BC5E4FBDD66C1CAC4D58314, E7DC2FBA4CDBB0A35CC58E0FDF37D68891F18A80E449C0AA2C66C43A596EC4A9 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
13:58:00.0266 0x1ce0  p2pimsvc - ok
13:58:00.0313 0x1ce0  [ DA97CD5815EC123BC88382C08D465B9E, 46F5EA2E3D590FB10E14BC811612B6EF87C805B359A652D2C6BFE4840D5D6AA2 ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
13:58:00.0375 0x1ce0  p2psvc - ok
13:58:00.0531 0x1ce0  [ 138FDB1EBCB61287A645BD3B06DBED5E, 1E59DE429B54E910688BF917F2AD97E66241EE3FB924C24E3627E9603E8A9C5D ] Parport         C:\WINDOWS\System32\drivers\parport.sys
13:58:00.0656 0x1ce0  Parport - ok
13:58:01.0391 0x1ce0  [ F08C0D5949AEBE93D5915A029F236D59, EDF6F50C7B558BFC0B15B7BDFF625C6A7FBE7BE670E142B2B5C18410C1E70A1B ] partmgr         C:\WINDOWS\system32\drivers\partmgr.sys
13:58:02.0266 0x1ce0  partmgr - ok
13:58:02.0500 0x1ce0  [ 9D21BE4D5FAD82D07149CD8DAFD6B473, D12B04CB5BA852281002F9C6CB44A229000E0A0BEFEF92A11FE501EF0F9AFE28 ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
13:58:02.0531 0x1ce0  PcaSvc - ok
13:58:02.0578 0x1ce0  [ CDD225BEAF56BC5E22470CD0E49D7B00, 24A44B37F46DC55B6B6E81B40DD6C844BA90C565716BFB2E22B1B20ACBC9E09B ] pci             C:\WINDOWS\system32\drivers\pci.sys
13:58:02.0609 0x1ce0  pci - ok
13:58:02.0672 0x1ce0  [ BAD670FD9848C0CF6DE1F5186581AF7E, 29DC84F04B90635825E621C7D249824C9C6F46112AFEF59E24B489C18C66507D ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
13:58:02.0672 0x1ce0  pciide - ok
13:58:02.0703 0x1ce0  [ 0543F01C97CE2D3ABB4F8CEA56B99721, CD84890DEB63C782A51A7F4D962B88CAC9AA226C3C7DDC2D2B0A56E81B00B07C ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
13:58:02.0750 0x1ce0  pcmcia - ok
13:58:02.0781 0x1ce0  [ FE3E9C016B908745987C45D40A31F4ED, 94CF7ECBE1F62A1952FF8E3FF8799ADCAA1AA3211B18395875A75EFCEA786DBC ] pcw             C:\WINDOWS\system32\drivers\pcw.sys
13:58:02.0828 0x1ce0  pcw - ok
13:58:02.0875 0x1ce0  [ AF7BE3A2E5DA866E340CC82FD2EADC8D, E650E5566D18ECF606005362D6DA2B1C4781E4608124A6B2DEC28806DB5609C0 ] pdc             C:\WINDOWS\system32\drivers\pdc.sys
13:58:02.0891 0x1ce0  pdc - ok
13:58:03.0000 0x1ce0  [ A26AD59A080EDDF8AD13E3B9483FA74B, F929BBCD9DE10BF1FE3E3CCB837BE1395A9CAECD126562C7B61F42A6F7CDC456 ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
13:58:03.0266 0x1ce0  PEAUTH - ok
13:58:03.0406 0x1ce0  [ 5F62D68297E0B68621E9F66A21BD27CC, 220FEF9F33D4BEB0D3E797FA081BDAF16CEFE6C06140E95E61AE0A9AACAD8E2C ] PeerDistSvc     C:\WINDOWS\system32\peerdistsvc.dll
13:58:04.0000 0x1ce0  PeerDistSvc - ok
13:58:04.0078 0x1ce0  [ 217DD189B66B68149ED4F7E8C9BA1DD9, F4A1550BFEFBDC09DA82F53CE94EF3261C75DB1CC7C1EDD1074D31F828A47316 ] perceptionsimulation C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe
13:58:04.0156 0x1ce0  perceptionsimulation - ok
13:58:04.0188 0x1ce0  [ 2E2E8BA514A93C297F124BAB53F4E921, D6B8116E5C920032A5926D5D047BFD72B05ACBB08E26F177A0B0E6B4EC735FA1 ] percsas2i       C:\WINDOWS\system32\drivers\percsas2i.sys
13:58:04.0203 0x1ce0  percsas2i - ok
13:58:04.0250 0x1ce0  [ 1C6720616FF300235509D5EFBB2CAE20, 92017ECB36EAA35AC454E890734915A658EB898C95970531D43C19461BE6562B ] percsas3i       C:\WINDOWS\system32\drivers\percsas3i.sys
13:58:04.0266 0x1ce0  percsas3i - ok
13:58:04.0547 0x1ce0  [ 2FC7CFCEDBF7E038351C7CEB1036D2E1, 41D7DA706F0CF613DF768B6795CD09C5C1035F9F101051FB58F5042EB4352DB6 ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
13:58:04.0766 0x1ce0  PerfHost - ok
13:58:04.0844 0x1ce0  [ 1D3DD2C778ABFA5AC62B995ACE39CEFB, 8CC03BB83DAC8E988A3F9BE5D895F34708EF0B0AA579899C1E1504D125529B17 ] PhoneSvc        C:\WINDOWS\System32\PhoneService.dll
13:58:04.0906 0x1ce0  PhoneSvc - ok
13:58:04.0953 0x1ce0  [ D6784996CCCF3CE1FCFB692D74F639D3, EF9BD3DA0E2BF4BE221D8EBD846EFB511E3AAB5AE35BEBE5588E4BBBA8D50D02 ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll
13:58:04.0984 0x1ce0  PimIndexMaintenanceSvc - ok
13:58:05.0063 0x1ce0  [ E70542D4BBD65D4F117A2C1C4BFF13AB, E34AB76E01B834314C0B09A0F92F8D9AE066B326BFD8B28F6778BCC13E2AB197 ] PktMon          C:\WINDOWS\system32\drivers\PktMon.sys
13:58:05.0078 0x1ce0  PktMon - ok
13:58:05.0188 0x1ce0  [ 9E431A5D697432DD6F4DB48C9A185104, 44C16E194258C9143A45F4022F9C5DE229E217D6FF7F944F105FE631BE9EF4A7 ] pla             C:\WINDOWS\system32\pla.dll
13:58:05.0359 0x1ce0  pla - ok
13:58:05.0406 0x1ce0  [ 47997A891009AD881DFA69E018D3DF41, 954BBFB9E4C7FF79A811123D31954840590837ECDC9108161717EE29C8EFB676 ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
13:58:05.0422 0x1ce0  PlugPlay - ok
13:58:05.0563 0x1ce0  [ 8D8575D069381877BAED88D2FC98EC11, 0C0C05CD071BADD691C99CB08EF6CEEB1DF9B0F011F4499C22BBE4636E7521A3 ] pmem            C:\WINDOWS\system32\drivers\pmem.sys
13:58:05.0578 0x1ce0  pmem - ok
13:58:05.0609 0x1ce0  [ 2769F200292C0F941A10BD60C33EA4A6, B8345C32585C45E6248D7194B1071F2B8617718E7C9B270AAF44C132D029DB4C ] PNPMEM          C:\WINDOWS\System32\drivers\pnpmem.sys
13:58:05.0656 0x1ce0  PNPMEM - ok
13:58:05.0688 0x1ce0  [ 6AAAC8AD69AEFBE5FE04738B687EE85E, 83427082298E2FC021D5D39A43DB4A5783D95213F2CA8D3A997DB6C815BD9CB2 ] PNRPAutoReg     C:\WINDOWS\system32\pnrpauto.dll
13:58:05.0734 0x1ce0  PNRPAutoReg - ok
13:58:05.0766 0x1ce0  [ F8CE0B4F1BC5E4FBDD66C1CAC4D58314, E7DC2FBA4CDBB0A35CC58E0FDF37D68891F18A80E449C0AA2C66C43A596EC4A9 ] PNRPsvc         C:\WINDOWS\system32\pnrpsvc.dll
13:58:05.0781 0x1ce0  PNRPsvc - ok
13:58:05.0828 0x1ce0  [ B142CEA84B7894B529333184C282E0A7, 3A44DE9764FA279CA56BBD5850CAD9CECF38F96AA858A725E283AE094B4C1964 ] PolicyAgent     C:\WINDOWS\System32\ipsecsvc.dll
13:58:05.0875 0x1ce0  PolicyAgent - ok
13:58:05.0891 0x1ce0  [ 562B9409AA8777204E78C629647344EC, 65C33D25E0C00731D7DEF3F127523AA5178133481915287F3267A52C74577572 ] portcfg         C:\WINDOWS\System32\drivers\portcfg.sys
13:58:05.0938 0x1ce0  portcfg - ok
13:58:05.0984 0x1ce0  [ 195D084F3080A411B9B750B24AF5F851, 2C22881A810578A3AC1AD97130294F871EB7429804796D27215772091F1D3574 ] Power           C:\WINDOWS\system32\umpo.dll
13:58:06.0016 0x1ce0  Power - ok
13:58:06.0062 0x1ce0  [ CC6EDCFAF5A19B948C46F92791AC452F, 9124AF703B5032254AAA9F42A2CC9FE5B26C0048B4C21FF14382935797F4D245 ] PptpMiniport    C:\WINDOWS\System32\drivers\raspptp.sys
13:58:06.0078 0x1ce0  PptpMiniport - ok
13:58:06.0266 0x1ce0  [ CA1045F2E1AA05A55829F3F5611FE50E, F13D5144B67473C61AC5977AFAE39757D785C3F1F3A5F528EC3662C7160E2FF2 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
13:58:06.0453 0x1ce0  PrintNotify - ok
13:58:06.0484 0x1ce0  [ 415528FD79A105F4C16FD25526D0F6BB, B3DF926CD3FEC9B8C9AC1FDB57393824BAEE84DBFB2F9789BD7C63862C344217 ] PrintWorkflowUserSvc C:\WINDOWS\System32\PrintWorkflowService.dll
13:58:06.0547 0x1ce0  PrintWorkflowUserSvc - ok
13:58:06.0609 0x1ce0  [ 60D37A270C6787EE0A1B6C88DD221A55, CCA7B29F8C552E48FD6B4D45DDDB2A8428E82747FB2ED847F3A54F87B4325DC8 ] Processor       C:\WINDOWS\System32\drivers\processr.sys
13:58:06.0641 0x1ce0  Processor - ok
13:58:06.0687 0x1ce0  [ A16B1972D3B265F4D8B1DAD8F4C93A2C, 942A2FC63CB66BA72A4BA67E8E9DB21A5FAE7551FD5DFED15253B0A4C99C6BBF ] ProfSvc         C:\WINDOWS\system32\profsvc.dll
13:58:06.0750 0x1ce0  ProfSvc - ok
13:58:06.0781 0x1ce0  [ 4E750557E2310F3875CC8CEAB4CCA2CB, 7906E70262F7D47A22CC18361749106E5B377660EF17A0F2AEB44B019F825A95 ] Psched          C:\WINDOWS\system32\drivers\pacer.sys
13:58:06.0797 0x1ce0  Psched - ok
13:58:06.0844 0x1ce0  [ 035CB63DB5FDE94BC90AC4F477B491E3, AD97109BA3CB2F3C63A7F3131EB889752FF54867B1229B26B03F01DC8C769947 ] PushToInstall   C:\WINDOWS\system32\PushToInstall.dll
13:58:06.0891 0x1ce0  PushToInstall - ok
13:58:06.0937 0x1ce0  [ 2F3808790D517E5E5E6ABF7177875C02, BE1A79A6498697EB86FC29638324A853197B49BC06AE3EB1130793F710926998 ] QWAVE           C:\WINDOWS\system32\qwave.dll
13:58:06.0969 0x1ce0  QWAVE - ok
13:58:07.0000 0x1ce0  [ CE51A9A997D2830C6C64A36D7F8D8879, 706D683CAF92C259C121222446D34ED43F6E8872407C3615E2ED118ACD24D21D ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
13:58:07.0047 0x1ce0  QWAVEdrv - ok
13:58:07.0094 0x1ce0  [ 9D377A5872A0A7A33E258FFCBDB3F25F, D461798C6348C5D96EA002E4A1AC588B87A1A9B01AD84AB1FA6D9C6393616892 ] Ramdisk         C:\WINDOWS\system32\DRIVERS\ramdisk.sys
13:58:07.0109 0x1ce0  Ramdisk - ok
13:58:07.0141 0x1ce0  [ 9500BA0F8F8E48449810BA0E802DF2CA, 3A79A1C48768C72B49913647336BF75CAFC10DCB8C6C54E4D05FBDC88FDADBCA ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
13:58:07.0187 0x1ce0  RasAcd - ok
13:58:07.0234 0x1ce0  [ 121A6FDCFF9EBB6C40B5C98D882C0644, 725FD3D8D03FF6272568761BBC19D3E35736909521470BC1F8485D5172CA6497 ] RasAgileVpn     C:\WINDOWS\System32\drivers\AgileVpn.sys
13:58:07.0281 0x1ce0  RasAgileVpn - ok
13:58:07.0312 0x1ce0  [ AC0179CC701DEBE60FF3ABACF1EFE18E, B9970819DB91FDF78D655A9A8A03ED9EE020B1F722DC4AB9D003CA0B3287FCCD ] RasAuto         C:\WINDOWS\System32\rasauto.dll
13:58:07.0344 0x1ce0  RasAuto - ok
13:58:07.0359 0x1ce0  [ 40CBDB4B80284451536C8CA49561E5CD, 69F7181CB25E6E32E7B9C68BC76F21A5C7311ADAF6CD35B0B54EC4B7095B46CC ] Rasl2tp         C:\WINDOWS\System32\drivers\rasl2tp.sys
13:58:07.0391 0x1ce0  Rasl2tp - ok
13:58:07.0437 0x1ce0  [ 14776644698C6329CC0B215ED0F50132, 156DE77570BBD1E6FCDF7D871E2C93981D33970FACD4D924B9379E571C36A17B ] RasMan          C:\WINDOWS\System32\rasmans.dll
13:58:07.0516 0x1ce0  RasMan - ok
13:58:07.0562 0x1ce0  [ E250ADBB0C3E564BAF7CBBA4BAFE0A60, 83B6ABFC0C5700089EA967939564EF5FA2F5C40D2CA378D427CE59FFACD99D71 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
13:58:07.0594 0x1ce0  RasPppoe - ok
13:58:07.0609 0x1ce0  [ FCF941424AB1AB3EF57B0ABE6DBCDF77, 6EC56F7E87D4D6241DD0E94148E388816EF9613B482DBD1891E698B2E7F0F585 ] RasSstp         C:\WINDOWS\System32\drivers\rassstp.sys
13:58:07.0641 0x1ce0  RasSstp - ok
13:58:07.0687 0x1ce0  [ C82AD8E0F9B74C20F8097CA5797691E2, C8960C4CA0153815621894C01D0BC3ABE855666D4EE76CB375C5E4CAFCF5E54F ] rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
13:58:07.0719 0x1ce0  rdbss - ok
13:58:07.0797 0x1ce0  [ B7BAD23CA994EFF8EA11261626326004, 056495FB4A54984CE9D28D7B45550990D4A4B0736669F0F69138BEF51A695EFA ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
13:58:07.0844 0x1ce0  rdpbus - ok
13:58:07.0906 0x1ce0  [ 64991B36F0BD38026F7589572C98E3D6, 9580C67C2891C34A23970B705BC64AC19CCA16AE5A6F141F59FA6AFD89F7EC44 ] RDPDR           C:\WINDOWS\system32\drivers\rdpdr.sys
13:58:07.0937 0x1ce0  RDPDR - ok
13:58:07.0984 0x1ce0  [ C18A026DDE98695368EA87C85CC77EA1, E4675C277BE4C32E01BCDD7ABD7EA182C587F3CB15453D2362A55BC2755BCA47 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
13:58:08.0000 0x1ce0  RdpVideoMiniport - ok
13:58:08.0047 0x1ce0  [ B4A6F3BFB5A07DAF4E18C14A6337A226, F906865E349390D24A3DCBC563154BBB9F307B97361832BE93BC9D44A9F3B486 ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
13:58:08.0062 0x1ce0  rdyboost - ok
13:58:08.0172 0x1ce0  [ B9175CA73B72FADA0B591CE318EA8AD5, 821FFDA240E9C584E6028F5FBAE15F45CBD99C35A954E9541DCF13C3DBB1329A ] ReFS            C:\WINDOWS\system32\drivers\ReFS.sys
13:58:08.0266 0x1ce0  ReFS - ok
13:58:08.0328 0x1ce0  [ B193441867F5CF0F06798A4A2F15E17F, 8FD6A0A6442424630655EA07841B4601716D867D53B91E8BB7ECE51336642630 ] ReFSv1          C:\WINDOWS\system32\drivers\ReFSv1.sys
13:58:08.0391 0x1ce0  ReFSv1 - ok
13:58:08.0453 0x1ce0  [ 53186BEA68E790FBC0CD98AF571CC3CE, 05E45B1E73205F2A4CC62A602DB40FD25E40E5FC733CBBDEDFDB377226792C70 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
13:58:08.0531 0x1ce0  RemoteAccess - ok
13:58:08.0547 0x1ce0  [ 58B3C0A2B0C130838588EF519ADCE495, 60360DD8EA1802C8F95EB93531FF9666BE1148253E6A1BD706D4CA98955C0F6E ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
13:58:08.0594 0x1ce0  RemoteRegistry - ok
13:58:08.0641 0x1ce0  [ 3432CBF3D68E3DC486BAA84B3DA715B2, 12C6773C1ADBB53F55900F751D5717D754D57E51A2FBFE5D53436910A677DE51 ] RetailDemo      C:\WINDOWS\system32\RDXService.dll
13:58:08.0719 0x1ce0  RetailDemo - ok
13:58:08.0750 0x1ce0  [ D2EE9CCE0187C616E50D61EB30ECA262, 825C918D22FC8DBF3EE9BDB41D121A0AC3CCBFFBA147E2B26F0197552E0675DE ] RFCOMM          C:\WINDOWS\System32\drivers\rfcomm.sys
13:58:08.0797 0x1ce0  RFCOMM - ok
13:58:08.0844 0x1ce0  [ 4DD0EFE49F0C020DAFEAE6F5F231362C, DF04978AF6CD34C8251B3DDE381CD77518684DCB1D2B16BD2DAFEE63AC9D5858 ] rhproxy         C:\WINDOWS\System32\drivers\rhproxy.sys
13:58:08.0875 0x1ce0  rhproxy - ok
13:58:08.0937 0x1ce0  [ 2A10F8D56DB7BA8FD83FD7BAD2F9E94F, 0257C0CFBE9001DFC51D382977C77BB1B52984D01BE38E47C6B8A0018AF1CAB0 ] RmSvc           C:\WINDOWS\System32\RMapi.dll
13:58:08.0969 0x1ce0  RmSvc - ok
13:58:09.0000 0x1ce0  [ E54BB972A5D80219D640F4C8FEB5D05A, 3B39E86C0434EE91765BF818B8D1001AC0B44B86665EDE87E770302D4102574E ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
13:58:09.0016 0x1ce0  RpcEptMapper - ok
13:58:09.0062 0x1ce0  [ D45676C47616B9ABBFAEC97DD3B240A8, E13985D667F66B7A0082356F23270F61A57B8C2DD211B1E09D66D7970D7B4D6A ] RpcLocator      C:\WINDOWS\system32\locator.exe
13:58:09.0172 0x1ce0  RpcLocator - ok
13:58:09.0250 0x1ce0  [ F760407909EE4DC6A17C24CEF36CB6C4, 5362E0B998B49629193A2BEFD480DE6A0887909788E59E0950F22502487C9910 ] RpcSs           C:\WINDOWS\system32\rpcss.dll
13:58:09.0312 0x1ce0  RpcSs - ok
13:58:09.0359 0x1ce0  [ EABD30C39742A79913B595A5B6F809D4, 9067160F566220A2B21FEEE181729A796A3F3EECF75FFB75815BE5CCC7BBA64F ] rspndr          C:\WINDOWS\system32\drivers\rspndr.sys
13:58:09.0406 0x1ce0  rspndr - ok
13:58:09.0484 0x1ce0  [ 2352FF8612847D9C2C70ADAD70D86A52, F0D56499859ACC36DC852C9325BE641668EB6812FD0CD12AC32BEF48B68EFD36 ] rt640x64        C:\WINDOWS\System32\drivers\rt640x64.sys
13:58:09.0515 0x1ce0  rt640x64 - ok
13:58:09.0672 0x1ce0  [ 301FEB2D456DE694F5B505399520488B, BC3915336E7AA0A308D485C8437CBB747B3D1647BAE23133AFC5C7BDC79E32B2 ] RtlWlanu_OldIC  C:\WINDOWS\System32\drivers\rtwlanu_oldIC.sys
13:58:09.0875 0x1ce0  RtlWlanu_OldIC - ok
13:58:09.0922 0x1ce0  [ 5914CC0C1E99A3C1711BDB1E224526D1, 54BB8636F27282B396D487B3FEA8BD73F2F6FE6DA4DE8D718EE498F75A6A5DCE ] s3cap           C:\WINDOWS\System32\drivers\vms3cap.sys
13:58:09.0922 0x1ce0  s3cap - ok
13:58:09.0953 0x1ce0  [ 15A556DEF233F112D127025AB51AC2D3, 362AB9743FF5D0F95831306A780FC3E418990F535013C80212DD85CB88EF7427 ] SamSs           C:\WINDOWS\system32\lsass.exe
13:58:09.0969 0x1ce0  SamSs - ok
13:58:10.0015 0x1ce0  [ ADED2859AB6FBCF988C7BCAE8AF79D6D, 9AB3723BB52D09CEF647EB4A9598F2A8A9F82BF148507CADCC4713F343825D37 ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
13:58:10.0031 0x1ce0  sbp2port - ok
13:58:10.0078 0x1ce0  [ 51EB2F7EE69BC9ED017D60441F0D1CE5, 7D40987B55BE7BA484E33CF60B63197059A3B92BBE84B3BD28CD0C25F6B02F92 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
13:58:10.0109 0x1ce0  SCardSvr - ok
13:58:10.0156 0x1ce0  [ 238D26351D9394A1A4A1682CEC9BD868, 1C656503302139A11BAE19BBDBEAABF5B31F292BFA7D952E8B4693FB59018FAA ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
13:58:10.0203 0x1ce0  ScDeviceEnum - ok
13:58:10.0219 0x1ce0  [ EC9BDBAF319AB30D1BB25A478E169CEF, B4A2BFADDA5925DD02FBDBE9CD3F508840F8F241EA4C2E11FC35CDBC4C576F1A ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
13:58:10.0265 0x1ce0  scfilter - ok
13:58:10.0344 0x1ce0  [ 9EE018DC5258E2360A748527DDFF6548, 710665A5D3F487E8CA66B4981F7FAE8DCB53A102BC8470C781219D4872C2DF79 ] Schedule        C:\WINDOWS\system32\schedsvc.dll
13:58:10.0437 0x1ce0  Schedule - ok
13:58:10.0484 0x1ce0  [ 14DD371343EFEC95013A273DEBCFE96F, A321C20A1221AC1F6D7BDEF9FAF0C6AE138353EF5F859EBF1ECF55A97414FBA3 ] scmbus          C:\WINDOWS\system32\drivers\scmbus.sys
13:58:10.0500 0x1ce0  scmbus - ok
13:58:10.0515 0x1ce0  [ 90A4F493C691ABF5A0C231A62F309D88, 9319B5AA78248E53DA529567CBA4D57DD7D93A43218FD66C9EFE2A10C7430581 ] SCPolicySvc     C:\WINDOWS\System32\certprop.dll
13:58:10.0547 0x1ce0  SCPolicySvc - ok
13:58:10.0594 0x1ce0  [ A97C8FF1615960B453EF511BED5735ED, 65D81CB144754C3A5B472E7869C5C9504A560C0014527B007B51D77995AF359D ] sdbus           C:\WINDOWS\System32\drivers\sdbus.sys
13:58:10.0609 0x1ce0  sdbus - ok
13:58:10.0656 0x1ce0  [ 3200667DB433F0A2032FAF4DC02E2089, 5E940CA63AD21CEA08C334AC61D985BAFDBA7DCB2D388F355B5C72EFA3E23E0A ] SDFRd           C:\WINDOWS\System32\drivers\SDFRd.sys
13:58:10.0672 0x1ce0  SDFRd - ok
13:58:10.0719 0x1ce0  [ 7D630290A1CB82946484DEC5F8EFD295, 13C5BE584FE5F9F991338E9F1CC538B8C4F389E897E48DD7BA13DEC2CA56032A ] SDRSVC          C:\WINDOWS\System32\SDRSVC.dll
13:58:10.0734 0x1ce0  SDRSVC - ok
13:58:10.0781 0x1ce0  [ 4C9E13C15F3116E417527F32C860C538, 0B168C9D29CDE31F37B0540D4A06D0487C03D49D33B706C2CB20097B39E72B1D ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
13:58:10.0797 0x1ce0  sdstor - ok
13:58:10.0844 0x1ce0  [ 016706A76857F914C99D2472B1E79BF9, 39A114EB591E243E0429DA7279413F046626DE7B52E057DDBCD26A0A1BF327FB ] seclogon        C:\WINDOWS\system32\seclogon.dll
13:58:10.0890 0x1ce0  seclogon - ok
13:58:10.0922 0x1ce0  [ 323BAD3E91131A26987CF9DED320EE52, 3395D4290EF4EF9F09A5DA974E74A6B7292C85E30055A9231D58C873FB74133F ] semav6msr64     C:\Windows\system32\drivers\semav6msr64.sys
13:58:10.0937 0x1ce0  semav6msr64 - ok
13:58:11.0000 0x1ce0  [ E580AAE89E9AD4190DEF77BD9F7180F9, 0FAAA993D43EE8F397A8B05B38F4C5D20F310F66FD6DB9AE335B3DB294D4BFD4 ] SEMgrSvc        C:\WINDOWS\system32\SEMgrSvc.dll
13:58:11.0094 0x1ce0  SEMgrSvc - ok
13:58:11.0140 0x1ce0  [ 1EA7972A4C7163FF1D3EFE9988404D4E, 56A94B1617815C1E8A79D832B0F0CBA683C3080105CC4C87DBB9B8EAB4CD2690 ] SENS            C:\WINDOWS\System32\sens.dll
13:58:11.0219 0x1ce0  SENS - ok
13:58:11.0328 0x1ce0  [ 5A3B2A346DD3822803FAE613842839BE, C3DE970DAA10864AD81F1D9B264C2043F7C7C77288E4F7CC38A56E0C724CCFFC ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
13:58:11.0422 0x1ce0  SensorDataService - ok
13:58:11.0500 0x1ce0  [ 207FA2E4C1C74D930C61F01E3DD8EAD6, FD98FF3DF2A33E4893D0E8E8E48F88DEC42443B9CDA289EA755D53471988488A ] SensorService   C:\WINDOWS\system32\SensorService.dll
13:58:11.0562 0x1ce0  SensorService - ok
13:58:11.0594 0x1ce0  [ 0BCFFAD6F3B180DD60C941B01768F733, A0B73C1BF636F14504B69606999287B6FE148C958A4F6E31E9022FF129A048E0 ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
13:58:11.0656 0x1ce0  SensrSvc - ok
13:58:11.0687 0x1ce0  [ 22068CA363EAF69A8EF6EBBBD580A8E8, 45F87C7D04B8F20290BBA8517BACE138D1E2112A268CCFFC2DFC407A81C0A197 ] SerCx           C:\WINDOWS\system32\drivers\SerCx.sys
13:58:11.0703 0x1ce0  SerCx - ok
13:58:11.0719 0x1ce0  [ A5E6D99D319610030C3CA982DCAA3624, 8F1BCEDC5FEA5AF0260B573EE171E1D895EBAB5A51BEA1F84D3043F6612050A9 ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
13:58:11.0734 0x1ce0  SerCx2 - ok
13:58:11.0765 0x1ce0  [ 7A289A4FFAA43D81F091A302512059A6, 9A4EC5EAF65ECB6518C462E837EB76286F1BA7A8C9E26DC46586DC4F189BD1B7 ] Serenum         C:\WINDOWS\System32\drivers\serenum.sys
13:58:11.0797 0x1ce0  Serenum - ok
13:58:11.0812 0x1ce0  [ DCE5D050F3B06D30985EE126257DEEB6, 024C1F9FBEFDCBC174733A5C97B121A6D7AD30E836C1820054BCB45F99FB4373 ] Serial          C:\WINDOWS\System32\drivers\serial.sys
13:58:11.0844 0x1ce0  Serial - ok
13:58:11.0859 0x1ce0  [ B13F5A8574F0B71B2E4C84B171C28724, C812F61726BDFEFFE468DFA3491E5F465D22835C54E3559E04B452940C0EEEEE ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
13:58:11.0890 0x1ce0  sermouse - ok
13:58:11.0953 0x1ce0  [ 2A22DD7A1CDA78F3725D203F49C465EE, FEAB610F6B5E644D961B43C225A04F635F429F3BC8375BC704797F80FFF05076 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
13:58:11.0984 0x1ce0  SessionEnv - ok
13:58:12.0015 0x1ce0  [ AD1B790A42984A825068B849A88AD322, 63881202D6D900656F50A0E40CB743D0769C2AD9810FE96387E9DAF2BC89E4C5 ] sfloppy         C:\WINDOWS\System32\drivers\sfloppy.sys
13:58:12.0047 0x1ce0  sfloppy - ok
13:58:12.0094 0x1ce0  [ C05648C2BE6176BE557D9C7F02916388, C65D8FEDDCD9A52B04F42C64DAD2A499BF51246D36042E8DC09DD04C4C0B7BEE ] SgrmAgent       C:\WINDOWS\system32\drivers\SgrmAgent.sys
13:58:12.0109 0x1ce0  SgrmAgent - ok
13:58:12.0156 0x1ce0  [ 3BA1A18A0DC30A0545E7765CB97D8E63, F9CBF1FF87D6F11920C4B7367EA2178BF13AA276C65D918950683983F268BC1F ] SgrmBroker      C:\WINDOWS\system32\SgrmBroker.exe
13:58:12.0172 0x1ce0  SgrmBroker - ok
13:58:12.0219 0x1ce0  [ 12C9DC58F761E72F9C889B213698AB67, 8BC382EC4102A118006E8CC67763198852BEB1DEE40184FDB384744D782C62A4 ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
13:58:12.0281 0x1ce0  SharedAccess - ok
13:58:12.0344 0x1ce0  [ 5A908C65D3CFF0236DF9B9D49514283B, 8E8EB9441DCB707810D64B6D30D1CADE1268A209C14D7F1353176F974CCF3235 ] SharedRealitySvc C:\WINDOWS\System32\SharedRealitySvc.dll
13:58:12.0390 0x1ce0  SharedRealitySvc - ok
13:58:12.0453 0x1ce0  [ BE44F2B19C4F61FED874C7FE26DF92AA, 07888C7575A1D7D46AE375B1CE6C13665CCEE0F0672EA8FDE71B955B5BC0EA70 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
13:58:12.0500 0x1ce0  ShellHWDetection - ok
13:58:12.0625 0x1ce0  [ 7D89ED048BCC01FD5F24B955B1DA9C9F, 248FBD4111ECB115D68282FC32AB4A3CD3DAF5A37B37B19387E277D627E9E557 ] ShMonitor       C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe
13:58:12.0656 0x1ce0  ShMonitor - ok
13:58:12.0703 0x1ce0  [ 2EA0380DAB8422E9648FD22AC88C281A, EB0EBAFDE3CBE9DB4BCF8735138BF36E55E9CFE2B7C11C2772776CCB18D9C86C ] shpamsvc        C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
13:58:12.0734 0x1ce0  shpamsvc - ok
13:58:12.0750 0x1ce0  [ 9AB1BADC5A324DA39186B81BC6CE6E2E, 567710C90BD71600A31A3408DB065B43C844DCFD12045FDE04CD59D932DC8353 ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
13:58:12.0765 0x1ce0  SiSRaid2 - ok
13:58:12.0937 0x1ce0  [ 60213AF297023C005453E1CBF7CB6FE7, 718C833E5EDFE642F3B254515E29641BF2D8E56E22F6B795024BF64721AB874E ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
13:58:12.0953 0x1ce0  SiSRaid4 - ok
13:58:12.0984 0x1ce0  [ 196A46BA842A219EC6DE7B7B7D9AAB7E, 4EF7BE37F92557C8B0D30999541F284CC4A3E8FD98E0D78146F9F00D54E11BB9 ] SmartSAMD       C:\WINDOWS\system32\drivers\SmartSAMD.sys
13:58:13.0000 0x1ce0  SmartSAMD - ok
13:58:13.0047 0x1ce0  [ FF75E3F42E77904238AED44E4E03BAEF, 535013A9E3324198E1016963EBF306F3D34583F7031EE753EC6095B15E2D492C ] smbdirect       C:\WINDOWS\system32\DRIVERS\smbdirect.sys
13:58:13.0109 0x1ce0  smbdirect - ok
13:58:13.0172 0x1ce0  [ CFD5A1637EAA3262742D1993156799DA, 505355174B613DE52D233F8BB1322CDCE1A251084D5DFCC819327485AE6247BB ] smphost         C:\WINDOWS\System32\smphost.dll
13:58:13.0172 0x1ce0  smphost - ok
13:58:13.0234 0x1ce0  [ B93199C67FD01A22DD402F457D00372C, 7F21D9C372946C08223DE716915FC0E6D2D08E5A503B218565D5360BFDCCD78E ] SmsRouter       C:\WINDOWS\system32\SmsRouterSvc.dll
13:58:13.0343 0x1ce0  SmsRouter - ok
13:58:13.0390 0x1ce0  [ 1971BBC71602B928CF9257759E3C05E8, 9D665698FF26ED333AD385B4B7A6C0F2B6806371D278E281FA4188002A5317E8 ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
13:58:13.0422 0x1ce0  SNMPTRAP - ok
13:58:13.0453 0x1ce0  [ 27B7D9E872939EBB34C30343F991893D, 879AFDC8C50487ED0D3CB58C70A206E185F94BE75C25C31C387F3F08740771F9 ] spaceparser     C:\WINDOWS\system32\drivers\spaceparser.sys
13:58:13.0484 0x1ce0  spaceparser - ok
13:58:13.0531 0x1ce0  [ 2C7EA4A2A4EA5E0DA7E319B67216916E, 56E61EEF45C7534A5168BE0745B1BD30488C727AF4AEBACFCBB912314D7EFF74 ] spaceport       C:\WINDOWS\system32\drivers\spaceport.sys
13:58:13.0562 0x1ce0  spaceport - ok
13:58:13.0609 0x1ce0  [ AB3BDEC793187CEDF1229AC98BB7DEDF, D2EA0C5FC534C89310207AA26A8816B30FEEF3F2708A067D8BB93D3CFF9C3936 ] SpatialGraphFilter C:\WINDOWS\system32\drivers\SpatialGraphFilter.sys
13:58:13.0625 0x1ce0  SpatialGraphFilter - ok
13:58:13.0656 0x1ce0  [ B6029A86D8DE5AE85E01506E0222A491, E8A7BB7D299B457EF9E3E32893E5DCF3DEE1704B9E02A0583439941CA6E1C9AD ] SpbCx           C:\WINDOWS\system32\drivers\SpbCx.sys
13:58:13.0672 0x1ce0  SpbCx - ok
13:58:13.0718 0x1ce0  [ 59AD6E59DE9E738C7B7C10C117209369, 327C97EBD48C86081164971661F943D389BFBA3CA52DEE84BEEF1B29491998CE ] spectrum        C:\WINDOWS\system32\spectrum.exe
13:58:13.0812 0x1ce0  spectrum - ok
13:58:13.0875 0x1ce0  [ 160B4438741AD44DB5E80FB119553860, 769B89B3B25EAB310D539FE97C12292DD60FDF0AED3CD75F2C100DC73DBF173B ] Spooler         C:\WINDOWS\System32\spoolsv.exe
13:58:13.0953 0x1ce0  Spooler - ok
13:58:14.0109 0x1ce0  [ 336E10FE532EB2DD8ADE24C6347D2BF8, CC584E1DE3229E4F45D9CC37B007ACF04F1FA43B99AFCC0F2A946FF1D92450FC ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
13:58:14.0312 0x1ce0  sppsvc - ok
13:58:14.0390 0x1ce0  [ F27E32CF8419B68A21F4A786AFB01BA2, EC1137DE2D89BD9C9B2481A390FC89301A4A7E7C963B888A241148C098E7DD32 ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
13:58:14.0468 0x1ce0  srv2 - ok
13:58:14.0531 0x1ce0  [ 8D2B538242293A4D780A0FB9C9284285, 7BF32FC6AAE0FD7AFBC7596500C288BA8A42443920BD34592B08ECD2ACC2CFDD ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
13:58:14.0578 0x1ce0  srvnet - ok
13:58:14.0656 0x1ce0  [ 3CC31E5EAA65FEC6591A32A202437E7C, 2F00674E4ADDC2E2F001F4008E0D382AD3E4A5AC842136A9632CBEFE3073F998 ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
13:58:14.0718 0x1ce0  SSDPSRV - ok
13:58:14.0797 0x1ce0  [ 66969AA56E77953E596470C73A9004E0, 71F4CC7595C6D5E93AAA14259DF817C6C1D4BBCF285545FD980F6DBC86A30379 ] ssh-agent       C:\WINDOWS\System32\OpenSSH\ssh-agent.exe
13:58:14.0890 0x1ce0  ssh-agent - ok
13:58:14.0937 0x1ce0  [ 2775EF3E0E76D9A44AB60D6143FA92A5, EDAE87919A509204967AFD9500021DCAE4EE9DC2D89DEF7960D5DDB1A594C9D3 ] SstpSvc         C:\WINDOWS\system32\sstpsvc.dll
13:58:14.0968 0x1ce0  SstpSvc - ok
13:58:15.0172 0x1ce0  [ 23001D13F66F284991D77BC1EA8277FF, 777BAEE42BFF1C1EAC599C227D4940C3047071A36B3B5043854D0F88C25AF6C1 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
13:58:15.0437 0x1ce0  StateRepository - ok
13:58:15.0468 0x1ce0  [ 09DC471B4573F3D01D7E448B526AE70A, 766FD1E1D2F73DE202FB337F6A6A5BA0317772AAAA644E9103BB5DF438162F51 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
13:58:15.0468 0x1ce0  stexstor - ok
13:58:15.0547 0x1ce0  [ 27CCDFB300302826F5CCFF0678F20D80, 84816CB7033FDEDA560E03995C254577E5BB23E15C7C03FB68074C2E60F31B66 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
13:58:15.0656 0x1ce0  stisvc - ok
13:58:15.0703 0x1ce0  [ 3BF9A305AE7104D0B6AEAAFF408F99D4, D66DBF1DB502F92AD657A31F4553C01263803DA3362180B483C8D099F723F3E5 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
13:58:15.0718 0x1ce0  storahci - ok
13:58:15.0765 0x1ce0  [ 5A129E186A7A4E3CCBF090682D48F8EB, EEF4D748F421A65B0CEECC3F499574FD1B4B2E654428C0693D76074A2BC257B7 ] storflt         C:\WINDOWS\system32\drivers\vmstorfl.sys
13:58:15.0765 0x1ce0  storflt - ok
13:58:15.0797 0x1ce0  [ 1DEF1E3DC73EDD14F3AA039FB88CE97B, 895E525F3D40604EF16274475857512517DEC93BDBA41A91F1D18191ECE849EE ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
13:58:15.0812 0x1ce0  stornvme - ok
13:58:15.0828 0x1ce0  [ 995F082126674C6D1423E29FBCEA9F39, E86386156F982B59C00991D40A6E1862CA322F151BF965B14572D13AA207D614 ] storqosflt      C:\WINDOWS\system32\drivers\storqosflt.sys
13:58:15.0843 0x1ce0  storqosflt - ok
13:58:15.0906 0x1ce0  [ 50D0680C66E639090AAF9F82FA397E6A, 7699B128B863A1CB6EB83340BC6B67DDB629271507E350DC381F8C6A80F72DB3 ] StorSvc         C:\WINDOWS\system32\storsvc.dll
13:58:16.0140 0x1ce0  StorSvc - ok
13:58:16.0187 0x1ce0  [ F41E76C56C00D645B85210478EF342E8, A044A778EFD19C87355F2B04B5A4C121080CC70F54EBFE04355A3283CE282850 ] storufs         C:\WINDOWS\system32\drivers\storufs.sys
13:58:16.0203 0x1ce0  storufs - ok
13:58:16.0234 0x1ce0  [ 0A13C67C267BFA1A0D1FE72A9D65BD5F, B44327F3134FA0166ED9E31BC724120B642AE5E96CEFF599867F03463ABB1406 ] storvsc         C:\WINDOWS\system32\drivers\storvsc.sys
13:58:16.0250 0x1ce0  storvsc - ok
13:58:16.0312 0x1ce0  [ D73F83E795F3BC100C21EDA2BD6DE307, 0DC828C46E057ADA9934424BF00067B17EEB8E0108CE1E309C8DEA4CC42448BA ] svsvc           C:\WINDOWS\system32\svsvc.dll
13:58:16.0359 0x1ce0  svsvc - ok
13:58:16.0547 0x1ce0  [ 0547BB19EFA07BEF0F679A054EB5CFEC, D618F57B78B3FFEC29E8C4472E0AA72EF1CA0C83DE968373B818ABA4D9747E2D ] swenum          C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys
13:58:16.0547 0x1ce0  swenum - ok
13:58:16.0625 0x1ce0  [ 126DFCA3C36BCA7BBB359CDC92C5C271, 9DFAEB2E3951A93236EE6BAF5328D46FB062D31A1077305A8A5B16039FA620AA ] swprv           C:\WINDOWS\System32\swprv.dll
13:58:17.0140 0x1ce0  swprv - ok
13:58:17.0296 0x1ce0  [ B39DC667DF14C7F1B9A58DE17BD45BE3, 52A4DBA20C16B2E34FBDDDE966700A3E8E183011A44ABECADCD4D3F93D29637B ] Synth3dVsc      C:\WINDOWS\System32\drivers\Synth3dVsc.sys
13:58:17.0359 0x1ce0  Synth3dVsc - ok
13:58:17.0437 0x1ce0  [ D898D409D20F00AE8F29E6076BE16CFC, CC59F0C50BD877C7972403692B9CD4708FA65158341AB44E1167EE7C98502016 ] SysMain         C:\WINDOWS\system32\sysmain.dll
13:58:17.0609 0x1ce0  SysMain - ok
13:58:17.0671 0x1ce0  [ A44A39FB49D1820AAB221A2EF5DC8BBB, F7D2CFF58621200AF6318FB4BAC53A5E595F7A76CB2FAB0272414AFA2702512E ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
13:58:17.0703 0x1ce0  SystemEventsBroker - ok
13:58:17.0812 0x1ce0  [ 29D4473036FB5939AD39AECABE697E80, 65287FE8B66CFF1F9C8CE97B7B43994C221540F3380DBA494067EF3909E089BC ] SystemUsageReportSvc_QUEENCREEK C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
13:58:17.0828 0x1ce0  SystemUsageReportSvc_QUEENCREEK - ok
13:58:17.0875 0x1ce0  [ 055070E3AC1F342125E3296641BDC4D3, 6385EE02D392FCFFB41CE5C5D4CD03C245828D98DCB01F0B4358B431257F9F5B ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
13:58:17.0937 0x1ce0  TabletInputService - ok
13:58:17.0984 0x1ce0  [ 20CEAECE4ECDEBC89C82F1998696D596, 439559DE34BE096824CB70A97524E843CE2802092A9C882167F4CB08FE9664A7 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
13:58:18.0078 0x1ce0  TapiSrv - ok
13:58:18.0203 0x1ce0  [ A618696DAFA91CA742FE4A3D02A5D236, 9FDE7269732EDF2941CDFF0348DB8827D3382FCA234543EABFCB9D27CD63E16E ] Tcpip           C:\WINDOWS\system32\drivers\tcpip.sys
13:58:18.0359 0x1ce0  Tcpip - ok
13:58:18.0437 0x1ce0  [ A618696DAFA91CA742FE4A3D02A5D236, 9FDE7269732EDF2941CDFF0348DB8827D3382FCA234543EABFCB9D27CD63E16E ] Tcpip6          C:\WINDOWS\system32\drivers\tcpip.sys
13:58:18.0546 0x1ce0  Tcpip6 - ok
13:58:18.0593 0x1ce0  [ 57BE670CF1D93717B628271B404D658A, EDD4C58EDAB985C87D6101D9CA5620146EE2BB8A1B899C635DD4CD36541DD46E ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
13:58:18.0640 0x1ce0  tcpipreg - ok
13:58:18.0703 0x1ce0  [ 9C4C6E0C590F789CECB7A6D437E5A284, 6516ED3DF480BA6071C8D97EFC0A7E2C78182BC7546B7DBEFCD010E9F3CC9500 ] tdx             C:\WINDOWS\system32\DRIVERS\tdx.sys
13:58:18.0718 0x1ce0  tdx - ok
13:58:18.0765 0x1ce0  [ 2213610676B404B157ADFFE312567458, B2E02C5049357A2DFF1CF4F6F64AC6E1DCCEDC245E96D5BC0585E88E7622D1B9 ] Telemetry       C:\WINDOWS\system32\drivers\IntelTA.sys
13:58:18.0765 0x1ce0  Telemetry - ok
13:58:18.0812 0x1ce0  [ C225B94F2B27AC97C3E66C0550AEA249, 6F88375DD12A648B77BB6EB4BE527FF6678EE76A2059DB5B4CC971CDB31D0DB8 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
13:58:18.0812 0x1ce0  terminpt - ok
13:58:18.0890 0x1ce0  [ 9282BC920354A4C9F25C2327076E9358, 73FD15F88B20AEAA09C8174C284C9D7563A33E960318128E249AA72B04604E25 ] TermService     C:\WINDOWS\System32\termsrv.dll
13:58:19.0000 0x1ce0  TermService - ok
13:58:19.0046 0x1ce0  [ 8EC4197962A0349DFFBDC11586099DB8, 8DD5348A4983C376F63E6B209227D4D02300555F8C80A0E0DB2EA16074ABC334 ] Themes          C:\WINDOWS\system32\themeservice.dll
13:58:19.0078 0x1ce0  Themes - ok

REPORTE TDSKILLER 4

13:58:19.0140 0x1ce0  [ 761EBB96C8217CF5795ACF429BDF9E88, 4CCDB591EE16507879D8F12C0BDD40FACBEEF03BFC553A84270284D4930B433F ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
13:58:19.0171 0x1ce0  TieringEngineService - ok
13:58:19.0203 0x1ce0  [ 6B761253F07F46BE2B16C768B1F22551, C4E63135EB9BAAB1B7DE928C914CACEAB1E4862D6C5913B23EFC5B8986B1D91E ] TimeBrokerSvc   C:\WINDOWS\System32\TimeBrokerServer.dll
13:58:19.0265 0x1ce0  TimeBrokerSvc - ok
13:58:19.0343 0x1ce0  [ 6513884E6FC2B85F601B49C8CF03B7C7, 9D85FD0F20F509E0059E00913267A6846B960A84D118F4389809E1BA01FCEFCD ] TokenBroker     C:\WINDOWS\System32\TokenBroker.dll
13:58:19.0484 0x1ce0  TokenBroker - ok
13:58:19.0531 0x1ce0  [ 8D0C4B0F6D48CF4750403971D7BF494D, 62ECE387CEAAD6296A35632AFC96E8A4E7018BD0A1037CD4AF8951F833AC38DA ] TPM             C:\WINDOWS\System32\drivers\tpm.sys
13:58:19.0546 0x1ce0  TPM - ok
13:58:19.0593 0x1ce0  [ 62636F77E0C51D59F043D9197C897AD4, F121E79E0A15ED6E362D7DEF72F9C1D2D5CC50BBEC3541DFAB91691BC3AFB191 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
13:58:19.0609 0x1ce0  TrkWks - ok
13:58:19.0656 0x1ce0  [ C87B6854C4D0DB8FB3BA538D5FBFFCF0, 74EC1CAF70EEE9A371695094E3E0B7EC088BB2FE5DC5AF348D1CF63E9F34D52E ] TroubleshootingSvc C:\WINDOWS\system32\MitigationClient.dll
13:58:19.0687 0x1ce0  TroubleshootingSvc - ok
13:58:19.0781 0x1ce0  [ 00C358B55509EAAE79292D8E61FC317E, 3759AB1B549F440D6769F9BDDF38A5562B0AB938B93A1CD172BEFAF133963EDE ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
13:58:19.0796 0x1ce0  TrustedInstaller - ok
13:58:19.0843 0x1ce0  [ F613A8618CC19DD96D1E0C81C5DCB7D1, AD6DE675AC033BE6BF75FF6303EAED4B5C672689D3AEC6DB94816D60E19B7030 ] TsUsbFlt        C:\WINDOWS\system32\drivers\tsusbflt.sys
13:58:19.0874 0x1ce0  TsUsbFlt - ok
13:58:19.0921 0x1ce0  [ BF1D6924E7949102DA6F14F7EFE8D2D5, EA6AE80568B8FEB5EAE213EC8222AD72FFD99D80321D7F2A52C1B42A88F583AD ] TsUsbGD         C:\WINDOWS\System32\drivers\TsUsbGD.sys
13:58:19.0937 0x1ce0  TsUsbGD - ok
13:58:19.0984 0x1ce0  [ 5600A496F7E579E64E5C63E566EDD71C, 9292DAE4FAEABFB97B0E78F846A154782CF6B14629D8A8D4691FE50B4DCFB481 ] tsusbhub        C:\WINDOWS\System32\drivers\tsusbhub.sys
13:58:20.0046 0x1ce0  tsusbhub - ok
13:58:20.0093 0x1ce0  [ 6244FD1056BF170E38245B4B9042BFDF, C32908B3C5800CD52EF9BDD26C77B8162831CFD19DBF1D399941B17FB909AD94 ] tunnel          C:\WINDOWS\system32\drivers\tunnel.sys
13:58:20.0124 0x1ce0  tunnel - ok
13:58:20.0156 0x1ce0  [ A7C58987094E1EEBD63FB94BBE5FBC2C, 1E2E68E68380CFE42C2D975E826F6301AA7F35566E9A733B881BDC6271EC1981 ] tzautoupdate    C:\WINDOWS\system32\tzautoupdate.dll
13:58:20.0187 0x1ce0  tzautoupdate - ok
13:58:20.0234 0x1ce0  [ BD806DA5C342A0074B8A1DAFB6216973, 0EEC7DBD83061DB34EA3FA48D334BB734FB2EA3D00F38548B38C3544A693B690 ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
13:58:20.0234 0x1ce0  UASPStor - ok
13:58:20.0281 0x1ce0  [ BF087CF6398F25E940882E094EB71ADB, C516019E7B9FE09B4307269DD8F266B5600D735C229FFD8317FB4CD63CEEC741 ] UcmCx0101       C:\WINDOWS\system32\Drivers\UcmCx.sys
13:58:20.0328 0x1ce0  UcmCx0101 - ok
13:58:20.0359 0x1ce0  [ 229B33B8499F4F2AAB1F3B590423611F, E70A2D9EEEF0C6894A0DB7990CFF6ECE3B8F389FD30B7B1949FCBDD3300B6148 ] UcmTcpciCx0101  C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
13:58:20.0390 0x1ce0  UcmTcpciCx0101 - ok
13:58:20.0437 0x1ce0  [ 7FDC3A6FD8547468CE554C8821640103, 3626760AEE42EE36E047DA6899A81E0646DFBA344A234270EAE5D635F049BE37 ] UcmUcsiAcpiClient C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys
13:58:20.0468 0x1ce0  UcmUcsiAcpiClient - ok
13:58:20.0500 0x1ce0  [ 1ADE4D1F65B4A1E52F701C69FB455769, 3E5CDCC098149853A7EFA05EA1B714182C82E4153F2DA3C50BA30DF2B3E05EB6 ] UcmUcsiCx0101   C:\WINDOWS\system32\Drivers\UcmUcsiCx.sys
13:58:20.0546 0x1ce0  UcmUcsiCx0101 - ok
13:58:20.0578 0x1ce0  [ D6BEDCCB2E48589944EDC675D335677E, 2F5A5BA7AEC40C1A440C8DFF81DCE5AB0BDF9CC70ADDE48F8B652665B61F9915 ] Ucx01000        C:\WINDOWS\system32\drivers\ucx01000.sys
13:58:20.0593 0x1ce0  Ucx01000 - ok
13:58:20.0624 0x1ce0  [ 6861422B7FFADDEAAA64A0539C910178, 4F8193C0A3525B78CA3CAF4731AE997A214F3DF180F0A3ADCEB2D31D3217850C ] UdeCx           C:\WINDOWS\system32\drivers\udecx.sys
13:58:20.0671 0x1ce0  UdeCx - ok
13:58:20.0687 0x1ce0  [ 26D2727935221EFB0063B43A74B375BE, AB809F7EDC5C8A6EEE9610477A79131EA6C3D1BDD3D837B56B6AFF3572923DB7 ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
13:58:20.0734 0x1ce0  udfs - ok
13:58:20.0812 0x1ce0  [ EFBDDA16F267167505DB05E69AECF701, 60226D4829AF8F3077BBA69264F076BA94C1E977B6ECE691D83A0C6918FE3571 ] UdkUserSvc      C:\WINDOWS\System32\windowsudk.shellcommon.dll
13:58:20.0953 0x1ce0  UdkUserSvc - ok
13:58:21.0031 0x1ce0  [ 264C183C222EF95D4C64DFA8BA5F0479, 3EF244E91851E03BE77DE49FA7E36769DE287B0CB732CD0140C39FE5118D80B9 ] UEFI            C:\WINDOWS\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys
13:58:21.0031 0x1ce0  UEFI - ok
13:58:21.0078 0x1ce0  [ 18829AAD996E5A6A9F9B347318200385, 9000E15B7ABA7E7407FDE2A6EC025E50FCF838ADD66A9620DB15A3868FFD9F0B ] UevAgentDriver  C:\WINDOWS\system32\drivers\UevAgentDriver.sys
13:58:21.0093 0x1ce0  UevAgentDriver - ok
13:58:21.0265 0x1ce0  [ 5E87EEF78E014C98E5C7D137A8E25DCA, 308F7F09CD5D71F29E800F969DE053ECB134544CAE1393098B9A7126EE0BC5A9 ] UevAgentService C:\WINDOWS\system32\AgentService.exe
13:58:21.0468 0x1ce0  UevAgentService - ok
13:58:21.0499 0x1ce0  [ FE96D3238836601C5D03623BD440F2C3, 96FEB3DF819AAD727A91F0359ECCCCFAD455BC900FA302F004EEFA22974748C8 ] Ufx01000        C:\WINDOWS\system32\drivers\ufx01000.sys
13:58:21.0531 0x1ce0  Ufx01000 - ok
13:58:21.0562 0x1ce0  [ EEEECAFD642DB20A8470090C2ACAA6AC, 70FEAD3371792160701D47A808FC78786766E4C7CA7C5ED8DA356BFC991A275A ] UfxChipidea     C:\WINDOWS\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys
13:58:21.0578 0x1ce0  UfxChipidea - ok
13:58:21.0609 0x1ce0  [ E884B3B8DDA9442F58E41C2ADE3C4234, 51F112449305C5F03FEA6F046CA007A8056A65EF84986393A1B4203F53A08833 ] ufxsynopsys     C:\WINDOWS\System32\drivers\ufxsynopsys.sys
13:58:21.0640 0x1ce0  ufxsynopsys - ok
13:58:21.0687 0x1ce0  [ 631E47BFE53B8AF18ADA1ED8B09E1259, C9967E074C1697017F67F202643B65DB05F9F0C58CE714A49BA365B6E0718DC9 ] uhssvc          C:\Program Files\Microsoft Update Health Tools\uhssvc.exe
13:58:21.0718 0x1ce0  uhssvc - ok
13:58:21.0781 0x1ce0  [ E0E764F688DCACBA011BAEB2017B903F, 7802DCDA6F49494245EC9304AECED7BB2E90908BED25A4D47F1FF4615B03DED0 ] umbus           C:\WINDOWS\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys
13:58:21.0812 0x1ce0  umbus - ok
13:58:21.0828 0x1ce0  [ 493AF687E60E144F59E3F5B7E27AA39B, 3062B25A7747BC417E1D498DB1B11C9631D80F57E4A048101EF5AA26206AE838 ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
13:58:21.0874 0x1ce0  UmPass - ok
13:58:21.0906 0x1ce0  [ A4AA744447EEB2B46EC60C7AA487B072, C55B91BBA36FBD18C43FC367C54267EF28CEB5CCCF04EA7E44FB4778748DF005 ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
13:58:21.0937 0x1ce0  UmRdpService - ok
13:58:22.0031 0x1ce0  [ DA04AA3DA8CD89AC26095DFCABA7740E, 971440911B04DAD4F9F7C5621EBFE5C1E69B7A8455F2F3D33A1D96FFA1171A81 ] UnistoreSvc     C:\WINDOWS\System32\unistore.dll
13:58:22.0124 0x1ce0  UnistoreSvc - ok
13:58:22.0187 0x1ce0  [ 8BFFE0333C9EA9C54797C7F0E6F7769A, 0C0C7524F1A6D375D5D60DC8C602A75CB79B7311C0735956A2F42152A15C5F40 ] upnphost        C:\WINDOWS\System32\upnphost.dll
13:58:22.0234 0x1ce0  upnphost - ok
13:58:22.0343 0x1ce0  [ 5C33B91675BE0C9693358C1AAA723D20, A5BB54ABBB0F7B13ACCA0997F567A81395688C6D68EB87F67F688737DC16918F ] UrsChipidea     C:\WINDOWS\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys
13:58:22.0343 0x1ce0  UrsChipidea - ok
13:58:22.0390 0x1ce0  [ ADFAB87405AE22290E24D0E8E6141AF1, BC0982BEFE4CABEA1E260C8A3266EA18A4CA158A07D1C5176890A04CC3B6A84A ] UrsCx01000      C:\WINDOWS\system32\drivers\urscx01000.sys
13:58:22.0406 0x1ce0  UrsCx01000 - ok
13:58:22.0468 0x1ce0  [ BBDE7BF496327115DD744E7D4105C7BC, 5A8CC47603A1C9D58A30A5E897F1BCDC56199B08317B9FF319D469D6DD6CAAF0 ] UrsSynopsys     C:\WINDOWS\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys
13:58:22.0484 0x1ce0  UrsSynopsys - ok
13:58:22.0531 0x1ce0  [ A0AEFF16C4C55CBC3E89EF8D24CF64BA, D44D2859DFC64016959F9180CC21CF33C69AC4148A2BCAF784F9A2F7EA977CF8 ] usbaudio        C:\WINDOWS\system32\drivers\usbaudio.sys
13:58:22.0609 0x1ce0  usbaudio - ok
13:58:22.0671 0x1ce0  [ FB9F25ACEBCBAEABFE30CACCB17D4EE6, 7D38FA294DA179E5535E3E481746F07E2AE47CE57192C2D1C5B780B583FD9C6D ] usbaudio2       C:\WINDOWS\System32\drivers\usbaudio2.sys
13:58:22.0703 0x1ce0  usbaudio2 - ok
13:58:22.0734 0x1ce0  [ C6D1E24E96FCE7662F7C09394241CC8F, D49772661BABE6FF688F6C1D21BA04BC0E0492432664C413F851264695A3D3A2 ] usbccgp         C:\WINDOWS\System32\drivers\usbccgp.sys
13:58:22.0749 0x1ce0  usbccgp - ok
13:58:22.0796 0x1ce0  [ 11561FC5BAA2DEB5AC8B179B591A882E, 2AD595BF4ABC146D8F533981848FF8271E983038566937BEB48A6A8F09BC60FB ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
13:58:22.0828 0x1ce0  usbcir - ok
13:58:22.0874 0x1ce0  [ D1E576C8A94A27D896B56F923ED4E4D6, 3AE5ED5EAFBC52028D082D3EC04B526EF60F5D74BBC79DD210A22D9238C61262 ] usbehci         C:\WINDOWS\System32\drivers\usbehci.sys
13:58:22.0890 0x1ce0  usbehci - ok
13:58:22.0921 0x1ce0  [ 804C51B11057869624D9292040B45E56, 42404EC0F658121F6553B7DAA3511ED512B7F4B336C2032BA85CD91E8879EEAE ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
13:58:22.0953 0x1ce0  usbhub - ok
13:58:23.0031 0x1ce0  [ 3942EC2884CE00104F7B63992BD9B449, 9D22DB8178B983F39DCC9DFC1FB616D07CCD5DD4F928675D47AF036CC630FF51 ] USBHUB3         C:\WINDOWS\System32\drivers\UsbHub3.sys
13:58:23.0062 0x1ce0  USBHUB3 - ok
13:58:23.0093 0x1ce0  [ 4E8C3BD185042836203F3AA26B1DE6BC, 8E2B1A8E3F8E1F88E73AE2A34B1726B5C5F6753BAE3FAB1E7CC82C53FF7EE891 ] usbohci         C:\WINDOWS\System32\drivers\usbohci.sys
13:58:23.0124 0x1ce0  usbohci - ok
13:58:23.0171 0x1ce0  [ E7D67614480D6365CA96FA6919F6CFF0, 7AC5FAC0D8E0A86CBD67407EA9EF95C6A2CBAA397EB959E074B6D87E85CEBD0A ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
13:58:23.0202 0x1ce0  usbprint - ok
13:58:23.0265 0x1ce0  [ AF024852586879C6D643B85DDAD94C09, 84D1B97E92854EE23F08055B7C932D02A1EB6B8AD70F99C397B663EE3E6F35F7 ] usbser          C:\WINDOWS\System32\drivers\usbser.sys
13:58:23.0312 0x1ce0  usbser - ok
13:58:23.0327 0x1ce0  [ 2B63370F71A99AEADE88117F4FFC6ECE, 6FE4ECB655A13EA8DD070F4D9D7335557E27137CB854DCC39DCF0FF2009643EF ] USBSTOR         C:\WINDOWS\System32\drivers\USBSTOR.SYS
13:58:23.0343 0x1ce0  USBSTOR - ok
13:58:23.0406 0x1ce0  [ 3D45E616CC66D475E7261875344622F1, 3D602EA3F0A83F8FA7B9FED579B21881BB92272307634B24E0423A9A482D2CD6 ] usbuhci         C:\WINDOWS\System32\drivers\usbuhci.sys
13:58:23.0437 0x1ce0  usbuhci - ok
13:58:23.0499 0x1ce0  [ 38A6980D2DAA486177E86DE24E15BE88, 35F0F8F089353524DE2AB308D5CDA641F1EC7B6A0D8F37C4124494B20B2031D7 ] usbvideo        C:\WINDOWS\System32\Drivers\usbvideo.sys
13:58:23.0515 0x1ce0  usbvideo - ok
13:58:23.0562 0x1ce0  [ 290C7E9C815B2AF0865D0B019124F695, 2D9590A58AF7A139C3080154E07532B7429B6B4E11772C3807F06B4DB6DD94E9 ] USBXHCI         C:\WINDOWS\System32\drivers\USBXHCI.SYS
13:58:23.0593 0x1ce0  USBXHCI - ok
13:58:23.0671 0x1ce0  [ B1F3989A13B65D3CAD4778F9D92418AC, 45B8C4BE560AB5C7BDF250DB4CB68FA4712570B841A11BB43722A14812376DCC ] UserDataSvc     C:\WINDOWS\System32\userdataservice.dll
13:58:23.0765 0x1ce0  UserDataSvc - ok
13:58:23.0859 0x1ce0  [ F9E1B05E0E502F29D1AC74807E6B5EBF, A0D752CB8418EB492AE4135CB9A43D79B7D8F2AC386FA917724ADF7651249AD9 ] UserManager     C:\WINDOWS\System32\usermgr.dll
13:58:23.0968 0x1ce0  UserManager - ok
13:58:24.0077 0x1ce0  [ 406C19A815FE7C361B3A2333CD58A2DB, 15E9C47893F068B3857505D50491D91E5BF4B60B60ED878A080FE62B35212DE3 ] USER_ESRV_SVC_QUEENCREEK C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
13:58:24.0109 0x1ce0  USER_ESRV_SVC_QUEENCREEK - ok
13:58:24.0171 0x1ce0  [ E39A8BDFA50D2F76C3CB1935EC4F16EF, 9C1A09A07DA8FA039C2A5AB233BDB0504800E7E3C8C704A77E4B30815FA5823E ] UsoSvc          C:\WINDOWS\system32\usosvc.dll
13:58:24.0234 0x1ce0  UsoSvc - ok
13:58:24.0296 0x1ce0  [ 5C5DC8E40CFC3979E793348A009434B7, 97AA8A487DAF0699E569B3E657EAC605302C74B75DAF2058856D799D32EA8026 ] VacSvc          C:\WINDOWS\System32\vac.dll
13:58:24.0327 0x1ce0  VacSvc - ok
13:58:24.0359 0x1ce0  [ 15A556DEF233F112D127025AB51AC2D3, 362AB9743FF5D0F95831306A780FC3E418990F535013C80212DD85CB88EF7427 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
13:58:24.0374 0x1ce0  VaultSvc - ok
13:58:24.0421 0x1ce0  [ 661233B58190B487682839F1559A7962, 2BE132106C26A9073B6E9CB646E6A2C003558B8924ED0BDC3A0533FC98E03BF4 ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
13:58:24.0437 0x1ce0  vdrvroot - ok
13:58:24.0468 0x1ce0  [ D28FB8A8DD61CFA35B6DE838E0A3978A, 250173049A54473E149FD6F58D45665469B497F6C181925D5FC4ED15F019DE55 ] vds             C:\WINDOWS\System32\vds.exe
13:58:24.0531 0x1ce0  vds - ok
13:58:24.0562 0x1ce0  [ 46684A95E908F0A6A2355AA46A3B2A77, A25DFDA0572EF014905619DF21427518EA5C01CFB13B9927ADA305B29DBBFEFE ] VerifierExt     C:\WINDOWS\system32\drivers\VerifierExt.sys
13:58:24.0593 0x1ce0  VerifierExt - ok
13:58:24.0624 0x1ce0  [ 9BF651CB9913A9F68A444454F0D181E0, A47000322938CEDE3A661E91CA7C0D616EE3F5A4DA1C677671C218417A5A8F8E ] vhdmp           C:\WINDOWS\System32\drivers\vhdmp.sys
13:58:24.0671 0x1ce0  vhdmp - ok
13:58:24.0718 0x1ce0  [ 7F2F04A354582D3D34F5B2B4EFF07189, 98188182D328414832D06E957601A997AD2B2B0F088B089181EDE8FAB0AF733C ] vhf             C:\WINDOWS\System32\drivers\vhf.sys
13:58:24.0749 0x1ce0  vhf - ok
13:58:24.0812 0x1ce0  [ 45078F20D2095B582A1289225898968A, 2FF2A639B4A25EEF5EEE4A99DD2A9E73B173FD99870F657D74DA5489629CFF56 ] Vid             C:\WINDOWS\System32\drivers\Vid.sys
13:58:24.0843 0x1ce0  Vid - ok
13:58:24.0890 0x1ce0  [ B37F0BF662BB504F0A9C247F24C281AD, 6281D573D9AD9AA204778C3823737726E882B17657B23CF5458C012FF7990E52 ] VirtualRender   C:\WINDOWS\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys
13:58:24.0952 0x1ce0  VirtualRender - ok
13:58:24.0968 0x1ce0  [ 8400F5228F706F501CF87E0402FEC491, E7C944B8B7AC6AB4DAA817E548BA35B2484611D8E2F77602E47DC981AB0DDD99 ] vmbus           C:\WINDOWS\system32\drivers\vmbus.sys
13:58:24.0984 0x1ce0  vmbus - ok
13:58:25.0015 0x1ce0  [ C29F63BB3B99B3F2030113160A741684, 43DF7A6DD305D1696D28A54E12B75AE041B075E789DB5D0C8DDF250E75585AA1 ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
13:58:25.0031 0x1ce0  VMBusHID - ok
13:58:25.0077 0x1ce0  [ E5BB075B6B5A1DA3C3F48CA5DFF54E77, E13E8F9523F51F976084561C9D0A843CAF550FA233521FF13FFE1C5634CA6472 ] vmgid           C:\WINDOWS\System32\drivers\vmgid.sys
13:58:25.0093 0x1ce0  vmgid - ok
13:58:25.0140 0x1ce0  [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
13:58:25.0156 0x1ce0  vmicguestinterface - ok
13:58:25.0171 0x1ce0  [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicheartbeat   C:\WINDOWS\System32\icsvc.dll
13:58:25.0187 0x1ce0  vmicheartbeat - ok
13:58:25.0202 0x1ce0  [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
13:58:25.0218 0x1ce0  vmickvpexchange - ok
13:58:25.0249 0x1ce0  [ D222598C027A7D87382C0CB8D0CD3994, FB6CA91F6F3FC650A9D12D54CFD25331A31404181755E7CADBC80A0A57327AEA ] vmicrdv         C:\WINDOWS\System32\icsvcext.dll
13:58:25.0281 0x1ce0  vmicrdv - ok
13:58:25.0296 0x1ce0  [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicshutdown    C:\WINDOWS\System32\icsvc.dll
13:58:25.0312 0x1ce0  vmicshutdown - ok
13:58:25.0327 0x1ce0  [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmictimesync    C:\WINDOWS\System32\icsvc.dll
13:58:25.0343 0x1ce0  vmictimesync - ok
13:58:25.0484 0x1ce0  [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicvmsession   C:\WINDOWS\System32\icsvc.dll
13:58:25.0515 0x1ce0  vmicvmsession - ok
13:58:25.0515 0x1ce0  [ D222598C027A7D87382C0CB8D0CD3994, FB6CA91F6F3FC650A9D12D54CFD25331A31404181755E7CADBC80A0A57327AEA ] vmicvss         C:\WINDOWS\System32\icsvcext.dll
13:58:25.0546 0x1ce0  vmicvss - ok
13:58:25.0562 0x1ce0  [ 0733F8C791B54D422EA7D44CDF009EC3, A03B110C6711EFBD8BCF4391941A2E77AEDAC5462C10479050F9318E94C62CED ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
13:58:25.0577 0x1ce0  volmgr - ok
13:58:25.0624 0x1ce0  [ 796F1C83861C02A97571D0EDAB490B70, 71CE8D930AE82C2B2628CBF3BB3AE1A8CF039BD702BDE912D499FCF45332F5A6 ] volmgrx         C:\WINDOWS\system32\drivers\volmgrx.sys
13:58:25.0640 0x1ce0  volmgrx - ok
13:58:25.0702 0x1ce0  [ 988A7A685BB51BAC62F4E176BE5432AC, CFEE4616C10EB0CDA65D4FCC2488B879D577E0F95B5E9AB9B61258F249ED6AC6 ] volsnap         C:\WINDOWS\system32\drivers\volsnap.sys
13:58:25.0718 0x1ce0  volsnap - ok
13:58:25.0749 0x1ce0  [ 770E710BEA3CCC595EE3703297B40D76, C03E3367B92307993BC169583CB298265FC1C35CF5973EC352C1E08FFCFD1928 ] volume          C:\WINDOWS\system32\drivers\volume.sys
13:58:25.0765 0x1ce0  volume - ok
13:58:25.0796 0x1ce0  [ A37A7788DABE4FF6E33FE50D7A33D8E8, 9E99D9D27BA3DFA6F89C77B9AD91BE495F15E4F612BB63B209157DFA13BCD7E0 ] vpci            C:\WINDOWS\system32\drivers\vpci.sys
13:58:25.0812 0x1ce0  vpci - ok
13:58:25.0843 0x1ce0  [ FA77459ECEEBE258F3CA3DC3DBC58603, 75D62B25E159B592E8270F597A1478213E056B03D826E72F58015251977D99C7 ] vpnpbus         C:\WINDOWS\System32\drivers\vpnpbus.sys
13:58:25.0859 0x1ce0  vpnpbus - ok
13:58:25.0874 0x1ce0  [ 1A4D9FAED669BC42E5A1CD8442729AB2, E70778AF6B0C9709CB8CEF655C6DD8B5A61CC70BFD35A43304C1308EA478C550 ] vsmraid         C:\WINDOWS\system32\drivers\vsmraid.sys
13:58:25.0890 0x1ce0  vsmraid - ok
13:58:25.0952 0x1ce0  [ AA98234C89499A69BD55C2DCCC4BCCC9, AED19CA1EEDF716640FAF70B1A4A10736C6C7ED0E2149C3D6CAA4D5E6DA8899A ] VSS             C:\WINDOWS\system32\vssvc.exe
13:58:26.0077 0x1ce0  VSS - ok
13:58:26.0109 0x1ce0  [ 6E0092973E35BE6A1F5ED5CBDD202036, 33DAF53C81D5BAF9337192A84DF50C108BAE9B8A858081E2208939CCFF2622F8 ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
13:58:26.0140 0x1ce0  VSTXRAID - ok
13:58:26.0171 0x1ce0  [ 7BC30ADCCC9BCF2B0A29A320A395EC3B, 373C85F659F07366649697823B4A8B14313F0042A7A04E932429D049D18C7646 ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
13:58:26.0249 0x1ce0  vwifibus - ok
13:58:26.0296 0x1ce0  [ E52E3DD859D4095E314E3EC78F9AD4E4, 2ABE2311C9C429308BA0D6BC490AC1C9570ECBC83D9BEDC561E438B7BB4436B2 ] vwififlt        C:\WINDOWS\system32\drivers\vwififlt.sys
13:58:26.0359 0x1ce0  vwififlt - ok
13:58:26.0452 0x1ce0  [ 39E78C9E9463C8D096021EA08682B5C3, 8E62D4CE0EE294B403AC2FC334C44D4AFFA3ACF07DF5E54645C271FFB0F27E40 ] vwifimp         C:\WINDOWS\System32\drivers\vwifimp.sys
13:58:26.0484 0x1ce0  vwifimp - ok
13:58:26.0562 0x1ce0  [ F547820151D4E231184F1625CF6A5086, EDABA8F659EBEC01487D1A5B85ACC355EA79EE3E493E313E9DB786C1CB24CDFD ] W32Time         C:\WINDOWS\system32\w32time.dll
13:58:26.0624 0x1ce0  W32Time - ok
13:58:26.0702 0x1ce0  [ 328BEF384D31C91D7C55E87EC1B0B1EA, 17D04E719009E5C5CF5A68CDCFC9B5C20E5001E2698C9CDB024BEEBBAC3AED6C ] WaaSMedicSvc    C:\WINDOWS\System32\WaaSMedicSvc.dll
13:58:26.0765 0x1ce0  WaaSMedicSvc - ok
13:58:26.0796 0x1ce0  [ 1F16C8283230EF1F1C4E135D1C2C859B, E4F672C7E58490F82F859CAEEDD57D8ABCC31DE62A42A956BEE47113D365BE35 ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
13:58:26.0812 0x1ce0  WacomPen - ok
13:58:26.0874 0x1ce0  [ D765B98325D89C076FEEAB1282CD08EA, AC2F0A68A2BCAAF2DECB0AAF1B50D652ED8B631B08D06B910B407FEF9069412E ] WalletService   C:\WINDOWS\system32\WalletService.dll
13:58:26.0937 0x1ce0  WalletService - ok
13:58:26.0984 0x1ce0  [ 438B3E55D9D700C1C0424642872C2E28, 161F9F1F666717D95AF7EC984DDDC4D7E13844617108346FFC49A4EE99AE812F ] wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
13:58:27.0015 0x1ce0  wanarp - ok
13:58:27.0030 0x1ce0  [ 438B3E55D9D700C1C0424642872C2E28, 161F9F1F666717D95AF7EC984DDDC4D7E13844617108346FFC49A4EE99AE812F ] wanarpv6        C:\WINDOWS\system32\DRIVERS\wanarp.sys
13:58:27.0062 0x1ce0  wanarpv6 - ok
13:58:27.0109 0x1ce0  [ 8449398F11D49864117105679B539816, 8FD3B9C72066D6A983D062DE72EEF9769339EACBF4E0D303B9E12343C9D5DE6C ] WarpJITSvc      C:\WINDOWS\System32\Windows.WARP.JITService.dll
13:58:27.0437 0x1ce0  WarpJITSvc - ok
13:58:27.0530 0x1ce0  [ 17270A354A66590953C4AAC1CF54E507, 9954394B43783061F9290706320CC65597C29176D5B8E7A26FA1D6B3536832B4 ] wbengine        C:\WINDOWS\system32\wbengine.exe
13:58:27.0624 0x1ce0  wbengine - ok
13:58:27.0718 0x1ce0  [ 647988450BAB664975432725E3025B68, 36C5D99C8237CD51B688CC5AFAA724E44C6949B8AF0093DD14663564F8F87B9F ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
13:58:27.0780 0x1ce0  WbioSrvc - ok
13:58:27.0843 0x1ce0  [ D853E4A4415D945A2E8622863D4A3EF4, E159FCE548156118ED6F2901314FB6C9A944623D1B267B5B00F1FB9B1B5C8D44 ] wcifs           C:\WINDOWS\system32\drivers\wcifs.sys
13:58:27.0859 0x1ce0  wcifs - ok
13:58:27.0937 0x1ce0  [ 7430AF6A0924263FB3A1B7CF44447BE7, A209C8856D5E2EC45D5AB3F9B4DEE7DE6187503668D59B9187AB806E12FDBC77 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
13:58:28.0030 0x1ce0  Wcmsvc - ok
13:58:28.0093 0x1ce0  [ 6CDE91D497A3EC19796DE53DEBD74FB0, ACBBCBFE7A953F3CFF10A035A52984D7DB0C0B4C6B735F53006036F4CCC15059 ] wcncsvc         C:\WINDOWS\System32\wcncsvc.dll
13:58:28.0140 0x1ce0  wcncsvc - ok
13:58:28.0202 0x1ce0  [ 2F814379FE1FF9DC891953674406BCA1, ACC9B126A8A5D58AF76F0A492C0EBC75925C3B59EAE89062AEF0FFADF60E3A2B ] wcnfs           C:\WINDOWS\system32\drivers\wcnfs.sys
13:58:28.0343 0x1ce0  wcnfs - ok
13:58:28.0405 0x1ce0  [ 65555F31D7CD2B40A3BC3C421CD1DD0A, 34A120E96A0960D7922275C6E5366421EBB5DA008AC1714F16C58C1EBAD6F248 ] WdBoot          C:\WINDOWS\system32\drivers\wd\WdBoot.sys
13:58:28.0421 0x1ce0  WdBoot - ok
13:58:28.0484 0x1ce0  [ BFC5268BE766E45EE1858BE1A61DBC69, ED5D3249D421D579C94159086B48016DA5CDCEA84BA69CB14B10B46D990971C8 ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
13:58:28.0530 0x1ce0  Wdf01000 - ok
13:58:28.0593 0x1ce0  [ BB37AF6E45E0F69222E057A74B4AFE1E, 4662064205BEC0DB7B10F1412E0A09A6E5E3B16DE443AEF7F79ACA3ACE24A51D ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
13:58:28.0640 0x1ce0  WdiServiceHost - ok
13:58:28.0640 0x1ce0  [ BB37AF6E45E0F69222E057A74B4AFE1E, 4662064205BEC0DB7B10F1412E0A09A6E5E3B16DE443AEF7F79ACA3ACE24A51D ] WdiSystemHost   C:\WINDOWS\system32\wdi.dll
13:58:28.0671 0x1ce0  WdiSystemHost - ok
13:58:28.0749 0x1ce0  [ 60C31BE6588C49FD4B05B5BD0266D55F, 0885049187DDAA520B07A3B81409E599FC17BB37591ECC4D39B42408EA120369 ] wdiwifi         C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
13:58:28.0827 0x1ce0  wdiwifi - ok
13:58:28.0874 0x1ce0  [ A6C92A5F2982EBB8788E0690C19048C4, 85C54A99DD43DC1FAC7FD2A31288CEC7501F795DE8FA86857790F4CCD5AF7C18 ] WdmCompanionFilter C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys
13:58:28.0890 0x1ce0  WdmCompanionFilter - ok
13:58:28.0937 0x1ce0  [ F7C782F1555B1E9CA62C4AEDC72B9944, 6D04257EC15BCAEF2B79CA668741D35E9431D3C3F6F39E80FB6DED545FBE0FAF ] WdNisDrv        C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
13:58:28.0952 0x1ce0  WdNisDrv - ok
13:58:28.0999 0x1ce0  [ 4A81FA6E29A3909FC620EC8B7AE0C8FF, 89F67C978A7F58FF1E51CE6DE17FE8FAF64A52A2E96BD188E911517AF1949275 ] WebClient       C:\WINDOWS\System32\webclnt.dll
13:58:29.0030 0x1ce0  WebClient - ok
13:58:29.0093 0x1ce0  [ BDD1061D880EC049CC42E5AED90AF4C6, B78334BEB2E83564A0775133F517D545B580ED14408D91F6C03A01C8AA8283EF ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
13:58:29.0124 0x1ce0  Wecsvc - ok
13:58:29.0187 0x1ce0  [ CBA85827716DE89106F8E4AD7430620C, EF2FEAD68FE003DAC52BC2098962F397DF80B7DCD79A8F45012A050C7C0E2DB1 ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
13:58:29.0202 0x1ce0  WEPHOSTSVC - ok
13:58:29.0234 0x1ce0  [ 0CA02EBDA174768BE1BFA3FB9090448F, A9D569B6B06B2DD4880ED62D2D9520BB10828E0EA65F1ACF9C8C4134611D1C58 ] wercplsupport   C:\WINDOWS\System32\wercplsupport.dll
13:58:29.0265 0x1ce0  wercplsupport - ok
13:58:29.0327 0x1ce0  [ 24FD4F8F7BBC74C74D2552E16384FFC3, 6E6B3A8A9E33CAE73F69B1D2D1543FEE9CDEEE6AC12C52765BA6304D88F06D58 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
13:58:29.0374 0x1ce0  WerSvc - ok
13:58:29.0468 0x1ce0  [ 39B758E2093B9FB42A086BF4BB1B8BEC, 473C61E7F4D734AE9C4BD2E111C6DCE595E9EF167C001CEDC35E53213F2987F6 ] WFDSConMgrSvc   C:\WINDOWS\System32\wfdsconmgrsvc.dll
13:58:29.0530 0x1ce0  WFDSConMgrSvc - ok
13:58:29.0577 0x1ce0  [ AEB8C2228CA9B0C0588C41E4B3758102, 5577559B942D8BB70B8FB65F3C12423FABEF4F922F336ACB658C0AD00823D662 ] WFPLWFS         C:\WINDOWS\system32\drivers\wfplwfs.sys
13:58:29.0593 0x1ce0  WFPLWFS - ok
13:58:29.0655 0x1ce0  [ 7AE4D5A054C5EEF9EF9F42926B52FA47, A58CB62992AB846A31E197DF5161F50323D120DF73B7D33FE7D5F5B1AF209291 ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
13:58:29.0671 0x1ce0  WiaRpc - ok
13:58:29.0749 0x1ce0  [ 5C0439FA47EB0BEF013D59CC7BD7E6F9, E47BDCF775229A739C81A6EE243CBB2919A9364554991AA22DDDB4FEA1F5DC77 ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
13:58:29.0749 0x1ce0  WIMMount - ok
13:58:29.0843 0x1ce0  [ B434A84F46C70F4E67B70ED70F024B7F, 64EEB8093BA2590E83D83C5AF7C2A025B88AF5681143BCA83671104266FEEA99 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
13:58:29.0859 0x1ce0  WindowsTrustedRT - ok
13:58:29.0937 0x1ce0  [ 982774B74EE1419D641CEB66E394A4BA, 090C4CE6B76B3904B5AE73E4F1EEBCE619194C358874D7584537012F954C54BE ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
13:58:29.0952 0x1ce0  WindowsTrustedRTProxy - ok
13:58:30.0030 0x1ce0  [ 0A353B977E27CE7A57FB808D90A7F69A, CBAA6186ACFC92AF5A3BCE28DE7A81FF339E902942D8687A143FD1688097A804 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
13:58:30.0093 0x1ce0  WinHttpAutoProxySvc - ok
13:58:30.0155 0x1ce0  [ 0816C30E3395E667EFFFB92B4EA66A05, F6A9E7026AA60A6627680F232AE785EA9CF55FE970708E6E49151F601CC42FEE ] WinMad          C:\WINDOWS\System32\drivers\winmad.sys
13:58:30.0171 0x1ce0  WinMad - ok
13:58:30.0280 0x1ce0  [ E2376F73AAA2A4BBEF5F94DE095C788A, 65E8FAF81245C08B6668EFB5B7264B2EEBCC90F30F714E1B60C2F7B60AE070C5 ] Winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
13:58:30.0343 0x1ce0  Winmgmt - ok
13:58:30.0405 0x1ce0  [ EE9539E7C30E2046E7A906681DE9464C, 8C7345B9A8A96AABC29342E214EE7FD7BADC38DD5915840B15FDF065FB4E535A ] WinNat          C:\WINDOWS\system32\drivers\winnat.sys
13:58:30.0640 0x1ce0  WinNat - ok
13:58:30.0952 0x1ce0  [ 5D698B4D953060214F62E6BB3E1E186E, 5E9A4B51B2C9763B51AFBA51A93EACA13570BBC8DF5FC5157B044E72FE160D94 ] WinRM           C:\WINDOWS\system32\WsmSvc.dll
13:58:31.0296 0x1ce0  WinRM - ok
13:58:31.0390 0x1ce0  [ 91D3DC62C6EDDB6554CE14C0E0B4290F, 6F8F89B350FC6BC0D23A50C593F02514854AB7D6CD234D8C8AD4B5DDDD586BA0 ] WINUSB          C:\WINDOWS\System32\drivers\WinUSB.SYS
13:58:31.0437 0x1ce0  WINUSB - ok
13:58:31.0483 0x1ce0  [ F4C4FD42F8DD657157823DB617CC3A3D, D2A5ED039ED83010E0BB4BB1A69F9D142D42BE2C75E56CFCF3F157A735CB688E ] WinVerbs        C:\WINDOWS\System32\drivers\winverbs.sys
13:58:31.0499 0x1ce0  WinVerbs - ok
13:58:31.0577 0x1ce0  [ 2E575D58347E1274DAE5142DF52102CF, CF1EFAFFCE216BDD747A0C496DBF3AFA9689709579409E0A486DC09A7DF18D83 ] wisvc           C:\WINDOWS\system32\flightsettings.dll
13:58:31.0624 0x1ce0  wisvc - ok
13:58:31.0765 0x1ce0  [ 4FE4B7740B86C37AF62867229AB39A87, F06D2C3DAE001449FE57778B972EA356FF2008388D2144A9DEA3D08B6EFD5F09 ] WlanSvc         C:\WINDOWS\System32\wlansvc.dll
13:58:31.0921 0x1ce0  WlanSvc - ok
13:58:32.0046 0x1ce0  [ 48AE66A72ECA846D1A0216D4CE2955E6, 1885F8AC0F95A3B891833A07193819894E3F6E00790B51C0E55AA63D57BD3FB0 ] wlidsvc         C:\WINDOWS\system32\wlidsvc.dll
13:58:32.0233 0x1ce0  wlidsvc - ok
13:58:32.0327 0x1ce0  [ 1B279ADD6A4150FD49A6276147098803, 6CC12957A0E7FF3DCCA28D8B715EDE9C94F329FD5BAB3366D4C70362325B31CE ] wlpasvc         C:\WINDOWS\System32\lpasvc.dll
13:58:32.0405 0x1ce0  wlpasvc - ok
13:58:32.0530 0x1ce0  [ 8D0B8A981E1D3791ABB63E3E0A23EDE8, 432FDAF7ED42D9EA98F9C8E44EA774CCC26AE610446E47F2FB6FC8ECBCC81B77 ] WManSvc         C:\WINDOWS\system32\Windows.Management.Service.dll
13:58:32.0624 0x1ce0  WManSvc - ok
13:58:32.0640 0x1ce0  [ E4F25E6E790747073A09F9F8C997889C, 98455DD24AE076A2413EA599F83E0894F608C335F3FF2F3624A17E8EAF3B3C42 ] WmiAcpi         C:\WINDOWS\System32\drivers\wmiacpi.sys
13:58:32.0655 0x1ce0  WmiAcpi - ok
13:58:32.0733 0x1ce0  [ 3C65841009FFA5A7C1F05E3555F40759, 4B5E41EEF2CD86B36B702CE00F6B8F97F9AA483FC0D91538DF5E2CA421B69E3B ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
13:58:32.0765 0x1ce0  wmiApSrv - ok
13:58:32.0858 0x1ce0  WMPNetworkSvc - ok
13:58:32.0905 0x1ce0  [ 9405C703D91F07F1F181DE916594EED3, 7626111256C3BECD0EE9E299A41149A367A28BACEE89CC2CDD46D7499B1B7D34 ] Wof             C:\WINDOWS\system32\drivers\Wof.sys
13:58:32.0937 0x1ce0  Wof - ok
13:58:33.0062 0x1ce0  [ 06C7A91BC84A2C287F67C7CCFB9D218F, 893DC216AE6D48A5A37FF60D4E62109AAE56CBF3F3EF7299076BF4058AFECE35 ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
13:58:33.0187 0x1ce0  workfolderssvc - ok
13:58:33.0327 0x1ce0  [ 98E6B137A27762573FC6B6127F2306D1, 0F877213D5BA83C92D4F0836741E0517554A9E1F5E363C5CF45A6EBE37B1FF49 ] WpcMonSvc       C:\WINDOWS\System32\WpcDesktopMonSvc.dll
13:58:33.0468 0x1ce0  WpcMonSvc - ok
13:58:33.0530 0x1ce0  [ 02876C4F9F4EEC8AC30BBCFFE3447AB6, 0744CBBD9F2B867DF456E2B0E113897B654F07E1C96FCB32D4B4B57BE6A3BE81 ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
13:58:33.0780 0x1ce0  WPDBusEnum - ok
13:58:33.0843 0x1ce0  [ 024924C9E79F51560B9133EEAB866BBF, F4D464BC02C7B96EF72AA9229A99A1AD32F56390F97972C33525EF0D85304261 ] WpdUpFltr       C:\WINDOWS\system32\drivers\WpdUpFltr.sys
13:58:33.0858 0x1ce0  WpdUpFltr - ok
13:58:33.0921 0x1ce0  [ B12FDDFD619C354D798E9E1C9FCF4642, 66F024A993834812277FB08AAD36FD69F79A92B403131FEB76E212ACFB58AB02 ] WpnService      C:\WINDOWS\system32\WpnService.dll
13:58:33.0952 0x1ce0  WpnService - ok
13:58:33.0983 0x1ce0  [ 3D1B4E335BB9CA8A998CD5E1B2EDE855, ECD704FE62C8920D7AC2B3DC040E9D41D8A6BEBCB457888B411D133635291F36 ] WpnUserService  C:\WINDOWS\System32\WpnUserService.dll
13:58:34.0030 0x1ce0  WpnUserService - ok
13:58:34.0093 0x1ce0  [ 2B98DFC181823C8D8AA39C4CC577DE3E, DAFF7CE8868299AF5EFA844C2E1F84B7EE7E498B1AFF16965CE41C2E75B2F4E4 ] ws2ifsl         C:\WINDOWS\system32\drivers\ws2ifsl.sys
13:58:34.0436 0x1ce0  ws2ifsl - ok
13:58:34.0452 0x1ce0  WSearch - ok
13:58:34.0515 0x1ce0  [ 7FC0072ECE3F5F860990EF4E10D3F8F4, 15444A3E540EAD214A674FF0EB99CD42899D6A1139E59D69DE1C2B6BA364A9E0 ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
13:58:34.0561 0x1ce0  WudfPf - ok
13:58:34.0640 0x1ce0  [ 24B093F34B25076A2A6605DDAC8A629B, 64BEEA0C054C91AD2CEB9F6B9238A8ED3696FC20B8CC4753D88B8BC482D766C0 ] WUDFRd          C:\WINDOWS\System32\drivers\WUDFRd.sys
13:58:34.0671 0x1ce0  WUDFRd - ok
13:58:34.0686 0x1ce0  [ 24B093F34B25076A2A6605DDAC8A629B, 64BEEA0C054C91AD2CEB9F6B9238A8ED3696FC20B8CC4753D88B8BC482D766C0 ] WUDFWpdFs       C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
13:58:34.0718 0x1ce0  WUDFWpdFs - ok
13:58:34.0733 0x1ce0  [ 24B093F34B25076A2A6605DDAC8A629B, 64BEEA0C054C91AD2CEB9F6B9238A8ED3696FC20B8CC4753D88B8BC482D766C0 ] WUDFWpdMtp      C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
13:58:34.0780 0x1ce0  WUDFWpdMtp - ok
13:58:34.0874 0x1ce0  [ E5342932948FC6C25EFFE41D4F85FF64, E6586057FE2399A258333624CA98FB506CEC0FDD6DDE2FB80B7F14F5C71D2DA6 ] WwanSvc         C:\WINDOWS\System32\wwansvc.dll
13:58:34.0983 0x1ce0  WwanSvc - ok
13:58:35.0061 0x1ce0  [ 75EBC3A65D03A7F9395B63AD77C2757B, DBC40FA04195FC2FAFD404993187E50BF5CA40B7256F3F415AB3AE475A656F49 ] XblAuthManager  C:\WINDOWS\System32\XblAuthManager.dll
13:58:35.0655 0x1ce0  XblAuthManager - ok
13:58:35.0733 0x1ce0  [ E079354E7F1DEA98C8F1A6AF3F0618C3, 78BBC0FDCBD91394E2C74205568703FD5AEE39C54BA43AA78E95ADE9DC75A8E6 ] XblGameSave     C:\WINDOWS\System32\XblGameSave.dll
13:58:35.0843 0x1ce0  XblGameSave - ok
13:58:35.0905 0x1ce0  [ 27FD0CDC191131BB09069FCAAFAA2315, CAD30647531CEB44039968BB6B588F4FF976B89C0D15918BF4ECF3B46CEF1ECC ] xboxgip         C:\WINDOWS\System32\drivers\xboxgip.sys
13:58:35.0968 0x1ce0  xboxgip - ok
13:58:36.0015 0x1ce0  [ 04BE9428D1E276DF3F6A7A5552AAB546, ACC3A8180601054BFD8FBE743A7F9CB5F2398FD463FD7EA5EF2EF78953BADBBD ] XboxGipSvc      C:\WINDOWS\System32\XboxGipSvc.dll
13:58:36.0061 0x1ce0  XboxGipSvc - ok
13:58:36.0140 0x1ce0  [ 5A4F5B800B1AE1B196D3D09D1E973C9F, 8BB5D0ABF6DF5E48F17480AE72D568EBBF59E2D69E359AD951970A5BF35BFDD8 ] XboxNetApiSvc   C:\WINDOWS\system32\XboxNetApiSvc.dll
13:58:36.0249 0x1ce0  XboxNetApiSvc - ok
13:58:36.0311 0x1ce0  [ 563F1F5C9AA93D575BC2D263066F3198, EC775B54DB846271789D90AE3CC445FFF0EB3DE3154453F341BA9B86218880D2 ] xinputhid       C:\WINDOWS\System32\drivers\xinputhid.sys
13:58:36.0327 0x1ce0  xinputhid - ok
13:58:36.0327 0x1ce0  ================ Scan global ===============================
13:58:36.0390 0x1ce0  [ 522F9EFF8C957F906154B91A8DA698AE, FCB686BB58782506BA6A8C4F924B0872608249091C8FF9DD7129D0146ACC2BFE ] C:\WINDOWS\system32\basesrv.dll
13:58:36.0436 0x1ce0  [ 19979E1729CFA0E56EB4CCCB198DFD05, 7F2A683F28877562409D810946DDCA2F069715CDFB249602251DFA50065FFF7A ] C:\WINDOWS\system32\winsrv.dll
13:58:36.0499 0x1ce0  [ 1985068B049D1FFBB8D3F837393DF81F, B99151A18AAA83C0D6931245E6DA250346F1A61B0F8F058123E47D9BC5C12BE8 ] C:\WINDOWS\system32\sxssrv.dll
13:58:36.0530 0x1ce0  [ D8E577BF078C45954F4531885478D5A9, DFBEA9E8C316D9BC118B454B0C722CD674C30D0A256340200E2C3A7480CBA674 ] C:\WINDOWS\system32\services.exe
13:58:36.0546 0x1ce0  [ Global ] - ok
13:58:36.0546 0x1ce0  ================ Scan MBR ==================================
13:58:36.0561 0x1ce0  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:58:46.0483 0x1ce0  \Device\Harddisk0\DR0 - ok
13:58:46.0483 0x1ce0  [ 66D0B28C8B44E531D0C19F436252ABAA ] \Device\Harddisk1\DR1
13:58:46.0608 0x1ce0  \Device\Harddisk1\DR1 - ok
13:58:46.0608 0x1ce0  ================ Scan VBR ==================================
13:58:46.0639 0x1ce0  [ 522AC08A40A4448A59AFE519CB6E2AC6 ] \Device\Harddisk0\DR0\Partition1
13:58:46.0639 0x1ce0  \Device\Harddisk0\DR0\Partition1 - ok
13:58:46.0655 0x1ce0  [ D6087AC30FFE81593678442A3B0AFD0A ] \Device\Harddisk0\DR0\Partition2
13:58:46.0655 0x1ce0  \Device\Harddisk0\DR0\Partition2 - ok
13:58:46.0655 0x1ce0  [ 3195E9B8D790A057EAE1B99C2FB57351 ] \Device\Harddisk1\DR1\Partition1
13:58:46.0655 0x1ce0  \Device\Harddisk1\DR1\Partition1 - ok
13:58:46.0655 0x1ce0  ================ Scan active images ========================
13:58:46.0655 0x1ce0  ================ Scan generic autorun ======================
13:58:46.0749 0x1ce0  [ 783C99AFD4C2AE6950FA5694389D2CFA, 570B37A7A3FFDAFCCECCC33CBC1968FEB857B73CA3CB4DFFEDC2E67E9ABD0878 ] C:\WINDOWS\system32\SecurityHealthSystray.exe
13:58:46.0764 0x1ce0  SecurityHealth - ok
13:58:47.0545 0x1ce0  [ 7544B6AD69D584CB2223D69E313086FF, B0A0FB07DC427D7CEDA102C819DE7184BBC4EAE0AA9CBC759B16EEF49A383ACD ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
13:58:48.0280 0x1ce0  RTHDVCPL - ok
13:58:48.0373 0x1ce0  [ 3402BBBC16E909985C4F184EB247E9BD, 715806A02C33060C3A20AA1387AC656D92A217115123A2BA16DBE4B37C31880F ] C:\WINDOWS\system32\igfxtray.exe
13:58:48.0389 0x1ce0  IgfxTray - ok
13:58:48.0420 0x1ce0  [ 22BF0CCB64AAE89004355E924E0AD463, BA8FA7DCFAD8396C7A2DB583FF6118361F959040837215FD5198D8D0A4D7E9B6 ] C:\WINDOWS\system32\hkcmd.exe
13:58:48.0452 0x1ce0  HotKeysCmds - ok
13:58:48.0514 0x1ce0  [ FDA7C3D4227097EC5B45BF9E769B5427, C8A41A3EA957A64CECD17B6E5AFAE2775541C0838CE27FD759031B84180FBFA0 ] C:\WINDOWS\system32\igfxpers.exe
13:58:48.0530 0x1ce0  Persistence - ok
13:58:49.0030 0x1ce0  OneDriveSetup - ok
13:58:49.0030 0x1ce0  OneDriveSetup - ok
13:58:49.0280 0x1ce0  [ D11EFD02C97D5654A95D9828EC226DD2, D99EE0D09972A36826AB55C7AEDA4FD5DF4255C02222462ADA4AD649E59A22E2 ] C:\Program Files (x86)\Internet Download Manager\IDMan.exe
13:58:49.0452 0x1ce0  IDMan - detected UnsignedFile.Multi.Generic ( 1 )
13:58:50.0608 0x1ce0  Detect skipped due to KSN trusted
13:58:50.0608 0x1ce0  IDMan - ok
13:58:50.0873 0x1ce0  [ 4D1A2E1A4B2308AFF4F73C037B1CEA89, B0301D5D920E9AE3B7AE8C6F604F68AB1216BF77A6A7B964893727A0C06A43A3 ] C:\Users\josev\AppData\Local\Discord\Update.exe
13:58:50.0936 0x1ce0  Discord - ok
13:58:50.0936 0x1ce0  pCloud - ok
13:58:50.0936 0x1ce0  Waiting for KSN requests completion. In queue: 6
13:58:51.0983 0x1ce0  AV detected via SS2: Windows Defender, windowsdefender:// (  ), 0x61100 ( enabled : updated )
13:58:52.0014 0x1ce0  Win FW state via NFP2: enabled ( trusted )
13:58:52.0858 0x1ce0  ============================================================
13:58:52.0858 0x1ce0  Scan finished
13:58:52.0858 0x1ce0  ============================================================
13:58:52.0873 0x1cd8  Detected object count: 0
13:58:52.0873 0x1cd8  Actual detected object count: 0

Todos son el mismo reporte pero enviado por partes ya que no cabía entero, de igual forma te dejo el .txt por si no se entiende Gracias y feliz dia TDSSKiller.3.1.0.28_01.06.2021_13.55.57_log.txt (299,2 KB)

Hola, buenas @Spacegiraffe

Primero de todo, a partir de ahora pon los reportes tal y como has realizado en tu último mensaje. Es decir, como archivos adjuntos o bien si lo deseas con las etiquetas [code] para ponerlo en formato código. Pero no los pongas más en imágenes, por favor.

Respecto Malwarebytes anti-rootkit >> traes el reporte en formato texto. Ya que con lo que sale en las imágenes no lo puedo analizar todo correctamente.

OK.

Respecto TDSKILLER >> está limpio. :+1:

Traes ese reporte de la forma correcta y seguimos.

Salu2.

1 me gusta

Que tal, disculpa hubo una falla eléctrica donde vivo, acaba de llegar la luz en un rato te mando el reporte Feliz dia

1 me gusta

mbar-log-2021-05-31 (13-07-51).txt (3,3 KB) system-log.txt (29,2 KB)

Aqui te adjunto los 2 reportes

Hola, buenas @Spacegiraffe

Ya he revisado esos logs, :+1: vamos por buen camino.

:one: EN BUSCA / ELIMINACIÓN DE MALWARE

Por favor, descarga todo el software de los enlaces que pongo/de sus respectivos manuales.

Ahora ejecutarás una serie de herramientas respetando el orden los pasos con todos los programas cerrados incluidos los navegadores.

Realiza los pasos que te pongo a continuación, sin cambiar el orden y síguelos al pie de la letra:

0) Descarga Ccleaner Aquí te dejo su manual: Manual de CCleaner , para que sepas como usarlo y configurarlo correctamente.

Lo instalas y lo ejecutas. En la pestaña Limpieza personalizada dejas la configuración predeterminada. Haces clic en Analizar y esperas a que termine. Seguidamente haz clic en Ejecutar Limpiador. Clic en la pestaña Registro > clic en Buscar Problemas esperas que termine. Finalmente clic en Reparar Seleccionadas y realizas una Copia de Seguridad del registro de Windows.

1) Descarga, instala, actualiza y ejecuta Malwarebytes’ Anti-Malware. Aquí te dejo su manual: Manual de Malwarebytes, para que sepas como usarlo y configurarlo correctamente.

  • Realizas un Análisis Personalizado, marcando Todas las casillas de la Derecha y de la Izquierda, actualizando si te lo pide. Es decir: conectas todos tus dispositivos externos (todos los discos duros externos que tengas, así como todas las USB que tengas, incluida la que me has dicho anteriormente y marcas todas las unidades de disco disponibles y las siguientes casillas:

1. Analizar objetos en memoria

2. Analizar configuracion de inicio y registro

3. Analizar dentro de los archivos

  • Pulsar en “Eliminar Seleccionados” para enviar las infecciones a la cuarentena y Reinicias el ordenador.
  • Para acceder posteriormente al informe del análisis te diriges a: Informes >> Registro de análisis >> pulsas en Exportar >> Copiar al Portapapeles y pones el informe en tu próxima respuesta.

2) Descarga Eset Online Scaner Manual de Uso y realizas un análisis del PC, lee detalladamente las instrucciones y realizas un Análisis Personalizado tal y como se indica en su manual. Me traes su reporte.

3) Descarga Kasperky Virus Removal Tool Manual de Uso y realizas un análisis del PC, lee detalladamente las instrucciones y lo realizas tal y como se indica en su manual. En este caso no da reporte alguno, cuando finalice, presionas en la pestaña Report tal y como se indica en su manual y haces una captura de pantalla y la subes.

¿Como subir imágenes al Foro?

4) Utiliza nuevamente CCleaner tal como te dije en el punto 0.

Pegas los reportes de: Malwarebytes, Eset y Kasperky y comentas como va el problema inicial planteado por el cual abriste este tema. También responde a las preguntas que te haya realizado a lo largo de este Post, siempre que te haya hecho alguna, si no, no

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

:warning: Muy Importante :warning: Coloca los diferentes reportes que te he pedido como se muestra en la siguiente imagen:

Salu2.

1 me gusta

Hola buenos dias aqui te dejo algunos reportes que me pediste

Reporte de Malwarebytes:

Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 2/6/21
Hora del análisis: 12:53
Archivo de registro: 1e09a064-c3c3-11eb-bed1-00c0243537e8.json

-Información del software-
Versión: 4.4.0.117
Versión de los componentes: 1.0.1308
Versión del paquete de actualización: 1.0.41251
Licencia: Prueba

-Información del sistema-
SO: Windows 10 (Build 19042.985)
CPU: x64
Sistema de archivos: NTFS
Usuario: DESKTOP-MKTF2H5\josev

-Resumen del análisis-
Tipo de análisis: Análisis personalizado
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 528082
Amenazas detectadas: 5
Amenazas en cuarentena: 5
Tiempo transcurrido: 14 hr, 2 min, 39 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 0
(No hay elementos maliciosos detectados)

Valor del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Secuencia de datos: 0
(No hay elementos maliciosos detectados)

Carpeta: 0
(No hay elementos maliciosos detectados)

Archivo: 5
Malware.AI.4194330616, C:\PROGRAM FILES\IMAGE-LINE\PLUGINS\VST\ADDLIBRARY.EXE, En cuarentena, 1000000, 0, 1.0.41251, 0F2F94BDA62E91B4FA0067F8, dds, 01271851, F7DF0571B151C140000B90A21A6364F1, C91E8C1E4DA704A9750356C5956DB806907458E35FBE7F434E5E5BA65F218F61
Malware.AI.3599888753, C:\USERS\JOSEV\DESKTOP\INSTALADORES\OTROS\UNLOCKER\UNLOCKER1.9.1 ALINSSOF.ZIP.PAAS, Se eliminará al reiniciar, 1000000, 0, 1.0.41251, A2F86349387BF3FAD691F171, dds, 01271851, BDBA229D6EB881D2BACD5B4E546D8DE6, 0ABBB41778D84D1D812C3B8B865178200176533F24B972AB0B687447CA616DB4
Malware.AI.3676333783, C:\USERS\JOSEV\DESKTOP\INSTALADORES\IOBIT\IU-CONTRASEÑA_ BYGERMANAGUILAR\IOBIT UNINSTALLER 10.4.0.11.EXE, Se eliminará al reiniciar, 1000000, 0, 1.0.41251, C73E755FD871827ADB2066D7, dds, 01271851, 1B5E9045D279C7D218605711F78FBF69, EA026DB71C164C0E58380DF5FE8AE605EB7D4F3FB838014E7E7F8B5AD5379117
Malware.AI.4256648491, C:\USERS\JOSEV\DESKTOP\INSTALADORES\GESTORES DE DESCARGAS\IDM (6.38.18)\IDM 6.38.18 2021 BY PCSOF\INTERNET.DOWNLOAD.MANAGER.V6.38.18.EXE, En cuarentena, 1000000, 0, 1.0.41251, 1134880555F3B630FDB74D2B, dds, 01271851, F17A3B85966B29DA4A82F267463534F6, 10910B1560105B2E36F108960D7E1152749E687A5507BD66B392AB8B270D7BFA
Malware.AI.2577125126, C:\USERS\JOSEV\DESKTOP\GILDRED\COSAS DE FAMILIA\FOTOS GILDRED VARIAS\MINECRAFT ACTUALIZABLE.EXE, Se eliminará al reiniciar, 1000000, 0, 1.0.41251, 92D57ADC3B590C58999BCF06, dds, 01271851, DEDC036E4DBCF18DD8C8F457C7FDF226, A63569213D865EA9FEBBEF257F305FBE517F97B645F656E8F3945ABB9F8EBAC0

Sector físico: 0
(No hay elementos maliciosos detectados)

WMI: 0
(No hay elementos maliciosos detectados)


(end)

Reporte de Eset:

3/6/2021 8:12:01 a. m.
Archivos explorados: 406553
Archivos detectados: 5
Archivos desinfectados: 5
Tiempo total de exploración 12:17:19
Estado de la exploración: Finalizado


C:\Users\josev\Desktop\Gildred\ARCHIVOS TOTAL\CURSOS NUEVOS OCTUBRE para imprimir\CURSOS NUEVOS OCTUBRE.pptx ACTUALIZADA.pptx1\Mas\disable_activation.cmd	BAT/HostsChanger.A aplicación potencialmente no segura	desinfectado por eliminación
C:\Users\josev\Desktop\Gildred\Cosas de familia\fotos gildred varias\Minecraft Actualizable.exe	Java/GameTool.A aplicación potencialmente no segura	desinfectado por eliminación
C:\Users\josev\Desktop\instaladores\IObit\IU-CONTRASEÑA_ ByGermanAguilar\IObit Uninstaller 10.4.0.11.exe	una variante de Win32/HackTool.Crack.KN aplicación potencialmente no segura	desinfectado por eliminación
C:\Users\josev\Desktop\instaladores\Otros\Unlocker\Unlocker1.9.1 AlinSsoF.zip.paas	una variante de Win32/Toolbar.Escort.C aplicación potencialmente no deseada,una variante de Win32/Toolbar.Babylon aplicación potencialmente no deseada,Win32/Toolbar.Babylon.S aplicación potencialmente no deseada,Win32/Toolbar.Babylon.R aplicación potencialmente no deseada,una variante de Win32/Toolbar.Babylon.AA aplicación potencialmente no deseada,Win32/Toolbar.Montiera.T aplicación potencialmente no deseada,Win32/Toolbar.Babylon.AH aplicación potencialmente no deseada,una variante de Win32/Bundled.Toolbar.Ask aplicación potencialmente no segura	eliminado
C:\Users\josev\Desktop\instaladores\Reproductores\Aimp\Aimp (4.70.2248).exe	una variante de Win32/AIMP.A aplicación potencialmente no deseada	desinfectado por eliminación

Estoy descargando el Virus Removal para pasarte su reporte

Referente al Malware, ya no se convierten mis archivos en .Paas, los que agrego nuevos, sin embargo hay aplicaciones que me dejaron de funcionar como el Windows Defender, el Opera GX y otros que no puedo ejecutar porque me pide descargarlos de nuevo, además de que el pc ya no esta consumiendo cpu y ram exageradamente como antes

Aqui te dejo el reporte del Kasperky Virus Removal, no me detecto ningún malware

Hola, buenas @Spacegiraffe

Respecto al Malwarebytes >> ha hecho lo que debía de hacer :+1:. De todas formas sí que quiero comentarte que el Análisis con este tardo tanto, ya que marcaste la opción de Rootkits (por lo que veo en el log). Pues puede hacer que el programa se cuelgue y no finalice el análisis o hacer que este tarde muchísimo (como lo ha sido en tu caso). Aparte, hay mejores formas de buscar Rootkits en una máquina y ya nos hemos encargado de buscar antes RootKits y formas sigilosas de malware.

Respecto Eset >> ha hecho lo que debía de hacer :+1:.

Respecto Kasperky >> :+1: está limpio.

Ok. Perfecto. Esto es buena señal, vamos por el buen camino. :+1: Pero nos hemos de asegurar que tu máquina está bien limpia de bichos. Por todo lo que he visto y lo que tu mismo comentas, casi seguro que ya esta limpia y es muy poco probable de que encuentre algo raro. Sí que es más probable que encuentre algunas aplicaciones, políticas del sistema u cosas varias dañadas o bloqueadas y con FRST las podremos reparar.

OK :+1:. Respecto a lo que comentas de las aplicaciones todo dependerá de en que partes del sistema haya afectado el RansomWare.

Así que vamos a analizar tu sistema a más bajo nivel (de forma más exhaustiva y detallada), para descartar que no queden restos de malware u elementos o partes del sistema corrompidas o dañadas.

Vamos a darle caña…

EN BUSCA / ELIMINACIÓN DE MALWARE

:one: Desactivas tu antivirus :arrow_forward: Como deshabilitar temporalmente un antivirus y cualquier programa de seguridad que tengas activado.

LO DESCARGAS EN TU ESCRITORIO MUY IMPORTANTE (y no en otro sitio).

Descargas Farbar Recovery Scan Tool MUY IMPORTANTE >> seleccionas la versión adecuada para la arquitectura correspondiente de tu Ordenador (32 o 64bits). :arrow_forward: ¿Cómo saber si mi Windows es de 32 o 64 bits.?

:warning: Una vez descargado FRST, desconectas tu equipo de completamente de Internet (apagas el router) >> Super Importante. Acto seguido, cierras también cualquier otro programa que tengas abierto.

:two: Farbar Recovery Scan Tool

  1. Ejecutas el FRST.exe (Si utilizas Windows Vista/7/8 o 10, presionas click derecho y seleccionas Ejecutar como Administrador).

  2. Aparecerá una ventana con un mensaje de Disclaimer/Responsabilidad, presionas sobre Si o Yes.

  3. En la ventana principal del programa presionas sobre Analizar/Scan y esperas a que finalice el análisis.

  4. Aparecerán dos logs/reportes que serán: Frst.txt y Addition.txt, estos quedarán guardados en el escritorio.

:three: Activas de nuevo tu antivirus y cualquier programa de seguridad que tengas activado. También conectas nuevamente tu equipo a Internet.

:four: PRÓXIMA RESPUESTA

Pegas los reportes de FRST.txt y Addition.txt. Debes de poner ambos reportes todos enteros con absolutamente todo su contenido. Deberás de realizar varios mensajes si recibes un mensaje de error/advertencia indicando que es muy largo dicho reporte que formará el mensaje (más de 50.000 carácteres aprox.).

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

:warning: Muy Importante :warning: Coloca los diferentes reportes que te he pedido como se muestra en la siguiente imagen:

Salu2.

1 me gusta

Disculpa los reenvió porque los subí mal FSRT.txt

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 02-06-2021
Ejecutado por josev (administrador) sobre DESKTOP-MKTF2H5 (ECS H61H2-CM) (04-06-2021 14:45:39)
Ejecutado desde C:\Users\josev\Desktop
Perfiles cargados: josev
Platform: Windows 10 Pro Versión 20H2 19042.985 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: Edge
Modo de Inicio: Normal

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

() [Archivo no firmado] C:\Riot Games\Riot Client\RiotClientCrashHandler.exe <2>
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) System Usage Report -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe
(Intel(R) System Usage Report -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe
(Intel(R) System Usage Report -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe
(Intel(R) System Usage Report -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avpui.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12104.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\RiotClientServices.exe
(Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\UX\RiotClientUx.exe
(Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\UX\RiotClientUxRender.exe <2>

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [19677688 2021-04-29] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\Run: [Discord] => C:\Users\josev\AppData\Local\Discord\Update.exe [1512040 2021-03-18] (Discord Inc. -> GitHub)
HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [33770112 2021-05-20] (Piriform Software Ltd -> Piriform Software Ltd)

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {1357A1FB-8D43-4C13-99A5-2C4A74DE7C32} - System32\Tasks\Opera GX scheduled Autoupdate 1619726949 => C:\Users\josev\AppData\Local\Programs\Opera GX\launcher.exe [1870488 2021-04-29] (Opera Software AS -> Opera Software)
Task: {170578EB-7553-41C5-8BAB-D2F7D621594C} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3098912 2020-11-05] (Intel(R) System Usage Report -> Intel Corporation)
Task: {1C4A8F6B-C6D8-4091-BB4B-1B8E1EF776C9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {2C579D36-BEAD-4BEC-BE27-34F5213B52CA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {3550F50C-D49B-4A6F-BB86-0BB3C65E6AF9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1557200 2021-01-25] (Adobe Inc. -> Adobe Inc.)
Task: {43EBFA15-AE95-4E28-88E5-4ABE3B70E770} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {4AB6C823-D077-44CE-9C52-A368486A0552} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {5445C3F5-BC6D-4F25-BCDD-0C9123539B99} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\josev\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [18007968 2021-06-02] (ESET, spol. s r.o. -> ESET)
Task: {595ECD05-05D3-45ED-994C-47589A0004DA} - System32\Tasks\Uninstaller_SkipUac_josev => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [6688256 2021-03-10] (IObit) [Archivo no firmado]
Task: {60EDC04A-07AB-4F93-9397-A9FF17C17844} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {644FA49C-9BC9-4F0C-9D61-55C994236AB3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {A236E8FC-E770-49EA-9123-2B6C96260A34} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2021-05-20] (Piriform Software Ltd -> Piriform)
Task: {A2EC52A8-BF64-4820-A46A-6FAFF1F1EC88} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [375416 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {A4673C02-24F6-4C1E-8716-CE11E8FD5343} - System32\Tasks\Driver Booster SkipUAC (josev) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [8225280 2021-04-02] (IObit) [Archivo no firmado]
Task: {A7BDD069-8FE5-45AC-913C-BF7C3F1DB31F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [28158080 2021-05-20] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {D9A24258-7A4D-43B9-B2FF-E8B97C781BB1} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [3098912 2020-11-05] (Intel(R) System Usage Report -> Intel Corporation)
Task: {E822178C-B835-4DA5-8D6F-3F760EC25822} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\josev\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [18007968 2021-06-02] (ESET, spol. s r.o. -> ESET)
Task: {F70FE66B-CCC4-404B-A116-BC4D2ACF4C51} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {FB0B32BA-1262-4139-B1A3-0E654707B8A9} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2104.14-0\MpCmdRun.exe [595288 2021-05-15] (Microsoft Windows Publisher -> Microsoft Corporation)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Tcpip\Parameters: [DhcpNameServer] 93.115.21.107 8.8.8.8
Tcpip\..\Interfaces\{2cad19c3-2bb6-45eb-8b39-21377fd24c67}: [DhcpNameServer] 93.115.21.107 8.8.8.8
Tcpip\..\Interfaces\{2ff2b570-ccea-4826-a6e9-b0aa666ab315}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{b3ee42b2-d659-4494-ad6b-7f3312726658}: [DhcpNameServer] 192.168.43.66

Edge: 
=======
Edge Extension: (Sin Nombre) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [no encontrado]
Edge Extension: (Sin Nombre) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [no encontrado]
Edge Extension: (Sin Nombre) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [no encontrado]
Edge Extension: (Sin Nombre) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [no encontrado]
Edge Profile: C:\Users\josev\AppData\Local\Microsoft\Edge\User Data\Default [2021-06-04]
Edge Notifications: Default -> hxxps://forospyware.com
Edge Extension: (Kaspersky Protection) - C:\Users\josev\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2021-05-31]
Edge HKU\S-1-5-21-2251894981-3858074833-453683670-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]
Edge HKU\S-1-5-21-2251894981-3858074833-453683670-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx <no encontrado>

FireFox:
========
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => no encontrado
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => no encontrado
FF HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\josev\AppData\Roaming\IDM\idmmzcc5 => no encontrado
FF HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => no encontrado
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2021-04-27] (Adobe Inc. -> Adobe Systems Inc.)

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <no encontrado>
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/kaspersky-protection/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <no encontrado>

Opera: 
=======
StartMenuInternet: (HKU\S-1-5-21-2251894981-3858074833-453683670-1001) Opera GXStable - "C:\Users\josev\AppData\Local\Programs\Opera GX\Launcher.exe"

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169672 2021-01-25] (Adobe Inc. -> Adobe Inc.)
R2 AVP21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe [384280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S2 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [12872144 2021-05-31] (EnigmaSoft Limited -> EnigmaSoft Limited)
S3 klvssbridge64_21.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\vssbridge64.exe [479280 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S2 KSDE5.3; C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.3\ksde.exe [646520 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S2 MBAMInstallerService; C:\Users\josev\AppData\Local\Temp\MBAMInstallerService.exe [6905952 2021-06-02] (Malwarebytes Inc -> Malwarebytes) <==== ATENCIÓN
R2 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [526800 2021-05-31] (EnigmaSoft Limited -> EnigmaSoft Limited)
S2 MBAMService; "C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe" [X]

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R1 cbfsconnect2017; C:\WINDOWS\system32\drivers\cbfsconnect2017.sys [481296 2020-06-24] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [250032 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18816 2021-05-11] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R3 GeneStor; C:\WINDOWS\system32\DRIVERS\GeneStor.sys [126168 2021-04-29] (Genesys Logic, Inc. -> GenesysLogic)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [110336 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [211704 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [126216 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [41656 2021-02-19] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [514840 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [657696 2021-05-08] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1439456 2021-05-08] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 klids; C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys [253736 2021-06-02] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1042712 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [98040 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [112392 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [112904 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [85256 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [96008 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [55592 2021-02-19] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [263888 2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [309104 2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [115744 2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [224880 2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [155912 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [327936 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [300808 2021-02-19] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 LifeCamTrueColor; C:\WINDOWS\system32\DRIVERS\LifeCamTrueColor.sys [37928 2016-07-27] (Microsoft Corporation -> Microsoft Corporation)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2021-06-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248992 2021-06-03] (Malwarebytes Inc -> Malwarebytes)
R3 mlkumidi; C:\WINDOWS\system32\drivers\mlkumidi.sys [57408 2012-08-29] (MusicLab, Inc. -> MusicLab, Inc.)
R3 vpnpbus; C:\WINDOWS\System32\drivers\vpnpbus.sys [20496 2020-06-24] (Microsoft Windows Hardware Compatibility Publisher -> Callback Technologies, Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [49560 2021-05-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [73960 2021-05-15] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) (Lista blanca) =========

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2021-06-04 14:27 - 2021-06-04 14:33 - 000032028 _____ C:\Users\josev\Desktop\Addition.txt
2021-06-04 14:16 - 2021-06-04 14:47 - 000018337 _____ C:\Users\josev\Desktop\FRST.txt
2021-06-04 14:15 - 2021-06-04 14:46 - 000000000 ____D C:\FRST
2021-06-04 14:15 - 2021-06-04 14:15 - 002300416 _____ (Farbar) C:\Users\josev\Desktop\FRST64.exe
2021-06-04 14:14 - 2021-06-04 14:15 - 002300416 _____ (Farbar) C:\Users\josev\Downloads\FRST64.exe
2021-06-03 23:24 - 2021-06-03 23:24 - 000000000 ____D C:\Users\josev\AppData\Local\ElevatedDiagnostics
2021-06-03 19:14 - 2021-06-03 19:14 - 000000000 ____D C:\Users\josev\Desktop\vainas pal ransom
2021-06-03 19:13 - 2021-06-03 19:13 - 000000000 ____D C:\Users\josev\Desktop\archivos encriptados ptm
2021-06-03 19:00 - 2021-06-03 19:00 - 001180768 _____ (Emsisoft Ltd.) C:\Users\josev\Desktop\decrypt_STOPDjvu.exe
2021-06-03 19:00 - 2021-06-03 19:00 - 000000000 _____ C:\Users\josev\Downloads\SIN CONFIRMAR 887832.CRDOWNLOAD
2021-06-03 19:00 - 2021-06-03 19:00 - 000000000 _____ C:\Users\josev\Downloads\SIN CONFIRMAR 763906.CRDOWNLOAD
2021-06-03 13:29 - 2021-06-03 13:29 - 000010626 _____ C:\Users\josev\Documents\cc_20210603_132949 2222.reg
2021-06-03 13:13 - 2021-06-03 13:13 - 000000000 ____D C:\KVRT2020_Data
2021-06-03 08:24 - 2021-06-03 08:40 - 104266608 _____ (AO Kaspersky Lab) C:\Users\josev\Downloads\KVRT.exe
2021-06-03 08:13 - 2021-06-03 08:13 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000004-000000.txt
2021-06-03 08:12 - 2021-06-03 08:12 - 000003858 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2021-06-03 08:12 - 2021-06-03 08:12 - 000003416 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2021-06-02 18:21 - 2021-06-02 18:21 - 000361313 _____ C:\Users\josev\Desktop\4.2.1 EL COMPOSITOR y el Copyright.pdf
2021-06-02 18:21 - 2021-06-02 18:21 - 000346934 _____ C:\Users\josev\Desktop\4.1. EL ARTISTA.pdf
2021-06-02 18:20 - 2021-06-02 18:21 - 000361313 _____ C:\Users\josev\Downloads\4.2.1 EL COMPOSITOR y el Copyright.pdf
2021-06-02 18:20 - 2021-06-02 18:21 - 000346934 _____ C:\Users\josev\Downloads\4.1. EL ARTISTA.pdf
2021-06-02 12:36 - 2021-06-02 12:36 - 000001423 _____ C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2021-06-02 12:25 - 2021-06-02 12:36 - 011697056 _____ (ESET) C:\Users\josev\Downloads\esetonlinescanner.exe
2021-06-02 12:16 - 2021-06-03 23:34 - 000248992 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2021-06-02 12:16 - 2021-06-02 12:16 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2021-06-02 12:15 - 2021-06-02 12:51 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2021-06-02 12:15 - 2021-06-02 12:49 - 000199128 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2021-06-02 11:58 - 2021-06-02 11:58 - 000000000 ____D C:\Program Files\Malwarebytes
2021-06-02 11:57 - 2021-06-02 11:57 - 002080712 _____ (Malwarebytes) C:\Users\josev\Downloads\MBSetup.exe
2021-06-02 11:54 - 2021-06-02 11:54 - 000110988 _____ C:\Users\josev\Documents\cc_20210602_115402.reg
2021-06-02 11:47 - 2021-06-04 14:03 - 000000000 ____D C:\Program Files\CCleaner
2021-06-02 11:47 - 2021-06-02 11:47 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2021-06-02 11:47 - 2021-06-02 11:47 - 000002888 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2021-06-02 11:47 - 2021-06-02 11:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2021-06-02 11:42 - 2021-06-02 11:46 - 031491256 _____ (Piriform Software Ltd) C:\Users\josev\Downloads\ccsetup580.exe
2021-06-01 13:53 - 2021-06-01 13:53 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000003-000000.txt
2021-06-01 13:46 - 2021-06-01 13:47 - 005190656 _____ C:\Users\josev\Downloads\windows-defender-7.0.msi
2021-05-31 23:39 - 2021-06-01 00:01 - 000000000 ____D C:\Users\josev\AppData\Local\pCloud
2021-05-31 23:39 - 2021-05-31 23:39 - 000000000 ____D C:\Users\josev\AppData\Local\pCloud_AG
2021-05-31 23:37 - 2020-06-25 03:19 - 000270088 _____ (Callback Technologies, Inc.) C:\WINDOWS\system32\cbfsconnectNetRdr2017.dll
2021-05-31 23:37 - 2020-06-25 03:19 - 000234248 _____ (Callback Technologies, Inc.) C:\WINDOWS\SysWOW64\cbfsconnectNetRdr2017.dll
2021-05-31 23:37 - 2020-06-25 03:19 - 000189192 _____ (Callback Technologies, Inc.) C:\WINDOWS\system32\cbfsconnectMntNtf2017.dll
2021-05-31 23:37 - 2020-06-25 03:19 - 000010504 _____ (Callback Technologies, Inc.) C:\WINDOWS\system32\cbfsconnectevtmsg.dll
2021-05-31 23:37 - 2020-06-25 03:18 - 000162056 _____ (Callback Technologies, Inc.) C:\WINDOWS\SysWOW64\cbfsconnectMntNtf2017.dll
2021-05-31 23:37 - 2020-06-24 23:55 - 000481296 _____ (Callback Technologies, Inc.) C:\WINDOWS\system32\Drivers\cbfsconnect2017.sys
2021-05-31 23:37 - 2020-06-24 23:55 - 000020496 _____ (Callback Technologies, Inc.) C:\WINDOWS\system32\Drivers\vpnpbus.sys
2021-05-31 23:23 - 2021-05-31 23:30 - 039634496 _____ (pCloud AG) C:\Users\josev\Downloads\pCloud_Windows_3.10.4_x86.exe
2021-05-31 23:11 - 2021-05-31 23:11 - 000974216 _____ (Emsisoft Ltd) C:\Users\josev\Downloads\decrypt_NemucodAES.exe
2021-05-31 23:11 - 2021-05-31 23:11 - 000000000 _____ C:\Users\josev\Downloads\SIN CONFIRMAR 127845.CRDOWNLOAD
2021-05-31 21:40 - 2021-05-31 21:40 - 000001079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpyHunter5.lnk
2021-05-31 21:40 - 2021-05-31 21:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnigmaSoft
2021-05-31 21:40 - 2021-05-31 21:40 - 000000000 ____D C:\ProgramData\EnigmaSoft Limited
2021-05-31 21:38 - 2021-05-31 21:39 - 000000000 ____D C:\sh5ldr
2021-05-31 21:23 - 2021-05-31 21:23 - 000000000 ____D C:\Program Files\EnigmaSoft
2021-05-31 21:22 - 2021-05-31 21:23 - 006611408 _____ (EnigmaSoft Limited) C:\Users\josev\Downloads\SpyHunter-Installer.exe
2021-05-31 21:22 - 2021-05-31 21:23 - 000000000 _____ C:\Users\josev\Downloads\SIN CONFIRMAR 471900.CRDOWNLOAD
2021-05-31 21:11 - 2021-05-31 21:11 - 000309104 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2021-05-31 21:08 - 2021-05-31 21:08 - 000000000 ____D C:\Program Files\Common Files\AV
2021-05-31 21:07 - 2021-05-31 21:07 - 000263888 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2021-05-31 21:07 - 2021-05-31 21:07 - 000224880 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2021-05-31 21:07 - 2021-05-31 21:07 - 000115744 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2021-05-31 21:07 - 2021-05-31 21:07 - 000002180 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2021-05-31 21:07 - 2021-05-31 21:07 - 000001165 _____ C:\Users\Public\Desktop\Kaspersky VPN.lnk
2021-05-31 21:07 - 2021-05-31 21:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky VPN
2021-05-31 21:07 - 2021-05-31 21:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2021-05-31 21:06 - 2021-05-31 21:07 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2021-05-31 21:06 - 2021-05-31 21:07 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2021-05-31 21:06 - 2021-02-19 21:09 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2021-05-31 21:06 - 2021-02-19 21:08 - 001042712 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2021-05-31 21:06 - 2021-02-19 21:08 - 000514840 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2021-05-31 20:02 - 2021-05-31 20:02 - 002769752 _____ (Kaspersky) C:\Users\josev\Downloads\kts21.3.10.391es_25617.exe
2021-05-31 17:05 - 2021-06-02 12:36 - 000000000 ____D C:\Users\josev\AppData\Local\ESET
2021-05-31 16:19 - 2021-05-31 16:26 - 008702880 _____ (ESET) C:\Users\josev\Desktop\eset_internet_security_live_installer.exe
2021-05-31 13:37 - 2021-06-04 14:10 - 000000000 ___HD C:\Users\josev\Downloads\.opera
2021-05-31 13:37 - 2021-06-04 14:10 - 000000000 ___HD C:\Users\josev\.opera
2021-05-31 13:32 - 2021-05-31 15:32 - 000000000 ____D C:\TDSSKiller_Quarantine
2021-05-31 13:07 - 2021-06-02 12:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2021-05-31 13:07 - 2021-05-31 13:07 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3623522A.sys
2021-05-31 13:04 - 2021-05-31 13:41 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2021-05-31 12:51 - 2021-06-03 22:57 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2021-05-31 01:03 - 2021-05-31 19:36 - 000000000 ____D C:\@RestoreQuarantine
2021-05-31 00:40 - 2021-05-31 08:07 - 000000000 ____D C:\Users\josev\Documents\RegRun2
2021-05-31 00:40 - 2021-05-31 01:01 - 000000000 ____D C:\Users\Public\Documents\RegRunInfo
2021-05-31 00:39 - 2021-05-31 00:47 - 044451582 _____ C:\Users\josev\Desktop\unhackme_setup.exe.paas
2021-05-31 00:32 - 2021-05-31 00:47 - 043941125 _____ C:\Users\josev\Downloads\unhackme-12-51.zip.paas
2021-05-31 00:14 - 2021-05-31 00:14 - 000000000 ____D C:\ProgramData\Q2DYW1LZCFOQ9F6WWXYFF4KNH
2021-05-31 00:13 - 2021-05-31 00:13 - 000000049 _____ C:\Users\josev\AppData\Local\script.ps1
2021-05-31 00:05 - 2021-05-31 00:16 - 035048230 _____ C:\Users\josev\Desktop\Windows-KB890830-x64-V5.89.exe.paas
2021-05-30 22:38 - 2021-05-30 22:38 - 000000000 ____D C:\Users\josev\AppData\Roaming\EaseUS
2021-05-30 22:38 - 2021-05-30 22:38 - 000000000 ____D C:\ProgramData\SystemAcCrux
2021-05-30 22:32 - 2021-05-30 22:32 - 000000000 ____D C:\Program Files\EaseUS
2021-05-30 22:32 - 2021-05-30 18:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard
2021-05-30 21:52 - 2021-05-30 21:52 - 000000000 ____D C:\ProgramData\3BR53LEZ3F00VNW921Y0VOTHL
2021-05-30 21:40 - 2021-05-30 21:40 - 000000560 _____ C:\Users\josev\AppData\Local\bowsakkdestx.txt
2021-05-30 21:40 - 2021-05-30 21:40 - 000000000 ____D C:\SystemID
2021-05-30 21:39 - 2021-05-30 21:39 - 000000000 ____D C:\Program Files (x86)\foler
2021-05-30 21:37 - 2021-05-30 21:37 - 000000000 ____D C:\ProgramData\XM5F4DB5NX1APE5P44PKAO610
2021-05-30 21:37 - 2021-05-30 18:34 - 000000000 ____D C:\Users\josev\Documents\iZotope iDrum Content
2021-05-30 21:36 - 2021-05-30 21:36 - 000000000 ____D C:\Users\josev\AppData\Roaming\Serian
2021-05-30 21:31 - 2021-05-30 21:31 - 000000000 ____D C:\ProgramData\Camel Audio
2021-05-30 21:30 - 2021-05-30 21:45 - 003099021 _____ C:\Users\josev\Desktop\215_redo_install_comp.exe.paas
2021-05-30 21:25 - 2021-05-30 21:47 - 000000000 ____D C:\Users\josev\Desktop\Nicky Romero Kickstart
2021-05-30 20:22 - 2021-05-30 21:45 - 000108892 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube (4).jpg.paas
2021-05-30 20:13 - 2021-05-30 21:45 - 001151858 _____ C:\Users\josev\Downloads\Photo_1622419694092_Processed.png.paas
2021-05-30 08:18 - 2021-05-30 21:45 - 058801621 _____ C:\Users\josev\Desktop\NI Massive v1.5.5.exe.paas
2021-05-30 01:53 - 2021-05-30 21:45 - 177227434 _____ C:\Users\josev\Desktop\serum.zip.paas
2021-05-29 21:03 - 2021-05-30 21:45 - 000007529 _____ C:\Users\josev\Documents\scpres.vbs.paas
2021-05-29 20:58 - 2021-05-31 08:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellar Phoenix Windows Data Recovery
2021-05-29 20:58 - 2021-05-30 22:24 - 000000000 _RSHD C:\ProgramData\Key-Base
2021-05-29 20:58 - 2021-05-29 20:58 - 000000000 ____D C:\ProgramData\{FBD48A78-14C4-559A-919F-E4CF1DF9C1C7}
2021-05-29 20:12 - 2021-05-30 21:45 - 004788613 _____ C:\Users\josev\Downloads\Chase Pulse.mp3.paas
2021-05-29 18:08 - 2021-05-31 19:36 - 000000000 ____D C:\Andries Benade
2021-05-29 18:08 - 2021-05-29 18:08 - 000000000 ____D C:\Users\josev\AppData\LocalLow\Unknown Vendor
2021-05-29 18:08 - 2021-05-29 18:08 - 000000000 ____D C:\Users\josev\AppData\LocalLow\Andries Benade'
2021-05-29 17:52 - 2021-05-30 21:45 - 066056142 _____ C:\Users\josev\Downloads\Floors II.zip.paas
2021-05-29 15:02 - 2021-05-29 15:02 - 000000000 ____D C:\Users\josev\AppData\LocalLow\MSCHF
2021-05-29 01:13 - 2021-05-31 08:07 - 000000000 ____D C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2021-05-29 01:05 - 2021-05-29 01:06 - 000000000 ____D C:\Users\josev\AppData\Local\Steam
2021-05-28 19:18 - 2021-06-01 13:05 - 000000000 ____D C:\Program Files (x86)\Steam
2021-05-28 19:18 - 2021-05-31 08:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2021-05-27 17:16 - 2021-05-30 21:45 - 061896908 _____ C:\Users\josev\Desktop\Olivia Rodrigo - deja vu (ZEXTONE & Juan Dileju Extended Remix).wav.paas
2021-05-27 16:47 - 2021-05-30 21:45 - 061896908 _____ C:\Users\josev\Downloads\Olivia Rodrigo - deja vu (ZEXTONE & Juan Dileju Extended Remix).wav.paas
2021-05-27 16:46 - 2021-05-30 21:45 - 000026446 _____ C:\Users\josev\Downloads\CANAIMA NATIONAL PARK.doc.paas
2021-05-27 16:42 - 2021-05-30 21:45 - 000397028 _____ C:\Users\josev\Downloads\image.png.paas
2021-05-25 20:57 - 2021-05-30 21:45 - 135200248 _____ C:\Users\josev\Downloads\T-Pain EFFECT.rar.paas
2021-05-25 20:49 - 2021-05-30 21:45 - 013824615 _____ C:\Users\josev\Downloads\Pumper 2 v1.0.1 WIN-OSX.rar.paas
2021-05-25 20:28 - 2021-05-30 21:45 - 004375831 _____ C:\Users\josev\Downloads\Nicky Romero Kickstart.rar.paas
2021-05-25 20:05 - 2021-05-30 21:45 - 007149839 _____ C:\Users\josev\Downloads\camelcrusher-win_mac.zip.paas
2021-05-22 18:12 - 2021-05-31 08:08 - 000000000 ____D C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2021-05-22 18:12 - 2021-05-31 08:08 - 000000000 ____D C:\Users\josev\AppData\Roaming\discord
2021-05-22 18:12 - 2021-05-31 08:08 - 000000000 ____D C:\Users\josev\AppData\Local\Discord
2021-05-22 18:12 - 2021-05-22 18:12 - 000002274 _____ C:\Users\josev\Desktop\Discord.lnk
2021-05-22 18:12 - 2021-05-22 18:12 - 000000000 ____D C:\Users\josev\AppData\Local\SquirrelTemp
2021-05-22 15:36 - 2021-05-30 21:45 - 000017343 _____ C:\Users\josev\Desktop\PROD01-U03-GR05 CO EVALUACION.docx.paas
2021-05-22 15:33 - 2021-05-30 21:45 - 002283345 _____ C:\Users\josev\Downloads\PRO1-U3-G24.pdf.paas
2021-05-22 15:19 - 2021-05-30 21:45 - 000017575 _____ C:\Users\josev\Downloads\Formato Co-Evaluación.docx.paas
2021-05-22 15:10 - 2021-05-30 21:45 - 000042318 _____ C:\Users\josev\Downloads\lectura1.doc.paas
2021-05-20 18:15 - 2021-05-30 21:45 - 000141052 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube (3).jpg.paas
2021-05-20 18:12 - 2021-05-30 21:45 - 000056714 _____ C:\Users\josev\Downloads\imagen_2021-05-20_181231.png.paas
2021-05-20 18:03 - 2021-05-30 21:45 - 001448763 _____ C:\Users\josev\Downloads\Photo_1621547605829_Processed.png.paas
2021-05-19 18:30 - 2021-05-30 21:45 - 239350315 _____ C:\Users\josev\Downloads\vscyrix_11_win_x64.zip.paas
2021-05-19 00:53 - 2021-05-30 21:45 - 000091568 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube (2).jpg.paas
2021-05-17 18:47 - 2021-05-31 08:08 - 000000000 ____D C:\Users\josev\Desktop\dxwnd
2021-05-17 18:22 - 2021-05-30 21:45 - 000635479 _____ C:\Users\josev\Downloads\Dialnet-25PoemasSobreLaCiudadEnTraduccionDeJoseLuisReinaPa-4865800.pdf.paas
2021-05-16 17:51 - 2021-05-30 21:45 - 000152308 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube (1).jpg.paas
2021-05-16 17:41 - 2021-05-30 21:45 - 001050663 _____ C:\Users\josev\Downloads\Photo_1621204052472_Processed.png.paas
2021-05-16 12:54 - 2021-05-30 21:45 - 192151965 _____ C:\Users\josev\Downloads\tux_trouble.zip.paas
2021-05-16 11:50 - 2021-05-30 21:45 - 164372251 _____ C:\Users\josev\Downloads\bf-ugh_1_3.zip.paas
2021-05-16 11:34 - 2021-05-16 11:34 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000002-000000.txt
2021-05-15 19:33 - 2021-05-15 20:02 - 000007602 _____ C:\Users\josev\AppData\Local\Resmon.ResmonCfg
2021-05-15 16:55 - 2021-05-15 16:55 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2021-05-14 20:44 - 2021-05-30 21:45 - 000124362 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube.jpg.paas
2021-05-14 19:20 - 2021-05-30 21:45 - 000008018 _____ C:\Users\josev\Downloads\itowngameplay_bopeebo.zip.paas
2021-05-14 19:05 - 2021-05-30 21:45 - 001380334 _____ C:\Users\josev\Downloads\friday-night-funkin-windows-64bit.zip.opdownload.paas
2021-05-14 18:36 - 2021-05-30 21:45 - 009369605 _____ C:\Users\josev\Downloads\WhatsApp Audio 2021-05-14 at 6.28.03 PM.mp4.paas
2021-05-14 18:22 - 2021-05-30 21:45 - 003141844 _____ C:\Users\josev\Downloads\La Industria Musical (1).pdf.paas
2021-05-14 17:33 - 2021-05-30 21:45 - 003141819 _____ C:\Users\josev\Downloads\La Industria Musical.pdf.paas
2021-05-13 19:48 - 2021-05-30 21:45 - 000023630 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-13 at 7.47.25 PM.jpeg.paas
2021-05-12 22:52 - 2021-05-30 21:45 - 000040270 _____ C:\Users\josev\Downloads\PAUL GAUGUIN.doc.paas
2021-05-12 22:49 - 2021-05-30 21:45 - 000036686 _____ C:\Users\josev\Downloads\The Prohibition Era.doc.paas
2021-05-12 22:02 - 2021-05-30 21:45 - 000121294 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-12 at 9.59.11 PM.jpeg.paas
2021-05-12 20:26 - 2021-05-30 21:45 - 000024217 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-12 at 8.25.56 PM.jpeg.paas
2021-05-12 20:15 - 2021-05-30 21:45 - 000051256 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-12 at 7.17.35 PM.jpeg.paas
2021-05-12 19:10 - 2021-05-30 21:45 - 000054439 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-12 at 7.05.52 PM.jpeg.paas
2021-05-12 18:00 - 2021-05-12 18:00 - 000000914 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2021-05-12 18:00 - 2021-05-12 18:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2021-05-12 18:00 - 2021-05-12 18:00 - 000000000 ____D C:\Program Files\CPUID

FSRT.txt parte 2

2021-05-12 16:47 - 2021-05-12 16:47 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2021-05-12 16:47 - 2021-05-12 16:47 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2021-05-12 16:47 - 2021-05-12 16:47 - 001687040 _____ C:\WINDOWS\system32\libcrypto.dll
2021-05-12 16:47 - 2021-05-12 16:47 - 000700928 _____ C:\WINDOWS\system32\FsNVSDeviceSource.dll
2021-05-12 16:47 - 2021-05-12 16:47 - 000157184 _____ C:\WINDOWS\system32\uwfcsp.dll
2021-05-12 16:47 - 2021-05-12 16:47 - 000153600 _____ C:\WINDOWS\system32\uwfcfgmgmt.dll
2021-05-12 16:46 - 2021-05-12 16:46 - 001823816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2021-05-12 16:46 - 2021-05-12 16:46 - 001393504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2021-05-12 16:46 - 2021-05-12 16:46 - 001314120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2021-05-12 16:46 - 2021-05-12 16:46 - 001163776 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2021-05-12 16:46 - 2021-05-12 16:46 - 000060928 _____ C:\WINDOWS\system32\runexehelper.exe
2021-05-12 16:46 - 2021-05-12 16:46 - 000011351 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2021-05-12 16:45 - 2021-05-12 16:45 - 000165888 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2021-05-12 16:45 - 2021-05-12 16:45 - 000013312 _____ C:\WINDOWS\system32\agentactivationruntimestarter.exe
2021-05-11 22:50 - 2021-05-11 22:50 - 000018816 _____ (Huawei Technologies Co., Ltd.) C:\WINDOWS\system32\Drivers\ew_usbccgpfilter.sys
2021-05-11 22:44 - 2021-05-30 21:45 - 000091326 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-11 at 10.39.42 PM.jpeg.paas
2021-05-11 19:27 - 2021-05-30 21:45 - 000063682 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-11 at 7.27.06 PM.jpeg.paas
2021-05-11 19:10 - 2021-05-30 21:45 - 000169915 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-11 at 7.09.14 PM.jpeg.paas
2021-05-11 18:57 - 2021-05-30 21:45 - 000042316 _____ C:\Users\josev\Desktop\WhatsApp Image 2021-05-10 at 11.29.55 PM.jpeg.paas
2021-05-11 18:50 - 2021-05-30 21:45 - 000042316 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-10 at 11.29.55 PM.jpeg.paas
2021-05-11 00:53 - 2021-05-11 00:53 - 001010720 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCHRT20.OCX
2021-05-11 00:53 - 2021-05-11 00:53 - 000224016 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\TABCTL32.OCX
2021-05-11 00:53 - 2021-05-11 00:53 - 000140488 ___RS (Microsoft Corporation) C:\WINDOWS\SysWOW64\COMDLG32.OCX
2021-05-11 00:53 - 2021-05-11 00:53 - 000000000 ____D C:\WINDOWS\PCHEALTH
2021-05-11 00:53 - 2021-05-11 00:53 - 000000000 ____D C:\Program Files (x86)\Technitium
2021-05-11 00:50 - 2021-05-30 21:45 - 002212796 _____ C:\Users\josev\Downloads\TMACv6.0.7_Setup.zip.paas
2021-05-11 00:34 - 2021-05-30 21:45 - 000217506 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube (1).zip.paas
2021-05-11 00:29 - 2021-05-30 21:45 - 001063083 _____ C:\Users\josev\Downloads\Photo_1620705996049_Processed.png.paas
2021-05-11 00:18 - 2021-05-30 21:45 - 000041168 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-11 at 12.15.32 AM.jpeg.paas
2021-05-11 00:18 - 2021-05-30 21:45 - 000034920 _____ C:\Users\josev\Downloads\WhatsApp Image 2021-05-11 at 12.15.32 AM (1).jpeg.paas
2021-05-10 22:08 - 2021-05-30 21:45 - 028739990 _____ C:\Users\josev\Downloads\274efc05-c557-4b06-a84f-fc1ad17d6a6b.tmp.paas
2021-05-10 21:37 - 2021-06-02 11:52 - 000000000 ____D C:\WINDOWS\Minidump
2021-05-09 20:05 - 2021-05-09 20:05 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2021-05-09 20:00 - 2021-05-09 20:00 - 000000020 ___SH C:\Users\josev\ntuser.ini
2021-05-09 19:56 - 2021-06-04 08:17 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2021-05-09 19:56 - 2021-06-04 00:10 - 000002956 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_josev
2021-05-09 19:56 - 2021-05-11 22:55 - 000002940 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (josev)
2021-05-09 19:56 - 2021-05-09 19:56 - 000003622 _____ C:\WINDOWS\system32\Tasks\Opera GX scheduled Autoupdate 1619726949
2021-05-09 19:56 - 2021-05-09 19:56 - 000003580 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2021-05-09 19:56 - 2021-05-09 19:56 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2021-05-09 19:56 - 2021-05-09 19:56 - 000003356 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2021-05-09 19:56 - 2021-05-09 19:56 - 000003042 _____ C:\WINDOWS\system32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2021-05-09 19:56 - 2021-05-09 19:56 - 000002970 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132
2021-05-09 19:56 - 2021-05-09 19:56 - 000002678 _____ C:\WINDOWS\system32\Tasks\USER_ESRV_SVC_QUEENCREEK
2021-05-09 19:56 - 2021-05-09 19:56 - 000002604 _____ C:\WINDOWS\system32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon
2021-05-09 19:56 - 2021-05-09 19:56 - 000000000 ____D C:\WINDOWS\system32\Tasks\S-1-5-21-2251894981-3858074833-453683670-1001
2021-05-09 19:55 - 2021-05-09 19:56 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2021-05-09 19:55 - 2021-05-09 19:56 - 000007623 _____ C:\WINDOWS\diagerr.xml
2021-05-09 19:47 - 2021-05-15 17:01 - 001772926 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2021-05-09 19:39 - 2021-05-31 19:36 - 000000000 ____D C:\Users\josev
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Reciente
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Plantillas
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Mis documentos
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Menú Inicio
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Impresoras
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Entorno de red
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Documents\Mis vídeos
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Documents\Mis imágenes
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Documents\Mi música
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Datos de programa
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\Configuración local
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\AppData\Local\Historial
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\AppData\Local\Datos de programa
2021-05-09 19:39 - 2021-05-09 19:39 - 000000000 _SHDL C:\Users\josev\AppData\Local\Archivos temporales de Internet
2021-05-09 19:39 - 2019-12-07 05:10 - 000001105 _____ C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2021-05-09 19:33 - 2021-06-04 14:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2021-05-09 19:33 - 2021-06-04 08:17 - 000008192 ___SH C:\DumpStack.log.tmp
2021-05-09 19:33 - 2021-05-31 00:16 - 000008526 ___SH C:\DumpStack.log.paas
2021-05-09 19:33 - 2021-05-12 17:03 - 000445648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2021-05-09 18:23 - 2021-05-09 18:23 - 000001425 _____ C:\WINDOWS\system32\default_error_stack-000001-000000.txt
2021-05-09 17:40 - 2021-05-31 08:08 - 000000000 ____D C:\Users\josev\Desktop\Shaggy_mod
2021-05-09 16:37 - 2021-05-30 21:47 - 000000000 ____D C:\Users\josev\Desktop\Neón Génesis Evangelion
2021-05-09 14:29 - 2021-05-09 14:32 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2021-05-09 14:25 - 2021-05-09 14:29 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2021-05-09 14:25 - 2021-05-09 14:25 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2021-05-09 14:20 - 2021-05-09 14:20 - 000000000 ____D C:\ProgramData\ssh
2021-05-09 14:11 - 2021-05-09 14:11 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2021-05-09 14:11 - 2021-05-09 14:11 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2021-05-09 14:11 - 2021-05-09 14:11 - 000480256 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2021-05-09 14:11 - 2021-05-09 14:11 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mpg2splt.ax
2021-05-09 14:11 - 2021-05-09 14:11 - 000138056 _____ C:\WINDOWS\system32\HvsiManagementApi.dll
2021-05-09 14:11 - 2021-05-09 14:11 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VBICodec.ax
2021-05-09 14:11 - 2021-05-09 14:11 - 000101704 _____ C:\WINDOWS\SysWOW64\HvsiManagementApi.dll
2021-05-09 14:11 - 2021-05-09 14:11 - 000095744 _____ C:\WINDOWS\system32\VirtualMonitorManager.dll
2021-05-09 14:11 - 2021-05-09 14:11 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2021-05-09 14:10 - 2021-05-09 14:10 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2021-05-09 14:10 - 2021-05-09 14:10 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appwiz.cpl
2021-05-09 14:10 - 2021-05-09 14:10 - 000304128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2021-05-09 14:10 - 2021-05-09 14:10 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpg2splt.ax
2021-05-09 14:10 - 2021-05-09 14:10 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2021-05-09 14:10 - 2021-05-09 14:10 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\VBICodec.ax
2021-05-09 14:10 - 2021-05-09 14:10 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2021-05-09 14:10 - 2021-05-09 14:10 - 000072704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2021-05-09 14:10 - 2021-05-09 14:10 - 000053760 _____ C:\WINDOWS\SysWOW64\BWContextHandler.dll
2021-05-09 14:10 - 2021-05-09 14:10 - 000045880 _____ C:\WINDOWS\system32\HvSocket.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 000729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2021-05-09 14:09 - 2021-05-09 14:09 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2021-05-09 14:09 - 2021-05-09 14:09 - 000178688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\intl.cpl
2021-05-09 14:09 - 2021-05-09 14:09 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncpa.cpl
2021-05-09 14:09 - 2021-05-09 14:09 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2021-05-09 14:09 - 2021-05-09 14:09 - 000067072 _____ C:\WINDOWS\system32\BWContextHandler.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2021-05-09 14:09 - 2021-05-09 14:09 - 000039936 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2021-05-09 14:08 - 2021-05-09 14:08 - 001333760 _____ C:\WINDOWS\SysWOW64\TextInputMethodFormatter.dll
2021-05-09 14:08 - 2021-05-09 14:08 - 000611952 _____ C:\WINDOWS\SysWOW64\TextShaping.dll
2021-05-09 14:08 - 2021-05-09 14:08 - 000455680 _____ C:\WINDOWS\SysWOW64\WindowManagementAPI.dll
2021-05-09 14:08 - 2021-05-09 14:08 - 000446976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2021-05-09 14:08 - 2021-05-09 14:08 - 000422912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2021-05-09 14:08 - 2021-05-09 14:08 - 000266240 _____ C:\WINDOWS\SysWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-05-09 14:08 - 2021-05-09 14:08 - 000235520 _____ C:\WINDOWS\SysWOW64\HeatCore.dll
2021-05-09 14:08 - 2021-05-09 14:08 - 000221184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bthprops.cpl
2021-05-09 14:08 - 2021-05-09 14:08 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\timedate.cpl
2021-05-09 14:08 - 2021-05-09 14:08 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\activeds.tlb
2021-05-09 14:08 - 2021-05-09 14:08 - 000047472 _____ C:\WINDOWS\SysWOW64\umpdc.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 000330752 _____ C:\WINDOWS\SysWOW64\ssdm.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 000240640 _____ C:\WINDOWS\SysWOW64\CoreMas.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\intl.cpl
2021-05-09 14:07 - 2021-05-09 14:07 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncpa.cpl
2021-05-09 14:07 - 2021-05-09 14:07 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2021-05-09 14:07 - 2021-05-09 14:07 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msacm32.drv
2021-05-09 14:07 - 2021-05-09 14:07 - 000010752 _____ C:\WINDOWS\SysWOW64\agentactivationruntimestarter.exe
2021-05-09 14:06 - 2021-05-09 14:06 - 002254336 _____ C:\WINDOWS\system32\dwmscene.dll
2021-05-09 14:06 - 2021-05-09 14:06 - 000544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2021-05-09 14:06 - 2021-05-09 14:06 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthprops.cpl
2021-05-09 14:06 - 2021-05-09 14:06 - 000190976 _____ C:\WINDOWS\system32\BthpanContextHandler.dll
2021-05-09 14:06 - 2021-05-09 14:06 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\activeds.tlb
2021-05-09 14:06 - 2021-05-09 14:06 - 000048640 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2021-05-09 14:06 - 2021-05-09 14:06 - 000001370 _____ C:\WINDOWS\system32\ThirdPartyNoticesBySHS.txt
2021-05-09 14:05 - 2021-05-09 14:05 - 002260480 _____ (The ICU Project) C:\WINDOWS\system32\icu.dll
2021-05-09 14:05 - 2021-05-09 14:05 - 000643072 _____ C:\WINDOWS\system32\WindowManagementAPI.dll
2021-05-09 14:05 - 2021-05-09 14:05 - 000231248 _____ C:\WINDOWS\system32\containerdevicemanagement.dll
2021-05-09 14:05 - 2021-05-09 14:05 - 000152064 _____ C:\WINDOWS\system32\EoAExperiences.exe
2021-05-09 14:05 - 2021-05-09 14:05 - 000091136 _____ C:\WINDOWS\system32\Drivers\cimfs.sys
2021-05-09 14:05 - 2021-05-09 14:05 - 000029696 _____ (The ICU Project) C:\WINDOWS\system32\icuuc.dll
2021-05-09 14:05 - 2021-05-09 14:05 - 000025088 _____ (The ICU Project) C:\WINDOWS\system32\icuin.dll
2021-05-09 14:04 - 2021-05-09 14:04 - 002260992 _____ C:\WINDOWS\system32\TextInputMethodFormatter.dll
2021-05-09 14:04 - 2021-05-09 14:04 - 000707016 _____ C:\WINDOWS\system32\TextShaping.dll
2021-05-09 14:04 - 2021-05-09 14:04 - 000363520 _____ C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2021-05-09 14:04 - 2021-05-09 14:04 - 000306688 _____ C:\WINDOWS\system32\HeatCore.dll
2021-05-09 14:04 - 2021-05-09 14:04 - 000243200 _____ (Microsoft Corporation) C:\WINDOWS\system32\timedate.cpl
2021-05-09 14:03 - 2021-05-09 14:03 - 004227116 _____ C:\WINDOWS\system32\DefaultHrtfs.bin
2021-05-09 14:03 - 2021-05-09 14:03 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2021-05-09 14:03 - 2021-05-09 14:03 - 000455168 _____ C:\WINDOWS\system32\ssdm.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000197632 _____ C:\WINDOWS\system32\IHDS.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000089088 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.proxystub.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000074240 _____ C:\WINDOWS\system32\rdsxvmaudio.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000073216 _____ C:\WINDOWS\system32\windows.applicationmodel.conversationalagent.internal.proxystub.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000064552 _____ C:\WINDOWS\system32\umpdc.dll
2021-05-09 14:03 - 2021-05-09 14:03 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msacm32.drv
2021-05-09 13:44 - 2021-05-09 13:44 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2021-05-09 13:44 - 2021-05-09 13:44 - 000000000 ____D C:\Program Files\Reference Assemblies
2021-05-09 13:44 - 2021-05-09 13:44 - 000000000 ____D C:\Program Files\MSBuild
2021-05-09 13:44 - 2021-05-09 13:44 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2021-05-09 13:44 - 2021-05-09 13:44 - 000000000 ____D C:\Program Files (x86)\MSBuild
2021-05-08 23:53 - 2021-05-08 23:53 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER.paas
2021-05-08 20:10 - 2021-05-31 08:30 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2021-05-08 20:10 - 2021-05-31 08:30 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2021-05-08 19:58 - 2021-05-30 21:45 - 000079233 _____ C:\Users\josev\Downloads\Habilidades Sociales y Comunicativas a traves del Arte.pdf.paas
2021-05-07 10:56 - 2021-05-30 21:45 - 000240366 _____ C:\Users\josev\Downloads\COMUNICADO IMPORTANTE.pdf.paas
2021-05-06 17:10 - 2021-05-30 21:45 - 006886264 _____ C:\Users\josev\Downloads\v2_05_69fx1_build.rar.paas
2021-05-06 17:01 - 2021-05-10 22:04 - 000001255 _____ C:\Users\josev\Desktop\nfs - Acceso directo.lnk
2021-05-06 16:53 - 2021-05-06 16:53 - 000000000 ____D C:\Users\josev\AppData\Roaming\Codeusa Software
2021-05-06 16:52 - 2021-05-09 14:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Borderless Gaming
2021-05-06 16:52 - 2021-05-06 16:52 - 000000000 ____D C:\Program Files (x86)\Borderless Gaming
2021-05-06 07:36 - 2021-05-06 07:36 - 000000000 ____D C:\Users\josev\Documents\League of Legends
2021-05-05 20:19 - 2021-05-05 20:19 - 000000000 ____D C:\ProgramData\TP-LINK
2021-05-05 17:56 - 2021-05-05 17:56 - 000001426 _____ C:\WINDOWS\system32\default_error_stack-000000-000000.txt
2021-05-05 14:55 - 2021-06-02 11:52 - 000000000 ___DC C:\WINDOWS\Panther

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2021-06-04 08:28 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2021-06-04 08:19 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2021-06-04 08:16 - 2019-12-07 05:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2021-06-04 01:44 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2021-06-03 23:26 - 2021-04-30 20:17 - 000000000 ____D C:\Users\josev\AppData\Local\CrashDumps
2021-06-03 20:19 - 2021-04-30 21:39 - 000005632 _____ C:\Users\josev\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2021-06-03 20:19 - 2021-04-30 18:29 - 000000000 ____D C:\Users\josev\Documents\Camtasia Studio
2021-06-03 13:28 - 2019-12-07 05:13 - 000000000 ____D C:\WINDOWS\INF
2021-06-02 12:27 - 2019-12-07 05:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2021-06-01 15:29 - 2021-04-29 14:58 - 000000000 ____D C:\Users\josev\Desktop\cosas produccion
2021-06-01 13:31 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2021-06-01 13:11 - 2019-12-07 05:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2021-06-01 13:10 - 2021-04-29 14:15 - 000000000 __RHD C:\Users\Public\AccountPictures
2021-06-01 00:11 - 2021-04-29 15:00 - 000000000 ____D C:\ProgramData\Package Cache
2021-05-31 23:08 - 2021-04-29 15:23 - 000000000 ____D C:\Program Files (x86)\Intel
2021-05-31 21:07 - 2019-12-07 05:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2021-05-31 19:36 - 2021-04-30 00:37 - 000000000 ___HD C:\$WinREAgent
2021-05-31 19:36 - 2021-04-29 14:34 - 000000000 ___HD C:\OneDriveTemp
2021-05-31 19:36 - 2021-04-29 14:15 - 000000000 ____D C:\Users\josev\AppData\Local\VirtualStore
2021-05-31 18:15 - 2021-04-29 23:29 - 000000000 ____D C:\Riot Games
2021-05-31 14:23 - 2021-04-29 14:49 - 000000000 ____D C:\Program Files\Image-Line
2021-05-31 14:23 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\System
2021-05-31 12:55 - 2021-04-29 16:09 - 000001438 _____ C:\Users\josev\Desktop\Navegador Opera GX.lnk
2021-05-31 08:30 - 2019-12-07 05:14 - 000000000 ___HD C:\Program Files\WindowsApps
2021-05-31 08:08 - 2021-05-01 16:47 - 000000000 ____D C:\Users\josev\Desktop\Need for Speed ProStreet
2021-05-31 08:08 - 2021-04-29 20:32 - 000000000 ____D C:\Users\josev\Desktop\instaladores
2021-05-31 08:08 - 2021-04-29 18:41 - 000000000 ____D C:\Users\josev\Documents\iZotope
2021-05-31 08:08 - 2021-04-29 15:05 - 000000000 ____D C:\Users\josev\Desktop\Fl Studios programas samples sonidos etc
2021-05-31 08:08 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\appcompat
2021-05-31 08:07 - 2021-04-29 18:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope
2021-05-31 08:07 - 2021-04-29 18:41 - 000000000 ____D C:\Program Files\Common Files\VST3
2021-05-31 08:07 - 2021-04-29 18:41 - 000000000 ____D C:\Program Files (x86)\iZotope
2021-05-31 08:07 - 2021-04-29 14:49 - 000000000 ____D C:\Program Files\Celemony
2021-05-31 07:54 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\registration
2021-05-31 07:52 - 2021-04-29 18:53 - 000000000 ____D C:\Users\josev\Documents\FabFilter
2021-05-31 07:52 - 2021-04-29 18:00 - 000000000 ____D C:\Users\josev\Documents\Image-Line
2021-05-31 07:52 - 2021-04-29 15:20 - 000000000 ____D C:\Users\josev\Desktop\Sd card
2021-05-31 07:52 - 2021-04-29 15:11 - 000000000 ____D C:\Users\josev\Desktop\PROYECTOS FL
2021-05-31 07:51 - 2021-04-29 15:15 - 000000000 ____D C:\Users\josev\Desktop\Gildred
2021-05-31 07:51 - 2021-04-29 15:11 - 000000000 ____D C:\Users\josev\Desktop\COSAS YT
2021-05-31 07:51 - 2021-04-29 14:42 - 000000000 ____D C:\Users\josev\Desktop\Albumes y Singles
2021-05-31 07:50 - 2021-04-29 15:42 - 000000000 ____D C:\Users\josev\AppData\LocalLow\Oracle
2021-05-31 07:49 - 2021-04-29 23:00 - 000000000 ____D C:\ProgramData\Riot Games
2021-05-30 23:21 - 2021-04-29 19:16 - 000000000 ____D C:\Users\josev\AppData\Roaming\DMCache
2021-05-30 21:47 - 2021-04-29 21:25 - 000000000 ____D C:\Users\josev\Documents\NFS SHIFT
2021-05-30 21:47 - 2021-04-29 15:21 - 000000000 ____D C:\Users\josev\Desktop\TAREAS PRIMER SEMETRE
2021-05-30 21:47 - 2021-04-29 15:20 - 000000000 ____D C:\Users\josev\Desktop\PAPELES UNIVERSIDAD
2021-05-30 21:45 - 2021-05-04 14:15 - 000534342 _____ C:\Users\josev\Downloads\PRUEBA DEF.pptx.paas
2021-05-30 21:45 - 2021-05-03 20:58 - 007583250 _____ C:\Users\josev\Downloads\ID.mp3.paas
2021-05-30 21:45 - 2021-05-03 16:01 - 004862393 _____ C:\Users\josev\Downloads\Hyp3d 3000x3000 - Spacee Giraffe - One Soul.jpg.paas
2021-05-30 21:45 - 2021-05-01 22:27 - 000259280 _____ C:\Users\josev\Downloads\Blanco y Rosa Neón Club Miniatura de YouTube.zip.paas
2021-05-30 21:45 - 2021-05-01 22:23 - 000240665 _____ C:\Users\josev\Downloads\jotovera.png.paas
2021-05-30 21:45 - 2021-04-30 23:03 - 069746534 _____ C:\Users\josev\Downloads\Install League of Legends la1.exe.paas
2021-05-30 21:45 - 2021-04-29 20:06 - 030576129 _____ C:\Users\josev\Downloads\funkin-windows-64bit.zip.opdownload.paas
2021-05-30 21:45 - 2021-04-29 14:42 - 011783704 _____ C:\Users\josev\Desktop\Static - Breathe.mp3.paas
2021-05-30 21:45 - 2021-04-29 14:42 - 008631301 _____ C:\Users\josev\Desktop\01 Loca (feat. Sara Jaramillo).mp3.paas
2021-05-30 21:45 - 2021-04-29 14:42 - 006238929 _____ C:\Users\josev\Desktop\ANDO CHILL.mp3.paas
2021-05-30 21:45 - 2021-04-29 14:19 - 000000000 ___RD C:\Users\josev\OneDrive
2021-05-30 18:34 - 2016-06-23 09:02 - 000000000 ____D C:\ProgramData\DevelopCalculator
2021-05-30 15:45 - 2021-04-29 19:47 - 000000000 ____D C:\Users\josev\AppData\Local\PlaceholderTileLogoFolder
2021-05-30 15:45 - 2021-04-29 14:33 - 000000000 ____D C:\ProgramData\Packages
2021-05-30 15:45 - 2021-04-29 14:15 - 000000000 ____D C:\Users\josev\AppData\Local\Packages
2021-05-25 20:26 - 2021-04-29 19:16 - 000000000 ____D C:\Users\josev\Downloads\Compressed
2021-05-19 21:12 - 2021-04-30 16:52 - 000000000 ____D C:\Users\josev\AppData\Roaming\ninjamuffin99
2021-05-16 14:44 - 2021-04-29 15:56 - 000000000 ____D C:\Users\josev\AppData\Local\D3DSCache
2021-05-15 17:01 - 2019-12-07 10:55 - 000788378 _____ C:\WINDOWS\system32\perfh00A.dat
2021-05-15 17:01 - 2019-12-07 10:55 - 000155766 _____ C:\WINDOWS\system32\perfc00A.dat
2021-05-15 16:59 - 2021-04-29 13:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2021-05-13 21:24 - 2021-04-29 18:55 - 000002136 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2021-05-12 18:23 - 2021-04-29 23:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2021-05-12 18:16 - 2021-05-01 16:37 - 000000001 _____ C:\WINDOWS\vgkbootstatus.dat
2021-05-12 16:59 - 2019-12-07 10:58 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2021-05-12 16:59 - 2019-12-07 10:56 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SystemResources
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\setup
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\Provisioning
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2021-05-12 16:59 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2021-05-12 16:53 - 2019-12-07 10:58 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2021-05-12 16:53 - 2019-12-07 05:03 - 000000000 ____D C:\WINDOWS\servicing
2021-05-12 16:13 - 2021-04-29 22:49 - 000000000 ____D C:\WINDOWS\system32\MRT
2021-05-12 16:09 - 2021-04-29 22:49 - 132732536 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2021-05-11 22:54 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2021-05-10 16:12 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2021-05-10 16:10 - 2021-05-01 16:41 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2021-05-09 20:03 - 2019-12-07 05:14 - 000000000 ____D C:\ProgramData\USOPrivate
2021-05-09 20:02 - 2021-04-29 14:15 - 000000000 ___RD C:\Users\josev\3D Objects
2021-05-09 19:56 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Windows NT
2021-05-09 19:56 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Windows Defender
2021-05-09 19:48 - 2019-12-07 05:14 - 000000000 __RHD C:\Users\Public\Libraries
2021-05-09 19:41 - 2021-04-29 17:47 - 000000000 ____D C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2021-05-09 19:41 - 2021-04-29 17:43 - 000000000 ____D C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2021-05-09 19:41 - 2021-04-29 14:29 - 000000000 ____D C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-05-09 19:40 - 2021-04-29 18:20 - 000000000 ____D C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dada Life
2021-05-09 19:38 - 2021-04-29 18:40 - 000000000 ____D C:\WINDOWS\SysWOW64\LifeCamTrueColor
2021-05-09 19:38 - 2021-04-29 18:40 - 000000000 ____D C:\WINDOWS\system32\LifeCamTrueColor
2021-05-09 19:38 - 2021-04-29 15:35 - 000000000 ____D C:\WINDOWS\system32\DAX3
2021-05-09 19:38 - 2021-04-29 15:35 - 000000000 ____D C:\WINDOWS\system32\DAX2
2021-05-09 19:38 - 2021-04-29 15:35 - 000000000 ____D C:\ProgramData\Audyssey Labs
2021-05-09 19:37 - 2021-04-29 15:35 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2021-05-09 19:33 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ServiceState
2021-05-09 14:32 - 2021-05-03 17:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Parallel Lines
2021-05-09 14:32 - 2021-05-01 19:44 - 000000000 ____D C:\Program Files\Intel
2021-05-09 14:32 - 2021-05-01 16:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO
2021-05-09 14:32 - 2021-04-30 18:15 - 000000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2021-05-09 14:32 - 2021-04-30 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2021-05-09 14:32 - 2021-04-30 03:31 - 000000000 ____D C:\Program Files\UNP
2021-05-09 14:32 - 2021-04-29 20:18 - 000000000 ____D C:\WINDOWS\SysWOW64\AGEIA
2021-05-09 14:32 - 2021-04-29 20:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2021-05-09 14:32 - 2021-04-29 19:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2021-05-09 14:32 - 2021-04-29 19:02 - 000000000 ____D C:\WINDOWS\SHELLNEW
2021-05-09 14:32 - 2021-04-29 18:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sylenth1
2021-05-09 14:32 - 2021-04-29 18:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\SoundToys
2021-05-09 14:32 - 2021-04-29 17:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2021-05-09 14:32 - 2021-04-29 15:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2021-05-09 14:32 - 2021-04-29 14:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2021-05-09 14:32 - 2019-12-07 05:18 - 000000000 ____D C:\WINDOWS\Setup
2021-05-09 14:32 - 2019-12-07 05:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2021-05-09 14:32 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2021-05-09 14:32 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\spool
2021-05-09 14:32 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2021-05-09 14:32 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2021-05-09 14:32 - 2019-03-19 00:52 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2021-05-09 14:29 - 2021-04-30 22:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2021-05-09 14:29 - 2021-04-29 18:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicLab
2021-05-09 14:29 - 2021-04-29 18:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reFX
2021-05-09 14:29 - 2021-04-29 15:35 - 000000000 ____D C:\Program Files\Realtek
2021-05-09 14:29 - 2021-04-29 14:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit
2021-05-09 14:20 - 2019-12-07 10:58 - 000000000 ___SD C:\WINDOWS\system32\AppV
2021-05-09 14:20 - 2019-12-07 10:58 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2021-05-09 14:20 - 2019-12-07 10:58 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\Com
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\IME
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files\Common Files\System
2021-05-09 14:20 - 2019-12-07 05:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2021-05-09 14:18 - 2019-12-07 10:58 - 000020908 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2021-05-09 13:48 - 2019-12-07 10:57 - 000000000 ____D C:\WINDOWS\OCR
2021-05-09 13:44 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2021-05-09 13:44 - 2019-12-07 05:14 - 000000000 ____D C:\WINDOWS\system32\MUI
2021-05-08 18:05 - 2021-02-19 21:09 - 001439456 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klhk.sys
2021-05-08 18:05 - 2021-02-19 21:09 - 000657696 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klgse.sys

==================== Archivos en la raíz de algunos directorios ========

2021-04-29 14:49 - 2018-12-18 11:30 - 003630080 _____ (Image-Line) C:\Program Files\FL Studio VSTi (Multi).dll
2021-04-29 14:49 - 2018-12-18 11:30 - 003630080 _____ (Image-Line) C:\Program Files\FL Studio VSTi.dll
2021-05-30 21:40 - 2021-05-30 21:40 - 000000560 _____ () C:\Users\josev\AppData\Local\bowsakkdestx.txt
2021-04-30 21:39 - 2021-06-03 20:19 - 000005632 _____ () C:\Users\josev\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2021-05-02 22:28 - 2021-05-02 22:28 - 000003390 _____ () C:\Users\josev\AppData\Local\icsys.icn
2021-05-15 19:33 - 2021-05-15 20:02 - 000007602 _____ () C:\Users\josev\AppData\Local\Resmon.ResmonCfg
2021-05-31 00:13 - 2021-05-31 00:13 - 000000049 _____ () C:\Users\josev\AppData\Local\script.ps1

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)

==================== Final de FRST.txt ========================```

Aqui el Addition.txt

Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 02-06-2021
Ejecutado por josev (04-06-2021 14:52:21)
Ejecutado desde C:\Users\josev\Desktop
Windows 10 Pro Versión 20H2 19042.985 (X64) (2021-05-09 23:59:20)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-2251894981-3858074833-453683670-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2251894981-3858074833-453683670-503 - Limited - Disabled)
Invitado (S-1-5-21-2251894981-3858074833-453683670-501 - Limited - Disabled)
josev (S-1-5-21-2251894981-3858074833-453683670-1001 - Administrator - Enabled) => C:\Users\josev
WDAGUtilityAccount (S-1-5-21-2251894981-3858074833-453683670-504 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 21.001.20155 - Adobe Systems Incorporated)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Borderless Gaming (HKLM-x32\...\Borderless Gaming_is1) (Version: 8.4 - Codeusa Software)
Camtasia Studio 8 (HKLM-x32\...\{BFA04EE0-8240-4667-8D53-45496A901C33}) (Version: 8.1.2.1327 - TechSmith Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 5.80 - Piriform)
CPUID CPU-Z 1.96 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.96 - CPUID, Inc.)
Discord (HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\Discord) (Version: 1.0.9001 - Discord Inc.)
Driver Parallel Lines MULTi7 - ElAmigos versión 1.0 (HKLM-x32\...\{2D70325A-60DC-4F45-B1A6-28CEDCEF0CC3}_is1) (Version: 1.0 - Ubisoft)
Eines de correcció del Microsoft Office 2013: català (HKLM-x32\...\{90150000-001F-0403-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Ferramentas de verificación de Microsoft Office 2013 - Galego (HKLM-x32\...\{90150000-001F-0456-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
FL Studio 20 (HKLM-x32\...\FL Studio 20) (Version:  - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
Intel(R) Computing Improvement Program (HKLM\...\{848F0123-CF5D-4192-90EC-A6574D8B1796}) (Version: 2.4.06522 - Intel Corporation)
IObit Driver Booster 8.4.0.420 (HKLM-x32\...\IObit Driver Booster_is1) (Version: 8.4.0.420 - LRepacks)
IObit Uninstaller 10.4.0.11 (HKLM-x32\...\IObit Uninstaller_is1) (Version: 10.4.0.11 - LRepacks)
Kaspersky Total Security (HKLM-x32\...\{4FC79BE9-AD63-46C0-9626-E4F6BCE6A976}) (Version: 21.3.10.391 - Kaspersky) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{4FC79BE9-AD63-46C0-9626-E4F6BCE6A976}) (Version: 21.3.10.391 - Kaspersky)
Kaspersky VPN (HKLM-x32\...\{FF2A12B8-AEB7-48C0-95C8-E2E3D67DFCB2}) (Version: 21.3.10.391 - Kaspersky) Hidden
Kaspersky VPN (HKLM-x32\...\InstallWIX_{FF2A12B8-AEB7-48C0-95C8-E2E3D67DFCB2}) (Version: 21.3.10.391 - Kaspersky)
League of Legends (HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\Riot Game league_of_legends.live) (Version:  - Riot Games, Inc)
Massive (HKLM\...\Massive_is1) (Version: 1.5.5 - Native Instruments & Team V.R)
Microsoft .NET Framework 4.8 SDK (español) (HKLM-x32\...\{59F4AEDD-1897-4E4C-BB25-61DC440429B9}) (Version: 4.8.03761 - Microsoft Corporation)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 91.0.864.37 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{A0E1B43D-5F4A-46AF-9925-ABA3423325DC}) (Version: 2.77.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.21.27702 (HKLM-x32\...\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}) (Version: 14.21.27702.2 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (HKLM-x32\...\{49697869-be8e-427d-81a0-c334d1d14950}) (Version: 14.21.27702.2 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MusicLab RealGuitar (HKLM\...\{1864B4F0-8888-5A57-9930-C2B307597966}) (Version: 3.0 - MusicLab, Inc.)
MusicLab Virtual MIDI Driver (HKLM\...\{A30B7FD7-04A1-46e1-ABDF-FD592C113253}) (Version: 2.0.1.0 - MusicLab, Inc.)
NVIDIA PhysX (HKLM-x32\...\{5DB65884-C963-4454-AABA-4CA3089281FA}) (Version: 9.09.0720 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera GX Stable 75.0.3969.259 (HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\Opera GX 75.0.3969.259) (Version: 75.0.3969.259 - Opera Software)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM-x32\...\{90150000-001F-040C-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Paquete de compatibilidad de Microsoft .NET Framework 4.8 (español) (HKLM-x32\...\{41F38056-60AB-4210-99EF-EF3F1FEF95C9}) (Version: 4.8.03761 - Microsoft Corporation)
Paquete de desarrollador de Microsoft .NET Framework 4.8 (español) (HKLM-x32\...\{d74790a6-c414-43cf-91c9-014bd3041031}) (Version: 4.8.3761 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.8899.1 - Realtek Semiconductor Corp.)
reFX Nexus VSTi RTAS v2.2.0 (HKLM-x32\...\reFX Nexus_is1) (Version:  - )
Revisores de Texto do Microsoft Office 2013 – Português do Brasil (HKLM-x32\...\{90150000-001F-0416-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
SpyHunter 5 (HKLM-x32\...\SpyHunter5) (Version: 5.10.10.233 - EnigmaSoft Limited)
Sylenth1 v2.20 (HKLM\...\Sylenth1_is1) (Version:  - )
Sylenth1 v2.20 (HKLM-x32\...\Sylenth1_is1) (Version:  - )
Technitium MAC Address Changer v6.0 (HKLM-x32\...\TMACv6.0) (Version: 6.0 - Technitium)
The T-Pain Effect Bundle (HKLM-x32\...\The T-Pain Effect Bundle_is1) (Version: 1.02 - iZotope, Inc.)
UltraISO Premium V9.71 (HKLM-x32\...\UltraISO_is1) (Version:  - )
WinRAR 5.90 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.90.0 - win.rar GmbH)

Packages:
=========
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.9.5060.0_x64__8wekyb3d8bbwe [2021-05-31] (Microsoft Studios) [MS Ad]

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

SSODL: CallbackTechMountNotificator-cbfsconnect2017 - {F0073880-8FEA-41D1-B358-84501EF4DC86} - C:\WINDOWS\system32\cbfsconnectMntNtf2017.dll (Callback Technologies, Inc. -> Callback Technologies, Inc.)
SSODL-x32: CallbackTechMountNotificator-cbfsconnect2017 - {F0073880-8FEA-41D1-B358-84501EF4DC86} - C:\WINDOWS\SysWOW64\cbfsconnectMntNtf2017.dll (Callback Technologies, Inc. -> Callback Technologies, Inc.)
ShellServiceObjects: Virtual Storage Mount Notification -> {F0073880-8FEA-41D1-B358-84501EF4DC86} => C:\WINDOWS\system32\cbfsconnectMntNtf2017.dll [2020-06-25] (Callback Technologies, Inc. -> Callback Technologies, Inc.)
ShellServiceObjects-x32: Virtual Storage Mount Notification -> {F0073880-8FEA-41D1-B358-84501EF4DC86} => C:\WINDOWS\SysWOW64\cbfsconnectMntNtf2017.dll [2020-06-25] (Callback Technologies, Inc. -> Callback Technologies, Inc.)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> Ningún archivo
ContextMenuHandlers1: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\shellex.dll [2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\shellex.dll [2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
ContextMenuHandlers2: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\Program Files (x86)\UltraISO\isoshl64.dll [2015-10-08] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers4: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\shellex.dll [2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
ContextMenuHandlers4: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\Program Files (x86)\UltraISO\isoshl64.dll [2015-10-08] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [Kaspersky Anti-Virus 21.3] -> {37303E08-14C9-4FC3-B1D9-7993682A4691} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\shellex.dll [2021-05-31] (Kaspersky Lab JSC -> AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers6: [UltraISO] -> {AD392E40-428C-459F-961E-9B147782D099} => C:\Program Files (x86)\UltraISO\isoshl64.dll [2015-10-08] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2020-03-26] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Lista blanca) ====================

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2021-04-30 00:34 - 2021-06-03 23:57 - 001231872 _____ () [Archivo no firmado] C:\Riot Games\Riot Client\UX\ffmpeg.dll
2021-04-30 00:34 - 2021-06-04 00:02 - 093489664 _____ () [Archivo no firmado] C:\Riot Games\Riot Client\UX\libcef.dll
2021-04-30 00:34 - 2021-06-03 23:57 - 000110592 _____ () [Archivo no firmado] C:\Riot Games\Riot Client\UX\libegl.dll
2021-04-30 00:34 - 2021-06-03 23:57 - 004717056 _____ () [Archivo no firmado] C:\Riot Games\Riot Client\UX\libglesv2.dll
2020-12-15 14:37 - 2020-12-15 14:37 - 001638912 _____ (Robert Simpson, et al.) [Archivo no firmado] C:\Program Files\Intel\SUR\QUEENCREEK\x64\SQLite.Interop.dll
2020-12-15 14:37 - 2020-12-15 14:37 - 001950208 _____ (SQLite Development Team) [Archivo no firmado] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
2021-06-03 23:55 - 2021-06-03 23:57 - 000707072 _____ (The Chromium Authors) [Archivo no firmado] C:\Riot Games\Riot Client\UX\chrome_elf.dll

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\05233923.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\40286740.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\58847501.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\69724752.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\05233923.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\40286740.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\58847501.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\69724752.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer (Lista blanca) ==========

BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll => Ningún archivo
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2020-01-31] (IObit Information Technology -> IObit)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll => Ningún archivo
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2019-03-19 00:49 - 2021-06-03 23:02 - 000000838 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKU\S-1-5-21-2251894981-3858074833-453683670-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\josev\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\b1d460ed98ecb78923df9fadc0551289.png
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

HKLM\...\StartupApproved\Run: => "IgfxTray"
HKLM\...\StartupApproved\Run32: => "Intel Driver & Support Assistant"
HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\StartupApproved\Run: => "IDMan"
HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Puntos de Restauración =========================

03-06-2021 16:46:34 Removed Need for Speed™ SHIFT

==================== Dispositivos defectuosos en el Administrador de dispositivos ============

Name: Dispositivo de High Definition Audio
Description: Dispositivo de High Definition Audio
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: HdAudAddService
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (06/04/2021 02:38:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa Music.UI.exe (versión 10.20122.1112.0) dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible sobre el problema, comprueba el historial de problemas en el panel de control de seguridad y mantenimiento.

Id. de proceso: 1214

Hora de Inicio: 01d759708035de49

Hora de finalización: 4294967295

Ruta de la aplicación: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20122.11121.0_x64__8wekyb3d8bbwe\Music.UI.exe

Id. de informe: b9a903c4-9c07-4be1-93bf-be115c55428b

Nombre completo del paquete con errores: Microsoft.ZuneMusic_10.20122.11121.0_x64__8wekyb3d8bbwe

Id. de la aplicación relativa al paquete con errores: Microsoft.ZuneMusic

Tipo de bloqueo: Activation

Error: (06/04/2021 02:09:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa msedge.exe (versión 91.0.864.37) dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible sobre el problema, comprueba el historial de problemas en el panel de control de seguridad y mantenimiento.

Id. de proceso: 4ec

Hora de Inicio: 01d7596c3830cbcf

Hora de finalización: 33

Ruta de la aplicación: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

Id. de informe: 1cecf4f5-fabc-4f1a-9b28-55b950f779da

Nombre completo del paquete con errores: 

Id. de la aplicación relativa al paquete con errores: 

Tipo de bloqueo: Cross-thread

Error: (06/04/2021 02:04:43 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=2

Error: (06/04/2021 02:04:25 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (06/04/2021 02:04:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=TimerEvent

Error: (06/04/2021 08:49:41 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x8007139F
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (06/04/2021 08:49:32 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x8007139F
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (06/04/2021 08:21:37 AM) (Source: Microsoft-Windows-PerfNet) (EventID: 2004) (User: DESKTOP-MKTF2H5)
Description: No se puede abrir el objeto de rendimiento del servicio del servidor. Los primeros cuatro bytes (DWORD) de la sección de datos contienen el código de estado.


Errores del sistema:
=============
Error: (06/04/2021 02:24:04 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Intel(R) SUR QC Software Asset Manager.

Error: (06/04/2021 02:05:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio Energy Server Service queencreek se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (06/04/2021 08:33:57 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {995C996E-D918-4A8C-A302-45719A6F4EA7} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (06/04/2021 08:33:56 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {995C996E-D918-4A8C-A302-45719A6F4EA7} no se registró con DCOM dentro del tiempo de espera requerido.

Error: (06/04/2021 08:27:56 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Intel(R) SUR QC Software Asset Manager.

Error: (06/04/2021 08:18:01 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Intel(R) SUR QC Software Asset Manager.

Error: (06/04/2021 08:17:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Malwarebytes Service no pudo iniciarse debido al siguiente error: 
El sistema no puede encontrar el archivo especificado.

Error: (06/04/2021 08:17:24 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio MBAMService no pudo iniciarse debido al siguiente error: 
El sistema no puede encontrar el archivo especificado.


Windows Defender:
================
Date: 2021-05-28 18:30:42
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {427F0FC8-DB7A-4B32-A2B0-5A464D6A69F8}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2021-05-28 18:00:10
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {A487131D-7AA4-4AB8-B1AC-1523BE5537B4}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2021-05-27 17:20:35
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {822E61F3-2476-42A1-BE81-F00DE3823186}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2021-05-26 18:46:42
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {C98DEAAB-266E-4217-91E1-0C727F7941A8}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2021-05-25 17:27:12
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {29F6C926-E36D-46D0-94E4-9FD7F66021B2}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

Date: 2021-05-12 17:32:54
Description: 
Antivirus de Microsoft Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.339.446.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor: 
Versión anterior del motor: 1.1.18100.6
Código de error: 0x8024402c
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2021-05-12 17:14:32
Description: 
Antivirus de Microsoft Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.339.446.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor: 
Versión anterior del motor: 1.1.18100.6
Código de error: 0x8007045b
Descripción del error: Se está cerrando el sistema. 

Date: 2021-05-12 16:16:16
Description: 
Antivirus de Microsoft Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.339.446.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor: 
Versión anterior del motor: 1.1.18100.6
Código de error: 0x80240438
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulte Ayuda y soporte técnico. 

Date: 2021-05-10 23:27:10
Description: 
Antivirus de Microsoft Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.337.684.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor: 
Versión anterior del motor: 1.1.18100.5
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

Date: 2021-05-10 23:27:10
Description: 
Antivirus de Microsoft Defender detectó un error al intentar actualizar la inteligencia de seguridad.
Nueva versión de inteligencia de seguridad: 
Versión anterior de inteligencia de seguridad: 1.337.684.0
Origen de actualización: Centro de protección contra malware de Microsoft
Tipo de inteligencia de seguridad: AntiSpyware
Tipo de actualización: Completa
Usuario: NT AUTHORITY\Servicio de red
Versión actual del motor: 
Versión anterior del motor: 1.1.18100.5
Código de error: 0x80072ee7
Descripción del error: No se pudo resolver el nombre de servidor o su dirección 

CodeIntegrity:
===============
Date: 2021-06-04 14:03:48
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\avp.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2021-06-04 08:19:53
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.


==================== Información de la memoria =========================== 

BIOS: American Megatrends Inc. 4.6.4 10/21/2011
Placa base: ECS H61H2-CM
Procesador: Intel(R) Pentium(R) CPU G620 @ 2.60GHz
Porcentaje de memoria en uso: 72%
RAM física total: 4040.63 MB
RAM física disponible: 1121.62 MB
Virtual total: 6024.63 MB
Virtual disponible: 2192.6 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:464.67 GB) (Free:234.56 GB) NTFS
Drive f: (GILDRED) (Removable) (Total:0.95 GB) (Free:0.59 GB) FAT32

\\?\Volume{01dedf7a-0000-0000-0000-100000000000}\ (Reservado para el sistema) (Fixed) (Total:0.57 GB) (Free:0.1 GB) NTFS
\\?\Volume{01dedf7a-0000-0000-0000-304f74000000}\ () (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 01DEDF7A)
Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=464.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=535 MB) - (Type=27)

==========================================================
Disk: 1 (Size: 974 MB) (Disk ID: 04030201)
Partition 1: (Not Active) - (Size=974 MB) - (Type=0B)

==================== Final de Addition.txt =======================```

Hola @Spacegiraffe, con el permiso del compañero @Marr0n te cuento que des-afortunadamente en tu caso fuiste afectado por una de las nuevas variantes (extension .paas) del STOP ransomware, la cual los archivos afectados no se puede descifrar/recuperar los archivos hasta el momento.

De todas maneras puedes probar y estar atento a este tema que actualizamos regularmente con nuevas versiones de la herramienta de descifrado:

Salu2

1 me gusta

Entiendo, pero los sistemas de windows se pueden recuperar? o directamente tengo que reinstalar windows Espero tu respuesta y muchas gracias

Como poder, poder, claro que se puede… ahora ya depende de cada uno y de que tanto el ransomware haya dañado. A veces lo mejor es o bien buscar si no se cargo los puntos de restauración y tirar de alguno de estos o directamente borrón y cuenta nueva con un buen formateo.

En cualquier caso, siempre guarda tus archivos cifrados que quieras recuperar en un futuro (no te olvides de probar la herramienta de descifrado con estos) en un disco/dispositivo externo.

De todas maneras, @Marr0n intentara seguir brindándote asistencia para poder recuperar tu sistema si es que así decides hacerlo.

1 me gusta

Entiendo, muchas gracias por tu ayuda Marcelo. Espero recuperar mi sistema operativo! Estaré al tanto Saludos y salud para ti y tu familia

Hola, buenas @Spacegiraffe y @Marcelo

Jejejej @Marcelo te me has avanzado. Yo esto sí que tenía en mente/presente hacerlo. Pero primero quería desinfectar el sistema del ransomware y de cualquier bicho que haya en este.

Sí, ahora analizaré los logs de FRST haver en como este ransomware ha afectado al sistema y si realmente es viable o no recuperarlo. Todo depende, en función de lo que vea… jugaremos una u otra carta de la baza.

Sí correcto. Esto es un punto importante a tener cuenta en que @Marcelo se me ha avanzado también. Después cuando hayamos desinfectado y estabilizado la máquina. Te daré unas pequeñas recomendaciones más concretas acerca de esto.

Bueno voy a analizar los logs. En un rato vuelvo.

En un rato vuelvo @Spacegiraffe haber como va.

Salu2 a ambos.

Hola, buenas @Spacegiraffe

:zero: PREGUNTAS

¿Tú has instalado en tu ordenador los siguientes programas o te suenan? Son estos:

Technitium MAC Address Changer v6.0 (HKLM-x32\...\TMACv6.0) (Version: 6.0 - Technitium)

Reconoces estas IPs: 93.115.21.107 93.115.21.107 192.168.43.66 :thinking: :thinking: ¿O las asocias a algún dispositivo de tu red o a algún servicio que tengas contratado?

:one: DESINSTALACIÓN PROGRAMAS

Si los programas que mencionado anteriormente, no los reconoces y tú no los has instalado en tu ordenador.

Los puedes quitar. Hazlo así:

Desinstalalos con Revo Uninstaller en su Modo Avanzado. Para ello sigues su manual la parte de desinstalación de programas.

Quitas los programas citados anteriormente, que encuentre Revo. Si fuese el caso en como te he dicho.

Pues en tu caso tienes instalados los siguientes:

Technitium MAC Address Changer v6.0 (HKLM-x32\...\TMACv6.0) (Version: 6.0 - Technitium)

Y estos otros sí que los debes de desinstalar sí o sí:

IObit Driver Booster 8.4.0.420 (HKLM-x32\...\IObit Driver Booster_is1) (Version: 8.4.0.420 - LRepacks)
IObit Uninstaller 10.4.0.11 (HKLM-x32\...\IObit Uninstaller_is1) (Version: 10.4.0.11 - LRepacks)
SpyHunter 5 (HKLM-x32\...\SpyHunter5) (Version: 5.10.10.233 - EnigmaSoft Limited)

Estos últimos deben de quedar completamente desinstalados.

:two: Ahora debes de hacer una COPIA DE SEGURIDAD DEL REGISTRO, para ello:

  • Reinicias el ordenador en Modo Normal.

  • Descargas DelFix en tu escritorio.

  • Doble clic para ejecutarlo. (Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona - Ejecutar como Administrador)

  • Marcas solamente la casilla de Create registry backup, el resto te aseguras de que no estén seleccionadas.

  • Presionas en Run.

Se abrirá el informe (DelFix.txt), puedes cerrarlo. Pero lo guardas por si en el futuro te lo pido/hace falta.

Seguidamente, CIERRAS TODOS LOS PROGRAMAS, vas a Inicio >> Ejecutar y escribes Notepad.exe

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
File: C:\WINDOWS\system32\FsNVSDeviceSource.dll;C:\WINDOWS\system32\uwfcsp.dll;C:\WINDOWS\system32\uwfcfgmgmt.dll;C:\Users\josev\AppData\Local\script.ps1
File: C:\Windows\System32\Wscript.exe;C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs
File: C:\Users\josev\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini;C:\Users\josev\AppData\Local\icsys.icn;C:\Users\josev\Desktop\nfs - Acceso directo.lnk
Folder: C:\Program Files\Common Files\AV
Folder: C:\ProgramData\Q2DYW1LZCFOQ9F6WWXYFF4KNH
Folder: C:\ProgramData\SystemAcCrux
Folder: C:\Program Files\Intel\SUR\QUEENCREEK\x64
Folder: C:\Program Files\Intel\SUR\QUEENCREEK
Folder: C:\Program Files\Intel\SUR
Folder: C:\sh5ldr
Folder: C:\@RestoreQuarantine
Folder: C:\ProgramData\3BR53LEZ3F00VNW921Y0VOTHL
Folder: C:\SystemID
Folder: C:\Program Files (x86)\foler
Folder: C:\ProgramData\XM5F4DB5NX1APE5P44PKAO610
Folder: C:\Users\josev\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dada Life
Folder: C:\Andries Benade
Folder: C:\Users\josev\AppData\LocalLow\Unknown Vendor
Folder: C:\Users\josev\AppData\LocalLow\Andries Benade'
Folder: C:\Users\josev\AppData\LocalLow\MSCHF
Folder: C:\Users\josev\AppData\Roaming\Serian
Folder: C:\ProgramData\Key-Base
Folder: C:\ProgramData\{FBD48A78-14C4-559A-919F-E4CF1DF9C1C7}
Folder: C:\WINDOWS\system32\Tasks\USER_ESRV_SVC_QUEENCREEK
Folder: C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (josev)
Folder: C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_josev
Folder: C:\Users\josev\Documents\RegRun2
Folder: C:\Users\Public\Documents\RegRunInfo
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe
Task: {595ECD05-05D3-45ED-994C-47589A0004DA} - System32\Tasks\Uninstaller_SkipUac_josev => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [6688256 2021-03-10] (IObit) [Archivo no firmado]
Task: {A4673C02-24F6-4C1E-8716-CE11E8FD5343} - System32\Tasks\Driver Booster SkipUAC (josev) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [8225280 2021-04-02] (IObit) [Archivo no firmado]
Task: {F70FE66B-CCC4-404B-A116-BC4D2ACF4C51} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Edge Extension: (Sin Nombre) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [no encontrado]
Edge Extension: (Sin Nombre) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [no encontrado]
Edge Extension: (Sin Nombre) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [no encontrado]
Edge Extension: (Sin Nombre) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [no encontrado]
Edge HKU\S-1-5-21-2251894981-3858074833-453683670-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [llbjbkhnmlidjebalopleeepgdfgcpec] - C:\Program Files (x86)\Internet Download Manager\IDMEdgeExt.crx <no encontrado>
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => no encontrado
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.3\FFExt\light_plugin_firefox\addon.xpi => no encontrado
FF HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\josev\AppData\Roaming\IDM\idmmzcc5 => no encontrado
FF HKU\S-1-5-21-2251894981-3858074833-453683670-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi => no encontrado
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <no encontrado>
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx <no encontrado>
S2 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [12872144 2021-05-31] (EnigmaSoft Limited -> EnigmaSoft Limited)
R2 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [526800 2021-05-31] (EnigmaSoft Limited -> EnigmaSoft Limited)
2021-05-31 21:40 - 2021-05-31 21:40 - 000001079 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpyHunter5.lnk
2021-05-31 21:40 - 2021-05-31 21:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnigmaSoft
2021-05-31 21:40 - 2021-05-31 21:40 - 000000000 ____D C:\ProgramData\EnigmaSoft Limited
2021-05-31 21:38 - 2021-05-31 21:39 - 000000000 ____D C:\sh5ldr
2021-05-31 21:23 - 2021-05-31 21:23 - 000000000 ____D C:\Program Files\EnigmaSoft
2021-05-31 21:22 - 2021-05-31 21:23 - 006611408 _____ (EnigmaSoft Limited) C:\Users\josev\Downloads\SpyHunter-Installer.exe
2021-05-31 01:03 - 2021-05-31 19:36 - 000000000 ____D C:\@RestoreQuarantine
2021-05-31 00:40 - 2021-05-31 08:07 - 000000000 ____D C:\Users\josev\Documents\RegRun2
2021-05-31 00:40 - 2021-05-31 01:01 - 000000000 ____D C:\Users\Public\Documents\RegRunInfo
2021-05-31 00:14 - 2021-05-31 00:14 - 000000000 ____D C:\ProgramData\Q2DYW1LZCFOQ9F6WWXYFF4KNH
2021-05-30 22:38 - 2021-05-30 22:38 - 000000000 ____D C:\ProgramData\SystemAcCrux
2021-05-30 21:52 - 2021-05-30 21:52 - 000000000 ____D C:\ProgramData\3BR53LEZ3F00VNW921Y0VOTHL
2021-05-30 21:40 - 2021-05-30 21:40 - 000000000 ____D C:\SystemID
2021-05-30 21:39 - 2021-05-30 21:39 - 000000000 ____D C:\Program Files (x86)\foler
2021-05-30 21:37 - 2021-05-30 21:37 - 000000000 ____D C:\ProgramData\XM5F4DB5NX1APE5P44PKAO610
2021-05-09 19:56 - 2021-06-04 00:10 - 000002956 _____ C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_josev
2021-05-09 19:56 - 2021-05-11 22:55 - 000002940 _____ C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (josev)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} =>  -> Ningún archivo
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} =>  -> Ningún archivo
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> Ningún archivo
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll => Ningún archivo
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2020-01-31] (IObit Information Technology -> IObit)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll => Ningún archivo
C:\Program Files\EnigmaSoft
C:\Program Files (x86)\IObit

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END

Lo guardas con el nombre de FIXLIST.TXT en tu escritorio (MUY IMPORTANTE). Pues en caso contrario no funcionará el SCRIPT, ambos ficheros (FRST.exe y FIXLIST.TXT ) y deben de estar en la ubicación del ESCRITORIO.

:warning: El anterior Script de reparación es personalizado para la máquina en concreto para la cual se fabricó y está hecho específicamente por un miembro del Staff. Si se tiene un problema parecido, por favor abra su propio tema para recibir ayuda personalizada y específica. Utilizar Scripts de otros Sistemas puede causar daños graves en su ordenador.

Finalmente (OJO, en MODO NORMAL):

  1. Ejecutas nuevamente FRST.exe (Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona - Ejecutar como Administrador).

  2. Presionas sobre Fix/Corregir y esperas a que finalice el proceso. No hagas nada con el PC mientras este realizando dichas reparaciones, incluso si parece ser que se ha quedado colgado. No lo toques y esperas.

  3. Cunado finalice, en el ESCRITORIO se creará el fichero FIXLOG.TXT lo traes en tu próxima respuesta.

  4. Reinicias el ordenador en Modo Normal compruebas durante un rato el funcionamiento de este y comentas como sigue el problema inicialmente planteado.

:warning: Muy Importante :warning: Coloca el reporte que te he pedido como se muestra en la siguiente imagen:

Salu2.

Hola buenas tardes, ya hice todo. EL ordenador igal que antes, solo que no lo siento tan lento ahora si El Windows defender y update inhabilitados aun, no me los deja activar porque me pide permisos de administrador en tiempo real, etc

Aqui te dejo informe de FIXLOG Fixlog.txt (121,4 KB)

Hola, buenas @Spacegiraffe

OK eso es bueno. :+1: pues por allí tenías algunos malware de tipo Adware entre otras cosas por allí medio escondidas, entre otros.

OK. Esto después lo arreglaremos sin ningún problema. Y es por esta línea:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Pues salen: (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) y deberían de ser en un ordenador normal (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) y eso se debe a que el malware ha hecho ciertas modificaciones en tu máquina.

Pero vayamos poco a poco y ya verás en como vamos tomando el control del equipo. Pero antes hay/he visto una cosa extraña. En el FIXLOG que me has puesto. En esta parte cocnreta:

C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe => No se encontró ningún proceso en ejecución
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{595ECD05-05D3-45ED-994C-47589A0004DA}" => no encontrado
"C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_josev" => no encontrado
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_josev" => no encontrado
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4673C02-24F6-4C1E-8716-CE11E8FD5343}" => no encontrado
"C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (josev)" => no encontrado
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (josev)" => no encontrado
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F70FE66B-CCC4-404B-A116-BC4D2ACF4C51}" => no encontrado
"C:\WINDOWS\System32\Tasks\USER_ESRV_SVC_QUEENCREEK" => no encontrado
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\USER_ESRV_SVC_QUEENCREEK" => no encontrado
"C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job" => no encontrado
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => no encontrado
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\BookReader_B171F20233094AC88D05A8EF7B9763E8 => no encontrado
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => no encontrado
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\ExtensionsStore\datastore\Config\PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => no encontrado
HKU\S-1-5-21-2251894981-3858074833-453683670-1001\SOFTWARE\Microsoft\Edge\Extensions\llbjbkhnmlidjebalopleeepgdfgcpec => no encontrado
"HKLM\Software\Mozilla\Firefox\Extensions\\[email protected]" => no encontrado
"HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\light_plugin_7571494CE0B94E[email protected]" => no encontrado
"HKU\S-1-5-21-2251894981-3858074833-453683670-1001\Software\Mozilla\SeaMonkey\Extensions\\[email protected]" => no encontrado
"HKU\S-1-5-21-2251894981-3858074833-453683670-1001\Software\Mozilla\SeaMonkey\Extensions\\[email protected]" => no encontrado
HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => no encontrado
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => no encontrado
EsgShKernel => servicio no encontrado.
ShMonitor => servicio no encontrado.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpyHunter5.lnk" => no encontrado
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnigmaSoft" => no encontrado
"C:\ProgramData\EnigmaSoft Limited" => no encontrado
"C:\sh5ldr" => no encontrado
"C:\Program Files\EnigmaSoft" => no encontrado
"C:\Users\josev\Downloads\SpyHunter-Installer.exe" => no encontrado
"C:\@RestoreQuarantine" => no encontrado
"C:\Users\josev\Documents\RegRun2" => no encontrado
"C:\Users\Public\Documents\RegRunInfo" => no encontrado
"C:\ProgramData\Q2DYW1LZCFOQ9F6WWXYFF4KNH" => no encontrado
"C:\ProgramData\SystemAcCrux" => no encontrado
"C:\ProgramData\3BR53LEZ3F00VNW921Y0VOTHL" => no encontrado
"C:\SystemID" => no encontrado
"C:\Program Files (x86)\foler" => no encontrado
"C:\ProgramData\XM5F4DB5NX1APE5P44PKAO610" => no encontrado
"C:\WINDOWS\system32\Tasks\Uninstaller_SkipUac_josev" => no encontrado
"C:\WINDOWS\system32\Tasks\Driver Booster SkipUAC (josev)" => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => no encontrado
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => no encontrado
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => no encontrado
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\MBAMShlExt => no encontrado
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\MBAMShlExt => no encontrado
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8} => no encontrado
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => no encontrado
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8} => no encontrado
"C:\Program Files\EnigmaSoft" => no encontrado
"C:\Program Files (x86)\IObit" => no encontrado

Fíjate que absolutamente en todas las líneas sale: no encontrado y eso es muy extraño. ¿Has ejecutado el Script de Reparación más de una vez en tu máquina? Me cuentas acerca de esto que comento.

También vuelves a ejecutar nuevamente FRST y me traes ambos reportes frescos de este. Lo haces tal y como te indique en:

Salu2.