Windows 7 e internet muy lento. Desespera hacer algo

No tengo windows original. Mi disco C es de 174 gigas. De los cuales hay libres actualmente 40 gigas. El disco D: que es la particion tiene en total 290 gigas, de los cuales hay libres 50 gigas. El Chequeo CHkdsk ha durado 1 hora y media. Tengo un monton de errores de diferentes numeros id. Te envio el analisis de todo lo que sale en Aplicaciones. Voy a intentar buscar lo que me pides. O por favor dime que es lo que necesitas para hacerlo bien y cuanto antes…

Nombre de registro:Application
Origen:        Microsoft-Windows-Wininit
Fecha:         14/12/2019 23:02:30
Id. del evento:1001
Categoría de la tarea:Ninguno
Nivel:         Información
Palabras clave:Clásico
Usuario:       No disponible
Equipo:        palote-PC

ES QUE ME QUEDAN MAS DE 45 ERRORES DE ESOS. DEBO DE ENVIARTE TODOS??? No quiero colapsar. solo dime si sigo enviandote todos los que me quedan. He seguido las instrucciones. pero es que me quedan mas de 50 errores. Pero si hay que hacerlo lo hago. No hay problema.


Con poner el único que YO acabo de dejar era suficiente, era cuestion de fijarse ademas de en :

Y lógicamente con el detalle-contenido del informe de ejemplo.

No parece que TU disco o su estructura lógica de índices este muy afectado en sus distintas fases :

Ahora quiero que revises con otra herramienta tu disco para verificar que NO tengas otro tipo de problemas en esos trozos del disco.

  • Descarga Hard Disk Sentinel Professional Trial v5.50 (ZIP) >> desde aquí (y guárdalo en tu escritorio).
  • Descomprime el fichero zip en una carpeta y ejecútalo.
  • Adjunta en tu próxima respuesta una captura de pantalla, donde se aprecie la pantalla principal de este programa, es decir, abre el programa y captura la primera pantalla que te dé. No des clic en ninguna opción dentro de él.
  • Si NO puedes hacer la instalación desde el modo normal de windows hazlo desde el modo seguro. :face_with_raised_eyebrow:

Para subir una imagen sigue estos pasos :arrow_right: Como Insertar una imagen.


Lo he hecho en modo normal.

Aunque va muy lento todavia. He notado algo de mejoria. Chrome muy lento tambien, pero al escribir algo parece que responde en menos tiempo que antes. Pero va de pena todavia.

Tengo el programa abierto segun las fotos que te he enviado hasta que me digais que debo hacer. GRacias


Pues parece que NO son problemas de tu disco duro, NO presenta errores NI haciendo la comprobacion desde windows con CHKDSK, NI tampoco conHard Disk Sentinel. :thinking:

Lo más lógico es que sea un problema de Windows o que sea de algun programa/software que hayas instalado recientemente o que hubiese alguna actualizacion que lo pueda provocar. :roll_eyes:

Desde que momento te están pasando estos problemas exactamente…??

Has tenido algún antivirus instalado que hayas desinstalado recientemente y sustituido por otro…??

Instalaste algun programa/software recientemente que pueda coincidir con este problema…??

Me pasa desde el dia 9. Estuve buscando y descargue adobe photoshop 2014 y camera raw. Instalñe camara raw, Pero no lo puedo desinstalar porque no me aparece como instalado. Ni camara raw ni el adobe photoshop 2014. Instalé adwcleanner y malwrebytes. y Eset online. Deberia de quitar todos los registros de todo eso. No es asi??? A ver que tal va. Pero no se como hacerlo. Me imagino que será manual. buscando las carpetas e ir eliminandolas. No es asi?? El único programa que me aparece instalado en Programas y caracteristicas es el hard disk sentinel y el Malwarebytes version 4. Ademas tambien pasé la herramienta Hitmanpro. Pero no pude desinfectar nada de todo lo que salia porque se necesitaba algun codigo. Gracias por vuestra ayuda. A ver si puedo desinfectarlo del todo. Ademas tengo el antivirus de microsoft esential. Va lento todavia. Pero interntet va demasiado. Es eterno abrir una pagina. Y no te digo nada si quiero abrir varias cosas a la vez.

Bien… pues haces lo siguiente, descarga e instala este programa :arrow_right: Manual de Revo Uninstaller :+1:

Y úsalo para desinstalar todos aquellos programas que TU quieras y que puedas ver con este programa.

Cuando Revo te pida, que selecciones el método de desinstalación, seleccionas “Avanzado”.

Si durante el proceso te solicita “Reiniciar” NO lo hagas, dile que NO y deja que Revo siga trabajando.

Cuando termines todos los procesos de desinstalación ya REINICIAS tú el ordenador.

Compruebas el funcionamiento y nos comentas.


Ayer utilice Revo. Desinstalé Malwarebytes y

y cual es la sorpresa que en Programas y caracteristicas no aparece. Pero está en inicio junto a su desistalador. Y cuando le doy a desinstalar, se queda bloqueado y no se desinstala. El ordenador sigue igual. Te envio un par de fotos, para que lo veas. No soy capaz de desinstalarlo. PUEDO INTENTAR HACER LO QUE SEA DESDE EL MODO PRUEBA DE FALLOS??? Porque este ordenador va fatal. y desdespera. Quiero desinstalar todo lo que sea, borrar el eset online, quiero borrar las carpetas de lo que instalé. a ver si es que está infectado en algun sitio de esos.


Usa RevoUninstaller desde el modo seguro de windows… :+1:

Para desinstalar cualquier programa NO solo se deben eliminar las carpetas de forma manual, esa manera de hacerlo es totalmente incorrecta, :-1:.

SI desde Windows NO se deja o NO se puede por la razón que sea, lo que se debe usar son programas alternativos que realizan la desinstalación TOTAL del programa, como puede ser RevoUninstaller.

Que despues de usar RevoUninstaller te puedan quedar o aparecer alguna entrada o resto de Malwarebytes o de cualquier otro antivirus es algo normal, basicamente por ser los antivirus “programas” bastante “rebeldes” en sus procesos de desinstalación.

Por eso la gran mayoría de fabricantes de antivirus disponen-proporcionan herramientas específicas para poder realizar la desinstalación “completa” de ese tipo de programas, por aqui te dejo una pagina nuestra con la recopilación de los más usuales :

:arrow_right: Herramientas de desinstalación de Antivirus, AntiSpyware y Firewall

En él encontrarás dos programas específicos para Malwarebytes, usa los dos, uno a uno, y después de usar cada uno de ellos REINICIA.

Despues entras en modo seguro de windows de nuevo y vuelves a usar RevoUninstaller para seguir desinstalando todo aquel programa que encuentres y quieras eliminar.


Buenas de nuevo. Al final he conseguido que vaya mucho mejor. Lo que hice fue utilizar el programa Revo . Desinstalé los antivirus que tenia restos de antes y e Hice todo lo que me mandasteis, También limpié archivos basura con Revo, y evidencias con Revo. Y por último Eliminacion irrecuperable. Bueno, Que limpié casi todo. También desinstalé el chrome y un el adobe photoshop que habia instalado ultimo por si acaso. Me queda quitar restos de programas que estan en C: Ejemplo Hard Disk Sentinel y Hitman Pro 3.8 y algun restos como mbamtray.exe de Malwarebytes en C:, tambien Farbar Recovery Scan tool (de First64) No se como desinstalar estos programas y lo más importante. He hecho 2 veces lo de desinstalar malwarebytes y nada de nada. te mando el último reporte:

Excelente. :+1:

Que restos de antivirus tenias…??

Que antivirus has dejado operativo…??

Correcto. :clap:

Esos programas deberias poder verlos desde Revouninstaller… :thinking:

Ese resto donde te aparece y te sigue apareciendo después de usar las dos herramientas específicas de Malwarebytes…??

Los programas o herramientas o al menos la gran mayoría que nosotros te indicamos de momento NO las elimines por si todavía las necesitamos, y YA te daremos instrucciones finales para poder eliminarlas.

Según el informe que pones de Malwarebytes éste YA no debe estar NI en tu ordenador NI tampoco debe figurar desde Revouninstaller, otra cosa es que por el mal funcionamiento de tu equipo haya quedado algún resto de él.

Pero de eso NO te preocupes porque con FRST podemos ver lo que queda de esos restos u otros y eliminarlos.


He vuelto a pasar el First.exe. He visto que tengo esto y se supone que he desinstalado. Podria intervenir para que vaya lento mi pc???

C:\Windows\Tasks\AdwCleaner_onReboot.job Task: {21AB56F4-A2E1-449B-A1E1-3FB111E310FD} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-12-2019
Ran by palote (administrator) on PALOTE-PC (Packard Bell EasyNote TS11HR) (18-12-2019 17:12:18)
Running from C:\Users\palote\Desktop
Loaded Profiles: palote (Available Profiles: palote)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Paquete de controladores de Windows - Sony Mobile Communications (ggsomc) SOMCFlashDevice  (12/06/2017 (HKLM\...\7AA77B236196DB9A6C04257060560ACDBB626F30) (Version: 12/06/2017 - Sony Mobile Communications)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PMB_ModeEditor (HKLM-x32\...\{F8063714-BD75-42DC-8FAA-D0E1EED92519}) (Version: 11.0.00 - Sony Corporation) Hidden
PMB_ServiceUploader (HKLM-x32\...\{CF081855-ED80-445A-BF63-025584939230}) (Version: 11.0.00 - Sony Corporation) Hidden
Real DVD Studio II (HKLM-x32\...\{5B6455A4-E812-479B-A762-C2356244CF97}) (Version: 1.00.0000 - NPG) Hidden
Real DVD Studio II (HKLM-x32\...\InstallShield_{5B6455A4-E812-479B-A762-C2356244CF97}) (Version: 1.00.0000 - NPG)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: - Renesas Electronics Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: - Renesas Electronics Corporation)
Revo Uninstaller 2.1.0 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.1.0 - VS Revo Group, Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: - Samsung Electronics Co., Ltd.)
Servicio Xperia Companion (HKLM\...\{ED9C6E7D-FA20-4FA0-BC6E-3D05703B03C5}) (Version: - Sony) Hidden
SketchUp Import for AutoCAD 2014 (HKLM-x32\...\{644E9589-F73A-49A4-AC61-A953B9DE5669}) (Version: 1.1.0 - Autodesk)
Software Intel® PROSet/Wireless WiMAX (HKLM\...\{FBCA6D68-2FBE-4A52-8EAA-856CFEA714C8}) (Version: 6.01.0000 - Intel Corporation)
Sony Mobile Software Update Drivers (HKLM\...\{4872001F-F67C-4C54-BC92-281C6A165251}) (Version: - Sony Mobile Communications)
Sony Mobile Update Engine (HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Update Engine) (Version: - Sony Mobile Communications Inc.)
Sony PC Companion 2.10.094 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.094 - Sony)
SoundTrax (HKLM-x32\...\{3097B151-1F61-4211-A4CC-D70127B226AE}) (Version: - Nero AG) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: - Synaptics Incorporated)
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: - 2BrightSparks)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.2.26558 - TeamViewer)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 3.88 - NCH Software)
Virtual DJ Pro Full - Atomix Productions (HKLM-x32\...\Virtual DJ Pro Full - Atomix Productions) (Version:  - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
WBFS Manager 4.0 (HKLM\...\{D34C07CA-DCF0-4A5C-A4DD-55522B17F4F2}) (Version: 4.0 - WBFS)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wondershare Filmora(Build 8.3.1) (HKLM\...\Wondershare Filmora_is1) (Version:  - Wondershare Software)
Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare Video Converter Ultimate(Build (HKLM-x32\...\Wondershare Video Converter Ultimate_is1) (Version: - Wondershare Software)
Wondershare Video Studio Express(Build (HKLM-x32\...\Wondershare Video Studio Express_is1) (Version:  - Wondershare Software)
Xperia Companion (HKLM-x32\...\{dd23851d-6b5f-4299-9299-7fa29040d157}) (Version: - Sony)
Xperia Companion (HKLM-x32\...\{E1C58CBB-69AA-4E5F-B464-8A633811D4BC}) (Version: - Sony) Hidden

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3253742837-1388098199-733594754-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\palote\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3253742837-1388098199-733594754-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\palote\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3253742837-1388098199-733594754-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\palote\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation -> Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3253742837-1388098199-733594754-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\palote\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation -> Microsoft Corporation)
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2217832 2009-02-26] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll [2008-09-19] (Nero AG -> Nero AG)
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [FormatFactoryShell] -> {A3777921-CFD3-4A6B-89BF-08E6B95716E8} => C:\Program Files (x86)\FreeTime\FormatFactory\ShellEx64_101.dll [2012-01-20] (Free Time) [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal) [File not signed]
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2012-06-09] (Alexander Roshal) [File not signed]
ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\Windows\SysWOW64\WSCM64.dll [2012-11-15] (Wondershare Software Co., Ltd.  -> )
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers4: [FormatFactoryShell] -> {A3777921-CFD3-4A6B-89BF-08E6B95716E8} => C:\Program Files (x86)\FreeTime\FormatFactory\ShellEx64_101.dll [2012-01-20] (Free Time) [File not signed]
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2018-01-19] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll [2006-10-22] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2012-06-09] (Alexander Roshal) [File not signed]
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2012-06-09] (Alexander Roshal) [File not signed]

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [File not signed]
HKLM\...\Drivers32: [vidc.MPG4] => C:\Windows\SysWOW64\MPG4c32.dll [413760 2001-09-20] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.MP42] => C:\Windows\SysWOW64\MPG4c32.dll [413760 2001-09-20] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.MP43] => C:\Windows\SysWOW64\MPG4c32.dll [413760 2001-09-20] (Microsoft Corporation) [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]
==================== Loaded Modules (Whitelisted) =============

2006-11-17 03:47 - 2006-11-17 03:47 - 003387392 _____ () [File not signed] c:\program files (x86)\adobe\acrobat 8.0\acrobat\exlang32.esp
2006-11-17 03:21 - 2006-11-17 03:21 - 000077824 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Accessibility.ESP
2006-11-17 03:22 - 2006-11-17 03:22 - 000802816 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\AcroForm.ESP
2006-11-17 03:23 - 2006-11-17 03:23 - 000009728 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ADBC.ESP
2006-11-17 03:24 - 2006-11-17 03:24 - 001216512 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Annots.ESP
2006-11-17 03:24 - 2006-11-17 03:24 - 000053248 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Catalog.ESP
2006-11-17 03:24 - 2006-11-17 03:24 - 000192512 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Checkers.ESP
2006-11-17 03:25 - 2006-11-17 03:25 - 000217088 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\DigSig.ESP
2006-11-17 03:25 - 2006-11-17 03:25 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\DistillerPI.ESP
2006-11-17 03:26 - 2006-11-17 03:26 - 000028672 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\eBook.ESP
2006-11-17 03:26 - 2006-11-17 03:26 - 000212992 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Editor.ESP
2006-11-17 03:27 - 2006-11-17 03:27 - 000098304 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\EScript.ESP
2006-11-17 03:27 - 2006-11-17 03:27 - 000006656 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\EWH32.ESP
2006-11-17 03:27 - 2006-11-17 03:27 - 000013312 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\HLS.ESP
2006-11-17 03:28 - 2006-11-17 03:28 - 000061440 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\HTML2PDF.ESP
2006-11-17 03:28 - 2006-11-17 03:28 - 000102400 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ImageConversion.ESP
2006-08-31 09:28 - 2006-08-31 09:28 - 000008192 ____R () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\InDesignPI.ESP
2006-11-17 03:29 - 2006-11-17 03:29 - 000245760 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\JDFProdDef.ESP
2006-11-17 03:29 - 2006-11-17 03:29 - 000086016 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\MakeAccessible.ESP
2006-11-17 03:29 - 2006-11-17 03:29 - 000159744 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Multimedia.ESP
2006-11-17 03:30 - 2006-11-17 03:30 - 000045056 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\PaperCapture.ESP
2006-11-17 03:30 - 2006-11-17 03:30 - 000011264 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\PDDom.ESP
2006-11-17 03:31 - 2006-11-17 03:31 - 000954368 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\PPKLite.ESP
2006-11-17 03:32 - 2006-11-17 03:32 - 000013312 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ReadOutLoud.ESP
2006-11-17 03:32 - 2006-11-17 03:32 - 000008704 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\reflow.ESP
2006-11-17 03:32 - 2006-11-17 03:32 - 000028672 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\SaveAsRTF.ESP
2006-11-17 03:32 - 2006-11-17 03:32 - 000019456 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\SaveAsXML.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000098304 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Scan.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000053248 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Search.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000011776 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Search5.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000032768 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\SendMail.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000036864 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Spelling.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\TablePicker.ESP
2006-11-17 03:34 - 2006-11-17 03:34 - 000176128 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\TouchUp.ESP
2006-11-17 03:33 - 2006-11-17 03:33 - 000005632 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Updater.ESP
2006-11-17 03:34 - 2006-11-17 03:34 - 000049152 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\weblink.ESP
2006-11-17 03:34 - 2006-11-17 03:34 - 000139264 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\WebPDF.ESP
2006-11-17 03:34 - 2006-11-17 03:34 - 000012800 _____ () [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\XPS2PDF.ESP
2018-07-05 16:25 - 2018-07-05 16:27 - 098275328 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2018-07-05 16:27 - 2018-07-05 16:27 - 000092672 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2018-07-05 16:27 - 2018-07-05 16:27 - 003922432 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2006-08-02 07:52 - 2006-08-02 07:52 - 000126976 ____R (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\asneu.dll
2006-10-23 01:10 - 2006-10-23 01:10 - 000467555 _____ (Adobe Systems Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ImageViewer.API
2006-10-23 01:24 - 2006-10-23 01:24 - 000671744 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\ACE.dll
2006-09-14 23:20 - 2006-09-14 23:20 - 000212992 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_epic.dll
2006-09-14 23:46 - 2006-09-14 23:46 - 000208896 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_pcd.dll
2006-09-14 23:20 - 2006-09-14 23:20 - 000346112 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\adobe_personalization.dll
2006-10-11 01:06 - 2006-10-11 01:06 - 000466944 ____R (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AdobeLinguistic.dll
2006-10-23 01:24 - 2006-10-23 01:24 - 004883456 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AGM.dll
2006-10-23 01:25 - 2006-10-23 01:25 - 000098816 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\BIB.dll
2006-10-23 01:26 - 2006-10-23 01:26 - 002281472 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\CoolType.dll
2006-10-23 01:09 - 2006-10-23 01:09 - 000352867 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Accessibility.api
2006-10-23 01:11 - 2006-10-23 01:11 - 007147107 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\AcroForm.api
2006-10-23 01:09 - 2006-10-23 01:09 - 000067683 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ADBC.api
2006-10-23 01:10 - 2006-10-23 01:10 - 004099171 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Annots.api
2006-10-23 01:09 - 2006-10-23 01:09 - 000224355 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Catalog.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000838755 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Checkers.api
2006-10-23 01:10 - 2006-10-23 01:10 - 001141859 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\DigSig.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000089187 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\DistillerPI.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000125027 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\DVA.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000050787 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\eBook.api
2006-10-23 01:11 - 2006-10-23 01:11 - 002932323 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Editor.api
2006-10-23 01:10 - 2006-10-23 01:10 - 001367651 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\EScript.api
2006-10-23 01:11 - 2006-10-23 01:11 - 000124003 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\EWH32.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000051299 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\HLS.api
2006-10-23 01:12 - 2006-10-23 01:12 - 002179171 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\HTML2PDF.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000083555 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\IA32.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000841827 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ImageConversion.api
2006-10-23 01:10 - 2006-10-23 01:10 - 000082019 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\InDesignPI.api
2006-10-23 01:20 - 2006-10-23 01:20 - 000778339 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\JDFProdDef.api
2006-10-23 01:11 - 2006-10-23 01:11 - 002028643 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\MakeAccessible.api
2006-10-23 01:11 - 2006-10-23 01:11 - 001343587 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Multimedia.api
2006-10-23 01:20 - 2006-10-23 01:20 - 000164451 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\PaperCapture.api
2006-10-23 01:19 - 2006-10-23 01:19 - 000397411 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\PDDom.api
2006-10-23 01:12 - 2006-10-23 01:12 - 006076003 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\PPKLite.api
2006-10-23 01:20 - 2006-10-23 01:20 - 000106595 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\ReadOutLoud.api
2006-10-23 01:21 - 2006-10-23 01:21 - 000362595 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\reflow.api
2006-10-23 01:20 - 2006-10-23 01:20 - 000300643 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\SaveAsRTF.api
2006-10-23 01:20 - 2006-10-23 01:20 - 000335459 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\SaveAsXML.api
2006-10-23 01:22 - 2006-10-23 01:22 - 000740963 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Scan.api
2006-10-23 01:21 - 2006-10-23 01:21 - 000352355 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Search.api
2006-10-23 01:21 - 2006-10-23 01:21 - 000085091 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Search5.api
2006-10-23 01:21 - 2006-10-23 01:21 - 000124515 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\SendMail.api
2006-10-23 01:21 - 2006-10-23 01:21 - 000267875 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Spelling.api
2006-10-23 01:22 - 2006-10-23 01:22 - 000124003 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\TablePicker.api
2006-10-23 01:22 - 2006-10-23 01:22 - 001773667 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\TouchUp.api
2006-10-23 01:22 - 2006-10-23 01:22 - 000157795 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Updater.api
2006-10-23 01:22 - 2006-10-23 01:22 - 000182883 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\weblink.api
2006-10-23 01:12 - 2006-10-23 01:12 - 000662115 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\WebPDF.api
2006-10-23 01:22 - 2006-10-23 01:22 - 001461859 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\XPS2PDF.api
2006-10-23 01:33 - 2006-10-23 01:33 - 002457600 _____ (Adobe Systems, Inc.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Adobelm.dll
2018-01-25 17:22 - 2012-06-09 19:20 - 000196096 _____ (Alexander Roshal) [File not signed] C:\Program Files\WinRAR\rarext.dll
2006-10-06 12:43 - 2006-10-06 12:43 - 000554083 ____R (callas software gmbh) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Preflight.api
2006-11-17 03:31 - 2006-11-17 03:31 - 000004608 _____ (Callas Software GMBH) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\plug_ins\Preflight.ESP
2012-01-20 12:45 - 2012-01-20 12:45 - 000086016 _____ (Free Time) [File not signed] C:\Program Files (x86)\FreeTime\FormatFactory\ShellEx64_101.dll
2010-11-07 11:01 - 2010-11-07 11:01 - 000506368 _____ (Intel(R) Corporation) [File not signed] C:\Windows\system32\iWmxSDK.dll
2010-11-07 10:54 - 2010-11-07 10:54 - 000222720 _____ (Intel(R) Corporation) [File not signed] C:\Windows\system32\PipeHandler.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000057344 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\es\WiMAXCU.resources.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000005120 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\es\WiMAXCU_UICustomControls.resources.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000009216 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\es\WiMAXCU_UIDisplayWiMAX.resources.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000061440 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_BizTier.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000061440 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_Common.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000073728 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_ServicePublisher.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000811008 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_UICustomControls.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000081920 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_UIDisplayWiMAX.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000297472 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_WiFiCoEx.dll
2010-11-14 11:22 - 2010-11-14 11:22 - 000081920 _____ (Intel® Corporation) [File not signed] C:\Program Files\Intel\WiMAX\Bin\WiMAXCU_WiMAXSDKInterop.dll
2006-10-23 01:33 - 2006-10-23 01:33 - 002531328 _____ (Macrovision Europe Ltd.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcrobatFNP.dll
2006-09-15 13:58 - 2006-09-15 13:58 - 000934400 ____R (Macrovision Europe Ltd.) [File not signed] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\FNP_Act_Installer.dll
2018-03-07 15:56 - 2018-03-07 15:56 - 001630720 _____ (SQLite Development Team) [File not signed] C:\Program Files\Intel\SUR\QUEENCREEK\x64\sqlite3.dll
2018-07-05 16:25 - 2018-07-05 16:25 - 000547840 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Windows:0504E1FDA6C88148 [50]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMInstallerService => ""="Service"

==================== Association (Whitelisted) =================

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1"

==================== Internet Explorer trusted/restricted ==========

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\localhost -> localhost

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2019-10-27 22:51 - 000000963 _____ C:\Windows\system32\drivers\etc\hosts          

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files\Calibre2\
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\palote\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{48FEF9F1-4AE2-4976-8608-76C62D30A07E}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel(R) Corporation) [File not signed]
FirewallRules: [{2C8FB6A9-2F26-460D-A9D6-56F3547E0066}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel(R) Corporation) [File not signed]
FirewallRules: [{4A689A11-1060-4CD1-B067-EBF0D3CC8C23}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.) [File not signed]
FirewallRules: [{36741235-577A-485E-915D-13930D9764E7}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.) [File not signed]
FirewallRules: [{4CA2F73D-B8FF-4C63-8479-A32AC1523929}] => (Allow) C:\Users\palote\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{850BC3B4-2EC4-408F-9BBC-1A12116402D6}] => (Allow) C:\Users\palote\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{06348DD1-D61C-4F04-BB8A-DDB30B88D149}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{A7780E03-97C4-4D8C-9955-16DB763B67F4}] => (Block) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{207FA9CA-CFE9-4EF2-9CBC-015A3A162CC5}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [{3560CD12-9443-42D4-A0C8-45E9FF7B238B}] => (Allow) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv_svc.exe (Intel(R) Software Development Products -> )
FirewallRules: [TCP Query User{CD64DC20-832A-4C1B-83B5-ED59A824B564}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{180A9278-7187-441F-985F-747BDCB44ADD}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{A4A517E2-0FA2-4B78-BCE4-445405AB8D1A}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{D516FDFA-93FE-4229-B3FA-F908BC5FB601}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{95AE8065-8436-4060-BA03-5D452767315C}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{BF2106E5-5B8E-4EAA-A7C5-94B376E22AE4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{849FF062-5805-48D8-9255-7161FCD084CE}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{1638B22A-E256-4702-9E46-ECE31EBE1321}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{A46AE097-3EE1-4CE6-A7F2-FA327AF8ED9B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C39588D7-A2BA-4F63-A746-7A34DE40DBCE}] => (Allow) C:\Users\palote\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7516BB06-CA72-40BD-A15D-9070C4C65A68}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2B662B60-D857-44A6-B851-8AF74DBFB421}] => (Allow) LPort=2869
FirewallRules: [{48A91FA4-1473-4868-87C7-737639AA9D91}] => (Allow) LPort=1900
FirewallRules: [{63654DA4-3B9C-418E-94B6-73EF9E049995}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{9A3F897E-600B-4E96-98B6-21920ED15C12}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{41ACA3CB-F21F-4C15-8C87-A3AE599D7B8E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{5AC34B7B-7736-489A-A31B-9076525572B4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{F3C257D0-2995-4FEE-B663-B57DC23CAD6C}] => (Allow) C:\Program Files\HP\HP Officejet 7500 E910\bin\FaxApplications.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{95FF04D1-5F5D-489A-85E6-F565688E9F5F}] => (Allow) C:\Program Files\HP\HP Officejet 7500 E910\bin\DigitalWizards.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{72A59829-B5D3-4587-A577-1855BF791840}] => (Allow) C:\Program Files\HP\HP Officejet 7500 E910\bin\SendAFax.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{6BDCD58D-8FAC-4283-A3A0-43107B86E44E}] => (Allow) C:\Program Files\HP\HP Officejet 7500 E910\Bin\DeviceSetup.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{0B8A7173-2BD9-4860-90B0-B841C7F5803C}] => (Allow) C:\Program Files\HP\HP Officejet 7500 E910\Bin\HPNetworkCommunicator.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{969837CF-B215-442E-9C92-CE1780C7CC50}] => (Allow) C:\Program Files\HP\HP Officejet 7500 E910\Bin\HPNetworkCommunicatorCom.exe (Hewlett Packard -> Hewlett-Packard Co.)
FirewallRules: [{E474A980-D3D2-41DB-B3FF-11FDB2B0FEF1}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{0A70AA9F-92DF-4C45-A308-4712AB127422}] => (Allow) C:\ProgramData\Sony Mobile\Update Engine\{8D2A56DB-ACD1-4868-865C-D48E3406598D}\Sony Mobile Update Engine.exe (Sony Mobile Communications AB -> )
FirewallRules: [{9FF85C59-8A29-4FD4-B1EF-8844FEE4353D}] => (Allow) C:\ProgramData\Sony Mobile\Update Engine\{8D2A56DB-ACD1-4868-865C-D48E3406598D}\Sony Mobile Update Engine.exe (Sony Mobile Communications AB -> )
FirewallRules: [TCP Query User{B809CF7C-B57C-467C-AC72-696D69804CDB}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{14E7CEB2-C3D0-4EDA-99ED-A2FF03D801C5}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{69CB3D56-EF3F-4015-BBA7-095E5526F9FE}] => (Allow) LPort=8317
FirewallRules: [{76C2E158-B600-473D-AF3D-85DB57D1975D}] => (Allow) C:\Program Files (x86)\Sony\Xperia Companion\XperiaCompanion.exe (Sony Mobile Communications AB -> Sony)
FirewallRules: [{C5FA2519-B8CA-48E8-9824-AA5B6662AB60}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)

==================== Restore Points =========================

16-12-2019 06:32:13 Revo Uninstaller's restore point - Google Chrome
17-12-2019 16:03:02 Windows Update

==================== Faulty Device Manager Devices ============

Name: WirelessKeyboardFilter_01
Description: WirelessKeyboardFilter_01
Class Guid: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Controladora Ethernet
Description: Controladora Ethernet
Class Guid: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: ========================

Application errors:
Error: (12/18/2019 04:48:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema.

Error: (12/17/2019 10:22:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema.

Error: (12/17/2019 10:15:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema.

Error: (12/17/2019 05:10:04 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa WINWORD.EXE, versión 12.0.6787.5000, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador de proceso: 6f4

Hora de inicio: 01d5b4f3c4e0faa9

Hora de finalización: 0

Ruta de acceso de la aplicación: C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE

Identificador de informe: a22fb864-20e7-11ea-9e35-eac7553f705a

Error: (12/17/2019 05:03:41 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema.

Error: (12/17/2019 04:41:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema.

Error: (12/17/2019 03:51:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema.

Error: (12/17/2019 01:25:04 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: Los Servicios de cifrado no pudieron inicializar el objeto "System Writer" de la copia de seguridad de VSS.

Could not query the status of the EventSystem service.

System Error:
Se está cerrando el sistema.

System errors:
Error: (12/18/2019 04:53:00 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 40.

Error: (12/18/2019 04:53:00 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 70.

Error: (12/18/2019 04:52:42 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 40.

Error: (12/18/2019 04:52:42 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 70.

Error: (12/18/2019 04:52:17 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: El servicio Energy Server Service queencreek no respondió después de iniciar.

Error: (12/18/2019 04:51:44 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 40.

Error: (12/18/2019 04:51:44 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Se recibió la siguiente alerta irrecuperable: 70.

Error: (12/18/2019 04:47:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Intel(R) System Usage Report Service SystemUsageReportSvc_QUEENCREEK no pudo iniciarse debido al siguiente error: 
El servicio no respondió a tiempo a la solicitud de inicio o de control.

==================== Memory info =========================== 

BIOS: Packard Bell V1.10 04/25/2011
Motherboard: Packard Bell SJV50_HR
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 83%
Total physical RAM: 3947.86 MB
Available physical RAM: 670.38 MB
Total Virtual: 7893.86 MB
Available Virtual: 4203.65 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:175 GB) (Free:37.9 GB) NTFS
Drive d: () (Fixed) (Total:290.66 GB) (Free:50.06 GB) NTFS

\\?\Volume{29eb5a16-fd59-11e7-a82f-806e6f6e6963}\ (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ====================

Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 59313647)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=175 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=290.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt =======================

Y quien te dijo que usaras de nuevo FRST…??

Lo que debes hacer es contestar las preguntas que tienes pendientes. :rage:

O sigues mis instrucciones o doy por terminado el tema y haces TU mismo lo que a ti te parezca. :triumph:


1 me gusta

En primer lugar decirte que tu mensaje al ir a trozos, ni me di cuenta de todo lo que ponías, leí el final del mensaje y como ponías lo de first que era para saber lo que había instalado, pues al no poner lo que tenia que hacer supuse que debería hacer eso. Ahora que he leído el mensaje que va por partes, decirte que: queda resto de avast software en task en System 32. queda restos de hard disk sentinel en C: Programa files x86 (no le veo con revounistaller) queda restos de malwarebites en C: programa files el antivirus que tengo es Microsoft security essential.


Hola @javisansegundo.

Veamos… precisamente mis respuestas van a “trozos” como tu dices, para ir respondiendo a las multiples cuestiones que cuentas y que te quede lo más claro y ordenado posible.

Cuando uno recibe un mensaje lo que debe hacer es posicionarse en el anterior(que será el tuyo) para releer lo que tú mismo dijiste y a continuación ver entero y completo el siguiente mensaje, con todas las respuesta, esa es la manera para NO perderse nada.

Claro…SI SOLO lees el final sacas las conclusiones que tu quieras, pero lo dicho, menos prisas y más leer tranquilamente TODO lo que te dicen, aplica lo que te habrá dicho tu abuela más de una vez…vísteme despacio que tengo prisa. :face_with_raised_eyebrow:

Nadie dice que vayas de listo, lo que debes IR es de LECTOR y seguidor de indicaciones, con calma y sin prisas de ningún tipo o hacer pasos por tu cuenta, somos un FORO y atendemos cuando podemos y sin tener delante nuestro a vuestros equipos lo que impide que podamos hacer de adivinos.

Necesitamos que seáis nuestros ojos y nos deis informes o respuesta a nuestras preguntas, NI más NI menos e iremos intentando daros instrucciones para poder ir avanzando poco a poco, aquí NO tenemos varitas mágicas y menos en equipos con tantos fallos y problemas como el tuyo.

Estudiaremos tus últimos informes y veremos qué indicaciones te damos.


Bien… y ahora sigue estos pasos, :arrow_forward: MUY Importante :arrow_backward: Realiza una copia de seguridad del registro :

  • Para hacerlo descarga :arrow_forward: DelFix.exe(en tu escritorio).

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona -Ejecutar como Administrador-).

  • Atención, ahora marca/selecciona únicamente la casilla :white_check_mark: Create registry backup, las demás casillas NO. :face_with_monocle:

  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.

:warning: Con los demás programas cerrados ve a :arrow_forward: Inicio :arrow_forward: Ejecutar :arrow_forward: y escribe Notepad.exe.

  • Ahora debes copiar y pegar los códigos/líneas que están en el interior del recuadro de más abajo, dentro del Notepad.
Advertising Center (HKLM-x32\...\{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}) (Version: - Nero AG) Hidden
DolbyFiles (HKLM-x32\...\{56BE5CC9-95E6-4128-ABEA-968414CA9C80}) (Version: 2.0 - Nero AG) Hidden
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: - Epic Games, Inc.) Hidden
Galería de fotos (HKLM-x32\...\{F7314CA2-F900-46D7-9EA1-FBDD9D73F765}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: - Nero AG) Hidden
Menu Templates - Starter Kit (HKLM-x32\...\{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}) (Version: - Nero AG) Hidden
Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{F25C8769-16B6-4B19-BB0B-76F213829AC6}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Templates - Starter Kit (HKLM-x32\...\{BCD82AB5-670D-4242-90FA-1F97103C16CD}) (Version: - Nero AG) Hidden
PMB_ModeEditor (HKLM-x32\...\{F8063714-BD75-42DC-8FAA-D0E1EED92519}) (Version: 11.0.00 - Sony Corporation) Hidden
Real DVD Studio II (HKLM-x32\...\{5B6455A4-E812-479B-A762-C2356244CF97}) (Version: 1.00.0000 - NPG) Hidden
Servicio Xperia Companion (HKLM\...\{ED9C6E7D-FA20-4FA0-BC6E-3D05703B03C5}) (Version: - Sony) Hidden
SoundTrax (HKLM-x32\...\{3097B151-1F61-4211-A4CC-D70127B226AE}) (Version: - Nero AG) Hidden
Xperia Companion (HKLM-x32\...\{E1C58CBB-69AA-4E5F-B464-8A633811D4BC}) (Version: - Sony) Hidden
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
AlternateDataStreams: C:\Windows:0504E1FDA6C88148 [50]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Run: [DriverMax] => [X]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Run: [DriverMax_RESTART] => [X]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Policies\Explorer: []
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {0ca4efe8-61c8-11e9-a6f6-b05bee847e5f} - F:\startme.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {53025a57-0adb-11ea-af64-f077d438f75c} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {5833cbe9-70d3-11e8-9a61-bccf7b3ad459} - G:\Setup.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {5833cbea-70d3-11e8-9a61-bccf7b3ad459} - G:\Setup.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {5833ccf9-70d3-11e8-9a61-bccf7b3ad459} - G:\shelexec.exe \index.htm
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {6d41e6f2-cbfd-11e8-9c9b-8595b2bb2c25} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {7934f69b-70ac-11e8-ba8f-bf4241aaae51} - G:\Setup.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {7a3cbb87-fb1b-11e9-96ed-968570daf421} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {f27181e7-be31-11e8-a5ce-8c630a438d5f} - G:\startme.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inicio rápido de Adobe Acrobat.lnk [2018-02-20]
ShortcutTarget: Inicio rápido de Adobe Acrobat.lnk -> C:\Windows\Installer\{AC76BA86-1040-7D00-7760-000000000003}\_SC_Acrobat.exe () [File not signed]
Task: {21AB56F4-A2E1-449B-A1E1-3FB111E310FD} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
Task: {469ADE91-9A19-4528-B874-23099FF2DBE9} - System32\Tasks\{004E9BDA-58C4-494E-81C4-6414580E37FB} => C:\Windows\system32\pcalua.exe -a E:\DRIVER\setup.exe -d E:\DRIVER
Task: {4D0524F6-B561-422A-8DB2-9CA649A80546} - System32\Tasks\{F1414C1C-1E8D-498C-8B92-2D986588BF45} => C:\Windows\system32\pcalua.exe -a "F:\DISCO DURO PORTATIL OCT2017\DRIVERS Y PROGRAMAS2\winamp3_0-full.exe" -d "F:\DISCO DURO PORTATIL OCT2017\DRIVERS Y PROGRAMAS2"
Task: {C69D7CEE-D549-42DE-8910-C231D1858135} - System32\Tasks\{3AEEEC24-24F1-40A8-90E0-F4EA3F088D42} => C:\Windows\system32\pcalua.exe -a "C:\Users\palote\Downloads\programas\reproductor windows media player win7\MPSetup.exe" -d "C:\Users\palote\Downloads\programas\reproductor windows media player win7"
Task: C:\Windows\Tasks\AdwCleaner_onReboot.job => C:\Users\palote\Downloads\adwcleaner_8.0.0.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin: -> disabled [No File]
FF Plugin-x32: -> disabled [No File]
FF Plugin-x32:,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
U3 aswbdisk; no ImagePath
S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]
2019-12-16 20:52 - 2018-03-13 17:59 - 000000000 ____D C:\ProgramData\AVAST Software
2019-12-13 23:23 - 2018-09-13 14:50 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset

Guárdalo bajo el nombre de FIXLIST.TXT en el escritorio :arrow_backward: Esto es muy importante.

:o: Nota :o: Es importante que la herramienta FRST.exe(Farbar Recovery Scanner Tool) y FIXLIST.TXT se encuentren en la misma ubicación (escritorio) o si no, no trabajara.

Y ahora inicia tu equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows

  • Ejecuta FRST.exe.(Si usas Windows Vista/7/8 o 10, presiona clic derecho y seleccionas -Ejecutar como Administrador-).

  • Presionar el botón FIX y aguardar a que termine.

  • La Herramienta guardara el reporte de reparación en el escritorio (FIXLOG.TXT).

Pegar el contenido de este fichero en tu próxima respuesta. :+1:

Reiniciar el equipo y comprobar su funcionamiento en relación al problema planteado y comentarlo.


Fix result of Farbar Recovery Scan Tool (x64) Version: 22-12-2019
Ran by palote (23-12-2019 00:07:12) Run:1
Running from C:\Users\palote\Desktop
Loaded Profiles: palote (Available Profiles: palote)
Boot Mode: Safe Mode (with Networking)

fixlist content:
Advertising Center (HKLM-x32\...\{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}) (Version: - Nero AG) Hidden
DolbyFiles (HKLM-x32\...\{56BE5CC9-95E6-4128-ABEA-968414CA9C80}) (Version: 2.0 - Nero AG) Hidden
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: - Epic Games, Inc.) Hidden
Galer�a de fotos (HKLM-x32\...\{F7314CA2-F900-46D7-9EA1-FBDD9D73F765}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: - Nero AG) Hidden
Menu Templates - Starter Kit (HKLM-x32\...\{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}) (Version: - Nero AG) Hidden
Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{F25C8769-16B6-4B19-BB0B-76F213829AC6}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Templates - Starter Kit (HKLM-x32\...\{BCD82AB5-670D-4242-90FA-1F97103C16CD}) (Version: - Nero AG) Hidden
PMB_ModeEditor (HKLM-x32\...\{F8063714-BD75-42DC-8FAA-D0E1EED92519}) (Version: 11.0.00 - Sony Corporation) Hidden
Real DVD Studio II (HKLM-x32\...\{5B6455A4-E812-479B-A762-C2356244CF97}) (Version: 1.00.0000 - NPG) Hidden
Servicio Xperia Companion (HKLM\...\{ED9C6E7D-FA20-4FA0-BC6E-3D05703B03C5}) (Version: - Sony) Hidden
SoundTrax (HKLM-x32\...\{3097B151-1F61-4211-A4CC-D70127B226AE}) (Version: - Nero AG) Hidden
Xperia Companion (HKLM-x32\...\{E1C58CBB-69AA-4E5F-B464-8A633811D4BC}) (Version: - Sony) Hidden
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
AlternateDataStreams: C:\Windows:0504E1FDA6C88148 [50]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Run: [DriverMax] => [X]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Run: [DriverMax_RESTART] => [X]
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\Policies\Explorer: []
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {0ca4efe8-61c8-11e9-a6f6-b05bee847e5f} - F:\startme.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {53025a57-0adb-11ea-af64-f077d438f75c} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {5833cbe9-70d3-11e8-9a61-bccf7b3ad459} - G:\Setup.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {5833cbea-70d3-11e8-9a61-bccf7b3ad459} - G:\Setup.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {5833ccf9-70d3-11e8-9a61-bccf7b3ad459} - G:\shelexec.exe \index.htm
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {6d41e6f2-cbfd-11e8-9c9b-8595b2bb2c25} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {7934f69b-70ac-11e8-ba8f-bf4241aaae51} - G:\Setup.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {7a3cbb87-fb1b-11e9-96ed-968570daf421} - F:\HiSuiteDownLoader.exe
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\...\MountPoints2: {f27181e7-be31-11e8-a5ce-8c630a438d5f} - G:\startme.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inicio r�pido de Adobe Acrobat.lnk [2018-02-20]
ShortcutTarget: Inicio r�pido de Adobe Acrobat.lnk -> C:\Windows\Installer\{AC76BA86-1040-7D00-7760-000000000003}\_SC_Acrobat.exe () [File not signed]
Task: {21AB56F4-A2E1-449B-A1E1-3FB111E310FD} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe
Task: {469ADE91-9A19-4528-B874-23099FF2DBE9} - System32\Tasks\{004E9BDA-58C4-494E-81C4-6414580E37FB} => C:\Windows\system32\pcalua.exe -a E:\DRIVER\setup.exe -d E:\DRIVER
Task: {4D0524F6-B561-422A-8DB2-9CA649A80546} - System32\Tasks\{F1414C1C-1E8D-498C-8B92-2D986588BF45} => C:\Windows\system32\pcalua.exe -a "F:\DISCO DURO PORTATIL OCT2017\DRIVERS Y PROGRAMAS2\winamp3_0-full.exe" -d "F:\DISCO DURO PORTATIL OCT2017\DRIVERS Y PROGRAMAS2"
Task: {C69D7CEE-D549-42DE-8910-C231D1858135} - System32\Tasks\{3AEEEC24-24F1-40A8-90E0-F4EA3F088D42} => C:\Windows\system32\pcalua.exe -a "C:\Users\palote\Downloads\programas\reproductor windows media player win7\MPSetup.exe" -d "C:\Users\palote\Downloads\programas\reproductor windows media player win7"
Task: C:\Windows\Tasks\AdwCleaner_onReboot.job => C:\Users\palote\Downloads\adwcleaner_8.0.0.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin: -> disabled [No File]
FF Plugin-x32: -> disabled [No File]
FF Plugin-x32:,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
U3 aswbdisk; no ImagePath
S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [X]
2019-12-16 20:52 - 2018-03-13 17:59 - 000000000 ____D C:\ProgramData\AVAST Software
2019-12-13 23:23 - 2018-09-13 14:50 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset


Error: Restore point can only be created in normal mode.
Processes closed successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{56BE5CC9-95E6-4128-ABEA-968414CA9C80}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{66C5838F-B854-4A55-89E6-A6138747A4DF}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F7314CA2-F900-46D7-9EA1-FBDD9D73F765}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{45898170-E68C-4F02-AA35-C2186BF347A3}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F25C8769-16B6-4B19-BB0B-76F213829AC6}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{BCD82AB5-670D-4242-90FA-1F97103C16CD}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F8063714-BD75-42DC-8FAA-D0E1EED92519}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5B6455A4-E812-479B-A762-C2356244CF97}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ED9C6E7D-FA20-4FA0-BC6E-3D05703B03C5}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3097B151-1F61-4211-A4CC-D70127B226AE}\\SystemComponent" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E1C58CBB-69AA-4E5F-B464-8A633811D4BC}\\SystemComponent" => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
C:\Windows => ":0504E1FDA6C88148" ADS removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Classes\AutoCADScriptFile => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Classes\.scr => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DriverMax" => removed successfully
"HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DriverMax_RESTART" => removed successfully
"HKU\S-1-5-21-3253742837-1388098199-733594754-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0ca4efe8-61c8-11e9-a6f6-b05bee847e5f} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{53025a57-0adb-11ea-af64-f077d438f75c} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5833cbe9-70d3-11e8-9a61-bccf7b3ad459} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5833cbea-70d3-11e8-9a61-bccf7b3ad459} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5833ccf9-70d3-11e8-9a61-bccf7b3ad459} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6d41e6f2-cbfd-11e8-9c9b-8595b2bb2c25} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7934f69b-70ac-11e8-ba8f-bf4241aaae51} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7a3cbb87-fb1b-11e9-96ed-968570daf421} => removed successfully
HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f27181e7-be31-11e8-a5ce-8c630a438d5f} => removed successfully
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Inicio r�pido de Adobe Acrobat.lnk" => not found
C:\Windows\Installer\{AC76BA86-1040-7D00-7760-000000000003}\_SC_Acrobat.exe => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{21AB56F4-A2E1-449B-A1E1-3FB111E310FD} => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21AB56F4-A2E1-449B-A1E1-3FB111E310FD} => could not remove. Access Denied.
C:\Windows\System32\Tasks\Avast Software\Overseer => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{469ADE91-9A19-4528-B874-23099FF2DBE9} => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{469ADE91-9A19-4528-B874-23099FF2DBE9} => could not remove. Access Denied.
C:\Windows\System32\Tasks\{004E9BDA-58C4-494E-81C4-6414580E37FB} => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{004E9BDA-58C4-494E-81C4-6414580E37FB} => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4D0524F6-B561-422A-8DB2-9CA649A80546} => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D0524F6-B561-422A-8DB2-9CA649A80546} => could not remove. Access Denied.
C:\Windows\System32\Tasks\{F1414C1C-1E8D-498C-8B92-2D986588BF45} => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F1414C1C-1E8D-498C-8B92-2D986588BF45} => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C69D7CEE-D549-42DE-8910-C231D1858135} => could not remove. Access Denied.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C69D7CEE-D549-42DE-8910-C231D1858135} => could not remove. Access Denied.
C:\Windows\System32\Tasks\{3AEEEC24-24F1-40A8-90E0-F4EA3F088D42} => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3AEEEC24-24F1-40A8-90E0-F4EA3F088D42} => could not remove. Access Denied.
C:\Windows\Tasks\AdwCleaner_onReboot.job => moved successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKLM\Software\MozillaPlugins\ => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\ => removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN" => not found
C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll => moved successfully
HKLM\System\CurrentControlSet\Services\aswbdisk => removed successfully
aswbdisk => service removed successfully
HKLM\System\CurrentControlSet\Services\k57nd60a => removed successfully
k57nd60a => service removed successfully
C:\ProgramData\AVAST Software => moved successfully
C:\Windows\system32\Tasks\Avast Software => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-3253742837-1388098199-733594754-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully

========= End of RemoveProxy: =========

========= netsh winsock reset =========

El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.

========= End of CMD: =========

========= ipconfig /renew =========

Configuraci¢n IP de Windows

No se puede realizar ninguna operaci¢n en Conexi¢n de red inal mbrica 2 mientras los medios
est‚n desconectados.

Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica 2:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica:

   Sufijo DNS espec¡fico para la conexi¢n. . : home
   V¡nculo: direcci¢n IPv6 local. . . : fe80::5523:a515:2abf:f3d0%11
   Direcci¢n IPv4. . . . . . . . . . . . . . :
   M scara de subred . . . . . . . . . . . . :
   Puerta de enlace predeterminada . . . . . :

Adaptador de t£nel isatap.{462BE81E-6AE6-419A-A914-810D3A642BE8}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel isatap.home:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel Teredo Tunneling Pseudo-Interface:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

Adaptador de t£nel isatap.{AD3CCA15-71F8-4226-9A6A-FECB86C3BBCB}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS espec¡fico para la conexi¢n. . : 

========= End of CMD: =========

========= ipconfig /flushdns =========

Configuraci¢n IP de Windows

Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

========= End of CMD: =========

========= bitsadmin /reset /allusers =========

BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to connect to BITS - 0x8007042c
No se puede iniciar el servicio o grupo de dependencia.

========= End of CMD: =========

========= netsh advfirewall reset =========


========= End of CMD: =========

========= netsh advfirewall set allprofiles state ON =========


========= End of CMD: =========

========= netsh int ipv4 reset =========

Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.

========= End of CMD: =========

========= netsh int ipv6 reset =========

Interfaz se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.

========= End of CMD: =========

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 6766164 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 42238233 B
Edge => 0 B
Chrome => 143584 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 66484 B
LocalService => 66484 B
NetworkService => 87194 B
palote => 37113893 B

RecycleBin => 10027 B
EmptyTemp: => 90.5 MB temporary data Removed.


Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 23-12-2019 00:12:49)

Result of scheduled keys to remove after reboot:

"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{21AB56F4-A2E1-449B-A1E1-3FB111E310FD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21AB56F4-A2E1-449B-A1E1-3FB111E310FD}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{469ADE91-9A19-4528-B874-23099FF2DBE9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{469ADE91-9A19-4528-B874-23099FF2DBE9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{004E9BDA-58C4-494E-81C4-6414580E37FB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4D0524F6-B561-422A-8DB2-9CA649A80546}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D0524F6-B561-422A-8DB2-9CA649A80546}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F1414C1C-1E8D-498C-8B92-2D986588BF45}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C69D7CEE-D549-42DE-8910-C231D1858135}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C69D7CEE-D549-42DE-8910-C231D1858135}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3AEEEC24-24F1-40A8-90E0-F4EA3F088D42}" => removed successfully

==== End of Fixlog 00:12:49 ====

Antes de hacer esto, iba un poco mejor, como te había comentado en un post anterior. Tardaba unos 4 o 5 minutos hasta que se ponía todo bien y se ponía todo en orden para poder trabajar rápido. Pero ahora tarda mas tiempo 8 o 9 minutos hasta que se pone en orden para poder abrir y cerrar cosas. Luego. Una vez ya ha arrancado va muchísimo mejor, incluso internet. Pero me falta instalar el chrome y hacerle probar a ver que tal. ¿Puedo instalar el chrome y probar? He guardado el registro de Delfix por si acaso. ¿Qué puedo hacer para que tarde menos en arrancar y se ponga en orden? Lo que pasa es que arranca, aparece el escritorio, pero de vez en cuando los iconos se hacen como un lavado de cara, es decir, que desaparecen y aparecen. Gracias.


Esos 8-9 minutos que indicas, han sido justo al terminar el proceso con FRST…??

Si ha sido justo después APAGA totalmente el equipo y vuelve a encenderlo TRES veces seguidas y compruebas en la ultima ocasión SI siguen siendo esos mismos minutos…??

Ya he reiniciado varias veces, he apagado varias veces. He quitado del escritorio casi 9 gigas en documentos y algún programa para si podía ser eso. Ahora he vueltoa comprobar todo desde que aprieto el botón de inicio.

  1. Aprieto botón de inicio y hasta que sale el sonio de Windows tarda 1 minuto y 30 segundos.
  2. Luego empieza a buscar la señal wifi y el antivirus de Microsoft está en rojo. Casi 2 minutos tarda en encontrar la señal wifi y ponerse el antivirus verde. EL LUMINOSO DEL DISCO DURO SIGUE TRABAJANDO y se ve que de vez en cuando el raton se vuelve redondo como trabajando.
  3.   1 minuto después los iconos vuelven a desaparecer y aparecer, lo que yo llamo volver a verlos bien.

Y es cuando veo que el disco duro sigue trabajando. Yo apriego algún documento para que se abra de office, por ejemplo y tarda en abrirse. Una vez se abre, lo cierro y tarda en cerrarse. Hasta que finalmente deja de trabajar el disco duro porque la luz ya se apaga. TOTAL 6 minutos. Después ya intengo abrir algún programa pero la primera vez tarda bastante. luego después, una vez abierto va mejor. Va mucho mucho mejor que al principio del problema. Antes de utilizar la copia de registro con first creo que tardaba menos en abrirse Windows, pero la verdad es que no me acuerdo muy bien. Tendría que volver a lo de antes y comprobarlo. No se que le puede pasar. Son 6 minutos hasta que uno puede hacer cosas. Y todavía no he instalado el chrome. Gracias, espero a ver que opináis.

Farbar Recovery Scan Tool (x64) Version: 22-12-2019
Ran by palote (24-12-2019 01:04:54)
Running from C:\Users\palote\Desktop
Boot Mode: Normal

================== Search Files: "SearchAll: *.au3" =============




====== End of Search ======

Después de llevar el ordenador mucho tiempo encendido y estar pasando cosas de un disco a otro. Cuando abro internet y abro algún documento del escritorio, parece que va muy rápido. pero al arrancar y hasta que lleva mucho tiempo encendido parece que no va bien. Pero estoy muy contento porque como ha cambiado a mejor. Ahora se puede pinchar para meterme en internet rápido. He vuelto a reiniciar y sigue lo mismo sus 6 minutos no los baja. y además me he dado cuenta que los iconos hacen lo de desparecer y aparecer en 3 ocasiones hasta que termina de arrancar.