Problemas con Pup Optional Legacy

Hola, buenos días,

Observe un comportamiento extraño en mi pc (al iniciar me cambiaba el tema a negro, paracía como si estuviese todo la pantalla en negativo). Pase el malwarabites y adwcleaner y salio el Pup Optinal Legacy como no lo eliminaba. Pase a hacer lo que decias por aqui en modo a prueba de fallos CCleaner, Malwarebites, Awcleaner, jrt y fsrt64 parecia que lo habia eliminado. Pero oh sorpresa esta mañana volvio a suceder he vuelto a hacer todo el proceso pero esta vez sin conexion a internet, parece ser que ahora esta limpio. ¿Me podeis ayudar a verificar que realmente sea asi? Gracias

Hola @Nubol.

Nos puedes poner los informes de las herramientas usadas para que podamos valorar los resultados…??

Saludos.

# -------------------------------

# Malwarebytes AdwCleaner 7.4.2.0

# -------------------------------

# Build: 10-21-2019

# Database: 2019-11-20.1 (Cloud)

# Support: https://www.malwarebytes.com/support

# -------------------------------

# Mode: Clean

# -------------------------------

# Start: 11-25-2019

# Duration: 00:00:03

# OS: Windows 7 Ultimate

# Cleaned: 2

# Failed: 0

***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Classes\tsckmna Deleted HKU\S-1-5-21-811658154-4134238313-3946999917-1001\Software\Myfree Codec

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.

[+] Delete Tracing Keys [+] Reset Winsock

AdwCleaner_Debug.log - [9084 octets] - [25/11/2019 14:48:41] AdwCleaner[S00].txt - [1521 octets] - [25/11/2019 14:49:18]
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 24-04-2020
Ejecutado por Carmen (26-04-2020 12:35:13)
Ejecutado desde C:\Users\Carmen\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2013-05-30 10:08:41)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-811658154-4134238313-3946999917-500 - Administrator - Disabled)
Carmen (S-1-5-21-811658154-4134238313-3946999917-1000 - Administrator - Enabled) => C:\Users\Carmen
HomeGroupUser$ (S-1-5-21-811658154-4134238313-3946999917-1003 - Limited - Enabled)
Invitado (S-1-5-21-811658154-4134238313-3946999917-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-811658154-4134238313-3946999917-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: ESET Security (Disabled - Out of date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: Spybot - Search and Destroy (Disabled - Out of date) {A16C3F68-9280-E053-1818-342707FECF4D}
AS: ESET Security (Disabled - Out of date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0015-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0016-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0018-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0019-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001A-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001B-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-0403-0000-0000000FF1CE}_ENTERPRISE_{A5B6B786-2D6F-4B75-940F-42B32D01D146}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{430971B1-C31E-45DA-81E0-72C095BAB72C}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{669EB263-0AFE-4FCB-A068-DB082CA6273C}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-042D-0000-0000000FF1CE}_ENTERPRISE_{042190ED-F17C-4A8D-95D8-87A37B4095BD}) (Version:  - ) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-0456-0000-0000000FF1CE}_ENTERPRISE_{D3064ADE-5D4C-4AA4-8F71-C63D87D4A263}) (Version:  - ) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{00C5525B-3CB3-467D-8100-2E6FB306CD86}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-002A-0C0A-1000-0000000FF1CE}_ENTERPRISE_{35B14BD6-6042-4A55-B326-58309DC8C72A}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}) (Version:  - Microsoft)
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0044-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-006E-0C0A-0000-0000000FF1CE}_ENTERPRISE_{35B14BD6-6042-4A55-B326-58309DC8C72A}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-00A1-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
2007 Microsoft Office Suite Service Pack 1 (SP1) (HKLM-x32\...\{90120000-00BA-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2CC8520D-6A74-4CCA-9539-8E774E2B50D1}) (Version:  - Microsoft) Hidden
4K Video Downloader 4.2 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.2.0.2175 - Open Media LLC)
µTorrent (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\uTorrent) (Version: 3.4.9.43295 - BitTorrent Inc.)
Actualización de NVIDIA 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.5.353 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.0 - Adobe Systems Incorporated)
Adobe Extension Manager CC (HKLM-x32\...\{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}) (Version: 7.3.2 - Adobe Systems Incorporated)
Adobe Flash Player 32 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 32.0.0.363 - Adobe)
Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.363 - Adobe)
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.363 - Adobe)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe InDesign CC 2017 (HKLM-x32\...\IDSN_12_0_0) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.9 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
Amazon Kindle (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Amazon Kindle) (Version: 1.26.0.55076 - Amazon)
APLI Master (HKLM-x32\...\{4767CC38-E667-4447-B60C-4C0721C1E091}) (Version: 6.4.11 - APLI Paper S.A.) Hidden
APLI Master (HKLM-x32\...\InstallShield_{4767CC38-E667-4447-B60C-4C0721C1E091}) (Version: 6.4.11 - APLI Paper S.A.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
ArcSoft PhotoBase 3 (HKLM-x32\...\{C1D14C0D-FDAA-4DF2-8441-A902805CCE8C}) (Version:  - )
ArcSoft PhotoStudio 5 (HKLM-x32\...\{03F1CC67-5BD8-4C36-8394-76311B2AE69A}) (Version:  - )
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.)
aTube Catcher versión 3.8 (HKLM-x32\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version:  - Audacity Team)
BCC 8 OFX 64Bit (HKLM\...\{24D38864-527F-4688-B831-A1A4CC60CD54}) (Version: 8.0.1 - Boris FX, Inc.)
Bitnami WordPress Stack (HKLM-x32\...\Bitnami WordPress Stack 3.9.2-0) (Version: 3.9.2-0 - Bitnami)
BusinessCards MX (HKLM-x32\...\{0D5B5ED2-3E38-4585-B1F3-64B2A9EA95D6}_is1) (Version: 4.94 - MOJOSOFT)
CCleaner (HKLM\...\CCleaner) (Version: 5.63 - Piriform)
Citrix Online Launcher (HKLM-x32\...\{3318B54A-B5A8-49B1-8016-753DC6CAC63B}) (Version: 1.0.110 - Citrix)
Compact First 2nd Edition content (HKLM-x32\...\Compact First 2nd Edition content) (Version: 1.0.0.0 - Cambridge University Press)
Compatibilidad con Aplicaciones de Apple (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Complemento Guardar como PDF o XPS de Microsoft para programas de Microsoft Office 2007 (HKLM-x32\...\{90120000-00B2-0C0A-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Compresor WinRAR (HKLM-x32\...\WinRAR archiver) (Version:  - )
ConvertHelper 3.1.1 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version:  - DownloadHelper)
Coowon (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Coowon) (Version: 1.6.8.0 - Coowon)
Digital Element Aurora Demo (HKLM-x32\...\{8A071001-2D1C-445A-ACFE-365D540C719B}) (Version:  - )
Discord (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Discord) (Version: 0.0.306 - Discord Inc.)
Dolby Axon - 1.5.1.1 (HKLM-x32\...\{17936630-5344-4F18-9970-616129E2A114}_is1) (Version: 1.5.1.1 - Dolby Laboratories)
Dropbox (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Dropbox) (Version: 95.4.441 - Dropbox, Inc.)
EPSON Attach To Email (HKLM-x32\...\{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON) Hidden
EPSON Attach To Email (HKLM-x32\...\InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}) (Version: 1.01.0000 - SEIKO EPSON)
Epson Easy Photo Print 2 (HKLM-x32\...\{30E01116-5666-4807-8EF1-D80E9FF16717}) (Version: 2.3.2.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
EPSON File Manager (HKLM-x32\...\{D02F30FB-0BC4-419A-9B9C-ADC610029B50}) (Version: 1.3.2.0 - )
Epson Print CD (HKLM-x32\...\{D16A31F9-276D-4968-A753-FFEAC56995D0}) (Version: 2.20.00 - SEIKO EPSON CORPORATION)
EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - )
ESET Security (HKLM\...\{C26AA376-9D1B-4B7B-A1F0-DC41E8530176}) (Version: 11.2.49.0 - ESET, spol. s r.o.)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology) Hidden
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FotoPrix FotoLibro v4 (HKLM-x32\...\{2FEC2258-5F07-400B-82AE-232510ED187D}) (Version: 6.10.0049 - FotoPrix, S.A.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.122 - Google LLC)
Google Earth Pro (HKLM\...\{70A0F34E-564B-4F93-ADD6-3BAEC6E44075}) (Version: 7.3.2.5776 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoToMeeting 5.4.0.1082 (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\GoToMeeting) (Version: 5.4.0.1082 - CitrixOnline)
HandBrake 1.0.7 (HKLM-x32\...\HandBrake) (Version: 1.0.7 - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Java 8 Update 241 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180241F0}) (Version: 8.0.2410.7 - Oracle Corporation)
K-Lite Mega Codec Pack 9.7.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.7.5 - )
League of Legends (HKLM-x32\...\{C3342033-211F-40DD-A03D-0E775B8DEA98}) (Version: 3.0.1 - Riot Games) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
MemoriesOnTV 4 Full (HKLM-x32\...\MemoriesOnTV 4 Full) (Version:  - )
MemoriesOnTV 4.1.2 (HKLM-x32\...\MemoriesOnTV4_is1) (Version:  - )
MemoriesOnTV ClipShow Volume 1 (HKLM-x32\...\MemoriesOnTV3-CS1_is1) (Version:  - )
MemoriesOnTV ClipShow Volume 2 (HKLM-x32\...\MemoriesOnTV-CS2_is1) (Version:  - )
Microsoft .NET Framework 4.6.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft MPEG-4 VKI Video Codec V1/V2/V3 (HKLM-x32\...\MS-MPEG4) (Version:  - )
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6215.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0C0A-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Mike Crash's Vegas Filters Uninstall (HKLM-x32\...\Mike Crash Vegas Filters) (Version:  - )
Mozilla Firefox 75.0 (x64 es-ES) (HKLM\...\Mozilla Firefox 75.0 (x64 es-ES)) (Version: 75.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0.2 - Mozilla)
MX5 (HKLM-x32\...\Maxthon5) (Version: 5.2.3.4000 - Maxthon International Limited)
Neat Video v2.6 Pro plug-in for Sony Vegas (64-bit) (HKLM\...\Neat Video for Sony Vegas_is1) (Version:  - Neat Video team, ABSoft)
Nero 8.3.2.1 (HKLM-x32\...\Nero8WinuE_is1) (Version: 8.3.2.1 - Bj @ WinuE)
NetLimiter 3 (HKLM\...\{913923AB-3AAB-4870-8910-627C4CD82789}) (Version: 3.0.0.11 - Locktime Software) Hidden
NetLimiter 3 (HKLM-x32\...\NetLimiter 3 3.0.0.11) (Version: 3.0.0.11 - Locktime Software)
NewBlue 3D Explosions for Vegas (HKLM-x32\...\NewBlue 3D Explosions for Vegas) (Version:  - )
NewBlue Art Blends 2.0 for Vegas (HKLM-x32\...\NewBlue Art Blends 2.0 for Vegas) (Version:  - )
NewBlue Art Effects 2.0 for Vegas (HKLM-x32\...\NewBlue Art Effects 2.0 for Vegas) (Version:  - )
NewBlue Film Effects for Vegas (HKLM-x32\...\NewBlue Film Effects for Vegas) (Version:  - )
NewBlue Motion Blends 2.0 for Vegas (HKLM-x32\...\NewBlue Motion Blends 2.0 for Vegas) (Version:  - )
NewBlue Motion Effects 2.0 for Vegas (HKLM-x32\...\NewBlue Motion Effects 2.0 for Vegas) (Version:  - )
NewBlue Motion Effects for Windows (HKLM-x32\...\NewBlue Motion Effects for Windows) (Version:  - )
NewBlue Paint Blends for Windows (HKLM-x32\...\NewBlue Paint Blends for Windows) (Version: 1.4 - NewBlue)
NewBlue Paint Effects for Windows (HKLM-x32\...\NewBlue Paint Effects for Windows) (Version: 1.4 - NewBlue)
NewBlue Sampler Pack for Windows (HKLM-x32\...\NewBlue Sampler Pack for Windows) (Version: 1.4 - NewBlue)
NewBlue Stabilizer for Windows (HKLM-x32\...\NewBlue Stabilizer for Windows) (Version: 1.4 - NewBlue)
NewBlue Video Essentials for Windows (HKLM-x32\...\NewBlue Video Essentials for Windows) (Version:  - )
NewBlue Video Essentials II  for Windows (HKLM-x32\...\NewBlue Video Essentials II  for Windows) (Version:  - )
NewBlue Video Essentials III  for Windows (HKLM-x32\...\NewBlue Video Essentials III  for Windows) (Version:  - )
NewBlue Video Essentials IV for Windows (HKLM-x32\...\NewBlue Video Essentials IV for Windows) (Version: 1.4 - NewBlue)
Nitro Pro 8 (HKLM\...\{CF85054A-065D-4A60-9789-71CAB54A04AB}) (Version: 8.5.3.14 - Nitro)
NMSDVDX64 v1.1 (HKLM\...\{49C4A807-A535-4E85-BD6D-5A7803473CA3}) (Version: 1.01.0001 - FOTOPRIX)
NVIDIA Controlador de 3D Vision 306.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 306.23 - NVIDIA Corporation)
NVIDIA Controlador de audio HD 1.3.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.18.0 - NVIDIA Corporation)
NVIDIA Controlador de gráficos 306.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.23 - NVIDIA Corporation)
NVIDIA Controlador de la controladora 3D Vision 306.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 306.23 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.12.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 22.0.2 - OBS Project)
Opera GX Stable 67.0.3575.130 (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Opera GX 67.0.3575.130) (Version: 67.0.3575.130 - Opera Software)
Opera Stable 67.0.3575.137 (HKLM-x32\...\Opera 67.0.3575.137) (Version: 67.0.3575.137 - Opera Software)
Panda Cloud Cleaner (HKLM-x32\...\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.1.10 - Panda Security)
Panel de control de NVIDIA 306.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 306.23 - NVIDIA Corporation) Hidden
PDF Settings CS5 (HKLM-x32\...\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Perfect Resize 7.5 (HKLM-x32\...\{EFBAD7A9-39AB-4C34-8745-0DEBA5BDC793}) (Version: 7.5 - onOne Software)
Photoshop Camera Raw (HKLM-x32\...\{CC75AB5C-2110-4A7F-AF52-708680D22FE8}) (Version: 5.0 - Adobe Systems Incorporated) Hidden
PokerStars.es (HKLM-x32\...\PokerStars.es) (Version:  - PokerStars.es)
proDAD Heroglyph 4.0 (64bit) (HKLM\...\proDAD-Heroglyph-4.0) (Version: 4.0.215.1 - proDAD GmbH)
proDAD Heroglyph 4.0 (HKLM-x32\...\proDAD-Heroglyph-4.0) (Version: 4.0.187.1 - proDAD GmbH)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RaidCall (HKLM-x32\...\RaidCall) (Version: 8.1.8-1.0.3112.146 - raidcall.com.ru)
Raton Automatico (HKLM-x32\...\{3DAB198C-CAB0-4DD4-90A5-97CF77386B10}) (Version: 2.0.0 - Nanduky)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6662 - Realtek Semiconductor Corp.)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.15013.17 - Samsung Electronics Co., Ltd.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.51.0 - SAMSUNG Electronics Co., Ltd.)
Skype versión 8.59 (HKLM-x32\...\Skype_is1) (Version: 8.59 - Skype Technologies S.A.)
Software de impresora EPSON (HKLM\...\EPSON Printer and Utilities) (Version:  - SEIKO EPSON Corporation)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Suite Shared Configuration CS4 (HKLM-x32\...\{842B4B72-9E8F-4962-B3C1-1C422A5C4434}) (Version: 1.0 - Adobe Systems Incorporated) Hidden
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1254 - SUPERAntiSpyware.com)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.10 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Update for Outlook 2007 Junk Email Filter (kb947945) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E397056B-7AE5-4FF1-8B13-276BF8201847}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden
Vegas Pro 11.0 (64-bit) (HKLM\...\{7ECB8630-029B-11E2-8624-F04DA23A5C58}) (Version: 11.0.701 - Sony)
Vivaldi (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Vivaldi) (Version: 1.10.867.42 - Vivaldi)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
VSO Video Converter 1 (HKLM-x32\...\{{5289246A-D537-4823-88C2-38C17840E45A}_is1) (Version: 1.2.0.10 - VSO Software)
VueScan (HKLM\...\VueScan) (Version:  - )
VueScan (HKLM-x32\...\VueScan) (Version:  - )
Windows Live Messenger (HKLM-x32\...\{1692CC0E-8798-493A-9580-23555E21C14B}) (Version: 8.1.0178.00 - Microsoft Corporation)
Wondershare Filmora9(Build 9.1.2) (HKLM\...\Wondershare Filmora9_is1) (Version:  - Wondershare Software)
Wondershare Helper Compact 2.6.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.6.0 - Wondershare)
XAMPP (HKLM-x32\...\xampp) (Version: 1.8.3-4 - Bitnami)
XviD MPEG-4 Video Codec (HKLM-x32\...\xvid) (Version:  - XviD Development Team)
ZD Soft Screen Recorder (HKLM-x32\...\{A5577679-F710-4250-BAEE-B64FF88FEBC2}) (Version: 5.0.0 - ZD Soft)
Zoom (HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\Citrix\GoToMeeting\1082\G2MOutlookAddin64.dll (Citrix Online -> Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-811658154-4134238313-3946999917-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll (Dropbox, Inc -> Dropbox, Inc.)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2212224 2007-08-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2018-10-29] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers1: [NP8ShellExtension] -> {9C4B85B8-956C-49BF-9BA5-101384E562B2} => C:\Program Files\Common Files\Nitro\Pro\8.0\NPShellExtension64.dll [2013-04-30] (Nitro PDF Software -> Nitro PDF)
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2006-12-11] () [Archivo no firmado]
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2007-09-20] () [Archivo no firmado]
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2018-10-29] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2006-12-11] () [Archivo no firmado]
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2007-09-20] () [Archivo no firmado]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2012-08-30] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] (Adobe Systems Incorporated -> )
ContextMenuHandlers6: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2018-10-29] (ESET, spol. s r.o. -> ESET)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2006-12-11] () [Archivo no firmado]
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2007-09-20] () [Archivo no firmado]
ContextMenuHandlers1_S-1-5-21-811658154-4134238313-3946999917-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-811658154-4134238313-3946999917-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-811658154-4134238313-3946999917-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Carmen\AppData\Roaming\Dropbox\bin\DropboxExt64.37.0.dll [2020-04-01] (Dropbox, Inc -> Dropbox, Inc.)

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [vidc.pDAD] => C:\Windows\system32\prodad-codec.dll [607688 2011-02-26] (proDAD GmbH -> proDAD GmbH)
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [180224 2006-11-01] () [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.HFYU] => C:\Windows\SysWOW64\huffyuv.dll [39936 2004-05-18] (Disappearing Inc.) [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112640 2013-02-06] () [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [4102656 2012-07-02] (x264vfw project) [Archivo no firmado]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [151552 2011-12-21] (fccHandler) [Archivo no firmado]
HKLM\...\Drivers32: [msacm.lameacm] => C:\Windows\SysWOW64\lameACM.acm [839680 2008-09-24] (hxxp://www.mp3dev.org/) [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.MPG4] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2001-01-07] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.MP42] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2001-01-07] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.MP43] => C:\Windows\SysWOW64\mpg4c32.dll [413760 2001-01-07] (Microsoft Corporation) [Archivo no firmado]
HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [Archivo no firmado]

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2018-06-16 20:07 - 2020-04-14 16:34 - 001899520 _____ () [Archivo no firmado] C:\Program Files (x86)\Microsoft\Skype for Desktop\ffmpeg.dll
2018-06-16 20:07 - 2020-04-14 16:34 - 000115712 _____ () [Archivo no firmado] C:\Program Files (x86)\Microsoft\Skype for Desktop\libegl.dll
2018-06-16 20:07 - 2020-04-14 16:34 - 006668800 _____ () [Archivo no firmado] C:\Program Files (x86)\Microsoft\Skype for Desktop\libglesv2.dll
2013-05-30 12:53 - 2006-12-11 02:14 - 000043008 _____ () [Archivo no firmado] C:\Program Files (x86)\WinRAR\rarext64.dll

==================== Alternate Data Streams (Lista blanca) ========

(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)

AlternateDataStreams: C:\ProgramData\TEMP:C36F1B98 [272]

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2009-07-14 04:34 - 2018-03-11 15:16 - 000000035 _____ C:\Windows\system32\drivers\etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Carmen\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

(Si una entrada es incluida en el fixlist, será eliminada.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: APLI Master AutoUpdater => 2
MSCONFIG\Services: EPSON_PM_RPCV4_01 => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: MaxthonUpdateSvc => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NitroDriverReadSpool8 => 2
MSCONFIG\Services: nlsvc => 2
MSCONFIG\Services: nlsX86cc => 2
MSCONFIG\Services: NMSAccess64 => 2
MSCONFIG\Services: ss_conn_service => 2
MSCONFIG\Services: wordpressApache => 2
MSCONFIG\Services: wordpressMySQL => 2
MSCONFIG\startupfolder: C:^Users^Carmen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeGCInvoker-1.0 => "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: B4AF.tmp => C:\Users\Carmen\AppData\Local\Temp\B4AF.tmp.exe
MSCONFIG\startupreg: Discord => C:\Users\Carmen\AppData\Local\Discord\app-0.0.301\Discord.exe
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Carmen\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: EPSON Stylus Photo R285 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICKE.EXE /FU "C:\Users\Carmen\AppData\Local\Temp\E_S4062.tmp" /EF "HKCU"
MSCONFIG\startupreg: Facebook Update => "C:\Users\Carmen\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: jjs => C:\Users\Carmen\AppData\Roaming\Java\3.5\jjs.exe
MSCONFIG\startupreg: Publisher => C:\Users\Carmen\AppData\Local\Temp\{852fe6dd5b974a2687ca0ba3ed14d906}\kCtTSN4Fun\publisher.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RaidCall => C:\Program Files (x86)\RaidCall.RU\raidcall.exe
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: SpybotPostWindows10UpgradeReInstall => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [{BD773BB7-04C5-440F-9BB9-7BDC336C8315}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{5744E31B-1E86-4B4E-AA98-F4663180E86F}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{B9326C98-7651-4038-BF74-8E7362D6293A}] => (Allow) C:\Program Files (x86)\MSN Messenger\msnmsgr.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{08A6EC49-1171-42C7-9E2F-1174F69B9391}] => (Allow) svchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{CED90711-AC49-4298-93EC-1BFE7D326587}] => (Allow) C:\Program Files (x86)\MSN Messenger\livecall.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3599A070-E506-4043-BF81-B77AAC43F574}] => (Allow) C:\Users\Carmen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [{5076DC96-6A26-4380-8B9A-0D7A6B05CBA3}] => (Allow) C:\Users\Carmen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [TCP Query User{1E62C2FB-A838-432A-AB55-B3BEE2E61B59}C:\users\carmen\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\carmen\appdata\roaming\dropbox\bin\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [UDP Query User{05D9F8E3-C365-4D81-948A-99B931C97541}C:\users\carmen\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\carmen\appdata\roaming\dropbox\bin\dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
FirewallRules: [TCP Query User{8E240FDD-458C-42D2-A4BE-87ADD30ECFAC}C:\program files (x86)\microsoft office\office12\groove.exe] => (Block) C:\program files (x86)\microsoft office\office12\groove.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{050F3423-DD5E-44AF-B311-C757B08DEE63}C:\program files (x86)\microsoft office\office12\groove.exe] => (Block) C:\program files (x86)\microsoft office\office12\groove.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BFB1A318-E2E7-446C-8883-8D238EF61384}] => (Allow) C:\Program Files (x86)\DolbyAxon\Axon.exe (Dolby Laboratories, Inc. -> Dolby Laboratories)
FirewallRules: [{8D091EEC-6DDE-4B02-BE4D-8FA31E363AC7}] => (Allow) C:\Program Files (x86)\DolbyAxon\Axon.exe (Dolby Laboratories, Inc. -> Dolby Laboratories)
FirewallRules: [TCP Query User{D0219BCD-6C50-4094-B2F3-AA2D2226FA5B}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe (Apache Software Foundation) [Archivo no firmado]
FirewallRules: [UDP Query User{96ECF92F-6A5C-426D-BEF6-1AF9B0C9F4DD}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe (Apache Software Foundation) [Archivo no firmado]
FirewallRules: [TCP Query User{88AA9989-6E8F-4F46-8D43-F3ED4ED8A2DD}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{2EDF2961-4186-4F35-B14A-5ADE031D00AE}C:\xampp\mysql\bin\mysqld.exe] => (Allow) C:\xampp\mysql\bin\mysqld.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{D036FC6A-134E-4D6D-B881-E8B2FA7FF4E0}C:\bitnami\wordpress-3.9.2-0\apache2\bin\httpd.exe] => (Allow) C:\bitnami\wordpress-3.9.2-0\apache2\bin\httpd.exe (Apache Software Foundation) [Archivo no firmado]
FirewallRules: [UDP Query User{F6F2B4E5-6915-415B-9F12-0CA1DA61345F}C:\bitnami\wordpress-3.9.2-0\apache2\bin\httpd.exe] => (Allow) C:\bitnami\wordpress-3.9.2-0\apache2\bin\httpd.exe (Apache Software Foundation) [Archivo no firmado]
FirewallRules: [{096ECBEA-01E4-4DE5-8122-E5FF735D50B8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{689FA6E3-8B54-453C-924E-9C9684D67094}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{79277413-D57C-448B-9F43-8AD2653AB68F}] => (Allow) C:\Windows\SysWOW64\muzapp.exe (Musiccity Co.Ltd.) [Archivo no firmado]
FirewallRules: [{F786D372-977D-4AEB-92A4-E846596932CC}] => (Allow) C:\Windows\SysWOW64\muzapp.exe (Musiccity Co.Ltd.) [Archivo no firmado]
FirewallRules: [{F21967A4-E0C3-4135-88B5-9A8BB468F0CB}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{85F4B94F-634E-43F5-8D0B-CB78C44D19A6}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.)
FirewallRules: [{42F097C6-669F-4602-B336-1530BD902875}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.)
FirewallRules: [{3B509461-147B-481C-912E-502192DCC60D}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.)
FirewallRules: [{129BBF6A-7BD2-428A-B205-8C6EECA1EB36}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe (Maxthon (Asia) Limited. -> Maxthon International ltd.)
FirewallRules: [TCP Query User{DA14B11C-7FE1-44D2-9CD6-BDC978252004}C:\program files\onone software\perfect resize 7.5\perfect resize 7.5.exe] => (Allow) C:\program files\onone software\perfect resize 7.5\perfect resize 7.5.exe (onOne Software) [Archivo no firmado]
FirewallRules: [UDP Query User{7AEA32D0-5A67-4FAC-B76F-7CA3BE6DFAD8}C:\program files\onone software\perfect resize 7.5\perfect resize 7.5.exe] => (Allow) C:\program files\onone software\perfect resize 7.5\perfect resize 7.5.exe (onOne Software) [Archivo no firmado]
FirewallRules: [TCP Query User{C45F1EAB-8E50-48F8-946A-99B4F4E39465}C:\program files\onone software\perfect photo suite 9\perfect photo suite 9.exe] => (Allow) C:\program files\onone software\perfect photo suite 9\perfect photo suite 9.exe (onOne Software, Inc. -> onOne Software)
FirewallRules: [UDP Query User{91DD23E2-17F6-4AFE-83CA-125904FCCCBE}C:\program files\onone software\perfect photo suite 9\perfect photo suite 9.exe] => (Allow) C:\program files\onone software\perfect photo suite 9\perfect photo suite 9.exe (onOne Software, Inc. -> onOne Software)
FirewallRules: [{0DF47FCA-23F7-4857-A96A-469E21B50884}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{C43B5C39-4408-40CE-B5F8-15D14A245950}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{D0AD0811-7C0A-47A5-8025-8CBF0F7BC45C}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe (RAIDCALL LIMITED. -> RAIDCALL.COM) [Archivo no firmado]
FirewallRules: [{B42FE430-321E-44A6-8293-8CEC6682CAAC}] => (Allow) C:\Program Files (x86)\RaidCall.RU\rcplugin.exe (RAIDCALL LIMITED. -> RAIDCALL.COM) [Archivo no firmado]
FirewallRules: [{4192D21C-3C3C-4B02-A733-D0D347BB15D9}] => (Allow) C:\Users\Carmen\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{13F4DF76-C733-4985-B394-3B8BC86B8A5B}] => (Allow) C:\Users\Carmen\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{044EF3BD-746B-4378-BDB0-3369DD763C88}] => (Allow) C:\Users\Carmen\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{48C68519-B265-44E5-929F-13A1D321BC9A}] => (Allow) C:\Users\Carmen\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{7C1841E7-7AC5-4E76-8355-05DD0AA8E425}] => (Allow) C:\Users\Carmen\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{E9EAA24B-EC8F-42CE-81F6-1CF0E6EDF28F}] => (Allow) C:\Users\Carmen\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{37D3EBD0-DB49-4A7D-AA71-A42CD7487046}] => (Block) %ProgramFiles%\Sony\Vegas Pro 11.0\vegas110.exe Ningún archivo
FirewallRules: [{5F56B637-6C87-4098-A5A0-9E8162366793}] => (Block) %ProgramFiles%\Sony\Vegas Pro 11.0\vegas110.exe Ningún archivo
FirewallRules: [{E26F3CD1-FAC3-41CD-84F5-04F0EA060A53}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{8EABAB05-10C6-42FE-9426-9E6600A5A621}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{00C43DB0-97D0-4658-ADB1-B8353A79F025}] => (Allow) C:\Program Files (x86)\Opera\67.0.3575.115\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{6B29CC3D-7127-4C1A-8055-6BABD3CC9029}] => (Allow) C:\Program Files (x86)\Opera\67.0.3575.137\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [TCP Query User{88FF9FDE-1F6A-4A79-82D3-80BDFCED4C32}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{4C02BEA7-31A7-4412-976C-6114D243E071}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{285D0A68-8070-42D0-912D-761176A9C2A2}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F205F05D-902A-43C3-B265-447832407FBA}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D3E85378-09F5-48D1-8CCD-D1187731B1B5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Puntos de Restauración =========================

26-04-2020 12:29:32 JRT Pre-Junkware Removal

==================== Dispositivos defectuosos en el Administrador de dispositivos ============


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (04/26/2020 12:28:14 PM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Error de activación de la licencia de Windows. Error 0x00000000.

Error: (04/26/2020 12:28:14 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
0x80070005

Error: (04/26/2020 11:09:40 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Error de activación de la licencia de Windows. Error 0x00000000.

Error: (04/26/2020 11:09:40 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
0x80070005

Error: (04/26/2020 11:03:45 AM) (Source: Winlogon) (EventID: 4103) (User: )
Description: Error de activación de la licencia de Windows. Error 0x00000000.

Error: (04/26/2020 11:03:45 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
0x80070005

Error: (04/25/2020 05:25:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: Explorer.EXE, versión: 6.1.7601.23537, marca de tiempo: 0x57c44efe
Nombre del módulo con errores: ntdll.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a499ad2
Código de excepción: 0xc015000f
Desplazamiento de errores: 0x0000000000087af6
Id. del proceso con errores: 0x9a4
Hora de inicio de la aplicación con errores: 0x01d61b11702d3239
Ruta de acceso de la aplicación con errores: C:\Windows\Explorer.EXE
Ruta de acceso del módulo con errores: C:\Windows\SYSTEM32\ntdll.dll
Id. del informe: f7964bcf-8708-11ea-b8a8-94de803c577f

Error: (04/25/2020 05:25:12 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: Explorer.EXE, versión: 6.1.7601.23537, marca de tiempo: 0x57c44efe
Nombre del módulo con errores: SHELL32.dll, versión: 6.1.7601.24000, marca de tiempo: 0x5a499a78
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x00000000000503f6
Id. del proceso con errores: 0x9a4
Hora de inicio de la aplicación con errores: 0x01d61b11702d3239
Ruta de acceso de la aplicación con errores: C:\Windows\Explorer.EXE
Ruta de acceso del módulo con errores: C:\Windows\system32\SHELL32.dll
Id. del informe: f469df2a-8708-11ea-b8a8-94de803c577f


Errores del sistema:
=============
Error: (04/26/2020 12:30:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio NVIDIA Display Driver Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (04/26/2020 12:28:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio CamMask Virtual Webcam no pudo iniciarse debido al siguiente error: 
No se puede iniciar el servicio, porque está deshabilitado o porque no tiene dispositivos habilitados asociados a él.

Error: (04/26/2020 12:28:00 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Se bloqueó la carga de \SystemRoot\SysWow64\drivers\pfc.sys por una incompatibilidad con este sistema. Póngase en contacto con el fabricante del software para obtener una versión compatible del controlador.

Error: (04/26/2020 12:27:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Protección de software terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 120000 milisegundos: Reiniciar el servicio.

Error: (04/26/2020 12:27:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio Intel(R) Management and Security Application User Notification Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (04/26/2020 12:27:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Servicio de uso compartido de red del Reproductor de Windows Media terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 30000 milisegundos: Reiniciar el servicio.

Error: (04/26/2020 12:27:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio NVIDIA Update Service Daemon se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (04/26/2020 12:27:07 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Spybot-S&D 2 Security Center Service terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos: Reiniciar el servicio.


CodeIntegrity:
===================================

Date: 2017-03-07 16:47:39.038
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 16:47:38.928
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 16:47:38.835
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 16:47:38.741
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 16:47:38.663
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 16:47:38.538
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 14:26:32.879
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2017-03-07 14:24:52.762
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume1\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

==================== Información de la memoria =========================== 

BIOS: Award Software International, Inc. F7 07/13/2012
Placa base: Gigabyte Technology Co., Ltd. H61M-D2H-USB3
Procesador: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Porcentaje de memoria en uso: 41%
RAM física total: 8175.24 MB
RAM física disponible: 4802.05 MB
Virtual total: 16348.65 MB
Virtual disponible: 13042.62 MB

==================== Unidades ================================

Drive c: (Windows 7) (Fixed) (Total:244.24 GB) (Free:42.61 GB) NTFS ==>[unidad con componentes de arranque (obtenido de BCD)]
Drive d: (Datos) (Fixed) (Total:687.27 GB) (Free:659.74 GB) NTFS
Drive f: (DATOS 2) (Fixed) (Total:298.09 GB) (Free:75.72 GB) NTFS
Drive g: (Sistema Operativo vIEJO) (Fixed) (Total:195.32 GB) (Free:43.72 GB) NTFS
Drive h: (datos E) (Fixed) (Total:270.44 GB) (Free:51.46 GB) NTFS


==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 9465A43D)
Partition 1: (Active) - (Size=244.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=687.3 GB) - (Type=0F Extended)

==========================================================
Disk: 1 (Size: 298.1 GB) (Disk ID: 8F658F65)
Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)

==========================================================
Disk: 2 (Size: 465.8 GB) (Disk ID: 18CC18CB)
Partition 1: (Not Active) - (Size=195.3 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=270.4 GB) - (Type=0F Extended)

==================== Final de Addition.txt =======================
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Ultimate x64 
Ran by Carmen (Administrator) on 26/04/2020 at 12:29:30,06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2 

Successfully deleted: C:\Users\Carmen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\677ZTJ8K (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\677ZTJ8K (Temporary Internet Files Folder) 



Registry: 0 





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/04/2020 at 12:32:07,95
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Este (FRST) no me deja ponerlo, me dice que no puedo nombrar a 10 usuarios???

Por cierto, hola Javier y gracias

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 24-04-2020
Ejecutado por Carmen (administrador) sobre CARMEN-PC (Gigabyte Technology Co., Ltd. H61M-D2H-USB3) (26-04-2020 12:33:35)
Ejecutado desde C:\Users\Carmen\Desktop
Perfiles cargados: Carmen & UpdatusUser (Perfiles disponibles: Carmen & UpdatusUser & DefaultAppPool)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Idioma: Español (España, internacional)
Internet Explorer Versión 11 (Navegador predeterminado: FF)
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel® Upgrade Service -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Nitro PDF Software -> Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Safer Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) [Archivo no firmado] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) [Archivo no firmado] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Skype Software Sarl -> Skype Technologies S.A.) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe <5>
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\ecmds.exe [177928 2018-10-29] (ESET, spol. s r.o. -> ESET)
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7964080 2018-01-12] (Support.com, Inc. -> SUPERAntiSpyware)
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [91591032 2020-04-14] (Skype Software Sarl -> Skype Technologies S.A.)
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\RunOnce: [Application Restart #2] => C:\Users\Carmen\AppData\Local\Vivaldi\Application\vivaldi.exe [921720 2017-06-21] (Vivaldi Technologies AS -> Vivaldi Technologies AS)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.122\Installer\chrmstp.exe [2020-04-24] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bit

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {03A1BBD3-FFC5-48BB-8840-7767FCA5D60D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {1089F0E8-5701-447F-9F0E-7A6CB2823579} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-811658154-4134238313-3946999917-1000Core => C:\Users\Carmen\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc -> Dropbox, Inc.)
Task: {24A22B6C-500E-4867-AF9A-59CAF3684A16} - System32\Tasks\{3263A8E7-E0CD-4D33-818D-E48B7A8058C1} => C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE [12829216 2007-12-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {341F4F05-70EA-44E7-8BCA-D757395112DE} - System32\Tasks\{C3B50838-C667-48B0-BBAE-0CB022082529} => C:\Program Files (x86)\ZD Soft\Screen Recorder\ScnRec.exe [1659392 2012-10-07] (ZD Soft) [Archivo no firmado]
Task: {38C4ACEC-9128-4FC5-8509-A337D5ECE961} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [6193080 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Archivo no firmado]
Task: {3CEA1EEA-0A8F-47D2-AF1A-7C242E2E4083} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [569416 2016-02-23] (Apple Inc. -> Apple Inc.)
Task: {40FA083A-9926-4A15-852D-B1BADE25616F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd)
Task: {48FAFC19-9FCF-47DD-B6B5-221E149CEA96} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-04-15] (Adobe Inc. -> Adobe)
Task: {4B00E1D2-AEAC-4CB3-A6F3-D35D4371EBC2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {4F3BD806-CC68-43C9-92F1-39B19FCEF751} - System32\Tasks\Opera scheduled Autoupdate 1432404393 => C:\Program Files (x86)\Opera\launcher.exe [1538584 2020-04-08] (Opera Software AS -> Opera Software)
Task: {5425661F-B410-4985-BC7C-F57308A43D87} - System32\Tasks\Opera GX scheduled Autoupdate 1582725757 => C:\Users\Carmen\AppData\Local\Programs\Opera GX\launcher.exe [1480216 2020-04-02] (Opera Software AS -> Opera Software)
Task: {57F64E36-8FF1-4061-8B73-8FB1E625BC2F} - System32\Tasks\{31D48B2D-0B18-4C0C-A2FC-7D19D35E67C4} => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [6895736 2018-10-29] (ESET, spol. s r.o. -> ESET)
Task: {7F29E9DB-0256-4039-BF8A-9C491B03B533} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [5753752 2016-03-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Archivo no firmado]
Task: {92A25A21-D813-4C84-8BEC-CBDF26E2AC92} - System32\Tasks\Opera scheduled assistant Autoupdate 1582274861 => C:\Program Files (x86)\Opera\launcher.exe [1538584 2020-04-08] (Opera Software AS -> Opera Software)
Task: {9778B2A3-9F29-434E-A0A2-BE2AC5C09B24} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3022416 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {A309D206-CD0D-4AD8-85E6-D9AAB6008282} - System32\Tasks\{76043FB6-F90C-4F9E-AA57-91FABF7AE378} => C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE [12829216 2007-12-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {AAA44365-92BC-41B7-B248-EA0584A36511} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [168736 2018-07-10] (Maxthon (Asia) Limited. -> Maxthon International ltd.)
Task: {BACC06DC-DFDF-477C-BFA3-8AB368716F88} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc -> Google Inc.)
Task: {C3216E06-E3B6-455A-90A8-B15E3B046008} - System32\Tasks\{04DBEDD2-15F6-43DB-AED1-510942B8B0C5} => C:\Program Files (x86)\ZD Soft\Screen Recorder\ScnRec.exe [1659392 2012-10-07] (ZD Soft) [Archivo no firmado]
Task: {C46FD7FA-EFF5-4BB8-9721-2090DDF8A324} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_363_pepper.exe [1454136 2020-04-15] (Adobe Inc. -> Adobe)
Task: {CA5EC0D6-AA6C-497C-9ADD-B3F675D28EED} - System32\Tasks\Maxthon5 Update => C:\Program Files (x86)\Maxthon\bin\Maxthon.exe [168736 2018-07-10] (Maxthon (Asia) Limited. -> Maxthon International ltd.)
Task: {DA13FCFC-FB83-4453-BCB5-56E3DE73DF99} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [4747720 2014-06-27] (Safer Networking Ltd. -> Safer-Networking Ltd.)
Task: {EC41F023-E5AF-4319-B428-8A555DBD81A5} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_363_Plugin.exe [1458232 2020-04-15] (Adobe Inc. -> Adobe)
Task: {F2DA2D7F-06F7-4DEF-81CB-6C4C14C765F2} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-811658154-4134238313-3946999917-1000UA => C:\Users\Carmen\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc -> Dropbox, Inc.)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-811658154-4134238313-3946999917-1000Core.job => C:\Users\Carmen\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-811658154-4134238313-3946999917-1000UA.job => C:\Users\Carmen\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 32fd9fbc-dd57-4e63-8d88-8652aa6c0d7d.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 595bf951-17b6-4f76-848f-a0e78ddbfed8.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Tcpip\Parameters: [DhcpNameServer] 212.166.211.3 212.166.132.96
Tcpip\..\Interfaces\{4CB0D5A1-6B4A-4F7F-90A1-359C46AB7D1A}: [DhcpNameServer] 212.166.211.3 212.166.132.96

Internet Explorer:
==================
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\ssv.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\jp2ssv.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll [2007-01-19] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\MSN Messenger\msgrapp.8.1.0178.00.dll [2007-01-19] (Microsoft Corporation -> Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  Ningún archivo

FireFox:
========
FF DefaultProfile: fgfeta3g.default-1439366737652-1572261556736
FF ProfilePath: C:\Users\Carmen\AppData\Roaming\Mozilla\Firefox\Profiles\fgfeta3g.default-1439366737652-1572261556736 [2020-04-26]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_363.dll [2020-04-15] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_363.dll [2020-04-15] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-07] (Adobe Systems, Inc.) [Archivo no firmado]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.241.2 -> C:\Program Files (x86)\Java\jre1.8.0_241\bin\plugin2\npjp2.dll [2020-01-15] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll [2013-04-30] (Nitro PDF Software -> Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-08-30] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-08-30] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Carmen\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall) [Archivo no firmado]
FF Plugin-x32: @raidcall.tw/RCplugin -> C:\Users\Carmen\AppData\Roaming\RCTW\plugins\nprcplugin.dll [2013-06-25] (Raidcall) [Archivo no firmado]
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Carmen\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-07-10] (Citrix Online -> Citrix Online)
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Carmen\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [Ningún archivo]
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @tools.coowon.com/Coowon Update;version=3 -> C:\Users\Carmen\AppData\Local\Coowon\Update\1.3.33.0\npCoowonUpdate3.dll [2019-10-15] (Google Inc (TEST) -> Coowon.) [Archivo no firmado]
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @tools.coowon.com/Coowon Update;version=9 -> C:\Users\Carmen\AppData\Local\Coowon\Update\1.3.33.0\npCoowonUpdate3.dll [2019-10-15] (Google Inc (TEST) -> Coowon.) [Archivo no firmado]
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\Carmen\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-05-11] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)

Chrome: 
=======
CHR Profile: C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default [2020-04-26]
CHR Extension: (Presentaciones) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-03-11]
CHR Extension: (Documentos) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-11]
CHR Extension: (Google Drive) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-11]
CHR Extension: (YouTube) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-11]
CHR Extension: (Video Downloader professional) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\dakbpnomcpnfffehgdgdcfkaljdfbggj [2020-02-06]
CHR Extension: (Hojas de cálculo) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-03-11]
CHR Extension: (Video Downloader PLUS) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhplmmllnpjjlncfjpbbpjadoeijkogc [2020-04-24]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-21]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Gmail) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-24]
CHR Extension: (Chrome Media Router) - C:\Users\Carmen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-23]

Opera: 
=======
OPR StartupUrls:  "hxxp://google.es/" 
OPR Session Restore: -> está habilitado.

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-12] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3374160 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3103824 2020-03-04] (Adobe Inc. -> Adobe Systems, Incorporated)
S4 APLI Master AutoUpdater; C:\Program Files (x86)\APLI Paper\APLI Master\ApliAutoUpdater.exe [167936 2011-10-24] (Home) [Archivo no firmado]
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2302152 2018-10-29] (ESET, spol. s r.o. -> ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2302152 2018-10-29] (ESET, spol. s r.o. -> ESET)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation -> Intel Corporation)
S4 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1872808 2015-11-26] (Maxthon (Asia) Limited. -> Maxthon)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-03-14] (Malwarebytes Inc -> Malwarebytes)
S2 MxService; C:\Program Files (x86)\Maxthon\Bin\MxService.exe [143648 2018-07-10] (Maxthon (Asia) Limited. -> Maxthon International ltd.)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2013-04-30] (Nitro PDF Software -> Nitro PDF Software)
S4 nlsvc; C:\Program Files\NetLimiter 3\nlsvc.exe [1851008 2013-10-10] (Locktime Software s.r.o. -> Locktime Software)
S4 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2012-12-21] (Nalpeiron LTD -> Nalpeiron Ltd.) [Archivo no firmado]
S4 NMSAccess64; C:\Windows\SysWOW64\NMSAccess64.exe [82872 2009-01-12] (Numedia Soft, Inc. -> )
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Archivo no firmado]
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [235984 2016-11-24] (Safer-Networking Ltd. -> Safer-Networking Ltd.) [Archivo no firmado]
S4 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S4 wordpressApache; C:\Bitnami\WORDPR~1.2-0\apache2\bin\httpd.exe [20992 2014-07-19] (Apache Software Foundation) [Archivo no firmado]
S4 wordpressMySQL; C:\Bitnami\wordpress-3.9.2-0\mysql\bin\mysqld.exe [8140288 2014-05-11] () [Archivo no firmado]

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

S3 61883; C:\Windows\System32\DRIVERS\61883.sys [60288 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
S2 CamMask; C:\Windows\System32\DRIVERS\cmvcamdrv64.sys [954072 2013-12-23] (SageTech -> )
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [110488 2014-12-03] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.(www.devguru.co.kr))
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [143448 2018-10-29] (ESET, spol. s r.o. -> ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [188832 2018-10-29] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [109864 2018-10-29] (ESET, spol. s r.o. -> ESET)
S3 ESETCleanersDriver; C:\Windows\system32\Drivers\ESETCleanersDriver.sys [170280 2017-02-03] (ESET, spol. s r.o. -> ESET)
R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [65152 2012-08-07] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [88832 2012-08-07] (Microsoft Windows Hardware Compatibility Publisher -> Etron Technology Inc)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [55232 2018-03-11] (SurfRight B.V. -> )
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [58280 2018-07-27] (ManyCam (VISICOM MÉDIA INC.) -> Visicom Media Inc.)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [214496 2020-04-25] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-04-26] (Malwarebytes Inc -> Malwarebytes)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35992 2014-12-29] (ManyCam LLC -> Visicom Media Inc.)
S3 mcdevice; C:\Windows\System32\DRIVERS\mcdevice.sys [334400 2019-11-16] (Hefei GreenXin Technology Co. Ltd. -> ShiningMorning Inc.)
R1 nltdi; C:\Program Files\NetLimiter 3\nltdi.sys [87472 2013-06-12] (Locktime Software s.r.o. -> Locktime Software)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2006-10-02] (Padus, Inc.) [Archivo no firmado]
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security S.L. -> Panda Security, S.L.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [206104 2014-12-03] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.(www.devguru.co.kr))

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) ===================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-04-26 12:32 - 2020-04-26 12:32 - 000000880 _____ C:\Users\Carmen\Desktop\JRT.txt
2020-04-26 12:28 - 2020-04-26 12:28 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2020-04-26 12:07 - 2020-04-26 12:07 - 000004804 _____ C:\Users\Carmen\Desktop\cc_20200426_120706.reg
2020-04-25 17:24 - 2020-04-25 17:24 - 000000000 ____D C:\Users\Martin\AppData\Roaming\Adobe
2020-04-25 17:24 - 2020-04-25 17:24 - 000000000 ____D C:\Users\Martin
2020-04-25 17:23 - 2020-04-25 17:23 - 000001950 _____ C:\Users\Carmen\Desktop\AdobeAfterEffectsPortable.exe - Acceso directo.lnk
2020-04-25 16:49 - 2020-04-25 16:50 - 000062606 _____ C:\Users\Carmen\Desktop\Addition.txt
2020-04-25 16:47 - 2020-04-26 12:34 - 000025023 _____ C:\Users\Carmen\Desktop\FRST.txt
2020-04-25 16:47 - 2020-04-26 12:34 - 000000000 ____D C:\FRST
2020-04-25 16:21 - 2020-04-25 16:21 - 000161290 _____ C:\Users\Carmen\Desktop\cc_20200425_162052.reg
2020-04-25 16:05 - 2020-04-25 16:05 - 002282496 _____ (Farbar) C:\Users\Carmen\Desktop\FRST64.exe
2020-04-25 16:03 - 2020-04-25 16:03 - 001790024 _____ (Malwarebytes) C:\Users\Carmen\Desktop\JRT.exe
2020-04-25 15:39 - 2020-04-25 15:39 - 008196784 _____ (Malwarebytes) C:\Users\Carmen\Desktop\adwcleaner_8.0.4.exe
2020-04-25 15:32 - 2020-04-25 15:32 - 008196784 _____ (Malwarebytes) C:\Users\Carmen\Downloads\adwcleaner_8.0.4.exe
2020-04-25 15:01 - 2020-04-25 15:01 - 000214496 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2020-04-25 14:11 - 2020-04-25 14:17 - 524288000 _____ C:\Users\Carmen\Downloads\SGM94.Adobe.After.Effects.2019.part3.rar
2020-04-25 14:11 - 2020-04-25 14:12 - 524288000 _____ C:\Users\Carmen\Downloads\SGM94.Adobe.After.Effects.2019.part4.rar
2020-04-25 14:11 - 2020-04-25 14:11 - 106541615 _____ C:\Users\Carmen\Downloads\SGM94.Adobe.After.Effects.2019.part5.rar
2020-04-25 14:10 - 2020-04-25 14:17 - 524288000 _____ C:\Users\Carmen\Downloads\SGM94.Adobe.After.Effects.2019.part2.rar
2020-04-25 14:09 - 2020-04-25 14:15 - 524288000 _____ C:\Users\Carmen\Downloads\SGM94.Adobe.After.Effects.2019.part1.rar
2020-04-25 10:43 - 2020-04-26 11:07 - 000003446 _____ C:\Windows\system32\Tasks\AdobeGCInvoker-1.0
2020-04-24 16:49 - 2020-04-24 16:50 - 055635505 _____ C:\Users\Carmen\Downloads\sonic-candle-1.1.11.jar
2020-04-24 14:04 - 2020-04-24 14:04 - 000000000 ____D C:\ProgramData\FLEXnet
2020-04-24 14:03 - 2020-04-24 14:03 - 000001328 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CS4.lnk
2020-04-24 14:01 - 2020-04-24 14:01 - 000001416 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS4.lnk
2020-04-24 13:41 - 2020-04-24 13:44 - 000000000 ____D C:\Windows\SysWOW64\Adobe After Effects CS4 [Portable]
2020-04-23 17:28 - 2020-04-23 17:28 - 000585228 _____ C:\Users\Carmen\Downloads\Nueva grabación 39.m4a
2020-04-22 16:43 - 2020-04-22 16:43 - 007750281 _____ C:\Users\Carmen\Downloads\RECOPILACION CONCURSO DE FOTOGRAFÍA DESDE MI VENTANA 21 04 bis.pdf
2020-04-18 11:24 - 2020-04-18 11:24 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2020-04-17 13:13 - 2020-04-17 13:13 - 003054923 _____ C:\Users\Carmen\Downloads\RECOPILACION CONCURSO DE FOTOGRAFÍA DESDE MI VENTANA DIA 16.pdf
2020-04-14 12:46 - 2020-04-14 12:46 - 001224264 _____ (Adobe Inc) C:\Users\Carmen\Downloads\flashplayer32pp_a_install.exe
2020-04-14 10:42 - 2020-04-14 10:53 - 000378464 _____ C:\Users\Carmen\Downloads\registro_jornada_COMPLETA CARME ROMERO.pdf
2020-04-14 10:42 - 2020-04-14 10:51 - 000428539 _____ C:\Users\Carmen\Downloads\registro_jornada_parcial_VERONICA RUIZ.pdf
2020-04-07 11:22 - 2020-04-07 11:22 - 012609681 _____ C:\Users\Carmen\Downloads\Abril
2020-04-03 17:44 - 2020-04-03 18:20 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\CamMask
2020-04-03 17:43 - 2020-04-03 18:20 - 000000000 ____D C:\Program Files (x86)\CamMask
2020-04-03 17:43 - 2013-12-23 17:08 - 000954072 _____ C:\Windows\system32\Drivers\cmvcamdrv64.sys
2020-04-03 17:42 - 2020-04-03 17:42 - 015323504 _____ (CamMask Studio ) C:\Users\Carmen\Downloads\CamMaskSetup.exe
2020-04-03 17:19 - 2020-04-03 17:19 - 000000000 ____D C:\Users\Carmen\AppData\Local\Visicom Media
2020-04-03 17:15 - 2020-04-03 17:37 - 000000000 ____D C:\Program Files (x86)\ManyCam
2020-04-03 17:12 - 2020-04-03 17:12 - 000574376 _____ C:\Users\Carmen\Downloads\ManyCamWebInstaller.exe
2020-04-03 17:00 - 2020-04-03 17:07 - 000000000 ____D C:\Users\Carmen\AppData\Local\MagicCamera
2020-04-03 17:00 - 2020-04-03 17:00 - 000000000 ____D C:\Program Files (x86)\ShiningMorning
2020-04-03 17:00 - 2019-11-16 16:13 - 000334400 _____ (ShiningMorning Inc.) C:\Windows\system32\Drivers\mcdevice.sys
2020-03-31 16:45 - 2020-03-31 16:45 - 000018730 _____ C:\Users\Carmen\Downloads\deals.csv

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-04-26 12:28 - 2013-05-30 12:37 - 000000000 ____D C:\ProgramData\NVIDIA
2020-04-26 12:28 - 2009-07-14 07:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-04-26 12:27 - 2016-11-22 23:12 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\discord
2020-04-26 12:27 - 2009-07-14 06:45 - 000009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-04-26 12:27 - 2009-07-14 06:45 - 000009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-04-26 12:27 - 2009-07-14 05:20 - 000000000 ____D C:\Windows\inf
2020-04-26 12:05 - 2016-04-26 20:29 - 000000000 ____D C:\Users\Carmen\AppData\Local\CrashDumps
2020-04-26 12:03 - 2016-11-18 18:05 - 000000000 ____D C:\Users\Carmen\AppData\LocalLow\Mozilla
2020-04-26 11:50 - 2015-06-20 09:49 - 000001006 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-811658154-4134238313-3946999917-1000UA.job
2020-04-25 17:05 - 2018-03-09 23:47 - 000000000 ____D C:\Windows\pss
2020-04-25 16:21 - 2013-05-30 12:36 - 000000000 ____D C:\temp
2020-04-25 15:03 - 2013-05-30 12:37 - 000000000 ____D C:\Users\UpdatusUser
2020-04-25 14:59 - 2019-11-05 16:53 - 000000000 ____D C:\Users\Carmen\AppData\Local\Adobe
2020-04-25 14:59 - 2018-07-08 12:13 - 000000000 ____D C:\Users\Carmen\Desktop\Activador - WWW.GBCOMPUTER.COM.AR
2020-04-25 14:26 - 2014-10-16 17:00 - 000000000 ____D C:\ProgramData\Package Cache
2020-04-25 14:18 - 2019-11-05 11:09 - 000000000 ____D C:\ProgramData\Adobe
2020-04-25 10:57 - 2019-10-03 16:05 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-04-25 10:57 - 2019-10-03 16:05 - 000000000 ___HD C:\ProgramData\Documents\AdobeGCData
2020-04-25 10:50 - 2015-06-20 09:49 - 000000954 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-811658154-4134238313-3946999917-1000Core.job
2020-04-25 10:39 - 2009-07-14 06:45 - 005643824 _____ C:\Windows\system32\FNTCACHE.DAT
2020-04-24 17:37 - 2013-06-26 11:47 - 000000132 _____ C:\Users\Carmen\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2020-04-24 17:30 - 2013-09-11 14:09 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\Audacity
2020-04-24 17:24 - 2020-02-21 10:47 - 000004052 _____ C:\Windows\system32\Tasks\Opera scheduled assistant Autoupdate 1582274861
2020-04-24 15:38 - 2013-09-01 13:23 - 000076800 ___SH C:\Users\Carmen\Thumbs.db
2020-04-24 14:05 - 2017-03-21 17:15 - 000000000 ____D C:\Users\Carmen\Documents\Adobe
2020-04-24 14:04 - 2013-05-30 12:43 - 000206248 _____ C:\Users\Carmen\AppData\Local\GDIPFONTCACHEV1.DAT
2020-04-24 14:03 - 2013-05-30 12:49 - 000000000 ____D C:\Program Files (x86)\Adobe
2020-04-24 14:02 - 2013-12-25 19:41 - 000000000 ____D C:\Program Files\Common Files\Adobe
2020-04-24 11:31 - 2018-03-11 15:56 - 000002231 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-04-24 11:31 - 2018-03-11 15:56 - 000002190 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-04-24 11:31 - 2018-03-11 15:56 - 000002190 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-04-24 11:26 - 2019-07-21 19:23 - 000153312 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2020-04-22 11:08 - 2018-06-16 20:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2020-04-18 11:25 - 2013-05-30 22:41 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\Dropbox
2020-04-16 10:49 - 2015-05-23 20:06 - 000000000 ____D C:\Program Files (x86)\Opera
2020-04-15 15:04 - 2015-06-11 11:13 - 000004320 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater
2020-04-15 15:04 - 2015-05-23 20:10 - 000004454 _____ C:\Windows\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-04-15 15:04 - 2013-05-31 10:34 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
2020-04-15 15:04 - 2013-05-31 10:34 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2020-04-15 15:04 - 2013-05-31 10:34 - 000000000 ____D C:\Windows\system32\Macromed
2020-04-15 15:04 - 2013-05-30 12:50 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2020-04-15 14:04 - 2018-03-14 11:04 - 000004496 _____ C:\Windows\system32\Tasks\Adobe Flash Player NPAPI Notifier
2020-04-15 11:02 - 2015-05-23 20:06 - 000003856 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1432404393
2020-04-14 10:51 - 2013-06-12 12:28 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\Nitro
2020-04-12 10:04 - 2016-11-18 12:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-04-12 10:04 - 2013-05-31 10:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-04-07 11:32 - 2020-02-26 16:02 - 000004082 _____ C:\Windows\system32\Tasks\Opera GX scheduled Autoupdate 1582725757
2020-04-06 17:05 - 2017-02-28 16:24 - 000089960 _____ C:\Users\Carmen\Desktop\tasques 2017.xlsx
2020-04-06 17:02 - 2013-08-09 14:14 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\Nitro PDF
2020-04-04 20:11 - 2019-02-07 19:21 - 000000000 ____D C:\Users\Carmen\AppData\Roaming\obs-studio
2020-04-03 17:19 - 2019-11-25 14:29 - 000000000 ____D C:\Users\Carmen\AppData\Local\cache
2020-04-03 17:04 - 2014-03-31 19:06 - 000012800 _____ C:\Users\Carmen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2020-04-03 17:03 - 2014-03-31 19:06 - 000000069 _____ C:\Windows\NeroDigital.ini
2020-04-01 09:30 - 2009-07-14 11:31 - 000782166 _____ C:\Windows\system32\perfh00A.dat
2020-04-01 09:30 - 2009-07-14 11:31 - 000169576 _____ C:\Windows\system32\perfc00A.dat
2020-04-01 09:30 - 2009-07-14 07:13 - 001758992 _____ C:\Windows\system32\PerfStringBackup.INI
2020-03-29 11:20 - 2009-07-14 07:08 - 000032650 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Archivos en la raíz de algunos directorios ========

2015-06-23 14:33 - 2015-06-23 14:33 - 000597624 _____ () C:\Users\Carmen\AppData\Roaming\gameboxsetup.exe
2016-01-12 19:51 - 2016-01-12 19:51 - 000007859 _____ () C:\Users\Carmen\AppData\Roaming\pcouffin.cat
2016-01-12 19:51 - 2016-01-12 19:51 - 000001167 _____ () C:\Users\Carmen\AppData\Roaming\pcouffin.inf
2016-01-12 19:51 - 2016-01-12 19:51 - 000000055 _____ () C:\Users\Carmen\AppData\Roaming\pcouffin.log
2016-01-12 19:51 - 2016-01-12 19:51 - 000082816 _____ (VSO Software) C:\Users\Carmen\AppData\Roaming\pcouffin.sys
2013-11-25 16:39 - 2013-11-25 16:39 - 000000132 _____ () C:\Users\Carmen\AppData\Roaming\Prefs. de formato AIFF de Adobe CS6
2015-12-18 14:52 - 2019-02-18 17:50 - 000000132 _____ () C:\Users\Carmen\AppData\Roaming\Prefs. de formato GIF de Adobe CS6
2013-06-26 11:47 - 2020-04-24 17:37 - 000000132 _____ () C:\Users\Carmen\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2014-01-18 16:59 - 2019-02-18 18:30 - 000001456 _____ () C:\Users\Carmen\AppData\Local\Adobe Guardar para Web 13.0 Prefs
2014-03-31 19:06 - 2020-04-03 17:04 - 000012800 _____ () C:\Users\Carmen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-15 21:01 - 2014-05-15 21:01 - 000004096 ____H () C:\Users\Carmen\AppData\Local\keyfile3.drm
2018-09-29 09:26 - 2019-11-05 11:34 - 000001025 _____ () C:\Users\Carmen\AppData\Local\oobelibMkey.log
2017-09-21 15:40 - 2017-09-21 15:40 - 000007597 _____ () C:\Users\Carmen\AppData\Local\Resmon.ResmonCfg
2018-03-08 18:43 - 2018-03-08 18:43 - 000000003 _____ () C:\Users\Carmen\AppData\Local\wbem.ini

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)


LastRegBack: 2020-04-17 16:34
==================== Final de FRST.txt ========================

Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
AlternateDataStreams: C:\ProgramData\TEMP:C36F1B98 [272]
MSCONFIG\startupreg: B4AF.tmp => C:\Users\Carmen\AppData\Local\Temp\B4AF.tmp.exe
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\RunOnce: [Application Restart #2] => C:\Users\Carmen\AppData\Local\Vivaldi\Application\vivaldi.exe [921720 2017-06-21] (Vivaldi Technologies AS -> Vivaldi Technologies AS)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.122\Installer\chrmstp.exe [2020-04-24] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bit
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Ningún archivo
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Carmen\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [Ningún archivo]
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security S.L. -> Panda Security, S.L.)
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

Y ahora inicia tu equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX/Corregir y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.

Resultados de la corrección de Farbar Recovery Scan Tool (x64) Versión: 24-04-2020
Ejecutado por Carmen (26-04-2020 16:49:36) Run:1
Ejecutado desde C:\Users\Carmen\Desktop
Perfiles cargados: Carmen (Perfiles disponibles: Carmen & UpdatusUser)
Modo de Inicio: Safe Mode (with Networking)
==============================================

fixlist contenido:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
AlternateDataStreams: C:\ProgramData\TEMP:C36F1B98 [272]
MSCONFIG\startupreg: B4AF.tmp => C:\Users\Carmen\AppData\Local\Temp\B4AF.tmp.exe
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\...\RunOnce: [Application Restart #2] => C:\Users\Carmen\AppData\Local\Vivaldi\Application\vivaldi.exe [921720 2017-06-21] (Vivaldi Technologies AS -> Vivaldi Technologies AS)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.122\Installer\chrmstp.exe [2020-04-24] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bitPCloudBroom64.exe \systemroot\system32\BroomData.bit
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Ning�n archivo
FF Plugin HKU\S-1-5-21-811658154-4134238313-3946999917-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Carmen\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [Ning�n archivo]
S3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [50320 2015-01-29] (Panda Security S.L. -> Panda Security, S.L.)
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: El punto de restauración solamente puede ser creado en modo normal.
Procesos cerrados correctamente.
C:\ProgramData\TEMP => ":C36F1B98" ADS eliminado correctamente
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\B4AF.tmp => eliminado correctamente
"HKU\S-1-5-21-811658154-4134238313-3946999917-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => eliminado correctamente
"HKU\S-1-5-21-811658154-4134238313-3946999917-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Application Restart #2" => eliminado correctamente
"HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SPReview" => eliminado correctamente
HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} => eliminado correctamente
HKLM\System\CurrentControlSet\Control\Session Manager\\"BootExecute"="autocheck autochk *" => valor restaurado correctamente
HKLM\Software\Classes\PROTOCOLS\Handler\skype4com => eliminado correctamente
HKU\S-1-5-21-811658154-4134238313-3946999917-1000\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin => eliminado correctamente
"C:\Users\Carmen\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll" => no encontrado
HKLM\System\CurrentControlSet\Services\PSKMAD => eliminado correctamente
PSKMAD => servicio eliminado correctamente
C:\Windows\System32\Drivers\etc\hosts => movido correctamente
Hosts restaurado correctamente.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-21-811658154-4134238313-3946999917-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-21-811658154-4134238313-3946999917-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente


========= Final de RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= Final de CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows


Adaptador de Ethernet Conexi¢n de  rea local:

   Sufijo DNS espec¡fico para la conexi¢n. . : home
   V¡nculo: direcci¢n IPv6 local. . . : fe80::3110:d295:f5c3:75ae%10
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.1.3
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.1.1

Adaptador de t£nel isatap.home:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel Teredo Tunneling Pseudo-Interface:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

========= Final de CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= Final de CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to connect to BITS - 0x8007042c
No se puede iniciar el servicio o grupo de dependencia.



========= Final de CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= Final de CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= Final de CMD: =========


========= netsh int ipv4 reset =========

Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


========= netsh int ipv6 reset =========

Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9579812 B
Java, Flash, Steam htmlcache => 2083 B
Windows/system/drivers => 25609646 B
Edge => 0 B
Chrome => 80468293 B
Firefox => 623715371 B
Opera => 157412 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 256 B
LocalService => 256 B
NetworkService => 256 B
Carmen => 2499439832 B
UpdatusUser => 2499439832 B
DefaultAppPool => 2499439832 B

RecycleBin => 2259329120 B
EmptyTemp: => 9.8 GB datos temporales eliminados.

================================


El sistema necesita reiniciarse.

==== Final de Fixlog 16:52:26 ====

Hola Javier, te comento: He reiniciado varias veces, la primera vez se invirtieron los colores del tema. Cambie el tema el resto de veces bienpero todas las veces se abre la lupa (no me deja manipularla). He vuelto a pasa el adwcleaner y sigue saliendo el legacy ese, te pongo el informe.

# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build:    04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    04-26-2020
# Duration: 00:00:01
# OS:       Windows 7 Ultimate
# Cleaned:  0
# Failed:   1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Not Deleted   HKU\S-1-5-21-811658154-4134238313-3946999917-1001\Software\Myfree Codec

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner_Debug.log - [18509 octets] - [25/11/2019 14:48:41]
AdwCleaner[S00].txt - [1521 octets] - [25/11/2019 14:49:18]
AdwCleaner[C00].txt - [1671 octets] - [25/11/2019 14:54:46]
AdwCleaner[S01].txt - [1634 octets] - [25/04/2020 15:34:39]
AdwCleaner[C01].txt - [1804 octets] - [25/04/2020 15:35:06]
AdwCleaner[S02].txt - [1783 octets] - [25/04/2020 15:42:39]
AdwCleaner[C02].txt - [1953 octets] - [25/04/2020 15:43:40]
AdwCleaner[S03].txt - [1905 octets] - [25/04/2020 15:49:24]
AdwCleaner[C03].txt - [2075 octets] - [25/04/2020 16:05:47]
AdwCleaner[S04].txt - [2027 octets] - [25/04/2020 16:42:00]
AdwCleaner[C04].txt - [2197 octets] - [25/04/2020 16:42:21]
AdwCleaner[S05].txt - [2082 octets] - [25/04/2020 16:52:28]
AdwCleaner[C05].txt - [2272 octets] - [25/04/2020 16:53:26]
AdwCleaner[S06].txt - [2320 octets] - [26/04/2020 11:06:29]
AdwCleaner[C06].txt - [2470 octets] - [26/04/2020 11:08:28]
AdwCleaner[S07].txt - [2393 octets] - [26/04/2020 12:26:53]
AdwCleaner[C07].txt - [2563 octets] - [26/04/2020 12:27:09]
AdwCleaner[S08].txt - [2448 octets] - [26/04/2020 12:43:26]
AdwCleaner[S09].txt - [2509 octets] - [26/04/2020 17:04:45]
AdwCleaner[S10].txt - [2570 octets] - [26/04/2020 17:05:33]
AdwCleaner[S11].txt - [2698 octets] - [26/04/2020 17:35:15]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C11].txt ##########

Hola.

Que navegador usas de forma predeterminada…??

Tienes sincronizado el navegador con algún otro dispositivo, teléfono, tablet o similar…??

Saludos.

Utilizo Firefox. No lo tengo sincronizado

Hola.

Bien y ahora usas estos pasos :arrow_right: Manual de HitmanPro y nos pones el informe al terminar el proceso.

Saludos.

HitmanPro 3.8.18.312
www.hitmanpro.com

   Computer name . . . . : CARMEN-PC
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Carmen-PC\Carmen
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free

   Scan date . . . . . . : 2020-04-27 11:02:35
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 5m 31s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 0
   Traces  . . . . . . . : 7

   Objects scanned . . . : 3.114.430
   Files scanned . . . . : 190.847
   Remnants scanned  . . : 1.237.159 files / 1.686.424 keys

Suspicious files ____________________________________________________________

   C:\Users\Carmen\Desktop\FRST64.exe
      Size . . . . . . . : 2.282.496 bytes
      Age  . . . . . . . : 1.8 days (2020-04-25 16:05:14)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 1AD9208B69028ACC5086061EDA6763B490E555F4EF96DE7623AC6E293D29C787
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      References
         HKU\S-1-5-21-811658154-4134238313-3946999917-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\Carmen\Desktop\FRST64.exe
      Forensic Cluster
         -10.2s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\72BA427A91F50409B9EAC87F2B59B951_5E10CFE7C0F60AF6A4B78BA25825DF49
         -10.2s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\72BA427A91F50409B9EAC87F2B59B951_5E10CFE7C0F60AF6A4B78BA25825DF49
         -10.2s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6BC2F9E736CA7FA49F83DB42BF3CC857
         -10.2s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6BC2F9E736CA7FA49F83DB42BF3CC857
         -10.0s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C7BFCCBC907B3655E99AFBD4A1224793
         -10.0s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C7BFCCBC907B3655E99AFBD4A1224793
         -9.7s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\96DFD42D3B6DBBA38B21E8FD11B98EC9_C913FA5DAEB7AA6B910140D022F2B37A
         -9.7s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\96DFD42D3B6DBBA38B21E8FD11B98EC9_C913FA5DAEB7AA6B910140D022F2B37A
         -1.5s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\349D186F1CB5682FA0194D4F3754EF36_1F7395BC27C7C3EF3BDDFB01A889FACD
         -1.5s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\349D186F1CB5682FA0194D4F3754EF36_1F7395BC27C7C3EF3BDDFB01A889FACD
          0.0s C:\Users\Carmen\Desktop\FRST64.exe

   C:\Users\Carmen\Documents\mio\ONPER75G_O\OnOne Perfect Resize 7.5\Medicina\Crack32\filechck.dll
      Size . . . . . . . : 324.496 bytes
      Age  . . . . . . . : 1651.8 days (2015-10-19 16:12:21)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : C863DE564F07CAA652E61DFE57C55DD18C1D1F9D3D385B1FAC2C823C6CABB929
      RSA Key Size . . . : 2048
      Authenticode . . . : Invalid
      Fuzzy  . . . . . . : 26.0
         Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.

   C:\Users\Carmen\Documents\mio\ONPER75G_O\OnOne Perfect Resize 7.5\Medicina\Crack32\onOneSuiteCheck.dll
      Size . . . . . . . : 324.496 bytes
      Age  . . . . . . . : 1651.8 days (2015-10-19 16:12:21)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : C863DE564F07CAA652E61DFE57C55DD18C1D1F9D3D385B1FAC2C823C6CABB929
      RSA Key Size . . . : 2048
      Authenticode . . . : Invalid
      Fuzzy  . . . . . . : 26.0
         Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.

   C:\Users\Carmen\Documents\mio\ONPER75G_O\OnOne Perfect Resize 7.5\Medicina\Crack64\FileChck.dll
      Size . . . . . . . : 359.824 bytes
      Age  . . . . . . . : 1651.8 days (2015-10-19 16:12:22)
      Entropy  . . . . . : 5.8
      SHA-256  . . . . . : 147C387FB604D557AB86463F87B7341C0733B909E8D395A28795A6102A791E9A
      RSA Key Size . . . : 2048
      Authenticode . . . : Invalid
      Fuzzy  . . . . . . : 26.0
         Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.

   C:\Users\Carmen\Documents\mio\ONPER75G_O\OnOne Perfect Resize 7.5\Medicina\Crack64\onOneSuiteCheck.dll
      Size . . . . . . . : 359.824 bytes
      Age  . . . . . . . : 1651.8 days (2015-10-19 16:12:22)
      Entropy  . . . . . : 5.8
      SHA-256  . . . . . : 147C387FB604D557AB86463F87B7341C0733B909E8D395A28795A6102A791E9A
      RSA Key Size . . . : 2048
      Authenticode . . . : Invalid
      Fuzzy  . . . . . . : 26.0
         Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.


Potential Unwanted Programs _________________________________________________

   C:\Users\Carmen\Desktop\JRT.exe (App/NirCmd-Gen)
      Size . . . . . . . : 1.790.024 bytes
      Age  . . . . . . . : 1.8 days (2020-04-25 16:03:07)
      Entropy  . . . . . : 8.0
      SHA-256  . . . . . : 2000ACF98EF0AC1A2D75C91586B5F30A2BC3ECE6E92388B324614C93A0645CF5
      RSA Key Size . . . : 2048
      Authenticode . . . : Valid
      Fuzzy  . . . . . . : 9.0
      Forensic Cluster
         -0.2s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F12703B35B1F82C21160A92376087C84_014DC1EAF5A4D3754F667DB6861790A7
         -0.2s C:\Users\Carmen\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F12703B35B1F82C21160A92376087C84_014DC1EAF5A4D3754F667DB6861790A7
          0.0s C:\Users\Carmen\Desktop\JRT.exe


Hola.

Correcto… y ahora quiero que sigas estos pasos :arrow_right: Manual de Eset Online Scanner, y al terminar nos pones el informe.

Saludos.

Hola Javier, después de casi 6 horas pego informe

27/04/2020 18:09:51
Archivos analizados: 1152814
Archivos detectados: 35
Archivos desinfectados: 35
Tiempo total de análisis 05:24:41
Estado del análisis: Finalizado


C:\Documents and Settings\Carmen\AppData\Roaming\uTorrent\updates\3.4.9_42973.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\AppData\Roaming\uTorrent\updates\3.4.9_43085.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\AppData\Roaming\uTorrent\updates\3.4.9_43295.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\AppData\Roaming\uTorrent\uTorrent.exe	una variante de Win32/uTorrent.C aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Desktop\wartool\Wartool.Exe	una variante de Win32/Injector.Autoit.CMX Troyano	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Desktop\Wartool.Exe	una variante de Win32/Injector.Autoit.CMX Troyano	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Downloads\ccsetup409.exe	Win32/Bundled.Toolbar.Google.D aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Downloads\ccsetup505.exe	Win32/Bundled.Toolbar.Google.D aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Downloads\ccsetup538.exe	Win32/Bundled.Toolbar.Google.D aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Downloads\Shockwave_Installer_Slim.exe	Win32/Bundled.Toolbar.Google.D aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
C:\Documents and Settings\Carmen\Downloads\Wartool.rar	una variante de Win32/Injector.Autoit.CMX Troyano	eliminado
C:\Program Files (x86)\ShiningMorning\MagicCamera\update.exe	una variante de Win32/Adware.YoutubeDownloaderGuru.C aplicación	no se ha podido desinfectar - archivo eliminado
C:\Windows\Installer\MSIB61B.tmp	una variante de Win32/Bundled.Toolbar.Ask.O aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
C:\Windows\Setup\scrwin\wimtd.exe	una variante de Win32/HiddenStart.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
F:\descargas pony\descarga\descarga\CClenar.sfx.exe	Win32/Bundled.Toolbar.Google.E aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
F:\TRASLADO\Downloads\SkypeSetup.exe	Win32/Bundled.Toolbar.Google.G aplicación potencialmente peligrosa	eliminado
G:\Archivos de programa\PDF Password Remover v3.0\winDecrypt.exe.BAK	Win32/PSWTool.PdfCracker.B aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
G:\Documents and Settings\Carmen\Datos de programa\Sun\Java\jre1.7.0_09\java_sp.dll	una variante de Win32/Bundled.Toolbar.Ask.G aplicación potencialmente peligrosa	eliminado
G:\Documents and Settings\Carmen\Mis documentos\Descargas\avc-free.exe	Win32/OpenCandy aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
G:\Documents and Settings\Carmen\Mis documentos\Descargas\Vuze_Installer.exe	una variante de Generik.DDPROLL aplicación potencialmente indeseable	no se ha podido desinfectar - archivo eliminado
G:\Documents and Settings\Carmen\Mis documentos\Downloads\Shockwave_Installer_Slim.exe	Win32/Bundled.Toolbar.Google.D aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
G:\Documents and Settings\Carmen\Mis documentos\Mipony\ID5\ID5.rar.part	una variante de Win32/HackTool.Patcher.P aplicación potencialmente peligrosa	eliminado
G:\Documents and Settings\Carmen\Mis documentos\Mipony\xp\descarga.rar	Win32/Bundled.Toolbar.Google.E aplicación potencialmente peligrosa	eliminado
G:\WINDOWS\system32\Adobe\Shockwave 12\gt.exe	Win32/Bundled.Toolbar.Google.D aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\DESCARGAS MIAS\Activador\Activador.exe	una variante de Win32/HiddenStart.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\DESCARGAS MIAS\Adobe Insesign 2018\amtemu.v0.9-painter.exe	una variante de Win32/HackTool.Crack.FS aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\DESCARGAS MIAS\AIDCS5.byCristhian\AIDCS5.byCristhian.part4.rar	una variante de Win32/HackTool.Patcher.P aplicación potencialmente peligrosa	eliminado
H:\DESCARGAS MIAS\descarga\CClenar.sfx.exe	Win32/Bundled.Toolbar.Google.E aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\DESCARGAS MIAS\indesign 2016\64 bits\x64\. x64\ADOBE_CC_V2015-XFORCE\Crack-OSX\xf-accm2015.dmg	una variante de OSX/Keygen.AI aplicación potencialmente peligrosa	eliminado
H:\DESCARGAS MIAS\indesign 2016\64 bits\x64\. x64\ADOBE_CC_V2015-XFORCE\Crack-Windows\disable_activation.cmd	BAT/HostsChanger.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\DESCARGAS MIAS\OJOsoft_Audio_Converter_V2.7.5.0412_Incl_Serial\OJOsoft_Audio_Converter_V2.7.5.0412_Incl_Serial\audio-converter.exe	una variante de Win32/Patched.F aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\personal\Mis documentos\jajajaja\Adobe Indesign CS4\Adobe Indesign CS4\Keygen + Fix ( Use only keygen or only fix )\Fix\Shockwave_Installer_Slim.exe	Win32/Bundled.Toolbar.Google.G aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\personal\Mis documentos\jajajaja\Adobe Indesign CS4\Adobe Indesign CS4\Keygen + Fix ( Use only keygen or only fix )\Keygen\disable_activation.cmd	BAT/HostsChanger.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\personal\Mis documentos\jajajaja\All Adobe CS4 Keygens\Adobe CS4 Master Collection Keygen\disable_activation.cmd	BAT/HostsChanger.A aplicación potencialmente peligrosa	no se ha podido desinfectar - archivo eliminado
H:\TRASLADO\Downloads\SkypeSetup.exe	Win32/Bundled.Toolbar.Google.G aplicación potencialmente peligrosa	eliminado

Hola.

Perfecto y como sigue el problema inicialmente planteado…??

Hola Javier, el pc aparentemente funciona bien. Pero… he vuelto a pasar el adwcleaner y sigue saliendo el legacy??

# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build:    04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    04-28-2020
# Duration: 00:00:01
# OS:       Windows 7 Ultimate
# Cleaned:  1
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKU\S-1-5-21-811658154-4134238313-3946999917-1001\Software\Myfree Codec

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner_Debug.log - [18509 octets] - [25/11/2019 14:48:41]
AdwCleaner[S00].txt - [1521 octets] - [25/11/2019 14:49:18]
AdwCleaner[C00].txt - [1671 octets] - [25/11/2019 14:54:46]
AdwCleaner[S01].txt - [1634 octets] - [25/04/2020 15:34:39]
AdwCleaner[C01].txt - [1804 octets] - [25/04/2020 15:35:06]
AdwCleaner[S02].txt - [1783 octets] - [25/04/2020 15:42:39]
AdwCleaner[C02].txt - [1953 octets] - [25/04/2020 15:43:40]
AdwCleaner[S03].txt - [1905 octets] - [25/04/2020 15:49:24]
AdwCleaner[C03].txt - [2075 octets] - [25/04/2020 16:05:47]
AdwCleaner[S04].txt - [2027 octets] - [25/04/2020 16:42:00]
AdwCleaner[C04].txt - [2197 octets] - [25/04/2020 16:42:21]
AdwCleaner[S05].txt - [2082 octets] - [25/04/2020 16:52:28]
AdwCleaner[C05].txt - [2272 octets] - [25/04/2020 16:53:26]
AdwCleaner[S06].txt - [2320 octets] - [26/04/2020 11:06:29]
AdwCleaner[C06].txt - [2470 octets] - [26/04/2020 11:08:28]
AdwCleaner[S07].txt - [2393 octets] - [26/04/2020 12:26:53]
AdwCleaner[C07].txt - [2563 octets] - [26/04/2020 12:27:09]
AdwCleaner[S08].txt - [2448 octets] - [26/04/2020 12:43:26]
AdwCleaner[S09].txt - [2509 octets] - [26/04/2020 17:04:45]
AdwCleaner[S10].txt - [2570 octets] - [26/04/2020 17:05:33]
AdwCleaner[S11].txt - [2698 octets] - [26/04/2020 17:35:15]
AdwCleaner[C11].txt - [2868 octets] - [26/04/2020 17:35:30]
AdwCleaner[S12].txt - [2820 octets] - [26/04/2020 17:45:24]
AdwCleaner[C12].txt - [2990 octets] - [26/04/2020 17:45:41]
AdwCleaner[S13].txt - [2942 octets] - [28/04/2020 10:47:38]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C13].txt ##########

Hola. :+1:

Bien… pues haces lo siguiente, descarga e instala este programa :arrow_right: Manual de Revo Uninstaller :+1:

Y úsalo para desinstalar Spybot - Search & Destroy(este programa nos puede estar interfiriendo en la eliminación y ademas ya es un programa poco útil).

Cuando Revo te pida, que selecciones el método de desinstalación, seleccionas “Avanzado”.

Si durante el proceso te solicita “Reiniciar” NO lo hagas, dile que NO y deja que Revo siga trabajando.

Cuando termines todos los procesos de desinstalación ya REINICIAS tú el ordenador.

Realiza un nuevo análisis con AdwCleaner y comprueba que se elimine correctamente esa entrada, SI te vuelve a salir la entrada(que seguro sale) REINICIAS el equipo y vuelves a pasar una segunda verificación con AdwCleaner y nos comentas.

Saludos.

Hola, He hecho lo que me has dicho, en el primer reinicio salía limpio, vuelvo a reiniciar y vuelve a aparecer. Lo he intentado 2 veces más y lo mismo.

# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build:    04-03-2020
# Database: 2020-04-08.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    04-28-2020
# Duration: 00:00:01
# OS:       Windows 7 Ultimate
# Cleaned:  0
# Failed:   1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Not Deleted   HKU\S-1-5-21-811658154-4134238313-3946999917-1001\Software\Myfree Codec

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner_Debug.log - [18509 octets] - [25/11/2019 14:48:41]
AdwCleaner[S00].txt - [1521 octets] - [25/11/2019 14:49:18]
AdwCleaner[C00].txt - [1671 octets] - [25/11/2019 14:54:46]
AdwCleaner[S01].txt - [1634 octets] - [25/04/2020 15:34:39]
AdwCleaner[C01].txt - [1804 octets] - [25/04/2020 15:35:06]
AdwCleaner[S02].txt - [1783 octets] - [25/04/2020 15:42:39]
AdwCleaner[C02].txt - [1953 octets] - [25/04/2020 15:43:40]
AdwCleaner[S03].txt - [1905 octets] - [25/04/2020 15:49:24]
AdwCleaner[C03].txt - [2075 octets] - [25/04/2020 16:05:47]
AdwCleaner[S04].txt - [2027 octets] - [25/04/2020 16:42:00]
AdwCleaner[C04].txt - [2197 octets] - [25/04/2020 16:42:21]
AdwCleaner[S05].txt - [2082 octets] - [25/04/2020 16:52:28]
AdwCleaner[C05].txt - [2272 octets] - [25/04/2020 16:53:26]
AdwCleaner[S06].txt - [2320 octets] - [26/04/2020 11:06:29]
AdwCleaner[C06].txt - [2470 octets] - [26/04/2020 11:08:28]
AdwCleaner[S07].txt - [2393 octets] - [26/04/2020 12:26:53]
AdwCleaner[C07].txt - [2563 octets] - [26/04/2020 12:27:09]
AdwCleaner[S08].txt - [2448 octets] - [26/04/2020 12:43:26]
AdwCleaner[S09].txt - [2509 octets] - [26/04/2020 17:04:45]
AdwCleaner[S10].txt - [2570 octets] - [26/04/2020 17:05:33]
AdwCleaner[S11].txt - [2698 octets] - [26/04/2020 17:35:15]
AdwCleaner[C11].txt - [2868 octets] - [26/04/2020 17:35:30]
AdwCleaner[S12].txt - [2820 octets] - [26/04/2020 17:45:24]
AdwCleaner[C12].txt - [2990 octets] - [26/04/2020 17:45:41]
AdwCleaner[S13].txt - [2942 octets] - [28/04/2020 10:47:38]
AdwCleaner[C13].txt - [3112 octets] - [28/04/2020 10:47:53]
AdwCleaner[S14].txt - [3064 octets] - [28/04/2020 12:27:13]
AdwCleaner[C14].txt - [3234 octets] - [28/04/2020 12:27:30]
AdwCleaner[S15].txt - [3119 octets] - [28/04/2020 12:46:06]
AdwCleaner[S16].txt - [3247 octets] - [28/04/2020 12:46:41]
AdwCleaner[C16].txt - [3417 octets] - [28/04/2020 12:46:52]
AdwCleaner[S17].txt - [3302 octets] - [28/04/2020 12:50:44]
AdwCleaner[S18].txt - [3430 octets] - [28/04/2020 12:51:16]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C18].txt ##########

Hola.

Ejecuta de nuevo FRST.exe, para poner unos nuevos informes(FRST.txt y Addition.txt) para ver SI hubiera quedado algo del Spybot - Search & Destroy que pudiera estar interfiriendo, gracias.

Saludos.