Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16.01.2019 01 Ran by Aaron (19-01-2019 11:29:55) Running from C:\Users\Aaron\Downloads Windows 7 Home Premium Service Pack 1 (X64) (2011-09-23 21:06:17) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Aaron (S-1-5-21-628076510-392984596-580012936-1000 - Administrator - Enabled) => C:\Users\Aaron Administrador (S-1-5-21-628076510-392984596-580012936-500 - Administrator - Disabled) HomeGroupUser$ (S-1-5-21-628076510-392984596-580012936-1002 - Limited - Enabled) Invitado (S-1-5-21-628076510-392984596-580012936-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKLM-x32\...\uTorrent) (Version: 3.0.0 - ) Active Directory Authentication Library for SQL Server (x86) (HKLM-x32\...\{F40FA676-46B1-4609-85EF-D2F1F79E0C0E}) (Version: 13.0.1601.5 - Microsoft Corporation) Hidden Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9130 - Adobe Systems Inc.) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.2.1.650 - Adobe Systems Incorporated) Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.1.102.63 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.6.602.168 - Adobe Systems Incorporated) Adobe Photoshop Elements 9 (HKLM-x32\...\Adobe Photoshop Elements 9) (Version: 9.0 - Adobe Systems Incorporated) Adobe Premiere Elements 9 (HKLM-x32\...\PremElem90) (Version: 9.0 - Adobe Systems Incorporated) Adobe Reader X MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.5.9.620 - Adobe Systems, Inc.) AIDA64 Extreme Edition v2.00 (HKLM-x32\...\AIDA64 Extreme Edition_is1) (Version: 2.00 - FinalWire Ltd.) Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{0E4C791E-B78E-477D-BD5A-CDD0985BA6EC}) (Version: 7.0.20622.1 - Microsoft Corporation) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.1.42 - Atheros Communications Inc.) Azure AD Authentication Connected Service (HKLM-x32\...\{8A1AD070-269F-4A15-AAB5-76AB896EF195}) (Version: 14.0.25420 - Microsoft Corporation) Hidden AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender) Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.32 - Piriform) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Crystal Reports for Visual Studio (HKLM-x32\...\{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}) (Version: 12.51.0.240 - SAP) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.1.3908 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dotfuscator and Analytics Community Edition 5.22.0 (HKLM-x32\...\{60018889-9E0F-43E8-9B89-29E8C828B40A}) (Version: 5.22.0.3788 - PreEmptive Solutions) Hidden Dotfuscator Software Services - Community Edition (HKLM-x32\...\{1AA5BD63-6614-44B2-88A7-605191EDB835}) (Version: 5.0.2500.0 - PreEmptive Solutions) Dropbox (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\Dropbox) (Version: 64.4.141 - Dropbox, Inc.) Elements 9 Organizer (HKLM-x32\...\{433EACD8-4747-4A6A-826A-FFA9F39B0D40}) (Version: 9.0 - Adobe Systems Incorporated) Hidden Elements STI Installer (HKLM-x32\...\{25175695-4B20-4298-9F34-C2C57CD277B3}) (Version: 1.0 - Adobe Systems Incorporated) Hidden Elements STI Installer (HKLM-x32\...\{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}) (Version: 1.0 - Adobe Systems Incorporated) Hidden Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Evernote v. 4.2.2 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.2.3979 - Evernote Corp.) Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited) Galería fotográfica de Windows Live (HKLM-x32\...\{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.) Google Talk (remove only) (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk) (Version: - ) Hacer clic y ejecutar de Microsoft Office 2010 (HKLM\...\{90140000-006D-0C0A-1000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Hacer clic y ejecutar de Microsoft Office 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) HP 3D DriveGuard (HKLM\...\{35919E9F-D1B9-44DE-B616-A275DC622C42}) (Version: 4.1.1.6 - Hewlett-Packard Company) HP Connection Manager (HKLM-x32\...\{0F35AE7E-DB8D-44FE-8C52-52355A4FF021}) (Version: 4.1.4.1 - Hewlett-Packard Company) HP CoolSense (HKLM-x32\...\{7270C835-15DB-4236-B235-DD6B2EBBD4BA}) (Version: 2.0.0 - Hewlett-Packard Company) HP Documentation (HKLM-x32\...\{4DDBDC46-B7F0-4D39-AAF9-53CA5B692499}) (Version: 1.1.0.0 - Hewlett-Packard) HP On Screen Display (HKLM-x32\...\{9B9B8EE4-2EDB-41C2-AF2E-63E75D37CDDF}) (Version: 1.1.2 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{B97E3520-C726-475E-BC0C-7561952633AB}) (Version: 1.2.1 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{EB58480C-0721-483C-B354-9D35A147999F}) (Version: 2.3.6 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{210A03F5-B2ED-4947-B27E-516F50CBB292}) (Version: 8.6.4530.3651 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13253.3682 - Hewlett-Packard Company) HP Software Framework (HKLM-x32\...\{2BC49E1C-8655-478B-9412-865C633671EE}) (Version: 4.0.110.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}) (Version: 6.1.12.1 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6329.0 - IDT) IIS 10.0 Express (HKLM\...\{13FD7E30-D2F1-498D-ABC2-A4242DB6610E}) (Version: 10.0.1736 - Microsoft Corporation) IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - ) IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - ) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!) Instalación de DivX (HKLM-x32\...\DivX Setup) (Version: 2.6.0.34 - DivX, LLC) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{C7B40C35-85AE-4303-9EEA-1A1EA779664D}) (Version: 1.0.2.0511 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.2.1004 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel(R) Wireless Display (HKLM-x32\...\{5B46CEC7-DAD0-46A2-BCD6-B46A3CFD9B61}) (Version: 2.0.30.0 - Intel Corporation) Java 8 Update 144 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 - Oracle Corporation) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JetBrains dotPeek 2017.1.3 (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\{1c9cfaa8-8d5f-58dc-81f3-41370a70ee73}) (Version: 2017.1.3 - JetBrains s.r.o.) JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.57.2 - JMicron Technology Corp.) Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LightScribe System Software (HKLM-x32\...\{E0E55FC1-C53D-4F8D-B14B-B59C312747C8}) (Version: 1.18.22.2 - LightScribe) LightScribe Template Labeler (HKLM-x32\...\{43523FEF-9D8E-4572-BB11-0E914D366E0A}) (Version: 1.18.15.1 - ) MagicDisc 2.7.106 (HKLM-x32\...\MagicDisc 2.7.106) (Version: - ) Malwarebytes versión 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes) Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\...\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation) Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation) Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.25420 - Microsoft Corporation) Microsoft ODBC Driver 11 for SQL Server (HKLM\...\{A106FA6F-E94C-44C9-8A0F-C34BD82C9FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Office 365 ProPlus - es-es (HKLM\...\O365ProPlusRetail - es-es) (Version: 16.0.11029.20108 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Starter 2010 - Español (HKLM-x32\...\{90140011-0066-0C0A-0000-0000000FF1CE}) (Version: 14.0.5128.5002 - Microsoft Corporation) Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\OneDriveSetup.exe) (Version: 18.222.1104.0007 - Microsoft Corporation) Microsoft redistributable runtime DLLs VS2005 SP1(x86) (HKLM-x32\...\{8E770F99-CF23-4BF9-BF4E-E3A2924FEB27}) (Version: 8.0.50727.762 - SAP) Microsoft Report Viewer 2014 Runtime (HKLM-x32\...\{327E9C0D-1687-414F-923E-F5979E549548}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation) Microsoft Silverlight 3 SDK (HKLM-x32\...\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation) Microsoft Silverlight 4 SDK (HKLM-x32\...\{05855322-BE43-41FE-B583-D3AE0C326D58}) (Version: 4.0.50826.0 - Microsoft Corporation) Microsoft SQL Server vNext T-SQL Language Service CTP1 (HKLM\...\{B4A533EA-4101-4AF0-9D23-EBF545CE5BF7}) (Version: 14.0.16000.64 - Microsoft Corporation) Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{6292D514-17A4-403F-98F9-E150F10C043D}) (Version: 10.3.5500.0 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{1385D3DB-8E80-427B-91D2-B7535862B8E4}) (Version: 11.3.6518.0 - Microsoft Corporation) Microsoft SQL Server 2014 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2014) (Version: - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Policies (HKLM-x32\...\{1C30FE7E-8A8C-4492-89D6-10CB20C3B0EB}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Setup (English) (HKLM\...\{0EEBDCCA-EF5D-4896-9FEA-D7D410A57E8A}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL Compiler Service (HKLM\...\{59DE4D1C-690E-4397-8A44-B684934E863C}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2016 LocalDB (HKLM\...\{E359515A-92E6-4FA3-A2C9-E1BA02D8DE6E}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (HKLM-x32\...\{0F1C8E2F-199A-4946-B3BF-0906DACFD032}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 Management Objects (x64) (HKLM\...\{20EA85AA-2A1D-4F11-B09F-4BA2BF3C8989}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL Language Service (HKLM-x32\...\{8BFDE775-C5B8-46DB-84EF-43FFC8A2E8AD}) (Version: 13.0.14500.10 - Microsoft Corporation) Microsoft SQL Server 2016 T-SQL ScriptDom (HKLM\...\{D091DE8C-EA0F-49AF-8DE3-BD6C79737C6E}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (14.0.60519.0) (HKLM-x32\...\{4E27B0EF-7BAB-432A-AF3D-3FC8F3F7353F}) (Version: 14.0.60519.0 - Microsoft Corporation) Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation) Microsoft Sync Framework Runtime v1.0 SP1 (x64) (HKLM\...\{8438EC02-B8A9-462D-AC72-1B521349C001}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Framework SDK v1.0 SP1 (HKLM-x32\...\{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Framework Services v1.0 SP1 (x64) (HKLM\...\{034106B5-54B7-467F-B477-5B7DBB492624}) (Version: 1.0.3010.0 - Microsoft Corporation) Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) (HKLM\...\{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}) (Version: 2.0.3010.0 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2016 (HKLM\...\{96EB5054-C775-4BEF-B7B9-AA96A295EDCD}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2016 (HKLM-x32\...\{84C23ECA-FE4D-494F-9247-3EBAD57E7F0C}) (Version: 13.0.1601.5 - Microsoft Corporation) Microsoft Team Foundation Server 2010 Object Model - ENU (HKLM\...\Microsoft Team Foundation Server 2010 Object Model - ENU) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319 (HKLM\...\{F5079164-1DB9-3BDA-853B-F78AF67CE071}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Professional - ENU (HKLM-x32\...\Microsoft Visual Studio 2010 Professional - ENU) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2015 Installer Projects Extension (HKLM-x32\...\{205eeeb7-54a3-4f3c-91de-2a63042c3658}) (Version: 14.0.25465 - Microsoft Corporation) Microsoft Visual Studio 2015 Shell (Isolated) (HKLM-x32\...\{d2981c27-a434-4c9a-96c7-0209e97c4eac}) (Version: 14.0.23107.10 - Microsoft Corporation) Microsoft Visual Studio Macro Tools (HKLM-x32\...\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Professional 2015 with Updates (HKLM-x32\...\{68432bbb-c9a5-4a7b-bab3-ae5a49b28303}) (Version: 14.0.25420.1 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2015 (HKLM-x32\...\{ab213ab7-4792-4c6f-a3fa-8485d06c3475}) (Version: 14.0.23829 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2015 Language Support (HKLM-x32\...\{bd4ef7af-dfb1-472e-8fa4-1b97f360a3e7}) (Version: 14.0.23107.20 - Microsoft Corporation) Microsoft VSS Writer for SQL Server 2014 (HKLM\...\{366CD715-2FF4-40B4-A8B4-A05E5D21A945}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Web Deploy 3.6 (HKLM\...\{94E1227C-08A9-4962-B388-1F05D89AEA75}) (Version: 3.1238.1962 - Microsoft Corporation) MSBuild/NuGet Integration 14.0 (x86) (HKLM-x32\...\{128C1654-3B9E-4959-8BFB-CE6F09C0A01D}) (Version: 14.0.25420 - Microsoft Corporation) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML4.0 redistributable (HKLM-x32\...\{44D66AD9-AE19-4AFD-BE7E-A1B44C856697}) (Version: 4.0.0.0 - SAP) Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden Notepad++ (64-bit x64) (HKLM\...\Notepad++) (Version: 7.4.2 - Notepad++ Team) Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11029.20108 - Microsoft Corporation) Hidden Oracle VM VirtualBox 5.2.2 (HKLM\...\{9F5D10F9-A372-4B1E-BEB3-001B47E0C325}) (Version: 5.2.2 - Oracle Corporation) Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.08 - Panda Security) Hidden Paquete de compatibilidad de Microsoft .NET Framework 4.6.1 (español) (HKLM-x32\...\{2ECA62A3-BA78-4B96-BEA3-0E9DA82F08D9}) (Version: 4.6.01055 - Microsoft Corporation) Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation) PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation) Prerequisites for SSDT (HKLM-x32\...\{B7E94916-7AE6-4F7F-A377-7A410A42BA19}) (Version: 13.0.1601.5 - Microsoft Corporation) Python 3.6.1 (32-bit) (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\{1babc3bc-6a32-44f7-bf4d-60eec36c9ad1}) (Version: 3.6.1150.0 - Python Software Foundation) Python 3.6.1 Add to Path (32-bit) (HKLM-x32\...\{ED8BD450-5015-4CB3-95B5-2D93F23E111B}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Core Interpreter (32-bit) (HKLM-x32\...\{E63E60CA-437B-4894-8395-81F2F66483B0}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Development Libraries (32-bit) (HKLM-x32\...\{3029D656-0C32-4AC9-84FB-A15056F356CC}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Documentation (32-bit) (HKLM-x32\...\{D1198C40-C6F5-4FFB-B98C-79BF1FE706C1}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Executables (32-bit) (HKLM-x32\...\{A7036382-80F1-4FC1-B244-D31AA50337F4}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 pip Bootstrap (32-bit) (HKLM-x32\...\{899F7F28-F6D3-4E5B-8FBE-F7929036172A}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Standard Library (32-bit) (HKLM-x32\...\{3BCCB89B-CD98-4F78-8436-78847FABFD68}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Tcl/Tk Support (32-bit) (HKLM-x32\...\{F6ED0771-FE83-4A1C-BE65-A06CB65B46D5}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Test Suite (32-bit) (HKLM-x32\...\{F44EF183-905E-48BB-998E-53FC99B36FE3}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python 3.6.1 Utility Scripts (32-bit) (HKLM-x32\...\{2AA7DAB3-6778-42A7-9F33-22615234540E}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden Python Launcher (HKLM-x32\...\{323AC113-C6CE-4F99-842F-4936332D055A}) (Version: 3.6.5923.0 - Python Software Foundation) Recovery Manager (HKLM-x32\...\{DBCD5E64-7379-4648-9444-8A6558DCB614}) (Version: 2.0.0 - Hewlett-Packard) Hidden Revo Uninstaller 1.93 (HKLM-x32\...\Revo Uninstaller) (Version: 1.93 - VS Revo Group) Roslyn Language Services - x86 (HKLM-x32\...\{6970C7E1-F99D-388D-8903-DF8FCE677FED}) (Version: 14.0.25431 - Microsoft Corporation) Hidden Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden SDK de Microsoft .NET Framework 4.6.1 (español) (HKLM-x32\...\{07570008-8840-4A14-A752-1367157138A5}) (Version: 4.6.01055 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.) SmartSound Quicktracks for Premiere Elements 9.0 (HKLM-x32\...\{6748E773-5DA0-4D19-8AA5-273B4133A09B}) (Version: 3.12.3090 - SmartSound Software Inc) Hidden SmartSound Quicktracks for Premiere Elements 9.0 (HKLM-x32\...\InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}) (Version: 3.12.3090 - SmartSound Software Inc) Software Intel(R) PROSet/Wireless WiFi (HKLM\...\{794E5C90-96E5-4413-B3F5-C803205AE30C}) (Version: 14.0.3000 - Intel Corporation) Spotify (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\Spotify) (Version: 1.0.67.582.g19436fa3 - Spotify AB) SQL Server 2014 Client Tools (HKLM\...\{2BA1811B-44C0-4C50-8C5A-CE68AB25ED71}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Client Tools (HKLM\...\{B5ECFA5C-AC4F-45A4-A12E-A76ABDD9CCBA}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Common Files (HKLM\...\{BD1CD96B-FE4B-4EAE-83D4-6EF55AB5779C}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Common Files (HKLM\...\{F7012F84-80F5-4C25-852E-B1BA03276FE6}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Services (HKLM\...\{17531BCD-C627-46A2-9F1E-7CC920E0E94A}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Services (HKLM\...\{5082A9F3-AEE5-4639-9BA7-C19661BA7331}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Shared (HKLM\...\{ACC530B8-B6B4-40D6-B59B-152468CF47D0}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Database Engine Shared (HKLM\...\{D1B847A9-B06B-4264-9EF0-78E6E1571E65}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Documentation Components (HKLM\...\{1D01EDF6-7E93-4FEE-AA09-C5669511100C}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Documentation Components (HKLM\...\{5EACF47D-EB70-4FE0-83DE-9FD9693C24B9}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Documentation Components (HKLM\...\{832D6A7D-13F7-42CB-9AC6-5859800269AE}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Full text search (HKLM\...\{B40B7A25-308B-4650-8B42-E51710CDD4D9}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Management Studio (HKLM\...\{75A54138-3B98-4705-92E4-F619825B121F}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Management Studio (HKLM\...\{839EF29A-3055-43DC-ADCE-8E84893798D5}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Reporting Services (HKLM\...\{026E123D-2160-46C7-A801-87D27D46835E}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server 2014 Reporting Services (HKLM\...\{700C00BA-E947-4B77-8EF1-588DF210E931}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden SQL Server Browser for SQL Server 2014 (HKLM-x32\...\{3204DE95-97D2-4261-A286-98A262E171D4}) (Version: 12.0.2000.8 - Microsoft Corporation) Sql Server Customer Experience Improvement Program (HKLM\...\{6476DB81-F263-4C04-8574-AAD31136C304}) (Version: 12.0.2000.8 - Microsoft Corporation) Hidden Sublime Text Build 3126 (HKLM\...\Sublime Text 3_is1) (Version: - Sublime HQ Pty Ltd) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.9.0 - Synaptics Incorporated) Team Explorer for Microsoft Visual Studio 2015 Update 3.1 (HKLM-x32\...\{7A95671A-759E-3B83-B763-4289D1D24D73}) (Version: 14.102.25619 - Microsoft) Hidden Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden TypeScript Power Tool (HKLM-x32\...\{465ACA24-B8D6-4FEC-A42D-9EFCB92CD560}) (Version: 1.8.34.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{BA5762C7-D35F-4725-A4BD-525854127018}) (Version: 1.8.36.0 - Microsoft Corporation) Hidden Unity Web Player (HKU\S-1-5-21-628076510-392984596-580012936-1000\...\UnityWebPlayer) (Version: - Unity Technologies ApS) VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation) Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation) Visual Studio 2015 Update 3 (KB3022398) (HKLM-x32\...\{7a68448b-9cf2-4049-bd73-5875f1aa7ba2}) (Version: 14.0.25420 - Microsoft Corporation) VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN) VS Update core components (HKLM-x32\...\{B2918D01-1D89-34D3-87EF-A28121BC6EB7}) (Version: 14.0.25431 - Microsoft Corporation) Hidden vs_update3notification (HKLM-x32\...\{AB3DF932-C990-34D4-BF43-970F760DA3CD}) (Version: 14.0.25431 - Microsoft Corporation) Hidden WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden WCF RIA Services V1.0 SP1 (HKLM-x32\...\{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}) (Version: 4.1.60114.0 - Microsoft Corporation) Web Deployment Tool (HKLM\...\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) HKU\S-1-5-21-628076510-392984596-580012936-1000\...\ChromeHTML: -> C:\Users\Aaron\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{A2C6CB58-C076-425C-ACB7-6D19D64428CD}\localserver32 -> C:\Users\Aaron\AppData\Local\Google\Chrome\Application\71.0.3578.98\notification_helper.exe (Google Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{A804CF1A-91E5-4F0C-9E8C-DB39E74056DD}\InprocServer32 -> C:\Users\Aaron\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Aaron\AppData\Local\Google\Update\1.3.33.23\psuser_64.dll (Google Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-628076510-392984596-580012936-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files\Notepad++\NppShell_06.dll [2017-06-18] () ContextMenuHandlers1: [BTMSentToExt] -> {0A7D34C2-E9DA-48A1-9E34-0CDFC2DE3B44} => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [2011-01-24] (Intel Corporation) ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> No File ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2011-05-28] () ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2011-05-28] () ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-04-05] (Intel Corporation) ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> No File ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes) ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> No File ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2011-05-28] () ContextMenuHandlers1_S-1-5-21-628076510-392984596-580012936-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ContextMenuHandlers4_S-1-5-21-628076510-392984596-580012936-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ContextMenuHandlers5_S-1-5-21-628076510-392984596-580012936-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Aaron\AppData\Roaming\Dropbox\bin\DropboxExt64.26.0.dll [2019-01-08] (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0440BE3C-5216-45CF-8315-C1A179DCDD62} - System32\Tasks\{EC66A4AA-0A0B-4E8A-BC9C-F3817DB2DA6D} => "C:\Program Files (x86)\Internet Explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.3.0.105/en/abandoninstall?page=tsProgressBar Task: {0E332A17-B963-41BF-8AB8-E8D5790065AA} - System32\Tasks\Microsoft\VisualStudio\VSIX Auto Update 14 => C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe [2016-06-20] (Microsoft Corporation) Task: {0E6B2169-70FA-4A42-AF09-E814BFC0D249} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2011-01-30] () Task: {1857EEB1-ECC9-4622-9385-D025E669E219} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-12-16] (Microsoft Corporation) Task: {192F8AB7-1302-4AC9-AC26-69F48A96A97F} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-12-16] (Microsoft Corporation) Task: {1AA985C9-B796-41DC-B90A-21496430C439} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000UA => C:\Users\Aaron\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-22] (Facebook Inc.) Task: {23E7BF65-902C-4DE3-93BC-0BC966D7F216} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-12-07] (Microsoft Corporation) Task: {2A7B504D-8EB6-45A8-BEA4-13E3F09419B8} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2018-11-15] (Bitdefender) Task: {3C2A5FF4-1E6E-459F-8869-E5B4322A9205} - System32\Tasks\{9DF987C9-0D91-48DD-8D37-80FF95541A0D} => C:\Windows\system32\pcalua.exe -a C:\Users\Aaron\Documents\Programas\unetbootin\unetbootin-win-549.exe -d C:\Users\Aaron\Documents\Programas\unetbootin Task: {53746CCE-A56D-4AEA-B90C-B4E54973E0C1} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000Core => C:\Users\Aaron\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {544B0163-356A-4371-B201-AD8AF7A9AEB6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000Core => C:\Users\Aaron\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-22] (Facebook Inc.) Task: {556785EF-A8E7-47AC-98F0-F86A05185F98} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [2018-12-16] (Microsoft Corporation) Task: {5FD73A9E-3065-4AC4-A128-EAADBC0A0A93} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-12-16] (Microsoft Corporation) Task: {6E87FA1B-6C9F-451D-A61F-F885C4665982} - System32\Tasks\{A084B1B7-AD69-41A5-AFE4-D5F5ABC395E6} => "C:\Program Files (x86)\Internet Explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/5.1.0.104.324/es/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled Task: {81D65852-44D6-4C3B-9073-107FED11924A} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-08] (CyberLink) Task: {85CF9891-BAB4-49DC-B1C8-3F2BD530A8EF} - System32\Tasks\AdobeAAMUpdater-1.0-AVD-HP-Aaron => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-07-28] (Adobe Systems Incorporated) Task: {8D540929-2A72-4C78-A082-ADE7625CBBD9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-30] (Piriform Ltd) Task: {929E2626-25B7-4BF2-B645-EF397AC23703} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000Core => C:\Users\Aaron\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {93242A9B-8E59-4DCD-B371-AAB4C4A35746} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-12-16] (Microsoft Corporation) Task: {99D39D00-CB8C-416E-8B77-A653E8CAE94D} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [2018-12-16] (Microsoft Corporation) Task: {A8F7339D-6B86-45FB-91D0-648695526EC3} - System32\Tasks\{CFF88524-86A3-4483-B645-8957B3D36692} => C:\Windows\system32\pcalua.exe -a "C:\Users\Aaron\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJEH2J14\JavaSetup8u144.exe" -d C:\Users\Aaron\Desktop Task: {D7FB2324-34AB-4274-AD14-484507069159} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-12-07] (Microsoft Corporation) Task: {DC7F55FE-B043-46D6-ABEC-F14629DA1707} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000UA => C:\Users\Aaron\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.) Task: {E4AF4317-9FA5-4608-A4F4-F961253F01EA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-12-16] (Microsoft Corporation) Task: {EED234B5-8AEC-43A8-8CAE-002A591B348A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS.exe [2012-09-08] () Task: {FA473D07-92CB-4C88-A3A0-3385B07818D3} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000UA => C:\Users\Aaron\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\AdwCleaner_onReboot.job => C:\Users\Aaron\Downloads\adwcleaner_7.2.6.0.exe Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000Core.job => C:\Users\Aaron\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000UA.job => C:\Users\Aaron\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000Core.job => C:\Users\Aaron\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-628076510-392984596-580012936-1000UA.job => C:\Users\Aaron\AppData\Local\Facebook\Update\FacebookUpdate.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\": WMI:subscription\__EventFilter->BVTFilter: WMI:subscription\CommandLineEventConsumer->BVTConsumer: ==================== Loaded Modules (Whitelisted) ============== 2011-02-04 07:42 - 2011-02-04 07:42 - 001501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2011-05-23 06:39 - 2011-01-27 10:11 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-06-23 18:21 - 2010-06-23 18:21 - 001102336 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\System.Data.SQLite.dll 2019-01-09 21:22 - 2019-01-08 07:07 - 001140552 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll 2019-01-09 21:22 - 2019-01-08 07:07 - 002103112 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\dropbox_crashpad.dll 2019-01-09 21:22 - 2019-01-08 07:09 - 000023376 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\tornado.speedups.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000025456 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000148968 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\_cffi_backend.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 001878888 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000025960 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000118232 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\pywintypes36.dll 2019-01-09 21:22 - 2019-01-08 07:07 - 000109024 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32api.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000082760 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\fastpath.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000418776 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\pythoncom36.dll 2019-01-09 21:22 - 2019-01-08 07:08 - 000074072 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000027616 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32event.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000049128 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32process.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000026600 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32clipboard.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000131552 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32file.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000182752 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32gui.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000027616 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32pipe.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000119272 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32security.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000401752 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32com.shell.shell.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000028640 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32job.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000034664 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000062304 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winshell.compiled._winshell.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000023520 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\mmapfile.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000053736 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32service.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000065504 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32evtlog.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000025944 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000068968 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winenumhandles.compiled._WinEnumHandles.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000028520 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000027488 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\crashpad.compiled._Crashpad.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000032224 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32ts.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000156504 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000092496 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt562.sip.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 001778000 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000518992 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000052056 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineCore.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 001929552 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 003821392 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000044888 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000132944 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000218456 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000205656 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000061408 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32print.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000051552 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000027624 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\win32profile.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000033632 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winreindex.compiled._winreindex.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000028008 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000025960 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000025448 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000025960 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000031600 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000486880 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winxpgui.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:09 - 000029040 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 011830608 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\nucleus_python.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000029024 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:07 - 000036312 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\librsync.dll 2019-01-09 21:22 - 2019-01-08 07:09 - 000025960 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.advapi32.compiled._winffi_advapi32.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000433992 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL 2019-01-09 21:22 - 2019-01-08 07:09 - 000038240 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\wind3d11.compiled._wind3d11.cp36-win32.pyd 2019-01-09 21:22 - 2019-01-08 07:08 - 000025920 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\libEGL.DLL 2019-01-09 21:22 - 2019-01-08 07:08 - 001592128 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2019-01-09 21:22 - 2019-01-08 07:09 - 000029544 _____ () C:\Users\Aaron\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.cp36-win32.pyd 2016-08-09 21:56 - 2016-08-09 21:56 - 000169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\8c02229a9868d155acb626160d3dd0b8\IsdiInterop.ni.dll 2011-05-23 06:40 - 2011-01-12 19:56 - 000058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2010-06-23 18:19 - 2010-06-23 18:19 - 000514570 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 20:34 - 2009-06-10 15:00 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\ProgramData\Oracle\Java\javapath;C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE;C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE;%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;%SYSTEMROOT%\SYSTEM32\WINDOWSPOWERSHELL\V1.0\;C:\PROGRAM FILES (X86)\WINDOWS LIVE\SHARED;C:\PROGRAM FILES\INTEL\WIFI\BIN\;C:\PROGRAM FILES\COMMON FILES\INTEL\WIRELESSCOMMON\;C:\Program Files (x86)\Skype\Phone\;%USERPROFILE%\.dnx\bin;C:\Program Files\Microsoft DNX\Dnvm\;C:\Program Files\Microsoft SQL Server\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\;C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\ HKCU\Environment\\Path: C:\ProgramData\Oracle\Java\javapath;C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE;C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE;%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;%SYSTEMROOT%\SYSTEM32\WINDOWSPOWERSHELL\V1.0\;C:\PROGRAM FILES (X86)\WINDOWS LIVE\SHARED;C:\PROGRAM FILES\INTEL\WIFI\BIN\;C:\PROGRAM FILES\COMMON FILES\INTEL\WIRELESSCOMMON\;C:\Program Files (x86)\Skype\Phone\;%USERPROFILE%\.dnx\bin;C:\Program Files\Microsoft DNX\Dnvm\;C:\Program Files\Microsoft SQL Server\130\Tools\Binn\;C:\Program Files\Microsoft SQL Server\Client SDK\ODBC\110\Tools\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\Tools\Binn\;C:\Program Files\Microsoft SQL Server\120\DTS\Binn\;C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\ManagementStudio\;C:\Program Files (x86)\Microsoft SQL Server\120\DTS\Binn\ HKU\S-1-5-21-628076510-392984596-580012936-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Aaron\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: Media is not connected to internet. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. MSCONFIG\startupfolder: C:^Users^Aaron^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Aaron^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => C:\Windows\pss\MagicDisc.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: Google Update => C:\Users\Aaron\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe MSCONFIG\startupreg: RESTART_STICKY_NOTES => C:\Windows\System32\StikyNot.exe MSCONFIG\startupreg: Spotify Web Helper => C:\Users\Aaron\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{BBF25FB4-5711-4200-8690-E0420003487A}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation) FirewallRules: [{57F67191-45A7-49AC-8929-EE6705DFEDA6}] => (Allow) LPort=2869 FirewallRules: [{4472BACC-5BD4-4BC5-8A2B-EDAD9EB35A9B}] => (Allow) LPort=1900 FirewallRules: [{0FED8204-E11D-47BB-B868-4B470C412DA1}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe (Microsoft Corporation) FirewallRules: [{4673B5C2-AF31-4E70-9BA3-055154499C92}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe () FirewallRules: [{9A522266-1CB5-46F9-8A48-B8866F64046F}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel Wireless Display\WiDiApp.exe (Intel Corporation) FirewallRules: [{DF3B2E87-583A-4397-8AF4-3D5BA4B5792F}] => (Allow) C:\Users\Aaron\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) FirewallRules: [{8EC5DF12-BEE4-4E6C-9CCA-003B55DC56B8}] => (Allow) C:\Users\Aaron\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) FirewallRules: [{13BE3E54-2535-4D57-BBE3-3BFE058194D2}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) FirewallRules: [{0C4CD54B-D846-4554-8AAD-B6B6B29CBD8E}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.) FirewallRules: [{1FCFBF62-6A93-4A72-89A6-514EA3E7C26F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) FirewallRules: [TCP Query User{72A2FA5D-AF4F-40FF-8706-4F9F8C52F203}C:\users\aaron\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\aaron\appdata\roaming\dropbox\bin\dropbox.exe (Dropbox, Inc.) FirewallRules: [UDP Query User{BDA42D90-1222-4811-9B08-F16BBE35BFCB}C:\users\aaron\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\aaron\appdata\roaming\dropbox\bin\dropbox.exe (Dropbox, Inc.) FirewallRules: [{82B20168-D716-4219-B326-75A17B6784B1}] => (Allow) C:\Users\Aaron\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe (Skype Limited) FirewallRules: [TCP Query User{BA8F9F00-D515-4F2B-9B86-AAF0D06E4A20}C:\users\aaron\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\aaron\appdata\roaming\spotify\spotify.exe (Spotify Ltd) FirewallRules: [UDP Query User{6FBD823D-4CBA-4C4D-B79E-FDF473AD2D35}C:\users\aaron\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\aaron\appdata\roaming\spotify\spotify.exe (Spotify Ltd) FirewallRules: [TCP Query User{87860BB6-D69B-4480-806C-503BFD13DCEE}C:\users\aaron\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\aaron\appdata\roaming\spotify\spotify.exe (Spotify Ltd) FirewallRules: [UDP Query User{0EDC8CAE-0001-4898-AC70-304E092440C3}C:\users\aaron\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\aaron\appdata\roaming\spotify\spotify.exe (Spotify Ltd) FirewallRules: [TCP Query User{2F70A10C-FD22-4659-98E9-7743325452C7}C:\users\aaron\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\aaron\appdata\local\google\chrome\application\chrome.exe (Google Inc.) FirewallRules: [UDP Query User{E227AEB4-4244-4FE6-BE4B-056AD4B06BF1}C:\users\aaron\appdata\local\google\chrome\application\chrome.exe] => (Allow) C:\users\aaron\appdata\local\google\chrome\application\chrome.exe (Google Inc.) FirewallRules: [{7DE6E672-A5D1-4A4D-8C8F-9BCF89FAB5EE}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe (Microsoft Corporation) FirewallRules: [{CABD8029-E72F-40AF-9F45-10BDCD31FCD8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation) FirewallRules: [{6378A698-0B55-444B-8E0D-23BFEDF87BD8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation) FirewallRules: [TCP Query User{6230601D-A18E-438A-A3F6-6B3C13390D70}C:\users\aaron\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\aaron\appdata\local\google\chrome\application\chrome.exe (Google Inc.) FirewallRules: [UDP Query User{EAC627FC-BF4B-4C2F-83BF-7BE05CC2AC4E}C:\users\aaron\appdata\local\google\chrome\application\chrome.exe] => (Block) C:\users\aaron\appdata\local\google\chrome\application\chrome.exe (Google Inc.) FirewallRules: [{69EA864B-CF5F-49BB-82C6-90A588367B73}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation) FirewallRules: [{E1399F1B-499F-44FC-80D9-4D3273D7E62E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation) FirewallRules: [{D1B5883B-A44D-4269-B878-56D36A191B9E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation) ==================== Restore Points ========================= 14-01-2019 21:15:16 Revo Uninstaller's restore point - Panda Safe Web 15-01-2019 22:36:01 Revo Uninstaller's restore point - Panda Internet Security ==================== Faulty Device Manager Devices ============= Name: PSINAflt Description: PSINAflt Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: PSINAflt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Teredo Tunneling Pseudo-Interface Description: Adaptador de tunelización Teredo de Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: PSINKnc Description: PSINKnc Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: PSINKNC Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: PSINProt Description: PSINProt Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: PSINProt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: PSINReg Description: PSINReg Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: PSINReg Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (01/19/2019 11:26:07 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: mbamtray.exe, versión: 3.1.0.1662, marca de tiempo: 0x5c070ada Nombre del módulo con errores: mbamtray.exe, versión: 3.1.0.1662, marca de tiempo: 0x5c070ada Código de excepción: 0xc0000005 Desplazamiento de errores: 0x000ba700 Id. del proceso con errores: 0xe60 Hora de inicio de la aplicación con errores: 0x01d4b01c0de54ebb Ruta de acceso de la aplicación con errores: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Ruta de acceso del módulo con errores: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe Id. del informe: 4d7e9674-1c0f-11e9-95f4-bc7737783ab5 Error: (01/19/2019 11:23:53 AM) (Source: Report Server Windows Service (SQLEXPRESS)) (EventID: 107) (User: ) Description: Report Server Windows Service (SQLEXPRESS) cannot connect to the report server database. Error: (01/19/2019 11:23:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema. Error: (01/19/2019 11:23:38 AM) (Source: MSSQL$SQLEXPRESS) (EventID: 3409) (User: ) Description: Performance counter shared memory setup failed with error -1. Reinstall sqlctr.ini for this instance, and ensure that the instance login account has correct registry permissions. Error: (01/19/2019 11:23:38 AM) (Source: MSSQL$SQLEXPRESS) (EventID: 8310) (User: ) Description: Cannot create (or open) named file mapping object 'Global\SQL_110_MEMOBJ_24_SQLEXPRESS_0'. SQL Server performance counters are disabled. Error: (01/19/2019 11:17:37 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema. Error: (01/17/2019 08:44:32 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: No se pudo reactivar el filtro de eventos con la consulta "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" en el espacio de nombres "//./root/CIMV2" por el error 0x80041003. Los eventos no se podrán entregar a través de este filtro hasta que se corrija este problema. Error: (01/17/2019 08:35:39 PM) (Source: CVHSVC) (EventID: 100) (User: ) Description: Solo información. (Patch task for {90140011-0066-0C0A-0000-0000000FF1CE}): DownloadLatest Failed: No se pudo resolver el nombre de servidor o su dirección System errors: ============= Error: (01/19/2019 11:23:54 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: El siguiente controlador de inicio del sistema o de inicio del arranque no se cargó correctamente: NNSHTTP NNSHTTPS NNSIDS NNSPICC NNSPOP3 NNSPROT NNSSMTP NNSSTRM NNSTLSC PSINKNC Error: (01/19/2019 11:23:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio Panda Product Service no pudo iniciarse debido al siguiente error: El sistema no puede encontrar el archivo especificado. Error: (01/19/2019 11:23:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio Panda Protection Service no pudo iniciarse debido al siguiente error: El sistema no puede encontrar el archivo especificado. Error: (01/19/2019 11:23:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio PSINReg no pudo iniciarse debido al siguiente error: Uno de los dispositivos conectados al sistema no funciona. Error: (01/19/2019 11:23:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio PSINProc no pudo iniciarse debido al siguiente error: Uno de los dispositivos conectados al sistema no funciona. Error: (01/19/2019 11:23:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio PSINFile no pudo iniciarse debido al siguiente error: Uno de los dispositivos conectados al sistema no funciona. Error: (01/19/2019 11:23:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio PSINProt no pudo iniciarse debido al siguiente error: Uno de los dispositivos conectados al sistema no funciona. Error: (01/19/2019 11:23:28 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: El servicio PSINAflt no pudo iniciarse debido al siguiente error: No se dispone de más datos. Windows Defender: =================================== Date: 2017-08-01 06:59:53.591 Description: El examen de Windows Defender se detuvo antes de completarse. Id. de examen:{5C24AE80-CEC3-47F1-97BC-E26C85DD8019} Tipo de examen:AntiSpyware Parámetros de examen:Examen rápido Usuario:NT AUTHORITY\Servicio de red Date: 2017-05-01 13:51:27.042 Description: Windows Defender detectó spyware u otro software potencialmente no deseado. Para obtener más información, consulte lo siguiente: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDropper:Win32/Virtumonde.B&threatid=17377 Nombre:TrojanDropper:Win32/Virtumonde.B Id.:17377 Gravedad:Grave Categoría:Instalador troyano de malware Ruta de acceso encontrada:file:C:\Users\Aaron\AppData\Roaming\Spotify\Spotify.exe;file:C:\Users\Aaron\Desktop\Spotify.lnk;regkey:HKCU@S-1-5-21-628076510-392984596-580012936-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Spotify;uninstall:HKCU@S-1-5-21-628076510-392984596-580012936-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Spotify Tipo de detección:Concreto Origen de detección:Sistema Estado:Desconocido Usuario:NT AUTHORITY\SYSTEM Nombre de proceso: Date: 2017-04-30 19:39:18.974 Description: Windows Defender detectó spyware u otro software potencialmente no deseado. Para obtener más información, consulte lo siguiente: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDropper:Win32/Virtumonde.B&threatid=17377 Nombre:TrojanDropper:Win32/Virtumonde.B Id.:17377 Gravedad:Grave Categoría:Instalador troyano de malware Ruta de acceso encontrada:file:C:\Users\Aaron\AppData\Roaming\Spotify\Spotify.exe;regkey:HKCU@S-1-5-21-628076510-392984596-580012936-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Spotify;uninstall:HKCU@S-1-5-21-628076510-392984596-580012936-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Spotify Tipo de detección:Concreto Origen de detección:Sistema Estado:Desconocido Usuario:NT AUTHORITY\SYSTEM Nombre de proceso: Date: 2017-04-23 21:34:12.374 Description: Windows Defender detectó spyware u otro software potencialmente no deseado. Para obtener más información, consulte lo siguiente: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDropper:Win32/Virtumonde.B&threatid=17377 Nombre:TrojanDropper:Win32/Virtumonde.B Id.:17377 Gravedad:Grave Categoría:Instalador troyano de malware Ruta de acceso encontrada:file:C:\Users\Aaron\AppData\Roaming\Spotify\Spotify.exe;regkey:HKCU@S-1-5-21-628076510-392984596-580012936-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Spotify;uninstall:HKCU@S-1-5-21-628076510-392984596-580012936-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Spotify Tipo de detección:Concreto Origen de detección:Sistema Estado:Desconocido Usuario:NT AUTHORITY\SYSTEM Nombre de proceso: Date: 2017-04-22 13:43:54.070 Description: Windows Defender detectó spyware u otro software potencialmente no deseado. Para obtener más información, consulte lo siguiente: http://go.microsoft.com/fwlink/?linkid=37020&name=TrojanDropper:Win32/Virtumonde.B&threatid=17377 Nombre:TrojanDropper:Win32/Virtumonde.B Id.:17377 Gravedad:Grave Categoría:Instalador troyano de malware Ruta de acceso encontrada:file:C:\Users\Aaron\AppData\Roaming\Spotify\Spotify.exe;process:pid:4972;process:pid:6840;process:pid:7452;process:pid:8068 Tipo de detección:Concreto Origen de detección:Protección en tiempo real Estado:Desconocido Usuario:\ Nombre de proceso: ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz Percentage of memory in use: 50% Total physical RAM: 4043.86 MB Available physical RAM: 2014.87 MB Total Virtual: 8085.9 MB Available Virtual: 5759.87 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:444.59 GB) (Free:207.26 GB) NTFS ==>[system with boot components (obtained from drive)] Drive d: (RECOVERY) (Fixed) (Total:20.87 GB) (Free:2.22 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: (Ingles US nvls I) (CDROM) (Total:0.17 GB) (Free:0 GB) CDFS \\?\Volume{f3d44116-e61e-11e0-b3e2-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS \\?\Volume{f3d44119-e61e-11e0-b3e2-806e6f6e6963}\ (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: B504969D) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=444.6 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20.9 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End of Addition.txt ============================