Teclado desconfigurado / Posible virus

Buenas tardes, necesito un poco de ayuda ya que el teclado de mi notebook está andando mal.

Cuando aprieto una tecla sale otra o sale una combinación o directamente no hace nada. Intenté utilizando otro teclado conectado a la computadora y si bien los resultados de cada tecla no son los mismos, tampoco anda como debería ya que en muchos casos pone números en lugar de teclas o las teclas no andan tampoco. Intente modificar la configuración del teclado, probé con los atajos básicos alt+shif, Fn+BloqNum, etc, pero ninguna funcionó. Así que a este punto no se si se trata de un problema de configuración o de un virus.

Espero que me puedan orientar un poco sobre el tema. Desde ya muchas gracias. Debajo les dejo algunos ejemplos de lo que sucede

Y = Y6 T = T5 Enter = No hace nada Tecla Función = * A, S y D = No hacen nada

Hola @ivan_chalan y Bienvenido al Foro…!!

Que sistema operativo de windows tienes instalado en ese equipo…??

Has verificado desde modo seguro de windows para ver SI ocurre exactamente lo mismo…??

Saludos.

Hola JavierHF, me olvide de poner eso. Es una notebook HP probook 4530 y tiene Windows 7.

Probe el modo seguro pero sigue igual. También pasé el Malwarebytes que no encontró nada e intente pasar el Superantispyware que pude ver que encuentra 3 “objetos” en el inicio del análisis pero llega hasta aproximadamente los 80 mil archivos analizados y me pone que se produjo un error y el programa debe reiniciarse, esto me paso las 3 veces que lo puse.

Saludos y gracias por responder

Bien… pues vamos a realizar una revisión completa de tu máquina, sigue estos pasos, en el orden indicado y leyendo todo lo explicado. :+1:

:one: Desactiva temporalmente el Antivirus :arrow_forward: Cómo deshabilitar temporalmente su Antivirus, mientras estemos realizando TODOS los pasos.

Vamos a descargar en TU ESCRITORIO(y NO en otro lugar :face_with_monocle:) todas las herramientas que vamos a utilizar en este procedimiento (pero no las ejecutes todavía) :


:two: Ejecutas las herramientas de una en una y en el orden indicado :



CCleaner.-

  • Instalas y Ejecutas CCleaner siguiendo los pasos indicados en el manual.

  • Úsalo primero en su opción de Limpiador para borrar cookies, temporales de Internet y todos los archivos que te muestre como obsoletos.

  • Después usa su opción de Registro para limpiar todo el registro de Windows(haciendo copia de seguridad).

Malwarebytes.-

  • Instalas y Ejecutas MBAM siguiendo los pasos indicados en el manual.

  • Realiza un Análisis Personalizado. :white_check_mark:

  • Seleccionando TODOS a Cuarentena para enviarlo a la cuarentena y Reinicias el sistema.

  • En el apartado del programa :arrow_forward: Historial de detecciones :arrow_backward: encontrarás el informe de MBAM, que debes copiar y pegar en tu próxima respuesta, para poder analizarlo.

AdwCleaner.-

  • Ejecuta Adwcleaner.exe.

  • Pulsamos en el botón Analizar ahora, y espera a que se realice el proceso, inmediatamente pulsa siempre sobre el botón Iniciar Reparación.

  • Espera a que se complete y sigue las instrucciones, si te pidiera Reiniciar el sistema Aceptas.

  • El log/informe lo encontramos en la pestaña “Informes”, volviendo a abrir el programa si fuese necesario, para poder copiarlo y pegarlo en tu próxima respuesta.

  • El informe también se puede encontrar en C:\AdwCleaner\Logs\AdwCleaner[C00].txt

Junkware Removal Tool.-

  • Ejecuta JRT.exe.

  • Y pulsar cualquier tecla para continuar, esperar pacientemente a que termine el proceso.

  • Si en algún momento te pide Reiniciar hazlo.

  • Al finalizar, un registro/informe (JRT.txt) se guardara en el escritorio y se abrirá automáticamente.

  • Copia y pega el contenido de JRT.txt en tu próxima respuesta.

Farbar Recovery Scan Tool.-

  • Ejecuta FRST.exe.

  • En el mensaje de la ventana del Disclaimer/Responsabilidad, pulsamos Sí/Yes

  • En la ventana principal pulsamos en el botón Analizar/Scan y esperamos a que concluya el proceso.

  • Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

:three: Poner los informes en tu próxima respuesta de :

  • Malwarebytes, AdwCleaner, JRT, FRST + Addition.txt, y en ese orden. :+1:

Debes copiarlos y pegarlos con todo su contenido y usaras varios mensajes si recibes un mensaje de error indicando que es muy largo(más de 64.000 caracteres aprox.).

Y nos cuentas como funciona tu equipo en relación al problema planteado. :face_with_monocle:

Saludos.

Edito porque no sé cómo borrar el mensaje. Estuve un tiempo largo intentando iniciar la computadora luego de pasar el adwcleaner y recién ahora pude. Sigo con los pasos.

1 me gusta

Hola.

Perfecto. :+1:

Hay que tener en cuenta que cuando se hacen procesos de desinfección y estos te piden REINICIAR, el proceso de inicio de Windows puede ser bastante mas laaarrrrgooooo de lo habitual y en muchas ocasiones o se queda la pantalla negra anterior al logo de windows mucho mas tiempo y/o el proceso de inicio con el logo de windows igualmente demora.

Debemos esperar y tener paciencia, SI has realizado un APAGÓN forzado en ese instante de demora y luego al REINICIAR te pide hacer una restauración estaremos “cortando” y retrocediendo el proceso de desinfección.

Por lo tanto cuando termines TODO el proceso puede ser necesario que repitas el paso con AdwCleaner para verificar que las infecciones que detecto se han eliminado correctamente.

Saludos.

Entiendo que eso puede suceder pero pasaron alrededor de dos horas y tampoco estoy seguro de que completo el proceso de restauración. En todo caso volveré a pasar el AdwCleaner si lo crees necesario. Te paso los logs en orden, por el momento no cambió nada con respecto al teclado.

Malwarebytes
www.malwarebytes.com

-Detalles del registro-
Fecha del análisis: 12/5/20
Hora del análisis: 14:35
Archivo de registro: ef36f1aa-9476-11ea-8523-101f74fe1e45.json

-Información del software-
Versión: 4.1.0.56
Versión de los componentes: 1.0.896
Versión del paquete de actualización: 1.0.23718
Licencia: Prueba

-Información del sistema-
SO: Windows 7 Service Pack 1
CPU: x64
Sistema de archivos: NTFS
Usuario: HP\Gabriela

-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 285312
Amenazas detectadas: 0
Amenazas en cuarentena: 0
Tiempo transcurrido: 12 min, 37 seg

-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar

-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)

Módulo: 0
(No hay elementos maliciosos detectados)

Clave del registro: 0
(No hay elementos maliciosos detectados)

Valor del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Secuencia de datos: 0
(No hay elementos maliciosos detectados)

Carpeta: 0
(No hay elementos maliciosos detectados)

Archivo: 0
(No hay elementos maliciosos detectados)

Sector físico: 0
(No hay elementos maliciosos detectados)

WMI: 0
(No hay elementos maliciosos detectados)


(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.4.0
# -------------------------------
# Build:    04-03-2020
# Database: 2020-04-03.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    05-12-2020
# Duration: 00:01:27
# OS:       Windows 7 Home Premium
# Cleaned:  88
# Failed:   2


***** [ Services ] *****

Deleted       iWinTrusted

***** [ Folders ] *****

Deleted       C:\Program Files (x86)\Conduit
Deleted       C:\Program Files (x86)\RCP
Deleted       C:\Program Files (x86)\Smart PC Cleaner
Deleted       C:\Program Files (x86)\iwin games
Deleted       C:\ProgramData\Ask
Deleted       C:\Users\Public\Documents\iWin
Deleted       C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Toolbar4

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\Sunisoft
Deleted       HKLM\SOFTWARE\Classes\Applications\amp.exe
Deleted       HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithApplianMP
Deleted       HKLM\SOFTWARE\Classes\DVD\shell\PlayWithApplianMP
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD7C0212-2E0D-4B5B-962E-8A5E036F3D82}
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD7C0212-2E0D-4B5B-962E-8A5E036F3D82}
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IHUninstallTrackingTASK
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayCDAudioOnArrival
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayDVDAudioOnArrival
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayDVDMovieOnArrival
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayMusicFilesOnArrival
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlaySVCDMovieOnArrival
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayVCDMovieOnArrival
Deleted       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayVideoFilesOnArrival
Deleted       HKLM\Software\Classes\AppID\{635ADC07-6F19-42A7-8043-EDD19678CE14}
Deleted       HKLM\Software\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Deleted       HKLM\Software\Classes\Interface\{E3ED53C5-7AD5-4DF5-9734-AFB6E7E5D9DB}
Deleted       HKLM\Software\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Deleted       HKLM\Software\Classes\Prod.cap
Deleted       HKLM\Software\Classes\SpeedUpMyPC
Deleted       HKLM\Software\Classes\TypeLib\{44E6B68E-8DA5-4093-921B-7275E5B3906A}
Deleted       HKLM\Software\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Deleted       HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{59C0C5BD-2579-433A-BBB8-AFFD59642BAF}
Deleted       HKLM\Software\Wow6432Node\Applian Technologies
Deleted       HKLM\Software\Wow6432Node\Conduit
Deleted       HKLM\Software\Wow6432Node\PIP
Deleted       HKLM\Software\Wow6432Node\\Classes\AppID\{635ADC07-6F19-42A7-8043-EDD19678CE14}
Deleted       HKLM\Software\Wow6432Node\\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Deleted       HKLM\Software\Wow6432Node\\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Deleted       HKLM\Software\Wow6432Node\\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Deleted       HKLM\Software\Wow6432Node\\Classes\CLSID\{635ADC07-6F19-42A7-8043-EDD19678CE14}
Deleted       HKLM\Software\Wow6432Node\\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474}
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{E3ED53C5-7AD5-4DF5-9734-AFB6E7E5D9DB}
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Deleted       HKLM\Software\Wow6432Node\\Classes\TypeLib\{44E6B68E-8DA5-4093-921B-7275E5B3906A}
Deleted       HKLM\Software\Wow6432Node\\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayCDAudioOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayDVDAudioOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayDVDMovieOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayMusicFilesOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlaySVCDMovieOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayVCDMovieOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ApplianMPPlayVideoFilesOnArrival
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{59C0C5BD-2579-433A-BBB8-AFFD59642BAF}
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Applian FLV and Media Player

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted       Preinstalled.HPHealthCheck   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\HP\SUPPORT
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Folder   C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Classes\CLSID\{335F9A62-FE4B-40CD-B4ED-BB4DE21DC95D}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Classes\CLSID\{335F9A62-FE4B-40CD-B4ED-BB4DE21DC95D}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Classes\CLSID\{C0ABBA07-B636-47B8-B9E1-BB96D7CD4831}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}
Deleted       Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}
Deleted       Preinstalled.HPTouchSmartMyDisplay   Folder   C:\Program Files (x86)\Common Files\PORTRAIT DISPLAYS\DRIVERS
Deleted       Preinstalled.HPTouchSmartMyDisplay   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}
Deleted       Preinstalled.LenovoEasyCamera   Registry   HKLM\Software\Sunplus SPUVCb
Deleted       Preinstalled.LenovoEasyCamera   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Sunplus SPUVCb
Deleted       Preinstalled.LenovoEasyCamera   Registry   HKU\.DEFAULT\Software\Sunplus SPUVCb
Deleted       Preinstalled.LenovoEasyCamera   Registry   HKU\S-1-5-18\Software\Sunplus SPUVCb
Deleted       Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES
Deleted       Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES\APP
Deleted       Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES\SHORTCUTPROVIDER
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangent wildgames Master Uninstall
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-darkorbit
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-seafight
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-worldofwarcraft
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-genres
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-main
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{80831F60-19D7-43B3-A60C-5CAF8C478DF6}
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{A39303AB-4898-4F12-BAA0-0B8630F86DB4}
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}
Deleted       Preinstalled.WildTangentGamesBundle   Registry   HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6}
Not Deleted   Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT SOLUTIONS
Not Deleted   Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [12149 octets] - [12/05/2020 14:53:41]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Home Premium x64 
Ran by Gabriela (Administrator) on 12/05/2020 at 17:19:51,20
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 401 

Failed to delete: C:\Program Files (x86)\iwin games (Folder) 
Successfully deleted: C:\ProgramData\ask (Folder) 
Successfully deleted: C:\ProgramData\babylon (Folder) 
Successfully deleted: C:\Program Files (x86)\rcp (Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4B4KJFDH (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5HT2TSDT (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C2TG6FLC (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZU2AEXF (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J90ZL1KP (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PLI42Q2E (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RT0KXTFO (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Gabriela\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UUYN02IY (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4B4KJFDH (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5HT2TSDT (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C2TG6FLC (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZU2AEXF (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J90ZL1KP (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PLI42Q2E (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RT0KXTFO (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UUYN02IY (Temporary Internet Files Folder) 
Successfully deleted: C:\windows\SysWOW64\sho1066.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho113F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho12DC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho12EE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1383.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho151E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1546.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho15A3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho15B4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1633.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho166F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho16BF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho16EE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho16FC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho17C7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho18C4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho197A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1A2A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1A38.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1B05.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1D50.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1F06.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho1F65.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2119.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2156.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho216B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho21A6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2211.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2293.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho22CD.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho242.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho251F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2551.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho258D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2733.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2742.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho281A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2874.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho29CE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho29EE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho29F3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2B27.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2D98.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2DC8.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2E50.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2E5F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho2EFF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho30B1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho32D3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3354.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3370.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3408.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho349D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho373D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3791.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3A74.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3AC5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3AF6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3BBD.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3D0.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3D2F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3D9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3DDA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3E76.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho3FDD.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho42BB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho42BC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho42CB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho43C9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho43D8.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho445.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho452B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4570.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho458E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho45F6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4616.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho46E3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho479D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho48C5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4C03.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4C0D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4CC8.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4D2D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4DB8.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4E96.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4E9D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4EFE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4F2B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho4F77.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5003.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho50A5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho50D2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho511D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho512E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho513F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho518A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho52CB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5300.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho532E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho534D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho538E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho53EA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5477.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho54A5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho54CB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho55B0.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho563C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho566B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5782.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho584F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho58D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5939.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5983.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5A4B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5A80.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5AB3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5AFF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5C44.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5D53.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5DB1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5DD9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho5EA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho602C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6058.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho606F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho60B6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho60D1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho60D2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho60D4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6232.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho628E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho652F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho65B6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6654.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho674B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho67CC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6853.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6874.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho68C3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6A05.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6A56.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6C6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6CB7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6CC6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6CF3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6E4D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho6E70.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7159.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho727.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho740C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7418.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7429.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho745B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho76F5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7742.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7766.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho79C4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho79DA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho79E6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho79F8.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7A1E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7A20.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7AF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7B2C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7D1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7D4B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7DB9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7E8A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7EA2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho7EC0.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho801A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8028.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho80D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho80E4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8151.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho82BE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho82C7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho83F2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8404.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho870A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho871A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8739.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8769.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8788.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8797.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho87EA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho88FF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho890E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8A18.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8A7A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8B41.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8B7E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8B81.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8D10.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8DFC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8E2E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8E2F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8EC9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho8F66.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho917.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9202.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9209.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9234.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9246.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho92F7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho933B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho983B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9871.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9899.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9AAA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9B84.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9C4F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9D3F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9D5F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9E13.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9E94.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\sho9F9C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA027.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA049.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA098.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA182.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA38F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA3C3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA44A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA5E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA610.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA68C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA6B2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA6D9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA708.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA737.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA7A4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA7B5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA871.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA8AF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoA8BE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoAADF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoAB4A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoACC3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoAD6F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoAD8B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoADF3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoAEAB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoAFAF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB220.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB260.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB4B2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB4CF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB50C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB635.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB701.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB712.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB75.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB751.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoB9EE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBAC4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBC00.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBCE9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBD.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBD48.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBDE5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBE8E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBE8F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBEB4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBED0.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoBF79.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC088.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC11F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC259.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC276.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC285.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC36E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC39E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC3FC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC402.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC504.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC517.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC5C1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC69B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC6B7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC707.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC7E2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC85E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC8DA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC92E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoC995.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCAF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCB20.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCB5C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCBB9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCBCA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCC93.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCC9C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCD16.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCD2F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCDD9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCEF4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCF13.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCF66.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoCFFC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD01C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD0C7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD0DB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD116.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD191.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD23D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD2D2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD3E7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD41D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD4FA.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD77D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoD913.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDA0D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDA7A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDB51.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDB86.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDC40.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDC7B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDD1A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDD93.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDE20.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDE30.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoDE5F.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE1F7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE208.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE2F1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE34E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE3CB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE3DB.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE466.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE582.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE61A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE62D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE6A2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE73A.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE7FF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE83C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE8E9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE946.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE95E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE9A4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoE9E4.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEA03.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEA37.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEAD1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEBF6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEC0.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEC07.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoED10.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoED4D.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEE3.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEEED.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEF12.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEF20.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoEFBC.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF188.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF1EE.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF1FD.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF2D7.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF2E.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF2EF.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF317.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF3B2.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF3E0.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF528.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF557.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF576.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF623.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF71C.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF759.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF7C9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoF7D9.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFAB6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFAC5.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFAD6.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFC6B.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFCA8.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFDC1.tmp (File) 
Successfully deleted: C:\windows\SysWOW64\shoFEB9.tmp (File) 



Registry: 2 

Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12/05/2020 at 17:34:44,27
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 11-05-2020
Ejecutado por Gabriela (administrador) sobre HP (Hewlett-Packard HP ProBook 4530s) (12-05-2020 17:48:27)
Ejecutado desde C:\Users\Gabriela\Desktop
Perfiles cargados: Gabriela
Platform: Windows 7 Home Premium Service Pack 1 (X64) Idioma: Español (España, internacional)
Internet Explorer Versión 8 (Navegador predeterminado: "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" -- "%1")
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(ArcSoft, Inc. -> ArcSoft, Inc.) C:\windows\SysWOW64\ArcVCapRender\uArcCapture.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\windows\System32\hpservice.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(IDT, Inc.) [Archivo no firmado] C:\Program Files\IDT\WDM\stacsv64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation -> Intel Corporation) C:\windows\System32\hkcmd.exe
(Intel® Identity Protection Technology Software -> Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(iWin, Inc -> iWin Inc.) C:\Program Files (x86)\iWin Games\iWinTrusted.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation -> Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Portrait Displays, Inc. -> Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Validity Sensors, Inc -> Validity Sensors, Inc.) C:\windows\System32\vcsFPService.exe
(WildTangent Inc -> ) C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2996792 2011-07-15] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-25] (IDT, Inc.) [Archivo no firmado]
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2812656 2014-12-13] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [108216 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] => C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] (Sunplus Innovation Technology Inc. -> ) [Archivo no firmado]
HKLM-x32\...\Run: [DTRun] => c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [517456 2010-11-24] (ArcSoft, Inc. -> ArcSoft Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Archivo no firmado]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restricción <==== ATENCIÓN
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [43984 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [9230256 2020-03-13] (Support.com Inc -> SUPERAntiSpyware)
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19476424 2018-11-06] (Piriform Software Ltd -> Piriform Software Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.138\Installer\chrmstp.exe [2020-05-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{10880D85-AAD9-4558-ABDC-2AB1552D831F}] -> C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe [2008-06-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.4053.113\Installer\chrmstp.exe [2020-05-11] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-02] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BootExecute: autocheck autochk *  PCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicyScripts-x32: Restricción <==== ATENCIÓN
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN
CHR HKLM\SOFTWARE\Policies\Google: Restricción <==== ATENCIÓN

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {05131EA6-3E2C-4FB6-A003-FC618F0AEFBA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-17] (Google Inc -> Google Inc.)
Task: {1153BFC2-EB9C-4C0F-B39E-416B85F095CD} - \{EFCB239E-A67B-4177-A64A-37DC58BAA823} -> Ningún archivo <==== ATENCIÓN
Task: {1364944A-DD99-483E-BA78-3C953CA28671} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software)
Task: {14516119-976B-40EA-BF19-147D00CD311F} - System32\Tasks\{DE8EA0AD-5C89-460F-A0BA-443AC883D8ED} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
Task: {15495120-92CF-4EA7-BBDF-29E22147A31E} - \{5EEB130B-C5E3-4E95-A8FE-ACE8DC7FFC51} -> Ningún archivo <==== ATENCIÓN
Task: {1AEF3106-B5B6-430E-83FF-50600CF0E635} - System32\Tasks\{D2FFBAA0-1161-4E5A-9A3B-7BED65E38539} => C:\Users\Erika\Desktop\Phv.exe
Task: {22947606-F103-4048-B1AB-559C32596739} - \{01B7CE4A-28BE-4081-94C5-D22132FCBF68} -> Ningún archivo <==== ATENCIÓN
Task: {2C42CF88-855D-47AC-9D8F-ACE1DEE9CCE1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {2E14DF65-CE6A-49B5-8772-8BADCAA07970} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-19] (Avast Software s.r.o. -> AVAST Software)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Ningún archivo <==== ATENCIÓN
Task: {36CE16B0-9EE7-4ADA-B523-5DA4656E076C} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [898000 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
Task: {3F21FF21-DD74-420A-9EB5-3BE2BAB91779} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [620424 2016-05-04] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {41109735-418E-4769-86F4-092523F83F0C} - System32\Tasks\Apagar PC => C:\Windows\System32\shutdown.exe [34304 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
Task: {4955A070-9A27-4951-B7AA-FE4E21791967} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {496B5CDC-C0E9-410A-B422-DDEA9D07C50C} - System32\Tasks\{816CB30A-676A-42E3-AD73-A371E0C479DE} => C:\windows\system32\pcalua.exe -a "C:\Users\Erika\Downloads\QuickTimeInstaller (1).exe" -d C:\Users\Erika\Downloads
Task: {4A4588E1-DA3C-40C6-9C9B-91A05637DC50} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\windows\ehome\ehrec.exe
Task: {5042C336-B165-41E5-BA30-2E6AB14A0F80} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\windows\ehome\mcupdate.exe
Task: {508CF8AB-A1DA-4B23-88D5-D4DE9480FBB4} - \MotoHelper MUM -> Ningún archivo <==== ATENCIÓN
Task: {50D96CE0-EFCD-406D-8AED-58B528C10888} - \MotoHelper Routing -> Ningún archivo <==== ATENCIÓN
Task: {5F0FEFF4-E156-4261-8D27-129FAB4E4054} - \{579A7337-5077-497D-BE7F-51D406B1326E} -> Ningún archivo <==== ATENCIÓN
Task: {65D3CF7E-02ED-4AE9-90AB-E41A9EC33874} - System32\Tasks\{40018D1E-61FC-4184-AEE0-79A92C6D3528} => C:\Users\Erika\Desktop\Phv.exe
Task: {69AC48F8-A74A-4CBE-BABA-36987C96D4E9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {6BE401B1-5B06-40AB-8F58-57D0FDADC7B8} - System32\Tasks\{8BC8674A-AFC5-4E11-8A32-2AE525F92652} => C:\Users\Erika\Desktop\Phv.exe
Task: {79A7CD2B-14FD-42D2-862D-8E04C5B848D5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-17] (Google Inc -> Google Inc.)
Task: {7FAD2AB7-D6E5-49BB-B1F1-11E311260E73} - System32\Tasks\{E6B7690B-3A0B-4F22-A859-BC07AEE9D346} => C:\Users\Erika\Desktop\Phv.exe
Task: {8239A271-7D2F-4D21-A8B5-27661566DDCA} - \SidebarExecute -> Ningún archivo <==== ATENCIÓN
Task: {86C97F62-D99F-4BCC-ACB5-802253042AE0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [336008 2018-11-16] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {8BD395AF-078E-40E1-87B7-8525D9CC083A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {8FB7217C-2602-435D-BDA6-CF0385026C13} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Ningún archivo <==== ATENCIÓN
Task: {95117969-6249-4D2D-966A-14C83C358FD7} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {9BE73A96-2B23-458D-B4CD-A8BB25327FAB} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {9D3E0D8E-F051-4C83-AEC9-EC8646EFE628} - System32\Tasks\SUPERAntiSpyware Scheduled Task 5bcb8957-24ae-47ce-a33a-7c198725a7e6 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2013-11-07] (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {A15551B0-D78A-4A81-BAFA-E93CF76401F0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {A516EBB0-85B2-4A7E-A21A-FE8E9387545A} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3325032 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
Task: {AB5B4B4E-5B68-4BAF-9837-8BC1A6416D07} - System32\Tasks\{516049F0-CC02-452B-A6A2-FF39927BF664} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Ningún archivo <==== ATENCIÓN
Task: {AE8BD54B-AD93-4B74-9945-06DBD3422D79} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core1d1e917899d532 => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {B170F6EE-B1FD-40BB-8636-21E0D248EDD0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA1d1e9178d09d70 => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {BA9F2783-3C1B-41DD-B647-72EF113E5D8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [107072 2016-05-09] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {BD7C0212-2E0D-4B5B-962E-8A5E036F3D82} - \IHUninstallTrackingTASK -> Ningún archivo <==== ATENCIÓN
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Ningún archivo <==== ATENCIÓN
Task: {D62C7F31-EECE-40FB-AACE-FD37116802B9} - \RunAsStdUser Task -> Ningún archivo <==== ATENCIÓN
Task: {D7961A06-DAD4-4B3E-9A60-9B82D133F5FC} - System32\Tasks\{54167D85-7CB6-443D-805E-7BFF8B1E844F} => C:\windows\system32\pcalua.exe -a C:\Users\Erika\Downloads\QuickTimeInstaller.exe -d C:\Users\Erika\Downloads
Task: {DA9B29E2-5EFB-4B5D-8357-A0F524101F0D} - System32\Tasks\SUPERAntiSpyware Scheduled Task c1f5af4c-b7ba-4b21-8e92-897cf9e971a1 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2013-11-07] (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {DC2DE33C-D5FE-4155-B6BC-37A550ED01DB} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {DE2C859E-279C-4115-A7C0-F25FA89CF22B} - \User_Feed_Synchronization-{BAC3944D-7C78-4B3D-9863-20FC40B19BC9} -> Ningún archivo <==== ATENCIÓN
Task: {DE65BF18-4593-47FF-A599-81C9595A90F7} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Ningún archivo <==== ATENCIÓN
Task: {E0D595D9-991E-4A13-A049-825DA3397F6C} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [134608 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
Task: {E129F494-CD81-4737-8D49-953CAAB06211} - System32\Tasks\{AC72203C-7D2B-47BC-88C2-279BD4ED6374} => C:\Users\Erika\Desktop\Phv.exe
Task: {E6ACB3BC-009D-4AED-90CB-603B33FC3874} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-19] (Avast Software s.r.o. -> AVAST Software)
Task: {F3E3AF7D-9D0F-44B7-8914-2BCD46EBEAAC} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {F437A0E7-173B-4764-9D82-CA5FD8EE54E1} - \MotoHelper Update -> Ningún archivo <==== ATENCIÓN
Task: {F5A0E31B-BE07-4D62-8F1D-46208052847A} - System32\Tasks\avastBCLRestartS-1-5-21-348586771-676038775-713973424-1001 => C:\Users\Erika\AppData\Local\Google\Chrome\Application\chrome.exe 
Task: {F67912CA-84DF-4653-8721-E6E996AB93F8} - \AutoKMS -> Ningún archivo <==== ATENCIÓN
Task: {F7796554-51ED-4FF6-8839-B3C6B734D650} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [548824 2018-11-06] (Piriform Software Ltd -> Piriform Ltd)
Task: {F79DF38C-99B1-4E09-B482-94CB331439A8} - System32\Tasks\{B34B8149-1109-4B73-B74C-8FA2AA19D911} => C:\Program Files (x86)\BlueStacks\HD-StartLauncher.exe
Task: {F96A136A-66F5-458D-9042-D0FE4025771C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14554696 2018-11-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Ningún archivo <==== ATENCIÓN
Task: {FFE259F5-5C2F-4A2F-82DA-46012A960FE9} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [126152 2020-04-10] (Mozilla Corporation -> Mozilla Foundation)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\windows\Tasks\AutoKMS.job => 
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 5bcb8957-24ae-47ce-a33a-7c198725a7e6.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task c1f5af4c-b7ba-4b21-8e92-897cf9e971a1.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Winsock: Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Tcpip\..\Interfaces\{73683B1B-4456-4748-B4DF-EDA1887E505C}: [DhcpNameServer] 200.49.130.41 200.42.4.204
Tcpip\..\Interfaces\{7DA4B6EA-6AB8-417C-813A-8EBF4643DB71}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{F91C9E14-971D-4A63-A326-F3E6500E84D3}: [DhcpNameServer] 186.130.128.250 186.130.129.250

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPALL/50
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPALL/50
HKU\S-1-5-21-348586771-676038775-713973424-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPALL/50
HKU\S-1-5-21-348586771-676038775-713973424-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPALL/50
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-348586771-676038775-713973424-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = 
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-07-08] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-08] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  Ningún archivo
Toolbar: HKLM - Sin Nombre - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  Ningún archivo
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 11-05-2020
Ejecutado por Gabriela (12-05-2020 17:44:18)
Ejecutado desde C:\Users\Gabriela\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-03-22 21:41:17)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-348586771-676038775-713973424-500 - Administrator - Disabled)
Gabriela (S-1-5-21-348586771-676038775-713973424-1003 - Administrator - Enabled) => C:\Users\Gabriela
Invitado (S-1-5-21-348586771-676038775-713973424-501 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 26.0.0.118 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.8.198 - Adobe Systems, Inc.)
Applian FLV and Media Player 3.1.1.12 (HKLM-x32\...\Applian FLV and Media Player) (Version: 3.1.1.12 - Applian Technologies)
ArcSoft TotalMedia (HKLM-x32\...\{4114A073-7385-4742-8A5E-A5788FAC838F}) (Version: 1.0.48.25 - ArcSoft) Hidden
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.30 - ArcSoft)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.2.2401 - Avast Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 81.0.4053.113 - Los creadores de Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.136.333 - AVAST Software) Hidden
Bejeweled 2 Deluxe (HKLM-x32\...\WT087428) (Version: 2.2.0.95 - WildTangent) Hidden
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
Blasterball 3 (HKLM-x32\...\WT089308) (Version: 2.2.0.95 - WildTangent) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.49 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Compresor WinRAR (HKLM-x32\...\WinRAR archiver) (Version:  - )
Corel Graphics - Windows Shell Extension 64 Bit (HKLM\...\{51DDB4F9-7FFF-4970-AED4-DB3C22A5C522}) (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Capture (x64) (HKLM\...\{1967EF95-E00B-4669-8B1C-A589BE8BF24F}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Common (x64) (HKLM\...\{35869A6C-BA31-4F23-B52D-BC1B1E41EC1B}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Connect (x64) (HKLM\...\{96AAAB95-AEBE-437A-B7CA-37C7BE13FFE9}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Custom Data (x64) (HKLM\...\{7386B5FA-8715-481D-821F-7785110506DF}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Draw (x64) (HKLM\...\{27AE72A4-B217-4CDC-B82B-3311E9D7460E}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - ES (x64) (HKLM\...\{839546C9-2E4E-4A42-B0D4-22E05E92E7AA}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Filters (x64) (HKLM\...\{E699230D-4B5E-411E-9F45-FF50789B18DD}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FontNav (x64) (HKLM\...\{3933C06C-8239-432B-87FC-F2BDC5B49A10}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (HKLM\...\{B6DF7031-2843-44FD-9CAB-DECAB4257456}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (HKLM\...\{D7C2687D-924E-4485-B367-C7D95CBF8DDD}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Photozoom Plugin (x64) (HKLM\...\{2C72B5E4-AA34-4F1A-8C7E-468530F9F6A3}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Redist (x64) (HKLM\...\{6099F026-0A98-4D40-9B3D-ED2123A8CBD0}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Setup Files (x64) (HKLM\...\{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VBA (x64) (HKLM\...\{10762393-1B90-4AC2-AF1A-4C0C04AE303F}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (HKLM\...\{7B79AE44-9B76-4815-84E5-ACAC3F0F0278}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VSTA (x64) (HKLM\...\{1E3A578C-0A7D-4820-990F-B7545C0B2303}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Writing Tools (x64) (HKLM\...\{DDE82E3D-20C4-48E1-AE1D-B1F10E42CA44}) (Version: 16.1 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 (x64) (HKLM\...\{CCE7423E-1D84-4CD3-9E32-220EC9358D97}) (Version: 16.1 - Corel Corporation) Hidden
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (HKLM-x32\...\WT087536) (Version: 2.2.0.95 - WildTangent) Hidden
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Evernote v. 4.6 (HKLM-x32\...\{A23AADDA-3DBF-11E2-A6F2-984BE15F174E}) (Version: 4.6.0.7670 - Evernote Corp.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Galería fotográfica de Windows Live (HKLM-x32\...\{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (HKLM-x32\...\{4736B0ED-F6A1-48EC-A1B7-C053027648F1}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (HKLM-x32\...\{488F0347-C4A7-4374-91A7-30818BEDA710}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Glary Utilities 5.73 (HKLM-x32\...\Glary Utilities 5) (Version: 5.73.0.94 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.138 - Google LLC)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Hacer clic y ejecutar de Microsoft Office 2010 (HKLM\...\{90140000-006D-0C0A-1000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Hacer clic y ejecutar de Microsoft Office 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{E5D02167-DD50-4E8C-B9F9-992182E08D6B}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\...\{5DCA44EB-03F6-44A3-A294-F3E5DE98D7F6}) (Version: 4.4.10.1 - Hewlett-Packard Company)
HP DayStarter (HKLM\...\{483D5A49-A26B-4CB8-AA2D-0D1811322061}) (Version: 2.0.0.12 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{6A9C9BE1-14A3-42ED-A388-42E30A1412E9}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
HP HD Webcam [Fixed] (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.3.4.09 - SunplusIT)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.6.4.1 - Hewlett-Packard Company)
HP Power Assistant (HKLM\...\{0DA545C1-8ECA-4B54-B787-31ED17429CF3}) (Version: 2.1.0.6 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{6B5E7B4F-64A2-4DEB-B210-0DD92F940A01}) (Version: 3.0.3.9925 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{FE465061-894A-4023-8580-56FCDD4F23F9}) (Version: 3.4.4.0 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{5877C85D-8CA5-4153-A366-C232ECFE7A2B}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{531000B3-DBEE-4115-BBF3-DA48B67C053F}) (Version: 8.2.1.1 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{7B649B69-BE85-4011-AFAE-4767BC9D934A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP System Default Settings (HKLM-x32\...\{EE5F1911-EA95-4F1A-AF97-495972F5032D}) (Version: 2.4.3.1 - Hewlett-Packard Company)
HP Wallpaper (HKLM-x32\...\{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}) (Version: 2.00 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6428.0 - IDT)
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Infovox Desktop 2.220 voices (HKLM-x32\...\ID2220Voices) (Version:  - )
Insaniquarium Deluxe (HKLM-x32\...\WT087480) (Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel(R) Identity Protection Technology 1.0.71.0 (HKLM-x32\...\{2C43790E-8470-1027-82D3-DF319F3C410F}) (Version: 1.0.71.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
iWin Games (remove only) (HKLM-x32\...\iWinArcade) (Version:  - )
Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Quest II (HKLM-x32\...\WT087485) (Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (HKLM-x32\...\WT087490) (Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (quitar) (HKLM-x32\...\Jewel Quest Solitaire) (Version:  - )
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.72.4 - JMicron Technology Corp.)
John Deere Drive Green (HKLM-x32\...\WT087380) (Version: 2.2.0.95 - WildTangent) Hidden
Juegos WildTangent (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LightScribe System Software  1.14.17.1 (HKLM-x32\...\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - ESN (HKLM-x32\...\{6D972506-DC01-39BC-A5DD-06DA86E00031}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - ESN (HKLM-x32\...\{4A28444E-0532-3264-B07D-5AFE590E30BE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
MotoHelper MergeModules (HKLM-x32\...\{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}) (Version: 1.0.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 4.7.1 (HKLM\...\{82ED9FB2-55AF-4A61-A6F3-506CEE112779}) (Version: 4.7.1 - Motorola Inc.) Hidden
Mozilla Firefox 75.0 (x64 es-AR) (HKLM\...\Mozilla Firefox 75.0 (x64 es-AR)) (Version: 75.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 63.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation)
Penguins! (HKLM-x32\...\WT087394) (Version: 2.2.0.95 - WildTangent) Hidden
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Plants vs. Zombies (HKLM-x32\...\WT087501) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\...\WT087396) (Version: 2.2.0.95 - WildTangent) Hidden
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
Readon TV Movie Radio Player 7.5.0.0 (HKLM-x32\...\{03840E8D-A75E-4C49-ADFC-09A867C7F943}) (Version: 7.5.0 - Readon Technology)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.58.411.2012 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.00.11.0323 - REALTEK Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.50 - Piriform)
Remo ONE 1.0.0 (HKLM\...\{8DB422C2-D359-49B1-A685-B71DA7358D5C}_is1) (Version: 1.0.0.4 - Remo Software)
Remo Recover 5.0 (HKLM\...\{A573D759-F894-448D-A420-3A9C31879F88}_is1) (Version: 5.0.0.34 - Remo Software)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Revisión para Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{6D972506-DC01-39BC-A5DD-06DA86E00031}.KB947789) (Version: 1 - Microsoft Corporation)
SDK (HKLM-x32\...\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}) (Version: 2.26.012 - Portrait Displays, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Web Plugin (HKLM-x32\...\{0F7D4832-16AE-4857-A6FA-2B141D75A59B}) (Version: 7.7.0.219 - Skype Technologies S.A.)
Skype Web Plugin (HKLM-x32\...\{15AF46DB-9EBA-4662-AA52-29EF23585035}) (Version: 3.2.0.23388 - Skype Technologies S.A.)
Slingo Deluxe (HKLM-x32\...\WT087510) (Version: 2.2.0.95 - WildTangent) Hidden
Spotify (HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1052 - SUPERAntiSpyware.com)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.18.17 - Synaptics Incorporated)
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - gamigo, Inc.) Hidden
Validity Fingerprint Sensor Driver (HKLM\...\{FFC3E41D-2C2B-45B7-9AD9-5EA19572DD26}) (Version: 4.3.117.0 - Validity Sensors, Inc.)
VIP Access SDK x64(1.0.0.50)  (HKLM-x32\...\VIP Access SDK) (Version: 1.0.0.50 - Symantec Inc.)
Virtual Villagers - The Secret City (HKLM-x32\...\WT087513) (Version: 2.2.0.95 - WildTangent) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Wedding Dash (HKLM-x32\...\WT087519) (Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames) (Version: 4.1.1.49 - WildTangent) Hidden
WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.5 - WildTangent) Hidden
WildTangent Helper (HKLM-x32\...\{A39303AB-4898-4F12-BAA0-0B8630F86DB4}) (Version: 1.0.0.409 - WildTangent) Hidden
WildTangent ShortcutProvider (HKLM-x32\...\{80831F60-19D7-43B3-A60C-5CAF8C478DF6}) (Version: 5.0.0.219 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinZip 14.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. )
Xobni (HKLM-x32\...\XobniMain) (Version: 1.9.5.13282 - Xobni Corp.)
Youda Jewel Shop (HKLM-x32\...\WTA-8d8094a7-cd05-4069-8bf0-6429dc99eca0) (Version: 3.0.2.32 - WildTangent) Hidden
Zoom (HKU\S-1-5-21-348586771-676038775-713973424-1003\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)
Zuma Deluxe (HKLM-x32\...\WT087533) (Version: 2.2.0.95 - WildTangent) Hidden

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} =>  -> Ningún archivo
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2011-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [Archivo no firmado]

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2011-11-11 07:41 - 2011-01-12 22:56 - 000058880 _____ ( () [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2011-05-04 21:56 - 2011-06-11 12:42 - 001083392 _____ ( () [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\System.Data.SQLite.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000006656 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IAStorDataMgr.resources.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000032768 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IAStorIcon.resources.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000004608 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IntelVisualDesign.resources.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 000165376 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUIHelper.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 001109504 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll
2012-03-23 20:05 - 2012-03-23 20:05 - 000225280 _____ ( (Microsoft Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
2011-04-27 17:05 - 2011-04-27 17:05 - 000514570 _____ () [Archivo no firmado] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2012-03-31 16:50 - 2008-06-20 00:41 - 000062464 _____ () [Archivo no firmado] C:\Program Files (x86)\WinRAR\rarext64.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000169472 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\61a733954a0da9a5988d596c76b2b891\IsdiInterop.ni.dll
2011-11-11 07:41 - 2011-01-17 16:19 - 001892352 _____ (Apache Software Foundation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\xerces-c_2_7.dll
2008-06-09 10:21 - 2008-06-09 10:21 - 000033280 _____ (Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSLog.dll
2008-06-09 10:21 - 2008-06-09 10:21 - 000110592 _____ (Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSSProxy.dll
2014-09-10 21:53 - 2014-09-10 21:53 - 000014336 _____ (Intel Corp.) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e8d9058b7f59f6d3d134b086916d8674\IAStorCommon.ni.dll
2011-11-11 07:41 - 2011-01-17 16:14 - 000069632 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\StatusStrings.dll
2011-11-11 07:41 - 2011-01-12 22:52 - 000275456 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000219136 _____ (Intel Corporation) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\79bc2712f1597303b790bfa64b222d41\IAStorDataMgr.ni.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000475648 _____ (Intel Corporation) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\7cfe3c97366e009a0a7bce795ec66f43\IAStorUtil.ni.dll

==================== Alternate Data Streams (Lista blanca) ========

(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)

AlternateDataStreams: C:\ProgramData\TEMP:E6540C35 [126]

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2009-07-13 23:34 - 2019-01-13 17:13 - 000000825 _____ C:\windows\system32\drivers\etc\hosts

2012-04-06 23:30 - 2014-10-16 20:16 - 000000375 _____ C:\windows\system32\drivers\etc\hosts.ics

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %C_EM64T_REDIST11%bin\Intel64;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Intel\Services\IPT\;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-348586771-676038775-713973424-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Gabriela\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [{B2D3BA98-68F5-47A5-868D-C1E6F278A051}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{900D6A16-8D89-4CC6-95A5-AE312874D0A4}] => (Allow) LPort=2869
FirewallRules: [{7F0B70FA-796D-49F0-9611-E03D9D0449CC}] => (Allow) LPort=1900
FirewallRules: [{8C22AA11-D491-42B5-A7D5-2F75D4585E75}] => (Allow) LPort=1542
FirewallRules: [{492E4ADD-6891-4ACB-9E31-C43B4D06618B}] => (Allow) LPort=1542
FirewallRules: [{C24C5143-AA92-4081-9A6B-C370E2B1A4D8}] => (Allow) LPort=53
FirewallRules: [{5EBE1633-728D-49E9-AC98-293E554C99B8}] => (Allow) C:\Windows\SysWOW64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{27631350-9188-475D-BA2E-F7B272E9CF5E}] => (Allow) C:\Windows\SysWOW64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{0D0B5E34-B82D-4554-ADE0-1D96C59188E2}C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe] => (Block) C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe (Readon Technology) [Archivo no firmado]
FirewallRules: [UDP Query User{DF3B8EB6-0EC4-434D-8330-65271DF0217B}C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe] => (Block) C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe (Readon Technology) [Archivo no firmado]
FirewallRules: [{BE894BD7-CC3B-40E2-9D72-795B9A8B8D0F}] => (Allow) C:\Program Files (x86)\iWin Games\iWinGames.exe => Ningún archivo
FirewallRules: [{21317B5A-CC73-4E1E-82A2-CB43F22FC0F3}] => (Allow) C:\Program Files (x86)\iWin Games\iWinGames.exe => Ningún archivo
FirewallRules: [{5B717D7F-ACF3-4D73-B5CC-E20818121B02}] => (Allow) C:\Program Files (x86)\iWin Games\WebUpdater.exe => Ningún archivo
FirewallRules: [{CA127852-6D1F-4D41-B7C7-8F602D417C35}] => (Allow) C:\Program Files (x86)\iWin Games\WebUpdater.exe => Ningún archivo
FirewallRules: [TCP Query User{C1EA3879-6043-4CD9-B511-5FBECCFF755F}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe
FirewallRules: [UDP Query User{59D08101-D3ED-46D1-AE4A-73BF883812C7}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe
FirewallRules: [{B510B2DE-7AA5-4E6D-B056-6FDEC7452D6B}] => (Allow) C:\Program Files (x86)\SkypeWebPlugin\3.2.0.23388\SkypeWebPlugin.exe (Skype Software Sarl -> Skype)
FirewallRules: [TCP Query User{C40D2717-8307-4B1C-BB22-C227B98373B8}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{89622048-5901-4B02-873A-0596F96A6FD8}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{923CDD66-7ACE-4BBF-9183-8C6C0F7BF6FF}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{12CE1836-81D6-49AA-8AEC-7B90AF9808AA}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{812D9CD9-DD2A-40F6-96D1-E7AD52D78DCD}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Ltd)
FirewallRules: [{0DAE30C5-0D56-496C-8D30-8E5F87BB9999}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Ltd)
FirewallRules: [{EC2C566A-1C37-468E-8F1D-C011157FB46F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7E598F04-D8CA-45D5-B2CE-C53F5D1FB5AC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{BAC6D019-86C4-4C3F-9996-BBCB7B1C1EEA}] => (Allow) C:\Users\Gabriela\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{B0D51C2F-4611-4E13-8F11-9E1BA2D3F32C}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{607BE7CE-FAC8-4192-963C-8157138F930E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Puntos de Restauración =========================

12-05-2020 17:19:52 JRT Pre-Junkware Removal

==================== Dispositivos defectuosos en el Administrador de dispositivos ============

Name: Adaptador de tunelización Teredo de Microsoft
Description: Adaptador de tunelización Teredo de Microsoft
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: ElbyCDIO Driver
Description: ElbyCDIO Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: ElbyCDIO
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (05/12/2020 02:55:48 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows no puede tener acceso al archivo  por alguna de las siguientes razones:
Hay un problema con la conexión de red, con el disco donde se almacena este archivo o con los controladores
de almacenamiento instalados en este equipo; o bien no se encuentra el disco.
Windows cerró el programa WildTangentHelperService.exe por este error.

Programa: WildTangentHelperService.exe
Archivo: 

El valor del error se muestra en la sección Datos adicionales.
Acción del usuario
1. Abra el archivo de nuevo.
Podría ser sólo un problema temporal que se corrige al ejecutar el programa de nuevo.
2.
Si todavía no se puede tener acceso al archivo y 
	- Está en la red,
el administrador de red debe comprobar que no exista ningún problema con la red y que es posible ponerse en contacto con el servidor.
	- Está en un disco extraíble, como un disquete o un CD-ROM, compruebe que el disco esté insertado en el equipo.
3. Compruebe y repare el sistema de archivos ejecutando CHKDSK. Para ejecutar CHKDSK, haga clic en Inicio y después en Ejecutar; escriba CMD y después haga clic en Aceptar. En el símbolo del sistema, escriba CHKDSK /F y después presione Entrar.
4. Si el problema continúa, restaure el archivo a partir de una copia de seguridad.
5. Compruebe si se pueden abrir otros archivos en el mismo disco. Si no se pueden abrir, el disco podría estar dañado. Si se trata de un disco duro, póngase en contacto con el administrador o con el fabricante del hardware del equipo
para obtener ayuda adicional.

Datos adicionales
Valor del error:00000000
Tipo de disco: 0

Error: (05/12/2020 02:55:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: WildTangentHelperService.exe, versión: 1.0.0.409, marca de tiempo: 0x5e8638b2
Nombre del módulo con errores: WildTangentHelperService.exe, versión: 1.0.0.409, marca de tiempo: 0x5e8638b2
Código de excepción: 0xc0000096
Desplazamiento de errores: 0x000dc90c
Id. del proceso con errores: 0x22ec
Hora de inicio de la aplicación con errores: 0x01d6288687cf8a89
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Ruta de acceso del módulo con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Id. del informe: cf385628-9479-11ea-92a5-101f74fe1e45


Errores del sistema:
=============
Error: (05/12/2020 05:13:34 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
ElbyCDIO

Error: (05/12/2020 05:11:33 PM) (Source: volsnap) (EventID: 25) (User: )
Description: Se eliminaron las instantáneas del volumen C: porque el almacenamiento de instantáneas no se completó a tiempo. Considere reducir la carga de E/S en el sistema o elija un volumen de almacenamiento de instantáneas del que no se esté haciendo una instantánea.

Error: (05/12/2020 05:03:56 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Error en la inicialización del archivo de volcado

Error: (05/12/2020 05:03:56 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Error en la inicialización del archivo de volcado

Error: (05/12/2020 02:55:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio HP Software Framework Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (05/12/2020 02:55:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio WildTangentHelper terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 5000 milisegundos: Ejecutar el programa de recuperación configurado.

Error: (05/12/2020 02:55:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio Application Virtualization Client se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (05/12/2020 02:55:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio Client Virtualization Handler se terminó de manera inesperada. Esto ha sucedido 1 veces.


CodeIntegrity:
===================================

Date: 2020-05-12 17:37:08.621
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 17:19:42.062
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 17:17:20.942
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 17:17:13.703
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 14:57:17.127
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 14:52:30.774
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 14:52:10.897
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 14:51:55.750
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

==================== Información de la memoria =========================== 

BIOS: Hewlett-Packard 68SRR Ver. F.40 03/12/2013
Placa base: Hewlett-Packard 167C
Procesador: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Porcentaje de memoria en uso: 89%
RAM física total: 4030.37 MB
RAM física disponible: 406.25 MB
Virtual total: 8058.92 MB
Virtual disponible: 4364.63 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:443.56 GB) (Free:272.13 GB) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive e: (HP_RECOVERY) (Fixed) (Total:16.9 GB) (Free:2.54 GB) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive f: (HP_TOOLS) (Fixed) (Total:4.98 GB) (Free:2.12 GB) FAT32

\\?\Volume{85a6513a-0c50-11e1-ba96-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.25 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 4166D6A8)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=443.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=16.9 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=5 GB) - (Type=0C)

==================== Final de Addition.txt =======================

Hola.

Lo primero revisa el informe que pusiste de FRST.txt que NO esta completo le falta al menos la mitad del mismo, busca el que tienes en escritorio para poner lo que falta en tu próxima respuesta y lo pueda analizar para darte nuevos pasos. :face_with_monocle:



Y ademas ahora haces lo siguiente, descarga e instala este programa :arrow_right: Manual de Revo Uninstaller :+1:

Y úsalo para desinstalar todos los programas que encuentres que se llamen o tengan en su nombre, cualquiera de estas denominaciones :

iWin Games
Java
JavaFX
VLC media player

Cuando Revo te pida, que selecciones el método de desinstalación, seleccionas “Avanzado”.

Si durante el proceso te solicita “Reiniciar” NO lo hagas, dile que NO y deja que Revo siga trabajando.

Cuando termines todos los procesos de desinstalación ya REINICIAS tú el ordenador.

Compruebas y nos comentas.

Si necesitas Java para algo cuando terminemos lo puedes instalar para actualizarlo y con VLC haces lo msimo.

Saludos.

Eso es todo lo que tengo en el txt del FRST, se corta ahí. Aprovecho para hacerte una consulta. Estuve leyendo el manual del Revo Uninstaller y dice Revo Uninstaller le mostrará la lista de elementos del registro que son desechables , estos estarán seleccionados todos con un tilde por defecto. Pero ya hice el primer paso con el Java y en ese segundo paso no me aparece ninguna casilla ya tildada, están todas sin marcar. Las marco yo o sigo sin eliminar esos archivos? Todavía no probe con los otros programas.

Hola.

Pues… realiza un nuevo proceso con FRST.exe para generar nuevos informes de FRST.txt y de Addition.txt y los pones los dos en tu próxima respuesta.

Con RevoUninstaller debes marcar TODO lo que salga o quede para que se elimine correctamente.

Saludos.

Desinstale los 4 programas y todos sus archivos. Además volví a pasar el FRST, pego ambos logs tal como salieron (el primero salió así, casi vacío). El teclado sigue igual. Aguardo instrucciones.

Perdón si soy poco descriptivo pero me está costando escribir con el teclado en pantalla o copiando y pegando :pensive:


==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)


LastRegBack: 2020-05-08 08:18
==================== Final de FRST.txt ========================
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 11-05-2020
Ejecutado por Gabriela (12-05-2020 22:12:57)
Ejecutado desde C:\Users\Gabriela\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-03-22 21:41:17)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-348586771-676038775-713973424-500 - Administrator - Disabled)
Gabriela (S-1-5-21-348586771-676038775-713973424-1003 - Administrator - Enabled) => C:\Users\Gabriela
Invitado (S-1-5-21-348586771-676038775-713973424-501 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 26.0.0.118 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.8.198 - Adobe Systems, Inc.)
Applian FLV and Media Player 3.1.1.12 (HKLM-x32\...\Applian FLV and Media Player) (Version: 3.1.1.12 - Applian Technologies)
ArcSoft TotalMedia (HKLM-x32\...\{4114A073-7385-4742-8A5E-A5788FAC838F}) (Version: 1.0.48.25 - ArcSoft) Hidden
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.30 - ArcSoft)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.2.2401 - Avast Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 81.0.4053.113 - Los creadores de Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.136.333 - AVAST Software) Hidden
Bejeweled 2 Deluxe (HKLM-x32\...\WT087428) (Version: 2.2.0.95 - WildTangent) Hidden
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
Blasterball 3 (HKLM-x32\...\WT089308) (Version: 2.2.0.95 - WildTangent) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.49 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Compresor WinRAR (HKLM-x32\...\WinRAR archiver) (Version:  - )
Corel Graphics - Windows Shell Extension 64 Bit (HKLM\...\{51DDB4F9-7FFF-4970-AED4-DB3C22A5C522}) (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Capture (x64) (HKLM\...\{1967EF95-E00B-4669-8B1C-A589BE8BF24F}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Common (x64) (HKLM\...\{35869A6C-BA31-4F23-B52D-BC1B1E41EC1B}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Connect (x64) (HKLM\...\{96AAAB95-AEBE-437A-B7CA-37C7BE13FFE9}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Custom Data (x64) (HKLM\...\{7386B5FA-8715-481D-821F-7785110506DF}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Draw (x64) (HKLM\...\{27AE72A4-B217-4CDC-B82B-3311E9D7460E}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - ES (x64) (HKLM\...\{839546C9-2E4E-4A42-B0D4-22E05E92E7AA}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Filters (x64) (HKLM\...\{E699230D-4B5E-411E-9F45-FF50789B18DD}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FontNav (x64) (HKLM\...\{3933C06C-8239-432B-87FC-F2BDC5B49A10}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (HKLM\...\{B6DF7031-2843-44FD-9CAB-DECAB4257456}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (HKLM\...\{D7C2687D-924E-4485-B367-C7D95CBF8DDD}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Photozoom Plugin (x64) (HKLM\...\{2C72B5E4-AA34-4F1A-8C7E-468530F9F6A3}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Redist (x64) (HKLM\...\{6099F026-0A98-4D40-9B3D-ED2123A8CBD0}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Setup Files (x64) (HKLM\...\{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VBA (x64) (HKLM\...\{10762393-1B90-4AC2-AF1A-4C0C04AE303F}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (HKLM\...\{7B79AE44-9B76-4815-84E5-ACAC3F0F0278}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VSTA (x64) (HKLM\...\{1E3A578C-0A7D-4820-990F-B7545C0B2303}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Writing Tools (x64) (HKLM\...\{DDE82E3D-20C4-48E1-AE1D-B1F10E42CA44}) (Version: 16.1 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 (x64) (HKLM\...\{CCE7423E-1D84-4CD3-9E32-220EC9358D97}) (Version: 16.1 - Corel Corporation) Hidden
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (HKLM-x32\...\WT087536) (Version: 2.2.0.95 - WildTangent) Hidden
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Evernote v. 4.6 (HKLM-x32\...\{A23AADDA-3DBF-11E2-A6F2-984BE15F174E}) (Version: 4.6.0.7670 - Evernote Corp.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Galería fotográfica de Windows Live (HKLM-x32\...\{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (HKLM-x32\...\{4736B0ED-F6A1-48EC-A1B7-C053027648F1}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (HKLM-x32\...\{488F0347-C4A7-4374-91A7-30818BEDA710}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Glary Utilities 5.73 (HKLM-x32\...\Glary Utilities 5) (Version: 5.73.0.94 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.138 - Google LLC)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Hacer clic y ejecutar de Microsoft Office 2010 (HKLM\...\{90140000-006D-0C0A-1000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Hacer clic y ejecutar de Microsoft Office 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{E5D02167-DD50-4E8C-B9F9-992182E08D6B}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\...\{5DCA44EB-03F6-44A3-A294-F3E5DE98D7F6}) (Version: 4.4.10.1 - Hewlett-Packard Company)
HP DayStarter (HKLM\...\{483D5A49-A26B-4CB8-AA2D-0D1811322061}) (Version: 2.0.0.12 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{6A9C9BE1-14A3-42ED-A388-42E30A1412E9}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
HP HD Webcam [Fixed] (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.3.4.09 - SunplusIT)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.6.4.1 - Hewlett-Packard Company)
HP Power Assistant (HKLM\...\{0DA545C1-8ECA-4B54-B787-31ED17429CF3}) (Version: 2.1.0.6 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{6B5E7B4F-64A2-4DEB-B210-0DD92F940A01}) (Version: 3.0.3.9925 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{FE465061-894A-4023-8580-56FCDD4F23F9}) (Version: 3.4.4.0 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{5877C85D-8CA5-4153-A366-C232ECFE7A2B}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{531000B3-DBEE-4115-BBF3-DA48B67C053F}) (Version: 8.2.1.1 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{7B649B69-BE85-4011-AFAE-4767BC9D934A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP System Default Settings (HKLM-x32\...\{EE5F1911-EA95-4F1A-AF97-495972F5032D}) (Version: 2.4.3.1 - Hewlett-Packard Company)
HP Wallpaper (HKLM-x32\...\{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}) (Version: 2.00 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6428.0 - IDT)
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Infovox Desktop 2.220 voices (HKLM-x32\...\ID2220Voices) (Version:  - )
Insaniquarium Deluxe (HKLM-x32\...\WT087480) (Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel(R) Identity Protection Technology 1.0.71.0 (HKLM-x32\...\{2C43790E-8470-1027-82D3-DF319F3C410F}) (Version: 1.0.71.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
Jewel Quest II (HKLM-x32\...\WT087485) (Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (HKLM-x32\...\WT087490) (Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (quitar) (HKLM-x32\...\Jewel Quest Solitaire) (Version:  - )
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.72.4 - JMicron Technology Corp.)
John Deere Drive Green (HKLM-x32\...\WT087380) (Version: 2.2.0.95 - WildTangent) Hidden
Juegos WildTangent (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LightScribe System Software  1.14.17.1 (HKLM-x32\...\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - ESN (HKLM-x32\...\{6D972506-DC01-39BC-A5DD-06DA86E00031}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - ESN (HKLM-x32\...\{4A28444E-0532-3264-B07D-5AFE590E30BE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
MotoHelper MergeModules (HKLM-x32\...\{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}) (Version: 1.0.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 4.7.1 (HKLM\...\{82ED9FB2-55AF-4A61-A6F3-506CEE112779}) (Version: 4.7.1 - Motorola Inc.) Hidden
Mozilla Firefox 76.0.1 (x64 es-AR) (HKLM\...\Mozilla Firefox 76.0.1 (x64 es-AR)) (Version: 76.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 63.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation)
Penguins! (HKLM-x32\...\WT087394) (Version: 2.2.0.95 - WildTangent) Hidden
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Plants vs. Zombies (HKLM-x32\...\WT087501) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\...\WT087396) (Version: 2.2.0.95 - WildTangent) Hidden
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
Readon TV Movie Radio Player 7.5.0.0 (HKLM-x32\...\{03840E8D-A75E-4C49-ADFC-09A867C7F943}) (Version: 7.5.0 - Readon Technology)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.58.411.2012 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.00.11.0323 - REALTEK Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.50 - Piriform)
Remo ONE 1.0.0 (HKLM\...\{8DB422C2-D359-49B1-A685-B71DA7358D5C}_is1) (Version: 1.0.0.4 - Remo Software)
Remo Recover 5.0 (HKLM\...\{A573D759-F894-448D-A420-3A9C31879F88}_is1) (Version: 5.0.0.34 - Remo Software)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Revisión para Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{6D972506-DC01-39BC-A5DD-06DA86E00031}.KB947789) (Version: 1 - Microsoft Corporation)
Revo Uninstaller 2.1.1 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.1.1 - VS Revo Group, Ltd.)
SDK (HKLM-x32\...\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}) (Version: 2.26.012 - Portrait Displays, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Web Plugin (HKLM-x32\...\{0F7D4832-16AE-4857-A6FA-2B141D75A59B}) (Version: 7.7.0.219 - Skype Technologies S.A.)
Skype Web Plugin (HKLM-x32\...\{15AF46DB-9EBA-4662-AA52-29EF23585035}) (Version: 3.2.0.23388 - Skype Technologies S.A.)
Slingo Deluxe (HKLM-x32\...\WT087510) (Version: 2.2.0.95 - WildTangent) Hidden
Spotify (HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1052 - SUPERAntiSpyware.com)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.18.17 - Synaptics Incorporated)
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - gamigo, Inc.) Hidden
Validity Fingerprint Sensor Driver (HKLM\...\{FFC3E41D-2C2B-45B7-9AD9-5EA19572DD26}) (Version: 4.3.117.0 - Validity Sensors, Inc.)
VIP Access SDK x64(1.0.0.50)  (HKLM-x32\...\VIP Access SDK) (Version: 1.0.0.50 - Symantec Inc.)
Virtual Villagers - The Secret City (HKLM-x32\...\WT087513) (Version: 2.2.0.95 - WildTangent) Hidden
Wedding Dash (HKLM-x32\...\WT087519) (Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames) (Version: 4.1.1.49 - WildTangent) Hidden
WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.5 - WildTangent) Hidden
WildTangent Helper (HKLM-x32\...\{A39303AB-4898-4F12-BAA0-0B8630F86DB4}) (Version: 1.0.0.409 - WildTangent) Hidden
WildTangent ShortcutProvider (HKLM-x32\...\{80831F60-19D7-43B3-A60C-5CAF8C478DF6}) (Version: 5.0.0.219 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinZip 14.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. )
Xobni (HKLM-x32\...\XobniMain) (Version: 1.9.5.13282 - Xobni Corp.)
Youda Jewel Shop (HKLM-x32\...\WTA-8d8094a7-cd05-4069-8bf0-6429dc99eca0) (Version: 3.0.2.32 - WildTangent) Hidden
Zoom (HKU\S-1-5-21-348586771-676038775-713973424-1003\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)
Zuma Deluxe (HKLM-x32\...\WT087533) (Version: 2.2.0.95 - WildTangent) Hidden

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} =>  -> Ningún archivo
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2011-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [Archivo no firmado]

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2011-06-11 12:44 - 2011-06-11 12:44 - 000007168 _____ ( ( ) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\SDKCOMServerLib.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 000058880 _____ ( () [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2011-05-04 21:56 - 2011-06-11 12:42 - 001083392 _____ ( () [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\System.Data.SQLite.dll
2012-09-05 15:31 - 2012-09-05 15:31 - 000349696 _____ ( (Hewlett-Packard Development Company, L.P.) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HP.Mobile.Resource.dll
2011-06-11 12:42 - 2011-06-11 12:42 - 000869888 _____ ( (HP) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\HP.SupportFramework.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000006656 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IAStorDataMgr.resources.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000032768 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IAStorIcon.resources.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000004608 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IntelVisualDesign.resources.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 000165376 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUIHelper.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 001109504 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll
2012-03-23 20:05 - 2012-03-23 20:05 - 000225280 _____ ( (Microsoft Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
2011-04-27 17:05 - 2011-04-27 17:05 - 000514570 _____ () [Archivo no firmado] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2012-03-31 16:50 - 2008-06-20 00:41 - 000062464 _____ () [Archivo no firmado] C:\Program Files (x86)\WinRAR\rarext64.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000169472 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\61a733954a0da9a5988d596c76b2b891\IsdiInterop.ni.dll
2011-11-11 07:41 - 2011-01-17 16:19 - 001892352 _____ (Apache Software Foundation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\xerces-c_2_7.dll
2008-06-09 10:21 - 2008-06-09 10:21 - 000033280 _____ (Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSLog.dll
2008-06-09 10:21 - 2008-06-09 10:21 - 000110592 _____ (Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSSProxy.dll
2014-09-10 21:53 - 2014-09-10 21:53 - 000014336 _____ (Intel Corp.) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e8d9058b7f59f6d3d134b086916d8674\IAStorCommon.ni.dll
2011-11-11 07:41 - 2011-01-17 16:14 - 000069632 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\StatusStrings.dll
2011-11-11 07:41 - 2011-01-12 22:52 - 000275456 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000219136 _____ (Intel Corporation) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\79bc2712f1597303b790bfa64b222d41\IAStorDataMgr.ni.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000475648 _____ (Intel Corporation) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\7cfe3c97366e009a0a7bce795ec66f43\IAStorUtil.ni.dll

==================== Alternate Data Streams (Lista blanca) ========

(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)

AlternateDataStreams: C:\ProgramData\TEMP:E6540C35 [126]

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2009-07-13 23:34 - 2019-01-13 17:13 - 000000825 _____ C:\windows\system32\drivers\etc\hosts

2012-04-06 23:30 - 2014-10-16 20:16 - 000000375 _____ C:\windows\system32\drivers\etc\hosts.ics

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %C_EM64T_REDIST11%bin\Intel64;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Intel\Services\IPT\;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-348586771-676038775-713973424-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Gabriela\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 186.130.128.250 - 186.130.129.250
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [{B2D3BA98-68F5-47A5-868D-C1E6F278A051}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{900D6A16-8D89-4CC6-95A5-AE312874D0A4}] => (Allow) LPort=2869
FirewallRules: [{7F0B70FA-796D-49F0-9611-E03D9D0449CC}] => (Allow) LPort=1900
FirewallRules: [{8C22AA11-D491-42B5-A7D5-2F75D4585E75}] => (Allow) LPort=1542
FirewallRules: [{492E4ADD-6891-4ACB-9E31-C43B4D06618B}] => (Allow) LPort=1542
FirewallRules: [{C24C5143-AA92-4081-9A6B-C370E2B1A4D8}] => (Allow) LPort=53
FirewallRules: [{5EBE1633-728D-49E9-AC98-293E554C99B8}] => (Allow) C:\Windows\SysWOW64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{27631350-9188-475D-BA2E-F7B272E9CF5E}] => (Allow) C:\Windows\SysWOW64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{0D0B5E34-B82D-4554-ADE0-1D96C59188E2}C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe] => (Block) C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe (Readon Technology) [Archivo no firmado]
FirewallRules: [UDP Query User{DF3B8EB6-0EC4-434D-8330-65271DF0217B}C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe] => (Block) C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe (Readon Technology) [Archivo no firmado]
FirewallRules: [TCP Query User{C1EA3879-6043-4CD9-B511-5FBECCFF755F}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe => Ningún archivo
FirewallRules: [UDP Query User{59D08101-D3ED-46D1-AE4A-73BF883812C7}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe => Ningún archivo
FirewallRules: [{B510B2DE-7AA5-4E6D-B056-6FDEC7452D6B}] => (Allow) C:\Program Files (x86)\SkypeWebPlugin\3.2.0.23388\SkypeWebPlugin.exe (Skype Software Sarl -> Skype)
FirewallRules: [TCP Query User{C40D2717-8307-4B1C-BB22-C227B98373B8}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{89622048-5901-4B02-873A-0596F96A6FD8}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{923CDD66-7ACE-4BBF-9183-8C6C0F7BF6FF}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{12CE1836-81D6-49AA-8AEC-7B90AF9808AA}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{812D9CD9-DD2A-40F6-96D1-E7AD52D78DCD}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Ltd)
FirewallRules: [{0DAE30C5-0D56-496C-8D30-8E5F87BB9999}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Ltd)
FirewallRules: [{EC2C566A-1C37-468E-8F1D-C011157FB46F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7E598F04-D8CA-45D5-B2CE-C53F5D1FB5AC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{BAC6D019-86C4-4C3F-9996-BBCB7B1C1EEA}] => (Allow) C:\Users\Gabriela\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{B0D51C2F-4611-4E13-8F11-9E1BA2D3F32C}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{607BE7CE-FAC8-4192-963C-8157138F930E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Puntos de Restauración =========================

12-05-2020 17:19:52 JRT Pre-Junkware Removal
12-05-2020 20:39:44 Revo Uninstaller's restore point - Java 7 Update 25
12-05-2020 20:40:42 Removed Java 7 Update 25
12-05-2020 21:49:00 Revo Uninstaller's restore point - JavaFX 2.1.1
12-05-2020 21:57:50 Quitado JavaFX 2.1.1
12-05-2020 22:00:30 Revo Uninstaller's restore point - iWin Games (remove only)
12-05-2020 22:02:03 Revo Uninstaller's restore point - iWin Games (remove only)
12-05-2020 22:04:02 Revo Uninstaller's restore point - VLC media player

==================== Dispositivos defectuosos en el Administrador de dispositivos ============

Name: Adaptador de tunelización Teredo de Microsoft
Description: Adaptador de tunelización Teredo de Microsoft
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: ElbyCDIO Driver
Description: ElbyCDIO Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: ElbyCDIO
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (05/12/2020 10:04:02 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

Details:
AddWin32ServiceFiles: Unable to back up image of service iWinTrusted since QueryServiceConfig API failed

System Error:
El sistema no puede encontrar el archivo especificado.
.

Error: (05/12/2020 08:39:37 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al consultar la interfaz IVssWriterCallback. HR = 0x80070005, Acceso denegado.
.
A menudo ocurre por una configuración de seguridad incorrecta en el proceso de escritura o de solicitud.


Operación:
   Recopilando datos del escritor

Contexto:
   Id. de clase del escritor: {e8132975-6f93-4464-a53e-1050253ae220}
   Nombre del escritor: System Writer
   Id. de instancia del escritor: {e17392e5-74f1-41c0-b128-2937484fdea8}

Error: (05/12/2020 05:53:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa chrome.exe, versión 81.0.4044.138, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: 1364

Hora de inicio: 01d6289ec55676e3

Hora de finalización: 60000

Ruta de acceso de la aplicación: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Identificador de informe: 7e1a08bc-9492-11ea-9584-101f74fe1e45

Error: (05/12/2020 05:50:42 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa FRST64.exe, versión 11.5.2020.0, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: 1cf8

Hora de inicio: 01d6289d1c21d360

Hora de finalización: 493

Ruta de acceso de la aplicación: C:\Users\Gabriela\Desktop\FRST64.exe

Identificador de informe:

Error: (05/12/2020 02:55:48 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows no puede tener acceso al archivo  por alguna de las siguientes razones:
Hay un problema con la conexión de red, con el disco donde se almacena este archivo o con los controladores
de almacenamiento instalados en este equipo; o bien no se encuentra el disco.
Windows cerró el programa WildTangentHelperService.exe por este error.

Programa: WildTangentHelperService.exe
Archivo: 

El valor del error se muestra en la sección Datos adicionales.
Acción del usuario
1. Abra el archivo de nuevo.
Podría ser sólo un problema temporal que se corrige al ejecutar el programa de nuevo.
2.
Si todavía no se puede tener acceso al archivo y 
	- Está en la red,
el administrador de red debe comprobar que no exista ningún problema con la red y que es posible ponerse en contacto con el servidor.
	- Está en un disco extraíble, como un disquete o un CD-ROM, compruebe que el disco esté insertado en el equipo.
3. Compruebe y repare el sistema de archivos ejecutando CHKDSK. Para ejecutar CHKDSK, haga clic en Inicio y después en Ejecutar; escriba CMD y después haga clic en Aceptar. En el símbolo del sistema, escriba CHKDSK /F y después presione Entrar.
4. Si el problema continúa, restaure el archivo a partir de una copia de seguridad.
5. Compruebe si se pueden abrir otros archivos en el mismo disco. Si no se pueden abrir, el disco podría estar dañado. Si se trata de un disco duro, póngase en contacto con el administrador o con el fabricante del hardware del equipo
para obtener ayuda adicional.

Datos adicionales
Valor del error:00000000
Tipo de disco: 0

Error: (05/12/2020 02:55:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: WildTangentHelperService.exe, versión: 1.0.0.409, marca de tiempo: 0x5e8638b2
Nombre del módulo con errores: WildTangentHelperService.exe, versión: 1.0.0.409, marca de tiempo: 0x5e8638b2
Código de excepción: 0xc0000096
Desplazamiento de errores: 0x000dc90c
Id. del proceso con errores: 0x22ec
Hora de inicio de la aplicación con errores: 0x01d6288687cf8a89
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Ruta de acceso del módulo con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Id. del informe: cf385628-9479-11ea-92a5-101f74fe1e45


Errores del sistema:
=============
Error: (05/12/2020 10:01:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio iWinTrusted se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (05/12/2020 08:30:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
ElbyCDIO

Error: (05/12/2020 05:13:34 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
ElbyCDIO

Error: (05/12/2020 05:11:33 PM) (Source: volsnap) (EventID: 25) (User: )
Description: Se eliminaron las instantáneas del volumen C: porque el almacenamiento de instantáneas no se completó a tiempo. Considere reducir la carga de E/S en el sistema o elija un volumen de almacenamiento de instantáneas del que no se esté haciendo una instantánea.

Error: (05/12/2020 05:03:56 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Error en la inicialización del archivo de volcado

Error: (05/12/2020 05:03:56 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Error en la inicialización del archivo de volcado

Error: (05/12/2020 02:55:27 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio HP Software Framework Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (05/12/2020 02:55:27 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio WildTangentHelper terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 5000 milisegundos: Ejecutar el programa de recuperación configurado.


CodeIntegrity:
===================================

Date: 2020-05-12 22:11:33.238
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:11:32.558
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:11:32.178
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:11:31.798
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:11:31.418
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:07:59.066
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:07:14.224
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:07:02.980
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

==================== Información de la memoria =========================== 

BIOS: Hewlett-Packard 68SRR Ver. F.40 03/12/2013
Placa base: Hewlett-Packard 167C
Procesador: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Porcentaje de memoria en uso: 89%
RAM física total: 4030.37 MB
RAM física disponible: 425.61 MB
Virtual total: 8058.92 MB
Virtual disponible: 3375.68 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:443.56 GB) (Free:269.22 GB) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive e: (HP_RECOVERY) (Fixed) (Total:16.9 GB) (Free:2.54 GB) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive f: (HP_TOOLS) (Fixed) (Total:4.98 GB) (Free:2.12 GB) FAT32

\\?\Volume{85a6513a-0c50-11e1-ba96-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.25 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 4166D6A8)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=443.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=16.9 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=5 GB) - (Type=0C)

==================== Final de Addition.txt =======================

Hola @ivan_chalan

Solo entro para hacerte un comentario y que no pierdas tiempo.

El informe que has puesto de FRST.txt esta incompleto nuevamente.

Elimina ambos informes (FRST.txt y Addition.txt) y vuelve a ejecutar la Herramienta como si fuera la primera vez.

Si aun así sale vacío, directamente elimina FRST y los reportes y vuelves a descargar y ejecutarla con los pasos que te ha dejado el compañero @JavierHF

Sigan ustedes. :+1:

Salu2

Ahora creo que si

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 13-05-2020 01
Ejecutado por Gabriela (administrador) sobre HP (Hewlett-Packard HP ProBook 4530s) (13-05-2020 12:39:35)
Ejecutado desde C:\Users\Gabriela\Desktop
Perfiles cargados: Gabriela
Platform: Windows 7 Home Premium Service Pack 1 (X64) Idioma: Español (España, internacional)
Internet Explorer Versión 8 (Navegador predeterminado: "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" -- "%1")
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Procesos (Lista blanca) =================

(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)

(ArcSoft, Inc. -> ArcSoft, Inc.) C:\windows\SysWOW64\ArcVCapRender\uArcCapture.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe <2>
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\SoftwareUpdate.exe
(Glarysoft LTD -> Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\x64\Win64ShellLink.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company -> Hewlett-Packard Company) C:\windows\System32\hpservice.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPConnectionManager.exe
(Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(IDT, Inc.) [Archivo no firmado] C:\Program Files\IDT\WDM\stacsv64.exe
(IDT, Inc.) [Archivo no firmado] C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation -> Intel Corporation) C:\windows\System32\hkcmd.exe
(Intel Corporation -> Intel Corporation) C:\windows\System32\igfxext.exe
(Intel Corporation -> Intel Corporation) C:\windows\System32\igfxpers.exe
(Intel Corporation -> Intel Corporation) C:\windows\System32\igfxsrvc.exe
(Intel Corporation -> Intel Corporation) C:\windows\System32\igfxtray.exe
(Intel® Identity Protection Technology Software -> Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation -> Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Windows Hardware Compatibility Publisher -> Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <8>
(Portrait Displays, Inc. -> Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Portrait Displays, Inc. -> Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe
(Portrait Displays, Inc. -> Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Sunplus Innovation Technology Inc. -> ) [Archivo no firmado] C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Support.com Inc -> SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Validity Sensors, Inc -> Validity Sensors, Inc.) C:\windows\System32\vcsFPService.exe

==================== Registro (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Run: [HPPowerAssistant] => C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2996792 2011-07-15] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-25] (IDT, Inc.) [Archivo no firmado]
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2812656 2014-12-13] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [108216 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation -> Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] => C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] (Sunplus Innovation Technology Inc. -> ) [Archivo no firmado]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Archivo no firmado]
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] => C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restricción <==== ATENCIÓN
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [43984 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [9230256 2020-03-13] (Support.com Inc -> SUPERAntiSpyware)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.138\Installer\chrmstp.exe [2020-05-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{10880D85-AAD9-4558-ABDC-2AB1552D831F}] -> C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe [2008-06-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.4053.113\Installer\chrmstp.exe [2020-05-11] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-02] (Adobe Inc. -> Adobe Systems, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BootExecute: autocheck autochk *  PCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicyScripts-x32: Restricción <==== ATENCIÓN
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN
CHR HKLM\SOFTWARE\Policies\Google: Restricción <==== ATENCIÓN

==================== Tareas programadas (Lista blanca) ============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

Task: {05131EA6-3E2C-4FB6-A003-FC618F0AEFBA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-17] (Google Inc -> Google Inc.)
Task: {1153BFC2-EB9C-4C0F-B39E-416B85F095CD} - \{EFCB239E-A67B-4177-A64A-37DC58BAA823} -> Ningún archivo <==== ATENCIÓN
Task: {1364944A-DD99-483E-BA78-3C953CA28671} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software)
Task: {14516119-976B-40EA-BF19-147D00CD311F} - System32\Tasks\{DE8EA0AD-5C89-460F-A0BA-443AC883D8ED} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
Task: {15495120-92CF-4EA7-BBDF-29E22147A31E} - \{5EEB130B-C5E3-4E95-A8FE-ACE8DC7FFC51} -> Ningún archivo <==== ATENCIÓN
Task: {1AEF3106-B5B6-430E-83FF-50600CF0E635} - System32\Tasks\{D2FFBAA0-1161-4E5A-9A3B-7BED65E38539} => C:\Users\Erika\Desktop\Phv.exe
Task: {22947606-F103-4048-B1AB-559C32596739} - \{01B7CE4A-28BE-4081-94C5-D22132FCBF68} -> Ningún archivo <==== ATENCIÓN
Task: {2C42CF88-855D-47AC-9D8F-ACE1DEE9CCE1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {2E14DF65-CE6A-49B5-8772-8BADCAA07970} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-19] (Avast Software s.r.o. -> AVAST Software)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Ningún archivo <==== ATENCIÓN
Task: {36CE16B0-9EE7-4ADA-B523-5DA4656E076C} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [898000 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
Task: {3F21FF21-DD74-420A-9EB5-3BE2BAB91779} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [620424 2016-05-04] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {41109735-418E-4769-86F4-092523F83F0C} - System32\Tasks\Apagar PC => C:\Windows\System32\shutdown.exe [34304 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
Task: {4955A070-9A27-4951-B7AA-FE4E21791967} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {496B5CDC-C0E9-410A-B422-DDEA9D07C50C} - System32\Tasks\{816CB30A-676A-42E3-AD73-A371E0C479DE} => C:\windows\system32\pcalua.exe -a "C:\Users\Erika\Downloads\QuickTimeInstaller (1).exe" -d C:\Users\Erika\Downloads
Task: {4A4588E1-DA3C-40C6-9C9B-91A05637DC50} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\windows\ehome\ehrec.exe
Task: {5042C336-B165-41E5-BA30-2E6AB14A0F80} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\windows\ehome\mcupdate.exe
Task: {508CF8AB-A1DA-4B23-88D5-D4DE9480FBB4} - \MotoHelper MUM -> Ningún archivo <==== ATENCIÓN
Task: {50D96CE0-EFCD-406D-8AED-58B528C10888} - \MotoHelper Routing -> Ningún archivo <==== ATENCIÓN
Task: {5F0FEFF4-E156-4261-8D27-129FAB4E4054} - \{579A7337-5077-497D-BE7F-51D406B1326E} -> Ningún archivo <==== ATENCIÓN
Task: {65D3CF7E-02ED-4AE9-90AB-E41A9EC33874} - System32\Tasks\{40018D1E-61FC-4184-AEE0-79A92C6D3528} => C:\Users\Erika\Desktop\Phv.exe
Task: {69AC48F8-A74A-4CBE-BABA-36987C96D4E9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {6BE401B1-5B06-40AB-8F58-57D0FDADC7B8} - System32\Tasks\{8BC8674A-AFC5-4E11-8A32-2AE525F92652} => C:\Users\Erika\Desktop\Phv.exe
Task: {79A7CD2B-14FD-42D2-862D-8E04C5B848D5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-11-17] (Google Inc -> Google Inc.)
Task: {7FAD2AB7-D6E5-49BB-B1F1-11E311260E73} - System32\Tasks\{E6B7690B-3A0B-4F22-A859-BC07AEE9D346} => C:\Users\Erika\Desktop\Phv.exe
Task: {8239A271-7D2F-4D21-A8B5-27661566DDCA} - \SidebarExecute -> Ningún archivo <==== ATENCIÓN
Task: {86C97F62-D99F-4BCC-ACB5-802253042AE0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [336008 2018-11-16] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {8BD395AF-078E-40E1-87B7-8525D9CC083A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {8FB7217C-2602-435D-BDA6-CF0385026C13} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Ningún archivo <==== ATENCIÓN
Task: {95117969-6249-4D2D-966A-14C83C358FD7} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {9BE73A96-2B23-458D-B4CD-A8BB25327FAB} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {9D3E0D8E-F051-4C83-AEC9-EC8646EFE628} - System32\Tasks\SUPERAntiSpyware Scheduled Task 5bcb8957-24ae-47ce-a33a-7c198725a7e6 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2013-11-07] (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {A15551B0-D78A-4A81-BAFA-E93CF76401F0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {A516EBB0-85B2-4A7E-A21A-FE8E9387545A} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3325032 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
Task: {AB5B4B4E-5B68-4BAF-9837-8BC1A6416D07} - System32\Tasks\{516049F0-CC02-452B-A6A2-FF39927BF664} => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Ningún archivo <==== ATENCIÓN
Task: {AE8BD54B-AD93-4B74-9945-06DBD3422D79} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core1d1e917899d532 => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {B170F6EE-B1FD-40BB-8636-21E0D248EDD0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA1d1e9178d09d70 => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {BA9F2783-3C1B-41DD-B647-72EF113E5D8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [107072 2016-05-09] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {BD7C0212-2E0D-4B5B-962E-8A5E036F3D82} - \IHUninstallTrackingTASK -> Ningún archivo <==== ATENCIÓN
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Ningún archivo <==== ATENCIÓN
Task: {D62C7F31-EECE-40FB-AACE-FD37116802B9} - \RunAsStdUser Task -> Ningún archivo <==== ATENCIÓN
Task: {D7961A06-DAD4-4B3E-9A60-9B82D133F5FC} - System32\Tasks\{54167D85-7CB6-443D-805E-7BFF8B1E844F} => C:\windows\system32\pcalua.exe -a C:\Users\Erika\Downloads\QuickTimeInstaller.exe -d C:\Users\Erika\Downloads
Task: {DA9B29E2-5EFB-4B5D-8357-A0F524101F0D} - System32\Tasks\SUPERAntiSpyware Scheduled Task c1f5af4c-b7ba-4b21-8e92-897cf9e971a1 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [49944 2013-11-07] (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {DC2DE33C-D5FE-4155-B6BC-37A550ED01DB} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {DE2C859E-279C-4115-A7C0-F25FA89CF22B} - \User_Feed_Synchronization-{BAC3944D-7C78-4B3D-9863-20FC40B19BC9} -> Ningún archivo <==== ATENCIÓN
Task: {DE65BF18-4593-47FF-A599-81C9595A90F7} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Ningún archivo <==== ATENCIÓN
Task: {E0D595D9-991E-4A13-A049-825DA3397F6C} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [134608 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
Task: {E129F494-CD81-4737-8D49-953CAAB06211} - System32\Tasks\{AC72203C-7D2B-47BC-88C2-279BD4ED6374} => C:\Users\Erika\Desktop\Phv.exe
Task: {E6ACB3BC-009D-4AED-90CB-603B33FC3874} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1853360 2020-04-19] (Avast Software s.r.o. -> AVAST Software)
Task: {F3E3AF7D-9D0F-44B7-8914-2BCD46EBEAAC} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {F437A0E7-173B-4764-9D82-CA5FD8EE54E1} - \MotoHelper Update -> Ningún archivo <==== ATENCIÓN
Task: {F5A0E31B-BE07-4D62-8F1D-46208052847A} - System32\Tasks\avastBCLRestartS-1-5-21-348586771-676038775-713973424-1001 => C:\Users\Erika\AppData\Local\Google\Chrome\Application\chrome.exe 
Task: {F67912CA-84DF-4653-8721-E6E996AB93F8} - \AutoKMS -> Ningún archivo <==== ATENCIÓN
Task: {F7796554-51ED-4FF6-8839-B3C6B734D650} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [548824 2018-11-06] (Piriform Software Ltd -> Piriform Ltd)
Task: {F79DF38C-99B1-4E09-B482-94CB331439A8} - System32\Tasks\{B34B8149-1109-4B73-B74C-8FA2AA19D911} => C:\Program Files (x86)\BlueStacks\HD-StartLauncher.exe
Task: {F96A136A-66F5-458D-9042-D0FE4025771C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [14554696 2018-11-06] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Ningún archivo <==== ATENCIÓN
Task: {FFE259F5-5C2F-4A2F-82DA-46012A960FE9} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [127176 2020-05-12] (Mozilla Corporation -> Mozilla Foundation)

(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)

Task: C:\windows\Tasks\AutoKMS.job => 
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => C:\Users\Erika\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 5bcb8957-24ae-47ce-a33a-7c198725a7e6.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task c1f5af4c-b7ba-4b21-8e92-897cf9e971a1.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

==================== Internet (Lista blanca) ====================

(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)

Winsock: Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 186.130.128.250 186.130.129.250
Tcpip\..\Interfaces\{73683B1B-4456-4748-B4DF-EDA1887E505C}: [DhcpNameServer] 200.49.130.41 200.42.4.204
Tcpip\..\Interfaces\{7DA4B6EA-6AB8-417C-813A-8EBF4643DB71}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{F91C9E14-971D-4A63-A326-F3E6500E84D3}: [DhcpNameServer] 186.130.128.250 186.130.129.250

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPALL/50
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPALL/50
HKU\S-1-5-21-348586771-676038775-713973424-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPALL/50
HKU\S-1-5-21-348586771-676038775-713973424-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPALL/50
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-348586771-676038775-713973424-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = 
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation -> Microsoft Corporation)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  Ningún archivo
Toolbar: HKLM - Sin Nombre - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  Ningún archivo
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2011-04-22] (Microsoft Windows -> Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 72j2pmrq.default-1542499827683
FF ProfilePath: C:\Users\Gabriela\AppData\Roaming\Mozilla\Firefox\Profiles\72j2pmrq.default-1542499827683 [2020-05-13]
FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Gabriela\AppData\Roaming\Mozilla\Firefox\Profiles\72j2pmrq.default-1542499827683\Extensions\[email protected] [2019-02-19]
FF Extension: (Avast Online Security) - C:\Users\Gabriela\AppData\Roaming\Mozilla\Firefox\Profiles\72j2pmrq.default-1542499827683\Extensions\[email protected] [2020-05-11] [UpdateUrl:hxxps://firefoxext.avcdn.net/firefoxext/avast/aos/update.json]
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\3.2.0.23388\npSkypeWebPlugin64.dll [2014-11-03] (Skype Software Sarl -> Skype)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1228198.dll [2017-02-27] (Adobe Systems, Inc.) [Archivo no firmado]
FF Plugin-x32: @canon.com/UCPlugin -> C:\Program Files (x86)\Canon\Uploader for CANON iMAGE GATEWAY Plugin\\npUploaderForCiG.dll [Ningún archivo]
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2013-07-08] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\3.2.0.23388\npSkypeWebPlugin.dll [2014-11-03] (Skype Software Sarl -> Skype)
FF Plugin-x32: @zylom.com/ZylomGamesPlayer -> C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll [2009-07-02] (Zylom) [Archivo no firmado]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-03-05] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-348586771-676038775-713973424-1003: @zoom.us/ZoomVideoPlugin -> C:\Users\Gabriela\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-04] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)

Chrome: 
=======
CHR Profile: C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default [2020-05-12]
CHR Notifications: Default -> hxxps://web.whatsapp.com; hxxps://www.bigbox.com.ar; hxxps://www.instagram.com; hxxps://www.latam.com
CHR Extension: (Presentaciones) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Documentos) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-28]
CHR Extension: (YouTube) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-28]
CHR Extension: (Adobe Acrobat) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2020-03-03]
CHR Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-03-19]
CHR Extension: (Hojas de cálculo) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-04-20]
CHR Extension: (AdBlock: el mejor bloqueador de anuncios) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-04-14]
CHR Extension: (Avast Online Security) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-02-28]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-22]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <no encontrado>

==================== Servicios (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-30] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft, Inc. -> ArcSoft Inc.)
R2 AESTFilters; C:\Program Files\IDT\WDM\AESTSr64.exe [89600 2013-05-25] (Microsoft Windows Hardware Compatibility Publisher -> Andrea Electronics Corporation)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5504928 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-19] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [345384 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-03-19] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.4053.113\elevation_service.exe [954600 2020-04-19] (Avast Software s.r.o. -> AVAST Software)
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company -> Hewlett-Packard Company)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-06-20] (Hewlett-Packard Company -> Hewlett-Packard Company)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company -> Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2008-06-09] (Hewlett-Packard Company) [Archivo no firmado]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-05-11] (Malwarebytes Inc -> Malwarebytes)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [323072 2013-05-25] (IDT, Inc.) [Archivo no firmado]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Archivo no firmado]
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc. -> ArcSoft, Inc.)
S3 WildTangentHelper; C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe [1642800 2020-04-02] (WildTangent Inc -> )
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2286976 2010-09-21] (Microsoft Corporation -> Microsoft Corp.)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation -> Xobni Corporation)

===================== Controladores (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

R3 Accelerometer; C:\windows\System32\DRIVERS\Accelerometer.sys [43840 2012-09-24] (Hewlett-Packard Company -> Hewlett-Packard Company)
S3 AgereSoftModem; C:\windows\System32\DRIVERS\agrsm64.sys [1146880 2009-06-10] (Microsoft Windows -> LSI Corp)
R3 ARCVCAM; C:\windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc. -> ArcSoft, Inc.)
R0 aswArDisk; C:\windows\System32\drivers\aswArDisk.sys [37856 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\windows\System32\drivers\aswArPot.sys [206120 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\windows\System32\drivers\aswbidsdriver.sys [234776 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\windows\System32\drivers\aswbidsh.sys [178968 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\windows\System32\drivers\aswbuniv.sys [60696 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\windows\System32\drivers\aswKbd.sys [42984 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\windows\System32\drivers\aswMonFlt.sys [175920 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\windows\System32\drivers\aswNetHub.sys [500960 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R3 aswNetNd6; C:\windows\System32\DRIVERS\aswNetNd6.sys [38152 2020-04-21] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\windows\System32\drivers\aswRdr2.sys [109480 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\windows\System32\drivers\aswRvrt.sys [85056 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\windows\System32\drivers\aswSnx.sys [851808 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\windows\System32\drivers\aswSP.sys [459408 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\windows\System32\drivers\aswStm.sys [235696 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\windows\System32\drivers\aswVmm.sys [317280 2020-04-21] (Avast Software s.r.o. -> AVAST Software)
S3 BTCFilterService; C:\windows\System32\DRIVERS\motfilt.sys [6144 2009-01-29] (Microsoft Windows Hardware Compatibility Publisher -> Motorola Inc)
R1 ElRawDisk; C:\windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation -> EldoS Corporation)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [153312 2020-05-11] (Malwarebytes Corporation -> Malwarebytes)
R1 GUBootStartup; C:\windows\System32\drivers\GUBootStartup.sys [20160 2017-04-18] (Glarysoft Ltd -> Glarysoft Ltd)
R0 hpdskflt; C:\windows\System32\DRIVERS\hpdskflt.sys [31040 2012-09-24] (Hewlett-Packard Company -> Hewlett-Packard Company)
R3 HpqKbFiltr; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [25912 2010-12-02] (Hewlett-Packard Company -> Hewlett-Packard Company)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [214496 2020-05-11] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [195432 2020-05-13] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\windows\system32\DRIVERS\mbam.sys [73368 2020-05-13] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [248968 2020-05-13] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [112752 2020-05-13] (Malwarebytes Inc -> Malwarebytes)
S3 motccgp; C:\windows\System32\DRIVERS\motccgp.sys [20992 2010-06-18] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 motccgpfl; C:\windows\System32\DRIVERS\motccgpfl.sys [9216 2009-01-29] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 motmodem; C:\windows\System32\DRIVERS\motmodem.sys [30208 2010-06-18] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 MotoSwitchService; C:\windows\System32\DRIVERS\motswch.sys [8576 2007-11-02] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 Motousbnet; C:\windows\System32\DRIVERS\Motousbnet.sys [26624 2010-04-01] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 motport; C:\windows\System32\DRIVERS\motport.sys [30208 2010-06-18] (Microsoft Windows Hardware Compatibility Publisher -> Motorola)
S3 motusbdevice; C:\windows\System32\DRIVERS\motusbdevice.sys [10240 2010-01-25] (Microsoft Windows Hardware Compatibility Publisher -> Motorola Inc)
S3 netr28ux; C:\windows\System32\DRIVERS\netr28ux.sys [867328 2009-06-10] (Microsoft Windows -> Ralink Technology Corp.)
R2 NPF; C:\windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 nusb3hub; C:\windows\System32\DRIVERS\nusb3hub.sys [80384 2010-12-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 nusb3xhc; C:\windows\System32\DRIVERS\nusb3xhc.sys [181248 2010-12-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R0 PxHlpa64; C:\windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation -> Corel Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SPUVCbv; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2612728 2011-02-12] (Sunplus Innovation Technology Inc. -> Sunplus Technology)
R3 STHDA; C:\windows\System32\DRIVERS\stwrt64.sys [543744 2013-05-25] (Microsoft Windows Hardware Compatibility Publisher -> IDT, Inc.)
S1 ElbyCDIO; System32\Drivers\ElbyCDIO.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]

==================== NetSvcs (Lista blanca) ===================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)


==================== Un mes (creado) ===================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-05-13 12:39 - 2020-05-13 12:43 - 000043101 _____ C:\Users\Gabriela\Desktop\FRST.txt
2020-05-13 12:38 - 2020-05-13 12:38 - 002286080 _____ (Farbar) C:\Users\Gabriela\Desktop\FRST64.exe
2020-05-13 12:34 - 2020-05-13 12:34 - 000073368 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2020-05-13 12:33 - 2020-05-13 12:33 - 000195432 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2020-05-13 12:33 - 2020-05-13 12:33 - 000112752 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2020-05-13 12:31 - 2020-05-13 12:31 - 000248968 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2020-05-12 20:35 - 2020-05-12 20:35 - 000000994 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2020-05-12 20:35 - 2020-05-12 20:35 - 000000994 _____ C:\ProgramData\Desktop\Revo Uninstaller.lnk
2020-05-12 20:35 - 2020-05-12 20:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2020-05-12 20:35 - 2020-05-12 20:35 - 000000000 ____D C:\Program Files\VS Revo Group
2020-05-12 20:33 - 2020-05-12 20:33 - 007432520 _____ (VS Revo Group ) C:\Users\Gabriela\Desktop\revosetup.exe
2020-05-12 18:07 - 2020-05-12 22:23 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-05-12 17:37 - 2020-05-13 12:41 - 000000000 ____D C:\FRST
2020-05-12 17:34 - 2020-05-12 17:34 - 000027902 _____ C:\Users\Gabriela\Desktop\JRT.txt
2020-05-12 14:52 - 2020-05-12 14:55 - 000000000 ____D C:\AdwCleaner
2020-05-12 14:51 - 2020-05-12 14:51 - 000001531 _____ C:\Users\Gabriela\Desktop\mb.txt
2020-05-12 14:33 - 2020-05-12 14:33 - 000175110 _____ C:\Users\Gabriela\Desktop\cc_20200512_143330.reg
2020-05-12 13:08 - 2020-05-12 13:09 - 008196784 _____ (Malwarebytes) C:\Users\Gabriela\Desktop\adwcleaner_8.0.4.exe
2020-05-12 13:07 - 2020-05-12 13:07 - 001790024 _____ (Malwarebytes) C:\Users\Gabriela\Desktop\JRT.exe
2020-05-11 01:26 - 2020-05-11 01:28 - 000214496 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2020-05-11 01:26 - 2020-05-11 01:26 - 000001920 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-05-11 00:33 - 2020-05-11 17:30 - 000000516 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 5bcb8957-24ae-47ce-a33a-7c198725a7e6.job
2020-05-11 00:33 - 2020-05-11 09:12 - 000000516 _____ C:\windows\Tasks\SUPERAntiSpyware Scheduled Task c1f5af4c-b7ba-4b21-8e92-897cf9e971a1.job
2020-05-11 00:33 - 2020-05-11 00:33 - 000003584 _____ C:\windows\system32\Tasks\SUPERAntiSpyware Scheduled Task c1f5af4c-b7ba-4b21-8e92-897cf9e971a1
2020-05-11 00:33 - 2020-05-11 00:33 - 000003510 _____ C:\windows\system32\Tasks\SUPERAntiSpyware Scheduled Task 5bcb8957-24ae-47ce-a33a-7c198725a7e6
2020-05-11 00:33 - 2020-05-11 00:33 - 000001768 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2020-05-11 00:33 - 2020-05-11 00:33 - 000001768 _____ C:\ProgramData\Desktop\SUPERAntiSpyware Free Edition.lnk
2020-05-11 00:33 - 2020-05-11 00:33 - 000000000 ____D C:\Users\Gabriela\AppData\Roaming\SUPERAntiSpyware.com
2020-05-11 00:33 - 2020-05-11 00:33 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2020-05-11 00:33 - 2020-05-11 00:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2020-05-11 00:33 - 2020-05-11 00:33 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2020-05-11 00:32 - 2020-05-11 00:32 - 045377080 _____ (SUPERAntiSpyware) C:\Users\Gabriela\Desktop\SUPERAntiSpyware.exe
2020-05-11 00:14 - 2020-04-21 13:00 - 000337048 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2020-05-04 19:51 - 2020-05-04 19:51 - 000002412 _____ C:\Users\Gabriela\Desktop\Avast Secure Browser.lnk
2020-05-04 17:51 - 2020-05-04 17:51 - 000000000 ____D C:\Users\Gabriela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom
2020-05-04 17:49 - 2020-05-04 17:51 - 000000000 ____D C:\Users\Gabriela\AppData\Roaming\Zoom
2020-04-22 17:42 - 2020-04-22 17:42 - 001393081 _____ C:\Users\Gabriela\Desktop\La broma - Milan Kundera.pdf
2020-04-22 10:42 - 2020-04-22 10:42 - 000015773 _____ C:\Users\Gabriela\Desktop\permiso de circulacion.pdf
2020-04-21 13:00 - 2020-04-21 13:01 - 000500960 _____ (AVAST Software) C:\windows\system32\Drivers\aswNetHub.sys
2020-04-21 13:00 - 2020-04-21 13:00 - 000235696 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2020-04-21 13:00 - 2020-04-21 13:00 - 000175920 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2020-04-21 13:00 - 2020-04-21 13:00 - 000038152 _____ (AVAST Software) C:\windows\system32\Drivers\aswNetNd6.sys
2020-04-16 13:13 - 2020-04-16 13:13 - 000127438 _____ C:\Users\Gabriela\6056_-_ddjj_para_resp_de_adultos_mayores (1).pdf
2020-04-16 11:53 - 2020-04-16 11:53 - 000122524 _____ C:\Users\Gabriela\Documents\6056_-_ddjj_para_resp_de_adultos_mayores.pdf
2020-04-16 11:49 - 2020-04-16 11:50 - 000127438 _____ C:\Users\Gabriela\6056_-_ddjj_para_resp_de_adultos_mayores.pdf
2020-04-13 09:40 - 2020-04-13 09:40 - 000000000 ____D C:\windows\system32\Tasks\Mozilla

==================== Un mes (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-05-13 12:42 - 2009-07-14 01:45 - 000019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-05-13 12:42 - 2009-07-14 01:45 - 000019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-05-13 12:36 - 2017-04-18 14:46 - 000000000 ____D C:\Program Files (x86)\Glary Utilities 5
2020-05-13 12:35 - 2017-06-11 14:42 - 000000000 ____D C:\Users\Gabriela\AppData\LocalLow\Mozilla
2020-05-13 12:33 - 2017-05-10 10:28 - 000004168 _____ C:\windows\system32\Tasks\Avast Emergency Update
2020-05-13 12:29 - 2013-09-02 11:14 - 000000006 ____H C:\windows\Tasks\SA.DAT
2020-05-12 23:20 - 2015-03-22 15:20 - 000002780 _____ C:\windows\system32\Tasks\CCleanerSkipUAC
2020-05-12 23:19 - 2019-04-11 17:20 - 000003734 _____ C:\windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-05-12 23:19 - 2019-04-11 17:20 - 000003152 _____ C:\windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2020-05-12 23:19 - 2018-11-17 09:28 - 000002980 _____ C:\windows\system32\Tasks\{DE8EA0AD-5C89-460F-A0BA-443AC883D8ED}
2020-05-12 23:19 - 2018-11-17 09:28 - 000002980 _____ C:\windows\system32\Tasks\{516049F0-CC02-452B-A6A2-FF39927BF664}
2020-05-12 23:19 - 2016-07-28 18:28 - 000003642 _____ C:\windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA1d1e9178d09d70
2020-05-12 23:19 - 2016-07-28 18:28 - 000003370 _____ C:\windows\system32\Tasks\GoogleUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core1d1e917899d532
2020-05-12 23:19 - 2014-12-27 22:48 - 000004478 _____ C:\windows\system32\Tasks\Adobe Acrobat Update Task
2020-05-12 22:23 - 2018-11-17 21:10 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-05-12 21:53 - 2016-07-09 13:44 - 000000000 ____D C:\Users\DefaultAppPool
2020-05-12 21:53 - 2013-01-24 18:33 - 000000000 ____D C:\Users\Public\Documents\iwin
2020-05-12 21:53 - 2013-01-24 18:33 - 000000000 ____D C:\ProgramData\Documents\iwin
2020-05-12 21:53 - 2012-08-24 12:17 - 000000000 ____D C:\Program Files (x86)\WildGames
2020-05-12 21:53 - 2012-03-26 00:16 - 000000000 ____D C:\Program Files (x86)\WildTangent Games
2020-05-12 21:53 - 2011-05-04 21:20 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2020-05-12 21:53 - 2009-07-14 00:20 - 000000000 ____D C:\windows\registration
2020-05-12 17:16 - 2011-05-04 21:20 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2020-05-12 17:15 - 2009-07-14 00:20 - 000000000 ____D C:\windows\inf
2020-05-12 17:11 - 2016-12-27 18:44 - 000000000 ____D C:\Users\Gabriela
2020-05-12 13:15 - 2019-07-08 21:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remo Recover
2020-05-12 13:15 - 2016-12-27 18:45 - 000000000 ____D C:\Users\Gabriela\AppData\Local\CrashDumps
2020-05-11 19:23 - 2017-08-04 21:21 - 000000000 ____D C:\Users\Gabriela\AppData\Roaming\Spotify
2020-05-11 17:51 - 2017-08-04 21:24 - 000000000 ____D C:\Users\Gabriela\AppData\Local\Spotify
2020-05-11 13:12 - 2018-03-19 09:36 - 000000000 ____D C:\Users\Gabriela\AppData\Local\AVAST Software
2020-05-11 10:51 - 2018-11-17 21:13 - 000002182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-05-11 10:51 - 2018-11-17 21:13 - 000002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-05-11 10:51 - 2018-11-17 21:13 - 000002141 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-05-11 10:46 - 2018-03-19 09:39 - 000002387 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-05-11 09:13 - 2017-10-29 12:52 - 000001963 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2020-05-11 09:13 - 2017-10-29 12:52 - 000001963 _____ C:\ProgramData\Desktop\Avast Free Antivirus.lnk
2020-05-11 01:26 - 2018-11-16 16:52 - 000001908 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2020-05-11 01:26 - 2018-11-16 16:52 - 000001908 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
2020-05-11 01:25 - 2018-11-16 16:52 - 000153312 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2020-05-11 00:10 - 2019-07-08 21:42 - 000000000 ____D C:\Program Files\Remo ONE
2020-05-11 00:09 - 2009-07-14 02:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2020-05-11 00:08 - 2019-07-08 21:42 - 000000000 ____D C:\Program Files\Remo Recover 5.0
2020-05-11 00:08 - 2018-03-19 09:36 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2020-05-11 00:08 - 2012-05-25 11:47 - 000000000 ____D C:\ProgramData\AVAST Software
2020-05-11 00:07 - 2016-12-28 16:58 - 000000000 ____D C:\Users\Gabriela\AppData\Roaming\AVAST Software
2020-04-28 13:01 - 2018-11-17 21:12 - 000003472 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-04-28 13:01 - 2018-11-17 21:12 - 000003344 _____ C:\windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-04-28 13:01 - 2017-04-18 14:46 - 000003306 _____ C:\windows\system32\Tasks\GlaryInitialize 5
2020-04-28 13:01 - 2017-04-18 14:46 - 000002966 _____ C:\windows\system32\Tasks\GU5SkipUAC
2020-04-28 13:01 - 2015-12-03 09:52 - 000000000 ____D C:\windows\system32\Tasks\AVAST Software
2020-04-21 13:01 - 2012-05-25 11:48 - 000459408 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2020-04-21 13:00 - 2019-01-16 21:03 - 000234776 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsdriver.sys
2020-04-21 13:00 - 2019-01-16 11:18 - 000178968 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsh.sys
2020-04-21 13:00 - 2019-01-16 11:18 - 000060696 _____ (AVAST Software) C:\windows\system32\Drivers\aswbuniv.sys
2020-04-21 13:00 - 2019-01-16 11:18 - 000037856 _____ (AVAST Software) C:\windows\system32\Drivers\aswArDisk.sys
2020-04-21 13:00 - 2018-10-22 22:29 - 000042984 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2020-04-21 13:00 - 2017-11-20 19:50 - 000206120 _____ (AVAST Software) C:\windows\system32\Drivers\aswArPot.sys
2020-04-21 13:00 - 2014-03-06 10:03 - 000317280 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2020-04-21 13:00 - 2014-03-06 10:03 - 000085056 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2020-04-21 13:00 - 2012-05-25 11:48 - 000851808 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2020-04-21 13:00 - 2012-05-25 11:48 - 000109480 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys

==================== Archivos en la raíz de algunos directorios ========

2017-06-11 20:44 - 2017-06-11 20:44 - 000000000 _____ () C:\Users\Gabriela\AppData\Local\{3ED27979-CD66-4AA4-B2B1-98EA03D8E978}

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)


LastRegBack: 2020-05-08 08:18
==================== Final de FRST.txt ========================
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 13-05-2020 01
Ejecutado por Gabriela (13-05-2020 12:44:38)
Ejecutado desde C:\Users\Gabriela\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-03-22 21:41:17)
Modo de Inicio: Normal
==========================================================


==================== Cuentas: =============================

Administrador (S-1-5-21-348586771-676038775-713973424-500 - Administrator - Disabled)
Gabriela (S-1-5-21-348586771-676038775-713973424-1003 - Administrator - Enabled) => C:\Users\Gabriela
Invitado (S-1-5-21-348586771-676038775-713973424-501 - Limited - Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Avast Antivirus (Disabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)

Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 20.006.20042 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 26.0.0.118 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.8.198 - Adobe Systems, Inc.)
Applian FLV and Media Player 3.1.1.12 (HKLM-x32\...\Applian FLV and Media Player) (Version: 3.1.1.12 - Applian Technologies)
ArcSoft TotalMedia (HKLM-x32\...\{4114A073-7385-4742-8A5E-A5788FAC838F}) (Version: 1.0.48.25 - ArcSoft) Hidden
ArcSoft Webcam Sharing Manager (HKLM-x32\...\{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}) (Version: 2.0.0.30 - ArcSoft)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.2.2401 - Avast Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 81.0.4053.113 - Los creadores de Avast Secure Browser)
Avast Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.4.136.333 - AVAST Software) Hidden
Bejeweled 2 Deluxe (HKLM-x32\...\WT087428) (Version: 2.2.0.95 - WildTangent) Hidden
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
Blasterball 3 (HKLM-x32\...\WT089308) (Version: 2.2.0.95 - WildTangent) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.49 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Compresor WinRAR (HKLM-x32\...\WinRAR archiver) (Version:  - )
Corel Graphics - Windows Shell Extension 64 Bit (HKLM\...\{51DDB4F9-7FFF-4970-AED4-DB3C22A5C522}) (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Capture (x64) (HKLM\...\{1967EF95-E00B-4669-8B1C-A589BE8BF24F}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Common (x64) (HKLM\...\{35869A6C-BA31-4F23-B52D-BC1B1E41EC1B}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Connect (x64) (HKLM\...\{96AAAB95-AEBE-437A-B7CA-37C7BE13FFE9}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Custom Data (x64) (HKLM\...\{7386B5FA-8715-481D-821F-7785110506DF}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Draw (x64) (HKLM\...\{27AE72A4-B217-4CDC-B82B-3311E9D7460E}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - ES (x64) (HKLM\...\{839546C9-2E4E-4A42-B0D4-22E05E92E7AA}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Filters (x64) (HKLM\...\{E699230D-4B5E-411E-9F45-FF50789B18DD}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FontNav (x64) (HKLM\...\{3933C06C-8239-432B-87FC-F2BDC5B49A10}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (HKLM\...\{B6DF7031-2843-44FD-9CAB-DECAB4257456}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (HKLM\...\{D7C2687D-924E-4485-B367-C7D95CBF8DDD}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Photozoom Plugin (x64) (HKLM\...\{2C72B5E4-AA34-4F1A-8C7E-468530F9F6A3}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Redist (x64) (HKLM\...\{6099F026-0A98-4D40-9B3D-ED2123A8CBD0}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Setup Files (x64) (HKLM\...\{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VBA (x64) (HKLM\...\{10762393-1B90-4AC2-AF1A-4C0C04AE303F}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (HKLM\...\{7B79AE44-9B76-4815-84E5-ACAC3F0F0278}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VSTA (x64) (HKLM\...\{1E3A578C-0A7D-4820-990F-B7545C0B2303}) (Version: 16.1 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Writing Tools (x64) (HKLM\...\{DDE82E3D-20C4-48E1-AE1D-B1F10E42CA44}) (Version: 16.1 -  Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 (x64) (HKLM\...\{CCE7423E-1D84-4CD3-9E32-220EC9358D97}) (Version: 16.1 - Corel Corporation) Hidden
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (HKLM-x32\...\WT087536) (Version: 2.2.0.95 - WildTangent) Hidden
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
Evernote v. 4.6 (HKLM-x32\...\{A23AADDA-3DBF-11E2-A6F2-984BE15F174E}) (Version: 4.6.0.7670 - Evernote Corp.)
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Galería fotográfica de Windows Live (HKLM-x32\...\{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (HKLM-x32\...\{4736B0ED-F6A1-48EC-A1B7-C053027648F1}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (HKLM-x32\...\{488F0347-C4A7-4374-91A7-30818BEDA710}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Glary Utilities 5.73 (HKLM-x32\...\Glary Utilities 5) (Version: 5.73.0.94 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 81.0.4044.138 - Google LLC)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Hacer clic y ejecutar de Microsoft Office 2010 (HKLM\...\{90140000-006D-0C0A-1000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Hacer clic y ejecutar de Microsoft Office 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Hewlett-Packard ACLM.NET v1.2.2.3 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{E5D02167-DD50-4E8C-B9F9-992182E08D6B}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\...\{5DCA44EB-03F6-44A3-A294-F3E5DE98D7F6}) (Version: 4.4.10.1 - Hewlett-Packard Company)
HP DayStarter (HKLM\...\{483D5A49-A26B-4CB8-AA2D-0D1811322061}) (Version: 2.0.0.12 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\...\{6A9C9BE1-14A3-42ED-A388-42E30A1412E9}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.1.5 - WildTangent)
HP HD Webcam [Fixed] (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.3.4.09 - SunplusIT)
HP Hotkey Support (HKLM-x32\...\{C97CC14E-4789-4FC5-BC75-79191F7CE009}) (Version: 4.6.4.1 - Hewlett-Packard Company)
HP Power Assistant (HKLM\...\{0DA545C1-8ECA-4B54-B787-31ED17429CF3}) (Version: 2.1.0.6 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{6B5E7B4F-64A2-4DEB-B210-0DD92F940A01}) (Version: 3.0.3.9925 - Hewlett-Packard Company)
HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{FE465061-894A-4023-8580-56FCDD4F23F9}) (Version: 3.4.4.0 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\...\{5877C85D-8CA5-4153-A366-C232ECFE7A2B}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\...\{531000B3-DBEE-4115-BBF3-DA48B67C053F}) (Version: 8.2.1.1 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{7B649B69-BE85-4011-AFAE-4767BC9D934A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP System Default Settings (HKLM-x32\...\{EE5F1911-EA95-4F1A-AF97-495972F5032D}) (Version: 2.4.3.1 - Hewlett-Packard Company)
HP Wallpaper (HKLM-x32\...\{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}) (Version: 2.00 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6428.0 - IDT)
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Infovox Desktop 2.220 voices (HKLM-x32\...\ID2220Voices) (Version:  - )
Insaniquarium Deluxe (HKLM-x32\...\WT087480) (Version: 2.2.0.95 - WildTangent) Hidden
Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
Intel(R) Identity Protection Technology 1.0.71.0 (HKLM-x32\...\{2C43790E-8470-1027-82D3-DF319F3C410F}) (Version: 1.0.71.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation)
Jewel Quest II (HKLM-x32\...\WT087485) (Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (HKLM-x32\...\WT087490) (Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest Solitaire (quitar) (HKLM-x32\...\Jewel Quest Solitaire) (Version:  - )
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.72.4 - JMicron Technology Corp.)
John Deere Drive Green (HKLM-x32\...\WT087380) (Version: 2.2.0.95 - WildTangent) Hidden
Juegos WildTangent (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LightScribe System Software  1.14.17.1 (HKLM-x32\...\{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}) (Version: 1.14.17.1 - LightScribe)
Malwarebytes version 4.1.0.56 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.1.0.56 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - ESN (HKLM-x32\...\{6D972506-DC01-39BC-A5DD-06DA86E00031}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - ESN (HKLM-x32\...\{4A28444E-0532-3264-B07D-5AFE590E30BE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
MotoHelper MergeModules (HKLM-x32\...\{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}) (Version: 1.0.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 4.7.1 (HKLM\...\{82ED9FB2-55AF-4A61-A6F3-506CEE112779}) (Version: 4.7.1 - Motorola Inc.) Hidden
Mozilla Firefox 76.0.1 (x64 es-AR) (HKLM\...\Mozilla Firefox 76.0.1 (x64 es-AR)) (Version: 76.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 63.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation)
Penguins! (HKLM-x32\...\WT087394) (Version: 2.2.0.95 - WildTangent) Hidden
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Plants vs. Zombies (HKLM-x32\...\WT087501) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\...\WT087396) (Version: 2.2.0.95 - WildTangent) Hidden
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
Readon TV Movie Radio Player 7.5.0.0 (HKLM-x32\...\{03840E8D-A75E-4C49-ADFC-09A867C7F943}) (Version: 7.5.0 - Readon Technology)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.58.411.2012 - Realtek)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.00.11.0323 - REALTEK Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.50 - Piriform)
Remo ONE 1.0.0 (HKLM\...\{8DB422C2-D359-49B1-A685-B71DA7358D5C}_is1) (Version: 1.0.0.4 - Remo Software)
Remo Recover 5.0 (HKLM\...\{A573D759-F894-448D-A420-3A9C31879F88}_is1) (Version: 5.0.0.34 - Remo Software)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Revisión para Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{6D972506-DC01-39BC-A5DD-06DA86E00031}.KB947789) (Version: 1 - Microsoft Corporation)
Revo Uninstaller 2.1.1 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.1.1 - VS Revo Group, Ltd.)
SDK (HKLM-x32\...\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}) (Version: 2.26.012 - Portrait Displays, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Web Plugin (HKLM-x32\...\{0F7D4832-16AE-4857-A6FA-2B141D75A59B}) (Version: 7.7.0.219 - Skype Technologies S.A.)
Skype Web Plugin (HKLM-x32\...\{15AF46DB-9EBA-4662-AA52-29EF23585035}) (Version: 3.2.0.23388 - Skype Technologies S.A.)
Slingo Deluxe (HKLM-x32\...\WT087510) (Version: 2.2.0.95 - WildTangent) Hidden
Spotify (HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Spotify) (Version: 1.1.12.449.g4109e645 - Spotify AB)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1052 - SUPERAntiSpyware.com)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.18.17 - Synaptics Incorporated)
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - gamigo, Inc.) Hidden
Validity Fingerprint Sensor Driver (HKLM\...\{FFC3E41D-2C2B-45B7-9AD9-5EA19572DD26}) (Version: 4.3.117.0 - Validity Sensors, Inc.)
VIP Access SDK x64(1.0.0.50)  (HKLM-x32\...\VIP Access SDK) (Version: 1.0.0.50 - Symantec Inc.)
Virtual Villagers - The Secret City (HKLM-x32\...\WT087513) (Version: 2.2.0.95 - WildTangent) Hidden
Wedding Dash (HKLM-x32\...\WT087519) (Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames) (Version: 4.1.1.49 - WildTangent) Hidden
WildTangent Games App (HP Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp) (Version: 4.0.10.5 - WildTangent) Hidden
WildTangent Helper (HKLM-x32\...\{A39303AB-4898-4F12-BAA0-0B8630F86DB4}) (Version: 1.0.0.409 - WildTangent) Hidden
WildTangent ShortcutProvider (HKLM-x32\...\{80831F60-19D7-43B3-A60C-5CAF8C478DF6}) (Version: 5.0.0.219 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinZip 14.5 (HKLM-x32\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. )
Xobni (HKLM-x32\...\XobniMain) (Version: 1.9.5.13282 - Xobni Corp.)
Youda Jewel Shop (HKLM-x32\...\WTA-8d8094a7-cd05-4069-8bf0-6429dc99eca0) (Version: 3.0.2.32 - WildTangent) Hidden
Zoom (HKU\S-1-5-21-348586771-676038775-713973424-1003\...\ZoomUMX) (Version: 5.0 - Zoom Video Communications, Inc.)
Zuma Deluxe (HKLM-x32\...\WT087533) (Version: 2.2.0.95 - WildTangent) Hidden

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> Ningún archivo
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} =>  -> Ningún archivo
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2011-03-26] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-04-21] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-22] (Glarysoft LTD -> Glarysoft Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} =>  -> Ningún archivo
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2008-06-20] () [Archivo no firmado]
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2008-09-16] () [Archivo no firmado]
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files (x86)\WinZip\wzshls64.dll [2010-04-05] (WinZip Computing -> WinZip Computing, S.L.)

==================== Codecs (Lista blanca) ====================

(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)

HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [Archivo no firmado]

==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2011-06-11 12:44 - 2011-06-11 12:44 - 000007168 _____ ( ( ) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\SDKCOMServerLib.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 000058880 _____ ( () [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2011-05-04 21:56 - 2011-06-11 12:42 - 001083392 _____ ( () [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\System.Data.SQLite.dll
2012-09-05 15:31 - 2012-09-05 15:31 - 000349696 _____ ( (Hewlett-Packard Development Company, L.P.) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HP.Mobile.Resource.dll
2011-06-11 12:42 - 2011-06-11 12:42 - 000869888 _____ ( (HP) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files\Hewlett-Packard\HP Power Assistant\HP.SupportFramework.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000006656 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IAStorDataMgr.resources.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000032768 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IAStorIcon.resources.dll
2011-11-11 07:41 - 2011-01-12 22:57 - 000004608 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\es-ES\IntelVisualDesign.resources.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 000165376 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUIHelper.dll
2011-11-11 07:41 - 2011-01-12 22:56 - 001109504 _____ ( (Intel Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll
2012-03-23 20:05 - 2012-03-23 20:05 - 000225280 _____ ( (Microsoft Corporation) [Archivo no firmado])  [El archivo está en uso ] C:\windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
2011-04-27 17:05 - 2011-04-27 17:05 - 000514570 _____ () [Archivo no firmado] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2012-03-31 16:50 - 2008-06-20 00:41 - 000062464 _____ () [Archivo no firmado] C:\Program Files (x86)\WinRAR\rarext64.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000169472 _____ () [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\61a733954a0da9a5988d596c76b2b891\IsdiInterop.ni.dll
2011-11-11 07:41 - 2011-01-17 16:19 - 001892352 _____ (Apache Software Foundation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\xerces-c_2_7.dll
2008-06-09 10:21 - 2008-06-09 10:21 - 000033280 _____ (Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSLog.dll
2008-06-09 10:21 - 2008-06-09 10:21 - 000110592 _____ (Hewlett-Packard Company) [Archivo no firmado] C:\Program Files (x86)\Common Files\LightScribe\LSSProxy.dll
2014-09-10 21:53 - 2014-09-10 21:53 - 000014336 _____ (Intel Corp.) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\e8d9058b7f59f6d3d134b086916d8674\IAStorCommon.ni.dll
2011-11-11 07:41 - 2011-01-17 16:14 - 000069632 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\StatusStrings.dll
2011-11-11 07:41 - 2011-01-12 22:52 - 000275456 _____ (Intel Corporation) [Archivo no firmado] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000219136 _____ (Intel Corporation) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\79bc2712f1597303b790bfa64b222d41\IAStorDataMgr.ni.dll
2016-05-12 19:47 - 2016-05-12 19:47 - 000475648 _____ (Intel Corporation) [Archivo no firmado] C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\7cfe3c97366e009a0a7bce795ec66f43\IAStorUtil.ni.dll

==================== Alternate Data Streams (Lista blanca) ========

(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)

AlternateDataStreams: C:\ProgramData\TEMP:E6540C35 [126]

==================== Modo Seguro (Lista blanca) ==================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Asociación (Lista blanca) =================

==================== Internet Explorer sitios de confianza/restringidos ==========

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)

2009-07-13 23:34 - 2019-01-13 17:13 - 000000825 _____ C:\windows\system32\drivers\etc\hosts

2012-04-06 23:30 - 2014-10-16 20:16 - 000000375 _____ C:\windows\system32\drivers\etc\hosts.ics

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %C_EM64T_REDIST11%bin\Intel64;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Intel\Services\IPT\;C:\Program Files (x86)\QuickTime\QTSystem\
HKU\S-1-5-21-348586771-676038775-713973424-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Gabriela\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 186.130.128.250 - 186.130.129.250
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [{B2D3BA98-68F5-47A5-868D-C1E6F278A051}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{900D6A16-8D89-4CC6-95A5-AE312874D0A4}] => (Allow) LPort=2869
FirewallRules: [{7F0B70FA-796D-49F0-9611-E03D9D0449CC}] => (Allow) LPort=1900
FirewallRules: [{8C22AA11-D491-42B5-A7D5-2F75D4585E75}] => (Allow) LPort=1542
FirewallRules: [{492E4ADD-6891-4ACB-9E31-C43B4D06618B}] => (Allow) LPort=1542
FirewallRules: [{C24C5143-AA92-4081-9A6B-C370E2B1A4D8}] => (Allow) LPort=53
FirewallRules: [{5EBE1633-728D-49E9-AC98-293E554C99B8}] => (Allow) C:\Windows\SysWOW64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{27631350-9188-475D-BA2E-F7B272E9CF5E}] => (Allow) C:\Windows\SysWOW64\msiexec.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{0D0B5E34-B82D-4554-ADE0-1D96C59188E2}C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe] => (Block) C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe (Readon Technology) [Archivo no firmado]
FirewallRules: [UDP Query User{DF3B8EB6-0EC4-434D-8330-65271DF0217B}C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe] => (Block) C:\program files (x86)\readon technology\readon tv movie radio player 7.5.0.0\internettv.exe (Readon Technology) [Archivo no firmado]
FirewallRules: [TCP Query User{C1EA3879-6043-4CD9-B511-5FBECCFF755F}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe => Ningún archivo
FirewallRules: [UDP Query User{59D08101-D3ED-46D1-AE4A-73BF883812C7}C:\program files (x86)\java\jre7\bin\java.exe] => (Allow) C:\program files (x86)\java\jre7\bin\java.exe => Ningún archivo
FirewallRules: [{B510B2DE-7AA5-4E6D-B056-6FDEC7452D6B}] => (Allow) C:\Program Files (x86)\SkypeWebPlugin\3.2.0.23388\SkypeWebPlugin.exe (Skype Software Sarl -> Skype)
FirewallRules: [TCP Query User{C40D2717-8307-4B1C-BB22-C227B98373B8}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{89622048-5901-4B02-873A-0596F96A6FD8}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [TCP Query User{923CDD66-7ACE-4BBF-9183-8C6C0F7BF6FF}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{12CE1836-81D6-49AA-8AEC-7B90AF9808AA}C:\users\gabriela\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\gabriela\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{812D9CD9-DD2A-40F6-96D1-E7AD52D78DCD}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Ltd)
FirewallRules: [{0DAE30C5-0D56-496C-8D30-8E5F87BB9999}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Ltd)
FirewallRules: [{EC2C566A-1C37-468E-8F1D-C011157FB46F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7E598F04-D8CA-45D5-B2CE-C53F5D1FB5AC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{BAC6D019-86C4-4C3F-9996-BBCB7B1C1EEA}] => (Allow) C:\Users\Gabriela\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [{B0D51C2F-4611-4E13-8F11-9E1BA2D3F32C}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{607BE7CE-FAC8-4192-963C-8157138F930E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Puntos de Restauración =========================

12-05-2020 17:19:52 JRT Pre-Junkware Removal
12-05-2020 20:39:44 Revo Uninstaller's restore point - Java 7 Update 25
12-05-2020 20:40:42 Removed Java 7 Update 25
12-05-2020 21:49:00 Revo Uninstaller's restore point - JavaFX 2.1.1
12-05-2020 21:57:50 Quitado JavaFX 2.1.1
12-05-2020 22:00:30 Revo Uninstaller's restore point - iWin Games (remove only)
12-05-2020 22:02:03 Revo Uninstaller's restore point - iWin Games (remove only)
12-05-2020 22:04:02 Revo Uninstaller's restore point - VLC media player

==================== Dispositivos defectuosos en el Administrador de dispositivos ============

Name: Adaptador de tunelización Teredo de Microsoft
Description: Adaptador de tunelización Teredo de Microsoft
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: ElbyCDIO Driver
Description: ElbyCDIO Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: ElbyCDIO
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (05/12/2020 10:04:02 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

Details:
AddWin32ServiceFiles: Unable to back up image of service iWinTrusted since QueryServiceConfig API failed

System Error:
El sistema no puede encontrar el archivo especificado.
.

Error: (05/12/2020 08:39:37 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al consultar la interfaz IVssWriterCallback. HR = 0x80070005, Acceso denegado.
.
A menudo ocurre por una configuración de seguridad incorrecta en el proceso de escritura o de solicitud.


Operación:
   Recopilando datos del escritor

Contexto:
   Id. de clase del escritor: {e8132975-6f93-4464-a53e-1050253ae220}
   Nombre del escritor: System Writer
   Id. de instancia del escritor: {e17392e5-74f1-41c0-b128-2937484fdea8}

Error: (05/12/2020 05:53:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa chrome.exe, versión 81.0.4044.138, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: 1364

Hora de inicio: 01d6289ec55676e3

Hora de finalización: 60000

Ruta de acceso de la aplicación: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Identificador de informe: 7e1a08bc-9492-11ea-9584-101f74fe1e45

Error: (05/12/2020 05:50:42 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa FRST64.exe, versión 11.5.2020.0, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: 1cf8

Hora de inicio: 01d6289d1c21d360

Hora de finalización: 493

Ruta de acceso de la aplicación: C:\Users\Gabriela\Desktop\FRST64.exe

Identificador de informe:

Error: (05/12/2020 02:55:48 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows no puede tener acceso al archivo  por alguna de las siguientes razones:
Hay un problema con la conexión de red, con el disco donde se almacena este archivo o con los controladores
de almacenamiento instalados en este equipo; o bien no se encuentra el disco.
Windows cerró el programa WildTangentHelperService.exe por este error.

Programa: WildTangentHelperService.exe
Archivo: 

El valor del error se muestra en la sección Datos adicionales.
Acción del usuario
1. Abra el archivo de nuevo.
Podría ser sólo un problema temporal que se corrige al ejecutar el programa de nuevo.
2.
Si todavía no se puede tener acceso al archivo y 
	- Está en la red,
el administrador de red debe comprobar que no exista ningún problema con la red y que es posible ponerse en contacto con el servidor.
	- Está en un disco extraíble, como un disquete o un CD-ROM, compruebe que el disco esté insertado en el equipo.
3. Compruebe y repare el sistema de archivos ejecutando CHKDSK. Para ejecutar CHKDSK, haga clic en Inicio y después en Ejecutar; escriba CMD y después haga clic en Aceptar. En el símbolo del sistema, escriba CHKDSK /F y después presione Entrar.
4. Si el problema continúa, restaure el archivo a partir de una copia de seguridad.
5. Compruebe si se pueden abrir otros archivos en el mismo disco. Si no se pueden abrir, el disco podría estar dañado. Si se trata de un disco duro, póngase en contacto con el administrador o con el fabricante del hardware del equipo
para obtener ayuda adicional.

Datos adicionales
Valor del error:00000000
Tipo de disco: 0

Error: (05/12/2020 02:55:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: WildTangentHelperService.exe, versión: 1.0.0.409, marca de tiempo: 0x5e8638b2
Nombre del módulo con errores: WildTangentHelperService.exe, versión: 1.0.0.409, marca de tiempo: 0x5e8638b2
Código de excepción: 0xc0000096
Desplazamiento de errores: 0x000dc90c
Id. del proceso con errores: 0x22ec
Hora de inicio de la aplicación con errores: 0x01d6288687cf8a89
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Ruta de acceso del módulo con errores: C:\Program Files (x86)\WildTangent Games\Integration\WildTangentHelperService.exe
Id. del informe: cf385628-9479-11ea-92a5-101f74fe1e45


Errores del sistema:
=============
Error: (05/13/2020 12:31:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Windows Search no pudo iniciarse debido al siguiente error: 
El servicio no respondió a tiempo a la solicitud de inicio o de control.

Error: (05/13/2020 12:31:34 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1053" al intentar iniciar el servicio WSearch con argumentos "" para ejecutar el servidor:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

Error: (05/13/2020 12:31:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Windows Search.

Error: (05/13/2020 12:31:03 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
ElbyCDIO

Error: (05/12/2020 10:26:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio HP Software Framework Service no pudo iniciarse debido al siguiente error: 
El servicio no respondió a tiempo a la solicitud de inicio o de control.

Error: (05/12/2020 10:26:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio HP Software Framework Service.

Error: (05/12/2020 10:26:07 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: Error de DCOM "1053" al intentar iniciar el servicio hpqwmiex con argumentos "" para ejecutar el servidor:
{F5539356-2F02-40D4-999E-FA61F45FE12E}

Error: (05/12/2020 10:25:35 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: 
ElbyCDIO


CodeIntegrity:
===================================

Date: 2020-05-13 12:39:03.894
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-13 12:38:46.255
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-13 12:35:07.805
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 23:24:01.257
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:31:38.986
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:31:38.053
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:30:56.447
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

Date: 2020-05-12 22:30:17.691
Description: 
Integridad de código no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\windows\System32\AESTAR64.dll porque el conjunto de hashes de imagen por página no se encuentra en el sistema.

==================== Información de la memoria =========================== 

BIOS: Hewlett-Packard 68SRR Ver. F.40 03/12/2013
Placa base: Hewlett-Packard 167C
Procesador: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz
Porcentaje de memoria en uso: 89%
RAM física total: 4030.37 MB
RAM física disponible: 416.16 MB
Virtual total: 8058.92 MB
Virtual disponible: 3117.38 MB

==================== Unidades ================================

Drive c: () (Fixed) (Total:443.56 GB) (Free:268.07 GB) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive e: (HP_RECOVERY) (Fixed) (Total:16.9 GB) (Free:2.54 GB) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive f: (HP_TOOLS) (Fixed) (Total:4.98 GB) (Free:2.12 GB) FAT32

\\?\Volume{85a6513a-0c50-11e1-ba96-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.29 GB) (Free:0.25 GB) NTFS

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 4166D6A8)
Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=443.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=16.9 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=5 GB) - (Type=0C)

==================== Final de Addition.txt =======================

Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> Ningún archivo
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> Ningún archivo
ContextMenuHandlers1: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => -> Ningún archivo
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Ningún archivo
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Ningún archivo
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Ningún archivo
AlternateDataStreams: C:\ProgramData\TEMP:E6540C35 [126]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [43984 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.138\Installer\chrmstp.exe [2020-05-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{10880D85-AAD9-4558-ABDC-2AB1552D831F}] -> C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe [2008-06-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.4053.113\Installer\chrmstp.exe [2020-05-11] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-02] (Adobe Inc. -> Adobe Systems, Inc.)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicyScripts-x32: Restricción <==== ATENCIÓN
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN
CHR HKLM\SOFTWARE\Policies\Google: Restricción <==== ATENCIÓN
Task: {1153BFC2-EB9C-4C0F-B39E-416B85F095CD} - \{EFCB239E-A67B-4177-A64A-37DC58BAA823} -> Ningún archivo <==== ATENCIÓN
Task: {15495120-92CF-4EA7-BBDF-29E22147A31E} - \{5EEB130B-C5E3-4E95-A8FE-ACE8DC7FFC51} -> Ningún archivo <==== ATENCIÓN
Task: {1AEF3106-B5B6-430E-83FF-50600CF0E635} - System32\Tasks\{D2FFBAA0-1161-4E5A-9A3B-7BED65E38539} => C:\Users\Erika\Desktop\Phv.exe
Task: {22947606-F103-4048-B1AB-559C32596739} - \{01B7CE4A-28BE-4081-94C5-D22132FCBF68} -> Ningún archivo <==== ATENCIÓN
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Ningún archivo <==== ATENCIÓN
Task: {41109735-418E-4769-86F4-092523F83F0C} - System32\Tasks\Apagar PC => C:\Windows\System32\shutdown.exe [34304 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
Task: {4955A070-9A27-4951-B7AA-FE4E21791967} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {496B5CDC-C0E9-410A-B422-DDEA9D07C50C} - System32\Tasks\{816CB30A-676A-42E3-AD73-A371E0C479DE} => C:\windows\system32\pcalua.exe -a "C:\Users\Erika\Downloads\QuickTimeInstaller (1).exe" -d C:\Users\Erika\Downloads
Task: {4A4588E1-DA3C-40C6-9C9B-91A05637DC50} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\windows\ehome\ehrec.exe
Task: {5042C336-B165-41E5-BA30-2E6AB14A0F80} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\windows\ehome\mcupdate.exe
Task: {508CF8AB-A1DA-4B23-88D5-D4DE9480FBB4} - \MotoHelper MUM -> Ningún archivo <==== ATENCIÓN
Task: {50D96CE0-EFCD-406D-8AED-58B528C10888} - \MotoHelper Routing -> Ningún archivo <==== ATENCIÓN
Task: {5F0FEFF4-E156-4261-8D27-129FAB4E4054} - \{579A7337-5077-497D-BE7F-51D406B1326E} -> Ningún archivo <==== ATENCIÓN
Task: {65D3CF7E-02ED-4AE9-90AB-E41A9EC33874} - System32\Tasks\{40018D1E-61FC-4184-AEE0-79A92C6D3528} => C:\Users\Erika\Desktop\Phv.exe
Task: {6BE401B1-5B06-40AB-8F58-57D0FDADC7B8} - System32\Tasks\{8BC8674A-AFC5-4E11-8A32-2AE525F92652} => C:\Users\Erika\Desktop\Phv.exe
Task: {7FAD2AB7-D6E5-49BB-B1F1-11E311260E73} - System32\Tasks\{E6B7690B-3A0B-4F22-A859-BC07AEE9D346} => C:\Users\Erika\Desktop\Phv.exe
Task: {8239A271-7D2F-4D21-A8B5-27661566DDCA} - \SidebarExecute -> Ningún archivo <==== ATENCIÓN
Task: {8BD395AF-078E-40E1-87B7-8525D9CC083A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {8FB7217C-2602-435D-BDA6-CF0385026C13} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Ningún archivo <==== ATENCIÓN
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Ningún archivo <==== ATENCIÓN
Task: {BD7C0212-2E0D-4B5B-962E-8A5E036F3D82} - \IHUninstallTrackingTASK -> Ningún archivo <==== ATENCIÓN
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Ningún archivo <==== ATENCIÓN
Task: {D62C7F31-EECE-40FB-AACE-FD37116802B9} - \RunAsStdUser Task -> Ningún archivo <==== ATENCIÓN
Task: {D7961A06-DAD4-4B3E-9A60-9B82D133F5FC} - System32\Tasks\{54167D85-7CB6-443D-805E-7BFF8B1E844F} => C:\windows\system32\pcalua.exe -a C:\Users\Erika\Downloads\QuickTimeInstaller.exe -d C:\Users\Erika\Downloads
Task: {DE2C859E-279C-4115-A7C0-F25FA89CF22B} - \User_Feed_Synchronization-{BAC3944D-7C78-4B3D-9863-20FC40B19BC9} -> Ningún archivo <==== ATENCIÓN
Task: {DE65BF18-4593-47FF-A599-81C9595A90F7} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Ningún archivo <==== ATENCIÓN
Task: {E129F494-CD81-4737-8D49-953CAAB06211} - System32\Tasks\{AC72203C-7D2B-47BC-88C2-279BD4ED6374} => C:\Users\Erika\Desktop\Phv.exe
Task: {F437A0E7-173B-4764-9D82-CA5FD8EE54E1} - \MotoHelper Update -> Ningún archivo <==== ATENCIÓN
Task: {F67912CA-84DF-4653-8721-E6E996AB93F8} - \AutoKMS -> Ningún archivo <==== ATENCIÓN
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Ningún archivo <==== ATENCIÓN
Task: C:\windows\Tasks\AutoKMS.job =>
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-348586771-676038775-713973424-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Ningún archivo
Toolbar: HKLM - Sin Nombre - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Ningún archivo
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin-x32: @canon.com/UCPlugin -> C:\Program Files (x86)\Canon\Uploader for CANON iMAGE GATEWAY Plugin\\npUploaderForCiG.dll [Ningún archivo]
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2013-07-08] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ningún archivo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <no encontrado>
S1 ElbyCDIO; System32\Drivers\ElbyCDIO.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
2017-06-11 20:44 - 2017-06-11 20:44 - 000000000 _____ () C:\Users\Gabriela\AppData\Local\{3ED27979-CD66-4AA4-B2B1-98EA03D8E978}
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

Y ahora inicia tu equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX/Corregir y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.

Saludos.

Realice los pasos y sigue el problema. Pego el nuevo log FRST

Resultados de la corrección de Farbar Recovery Scan Tool (x64) Versión: 13-05-2020 01
Ejecutado por Gabriela (13-05-2020 13:51:24) Run:1
Ejecutado desde C:\Users\Gabriela\Desktop
Perfiles cargados: Gabriela
Modo de Inicio: Safe Mode (with Networking)
==============================================

fixlist contenido:
*****************
START
CREATERESTOREPOINT:
CLOSEPROCESSES:
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> Ning�n archivo
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> Ning�n archivo
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> Ning�n archivo
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> Ning�n archivo
ContextMenuHandlers1: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => -> Ning�n archivo
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Ning�n archivo
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Ning�n archivo
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> Ning�n archivo
AlternateDataStreams: C:\ProgramData\TEMP:E6540C35 [126]
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-348586771-676038775-713973424-1003\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [43984 2017-04-07] (Glarysoft LTD -> Glarysoft Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\81.0.4044.138\Installer\chrmstp.exe [2020-05-11] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{10880D85-AAD9-4558-ABDC-2AB1552D831F}] -> C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe [2008-06-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\81.0.4053.113\Installer\chrmstp.exe [2020-05-11] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2019-05-02] (Adobe Inc. -> Adobe Systems, Inc.)
BootExecute: autocheck autochk * PCloudBroom64.exe \systemroot\system32\BroomData.bit
GroupPolicyScripts-x32: Restricci�n <==== ATENCI�N
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricci�n <==== ATENCI�N
CHR HKLM\SOFTWARE\Policies\Google: Restricci�n <==== ATENCI�N
Task: {1153BFC2-EB9C-4C0F-B39E-416B85F095CD} - \{EFCB239E-A67B-4177-A64A-37DC58BAA823} -> Ning�n archivo <==== ATENCI�N
Task: {15495120-92CF-4EA7-BBDF-29E22147A31E} - \{5EEB130B-C5E3-4E95-A8FE-ACE8DC7FFC51} -> Ning�n archivo <==== ATENCI�N
Task: {1AEF3106-B5B6-430E-83FF-50600CF0E635} - System32\Tasks\{D2FFBAA0-1161-4E5A-9A3B-7BED65E38539} => C:\Users\Erika\Desktop\Phv.exe
Task: {22947606-F103-4048-B1AB-559C32596739} - \{01B7CE4A-28BE-4081-94C5-D22132FCBF68} -> Ning�n archivo <==== ATENCI�N
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> Ning�n archivo <==== ATENCI�N
Task: {41109735-418E-4769-86F4-092523F83F0C} - System32\Tasks\Apagar PC => C:\Windows\System32\shutdown.exe [34304 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
Task: {4955A070-9A27-4951-B7AA-FE4E21791967} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {496B5CDC-C0E9-410A-B422-DDEA9D07C50C} - System32\Tasks\{816CB30A-676A-42E3-AD73-A371E0C479DE} => C:\windows\system32\pcalua.exe -a "C:\Users\Erika\Downloads\QuickTimeInstaller (1).exe" -d C:\Users\Erika\Downloads
Task: {4A4588E1-DA3C-40C6-9C9B-91A05637DC50} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\windows\ehome\ehrec.exe
Task: {5042C336-B165-41E5-BA30-2E6AB14A0F80} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\windows\ehome\mcupdate.exe
Task: {508CF8AB-A1DA-4B23-88D5-D4DE9480FBB4} - \MotoHelper MUM -> Ning�n archivo <==== ATENCI�N
Task: {50D96CE0-EFCD-406D-8AED-58B528C10888} - \MotoHelper Routing -> Ning�n archivo <==== ATENCI�N
Task: {5F0FEFF4-E156-4261-8D27-129FAB4E4054} - \{579A7337-5077-497D-BE7F-51D406B1326E} -> Ning�n archivo <==== ATENCI�N
Task: {65D3CF7E-02ED-4AE9-90AB-E41A9EC33874} - System32\Tasks\{40018D1E-61FC-4184-AEE0-79A92C6D3528} => C:\Users\Erika\Desktop\Phv.exe
Task: {6BE401B1-5B06-40AB-8F58-57D0FDADC7B8} - System32\Tasks\{8BC8674A-AFC5-4E11-8A32-2AE525F92652} => C:\Users\Erika\Desktop\Phv.exe
Task: {7FAD2AB7-D6E5-49BB-B1F1-11E311260E73} - System32\Tasks\{E6B7690B-3A0B-4F22-A859-BC07AEE9D346} => C:\Users\Erika\Desktop\Phv.exe
Task: {8239A271-7D2F-4D21-A8B5-27661566DDCA} - \SidebarExecute -> Ning�n archivo <==== ATENCI�N
Task: {8BD395AF-078E-40E1-87B7-8525D9CC083A} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {8FB7217C-2602-435D-BDA6-CF0385026C13} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> Ning�n archivo <==== ATENCI�N
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> Ning�n archivo <==== ATENCI�N
Task: {BD7C0212-2E0D-4B5B-962E-8A5E036F3D82} - \IHUninstallTrackingTASK -> Ning�n archivo <==== ATENCI�N
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> Ning�n archivo <==== ATENCI�N
Task: {D62C7F31-EECE-40FB-AACE-FD37116802B9} - \RunAsStdUser Task -> Ning�n archivo <==== ATENCI�N
Task: {D7961A06-DAD4-4B3E-9A60-9B82D133F5FC} - System32\Tasks\{54167D85-7CB6-443D-805E-7BFF8B1E844F} => C:\windows\system32\pcalua.exe -a C:\Users\Erika\Downloads\QuickTimeInstaller.exe -d C:\Users\Erika\Downloads
Task: {DE2C859E-279C-4115-A7C0-F25FA89CF22B} - \User_Feed_Synchronization-{BAC3944D-7C78-4B3D-9863-20FC40B19BC9} -> Ning�n archivo <==== ATENCI�N
Task: {DE65BF18-4593-47FF-A599-81C9595A90F7} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> Ning�n archivo <==== ATENCI�N
Task: {E129F494-CD81-4737-8D49-953CAAB06211} - System32\Tasks\{AC72203C-7D2B-47BC-88C2-279BD4ED6374} => C:\Users\Erika\Desktop\Phv.exe
Task: {F437A0E7-173B-4764-9D82-CA5FD8EE54E1} - \MotoHelper Update -> Ning�n archivo <==== ATENCI�N
Task: {F67912CA-84DF-4653-8721-E6E996AB93F8} - \AutoKMS -> Ning�n archivo <==== ATENCI�N
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> Ning�n archivo <==== ATENCI�N
Task: C:\windows\Tasks\AutoKMS.job =>
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => C:\Users\Erika\AppData\Local\Facebook\Update\FacebookUpdate.exe
SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://ar.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF
SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-348586771-676038775-713973424-1003 -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL =
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - Ning�n archivo
Toolbar: HKLM - Sin Nombre - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - Ning�n archivo
FF Plugin: @microsoft.com/GENUINE -> disabled [Ning�n archivo]
FF Plugin-x32: @canon.com/UCPlugin -> C:\Program Files (x86)\Canon\Uploader for CANON iMAGE GATEWAY Plugin\\npUploaderForCiG.dll [Ning�n archivo]
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2013-07-08] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ning�n archivo]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <no encontrado>
S1 ElbyCDIO; System32\Drivers\ElbyCDIO.sys [X]
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
2017-06-11 20:44 - 2017-06-11 20:44 - 000000000 _____ () C:\Users\Gabriela\AppData\Local\{3ED27979-CD66-4AA4-B2B1-98EA03D8E978}
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
END
*****************

Error: El punto de restauración solamente puede ser creado en modo normal.
Procesos cerrados correctamente.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1 => eliminado correctamente
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2 => eliminado correctamente
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3 => eliminado correctamente
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4 => eliminado correctamente
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Cover Designer => eliminado correctamente
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UAContextMenu => eliminado correctamente
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\UAContextMenu => eliminado correctamente
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UAContextMenu => eliminado correctamente
C:\ProgramData\TEMP => ":E6540C35" ADS eliminado correctamente
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => eliminado correctamente
"HKU\S-1-5-21-348586771-676038775-713973424-1003\Software\Microsoft\Windows\CurrentVersion\Run\\GUDelayStartup" => eliminado correctamente
HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} => eliminado correctamente
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{10880D85-AAD9-4558-ABDC-2AB1552D831F} => eliminado correctamente
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{30C521FB-255B-46C8-9F0D-EE5AE371C9AA} => eliminado correctamente
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{A6EADE66-0000-0000-484E-7E8A45000000} => eliminado correctamente
HKLM\System\CurrentControlSet\Control\Session Manager\\"BootExecute"="autocheck autochk *" => valor restaurado correctamente
C:\windows\SysWOW64\GroupPolicy\Machine => movido correctamente
C:\windows\SysWOW64\GroupPolicy\GPT.ini => movido correctamente
HKLM\SOFTWARE\Policies\Mozilla => eliminado correctamente
HKLM\SOFTWARE\Policies\Google => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1153BFC2-EB9C-4C0F-B39E-416B85F095CD}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1153BFC2-EB9C-4C0F-B39E-416B85F095CD}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EFCB239E-A67B-4177-A64A-37DC58BAA823}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15495120-92CF-4EA7-BBDF-29E22147A31E}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15495120-92CF-4EA7-BBDF-29E22147A31E}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5EEB130B-C5E3-4E95-A8FE-ACE8DC7FFC51}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1AEF3106-B5B6-430E-83FF-50600CF0E635}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1AEF3106-B5B6-430E-83FF-50600CF0E635}" => eliminado correctamente
C:\windows\System32\Tasks\{D2FFBAA0-1161-4E5A-9A3B-7BED65E38539} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D2FFBAA0-1161-4E5A-9A3B-7BED65E38539}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{22947606-F103-4048-B1AB-559C32596739}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22947606-F103-4048-B1AB-559C32596739}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{01B7CE4A-28BE-4081-94C5-D22132FCBF68}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{41109735-418E-4769-86F4-092523F83F0C}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41109735-418E-4769-86F4-092523F83F0C}" => eliminado correctamente
C:\windows\System32\Tasks\Apagar PC => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apagar PC" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4955A070-9A27-4951-B7AA-FE4E21791967}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4955A070-9A27-4951-B7AA-FE4E21791967}" => eliminado correctamente
C:\windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{496B5CDC-C0E9-410A-B422-DDEA9D07C50C}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{496B5CDC-C0E9-410A-B422-DDEA9D07C50C}" => eliminado correctamente
C:\windows\System32\Tasks\{816CB30A-676A-42E3-AD73-A371E0C479DE} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{816CB30A-676A-42E3-AD73-A371E0C479DE}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4A4588E1-DA3C-40C6-9C9B-91A05637DC50}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4A4588E1-DA3C-40C6-9C9B-91A05637DC50}" => eliminado correctamente
C:\windows\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5042C336-B165-41E5-BA30-2E6AB14A0F80}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5042C336-B165-41E5-BA30-2E6AB14A0F80}" => eliminado correctamente
C:\windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{508CF8AB-A1DA-4B23-88D5-D4DE9480FBB4}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{508CF8AB-A1DA-4B23-88D5-D4DE9480FBB4}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MotoHelper MUM" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{50D96CE0-EFCD-406D-8AED-58B528C10888}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50D96CE0-EFCD-406D-8AED-58B528C10888}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MotoHelper Routing" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5F0FEFF4-E156-4261-8D27-129FAB4E4054}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F0FEFF4-E156-4261-8D27-129FAB4E4054}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{579A7337-5077-497D-BE7F-51D406B1326E}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{65D3CF7E-02ED-4AE9-90AB-E41A9EC33874}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{65D3CF7E-02ED-4AE9-90AB-E41A9EC33874}" => eliminado correctamente
C:\windows\System32\Tasks\{40018D1E-61FC-4184-AEE0-79A92C6D3528} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{40018D1E-61FC-4184-AEE0-79A92C6D3528}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6BE401B1-5B06-40AB-8F58-57D0FDADC7B8}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6BE401B1-5B06-40AB-8F58-57D0FDADC7B8}" => eliminado correctamente
C:\windows\System32\Tasks\{8BC8674A-AFC5-4E11-8A32-2AE525F92652} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8BC8674A-AFC5-4E11-8A32-2AE525F92652}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7FAD2AB7-D6E5-49BB-B1F1-11E311260E73}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7FAD2AB7-D6E5-49BB-B1F1-11E311260E73}" => eliminado correctamente
C:\windows\System32\Tasks\{E6B7690B-3A0B-4F22-A859-BC07AEE9D346} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E6B7690B-3A0B-4F22-A859-BC07AEE9D346}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8239A271-7D2F-4D21-A8B5-27661566DDCA}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8239A271-7D2F-4D21-A8B5-27661566DDCA}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SidebarExecute" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8BD395AF-078E-40E1-87B7-8525D9CC083A}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BD395AF-078E-40E1-87B7-8525D9CC083A}" => eliminado correctamente
C:\windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FB7217C-2602-435D-BDA6-CF0385026C13}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FB7217C-2602-435D-BDA6-CF0385026C13}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD7C0212-2E0D-4B5B-962E-8A5E036F3D82}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD7C0212-2E0D-4B5B-962E-8A5E036F3D82}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\IHUninstallTrackingTASK" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D62C7F31-EECE-40FB-AACE-FD37116802B9}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D62C7F31-EECE-40FB-AACE-FD37116802B9}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser Task" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D7961A06-DAD4-4B3E-9A60-9B82D133F5FC}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7961A06-DAD4-4B3E-9A60-9B82D133F5FC}" => eliminado correctamente
C:\windows\System32\Tasks\{54167D85-7CB6-443D-805E-7BFF8B1E844F} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{54167D85-7CB6-443D-805E-7BFF8B1E844F}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE2C859E-279C-4115-A7C0-F25FA89CF22B}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE2C859E-279C-4115-A7C0-F25FA89CF22B}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\User_Feed_Synchronization-{BAC3944D-7C78-4B3D-9863-20FC40B19BC9}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DE65BF18-4593-47FF-A599-81C9595A90F7}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DE65BF18-4593-47FF-A599-81C9595A90F7}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E129F494-CD81-4737-8D49-953CAAB06211}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E129F494-CD81-4737-8D49-953CAAB06211}" => eliminado correctamente
C:\windows\System32\Tasks\{AC72203C-7D2B-47BC-88C2-279BD4ED6374} => movido correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AC72203C-7D2B-47BC-88C2-279BD4ED6374}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F437A0E7-173B-4764-9D82-CA5FD8EE54E1}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F437A0E7-173B-4764-9D82-CA5FD8EE54E1}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MotoHelper Update" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{F67912CA-84DF-4653-8721-E6E996AB93F8}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F67912CA-84DF-4653-8721-E6E996AB93F8}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => eliminado correctamente
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector" => eliminado correctamente
C:\windows\Tasks\AutoKMS.job => movido correctamente
C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001Core.job => movido correctamente
C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-348586771-676038775-713973424-1001UA.job => movido correctamente
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => valor restaurado correctamente
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => eliminado correctamente
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => valor restaurado correctamente
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => eliminado correctamente
"HKU\S-1-5-21-348586771-676038775-713973424-1003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => eliminado correctamente
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => eliminado correctamente
HKLM\Software\Classes\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => eliminado correctamente
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => eliminado correctamente
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => eliminado correctamente
HKLM\Software\Wow6432Node\MozillaPlugins\@canon.com/UCPlugin => eliminado correctamente
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.25.2 -> C:\windows\SysWOW64\npDeployJava1.dll [2013-07-08] (Oracle America, Inc." => no encontrado
C:\windows\SysWOW64\npDeployJava1.dll => movido correctamente
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => eliminado correctamente
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => eliminado correctamente
HKLM\System\CurrentControlSet\Services\ElbyCDIO => eliminado correctamente
ElbyCDIO => servicio eliminado correctamente
HKLM\System\CurrentControlSet\Services\lmimirr => eliminado correctamente
lmimirr => servicio eliminado correctamente
C:\Users\Gabriela\AppData\Local\{3ED27979-CD66-4AA4-B2B1-98EA03D8E978} => movido correctamente
C:\Windows\System32\Drivers\etc\hosts => movido correctamente
Hosts restaurado correctamente.

========= RemoveProxy: =========

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente
"HKU\S-1-5-21-348586771-676038775-713973424-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => eliminado correctamente
"HKU\S-1-5-21-348586771-676038775-713973424-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => eliminado correctamente


========= Final de RemoveProxy: =========


========= netsh winsock reset =========


El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= Final de CMD: =========


========= ipconfig /renew =========


Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Conexi¢n de red inal mbrica 3 mientras los medios
est‚n desconectados.
No se puede realizar ninguna operaci¢n en Conexi¢n de  rea local mientras los medios
est‚n desconectados.

Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica 3:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica:

   Sufijo DNS espec¡fico para la conexi¢n. . : 
   Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.1.38
   M scara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.1.1

Adaptador de Ethernet Conexi¢n de  rea local:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

========= Final de CMD: =========


========= ipconfig /flushdns =========


Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= Final de CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to connect to BITS - 0x8007042c

========= Final de CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= Final de CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= Final de CMD: =========


========= netsh int ipv4 reset =========

Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


========= netsh int ipv6 reset =========

Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.


========= Final de CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 12582912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12284832 B
Java, Flash, Steam htmlcache => 1078 B
Windows/system/drivers => 108262 B
Edge => 0 B
Chrome => 44148041 B
Firefox => 61057464 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 33125 B
Public => 33125 B
ProgramData => 33125 B
systemprofile => 15469270 B
systemprofile32 => 15617699 B
LocalService => 15716840 B
NetworkService => 15749965 B
Gabriela => 22547399 B
DefaultAppPool => 22580524 B

RecycleBin => 0 B
EmptyTemp: => 226.9 MB datos temporales eliminados.

================================


El sistema necesita reiniciarse.

==== Final de Fixlog 13:54:48 ====

Hola.

Bien y ahora sigue los pasos que se dan aquí :arrow_right: Manual de HitmanPro , cuando termines nos pones el informe y REINICIAS El equipo.

Saludos.

Hola. Pasé el programa HitmanPro (cuando quise hacer el proceso, el mouse casi no andaba), creo que encontró una sóla amenaza real, el resto no parecían ofensivos pero igualmente los eliminó. No me pidió reiniciar la computadora pero igualmente lo hice. Al reiniciarse me preguntó qué sistema operativo quería iniciar, teniendo sólo la opción de windows 7. Le di enter (el del teclado numérico porque el otro no me anda ni en esa parte) y lamentablemente me volvió a suceder que no inició. Luego de tenerla 5 horas en pantalla de inicio decidí apagarla, ya que la computadora tiene un indicador de cuando el procesador está trabajando y ya estaba apagada hace mucho tiempo. No pude iniciarla normalmente por lo que tuve que iniciarla en modo seguro a prueba de fallos Pude ver que las teclas que fallan poniendo dos caracteres, en este modo ni siquiera responden.

Todo esto (teclado, mouse y fallas en el inicio del windows) puede deberse a un virus?

En el siguiente mensaje pego el log del programa

HitmanPro 3.8.18.312
www.hitmanpro.com

   Computer name . . . . : HP
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : HP\Gabriela
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Trial (32 days left)

   Scan date . . . . . . : 2020-05-13 20:53:46
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 6m 24s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 1
   Traces  . . . . . . . : 468

   Objects scanned . . . : 2.699.171
   Files scanned . . . . : 143.411
   Remnants scanned  . . : 813.757 files / 1.742.003 keys

Suspicious files ____________________________________________________________

   C:\Users\Gabriela\Desktop\FRST64.exe
      Size . . . . . . . : 2.286.080 bytes
      Age  . . . . . . . : 0.3 days (2020-05-13 12:38:50)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : E453A641E96BA8DB3E94D670E102E128B25353D52489E4926C4A10B0E3792192
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      References
         HKU\S-1-5-21-348586771-676038775-713973424-1003\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Users\Gabriela\Desktop\FRST64.exe


Malware remnants ____________________________________________________________

   HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}\ (Jotzey) -> Deleted

Potential Unwanted Programs _________________________________________________

   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ar\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ar\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\be\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\be\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\bg\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\bg\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\bn\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\bn\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ca\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ca\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\cs\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\cs\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\da\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\da\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\de\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\de\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\el\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\el\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\en\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\en\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\en_GB\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\en_GB\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\es\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\es\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\et\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\et\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\fa\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\fa\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\fi\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\fi\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\fr\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\fr\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\he\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\he\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\hi\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\hi\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\hr\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\hr\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\hu\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\hu\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\id\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\id\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\it\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\it\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ja\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ja\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ko\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ko\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\lt\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\lt\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\lv\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\lv\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ms\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ms\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\nb\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\nb\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\nl\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\nl\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\pl\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\pl\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\pt_BR\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\pt_BR\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\pt_PT\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\pt_PT\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ro\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ro\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ru\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ru\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sk\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sk\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sl\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sl\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sr\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sr\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sv\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\sv\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\th\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\th\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\tr\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\tr\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\uk\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\uk\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ur\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\ur\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\vi\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\vi\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\zh_CN\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\zh_CN\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\zh_TW\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_locales\zh_TW\messages.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_metadata\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\_metadata\verified_contents.json (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\burger.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\csl.parser.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\eventemitter2.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\jquery.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\lodash.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\mustache.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\protobuf.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\libs\q.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\bal.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\gpb.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\ial.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\options.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\query.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\templates.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\usettings.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\scripts\wrc.js (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\css\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\css\extension.css (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\css\options.css (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-Bold.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-BoldItalic.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-ExtraBold.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-ExtraBoldItalic.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-Italic.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-Light.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-LightItalic.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-Regular.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-SemiBold.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\asp-open-sans\OpenSans-SemiBoldItalic.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\fonts.css (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-300.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-300.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-300.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-300.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-300.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-600.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-600.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-600.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-600.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-600.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-700.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-700.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-700.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-700.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-700.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-regular.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-regular.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-regular.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-regular.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\open-sans\open-sans-v15-latin_latin-ext-regular.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-500.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-500.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-500.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-500.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-500.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-700.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-700.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-700.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-700.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-700.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-regular.eot (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-regular.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-regular.ttf (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-regular.woff (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\fonts\roboto\roboto-v18-latin-regular.woff2 (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\ (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Anim-Coupons-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Anim-Deals-Coupons-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Anim-Deals-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Anim-Hotels-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\arrow-feedback.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\arrow-rate.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\arrow.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\arrow.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\arrowDI.svg (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\avast-logo-opt-in.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\back.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Car-Rental-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Car-Rental.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\checkbox-checked.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\checkbox-unchecked.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\checkmark-icon.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\close-icon-copy-8.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\close-tooltip-image.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\combined-shape-offers.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\coupons-default.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Coupons-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\dark-star.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\dashed-line.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Deals-Coupons-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Deals-Horizontal.gif (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Default-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\default-offers.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Default.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Electricity-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Electronics-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\fbLogo5x11.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\fbLogo5x11HoverAndActive.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Flights-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Flights.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Gas-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\general.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\half-star.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Health-Insurance-90x30.png (Avast.SafePrice) -> Deleted
   C:\Users\Gabriela\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck\20.1.1601_0\common\ui\icons\Health-Insurance.png (Avast.SafePrice) -> Deleted