Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04.10.2018 Ran by chefcito (04-10-2018 22:39:04) Running from C:\Users\chefcito\Downloads Windows 10 Home Single Language Version 1803 17134.285 (X64) (2018-06-06 15:46:43) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-3116818766-2193367744-924395030-500 - Administrator - Disabled) anett (S-1-5-21-3116818766-2193367744-924395030-1003 - Limited - Enabled) => C:\Users\anett chefcito (S-1-5-21-3116818766-2193367744-924395030-1001 - Administrator - Enabled) => C:\Users\chefcito DefaultAccount (S-1-5-21-3116818766-2193367744-924395030-503 - Limited - Disabled) Invitado (S-1-5-21-3116818766-2193367744-924395030-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-3116818766-2193367744-924395030-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\uTorrent) (Version: 3.5.3.44494 - BitTorrent Inc.) 5KPlayer 4.2 (HKLM-x32\...\5KPlayer_is1) (Version: - DearMob, Inc.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.008.20071 - Adobe Systems Incorporated) Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.108 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{308F2F8C-9D33-4B22-8A6C-D9C13DBEF8C6}) (Version: 7.0.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{0CB84A7D-9697-4526-A819-60FB050E8F05}) (Version: 7.0.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{77F8C879-88CD-4145-945A-541C35285285}) (Version: 12.0.0.1039 - Apple Inc.) Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.) BioShock 2 (HKLM-x32\...\BioShock 2_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.47 - Piriform) CGS17_Setup_x64 (HKLM\...\{83646B67-A878-4E95-BB4B-AF4A6E61F28C}) (Version: 17.0 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension (HKLM\...\_{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.0.491 - Corel Corporation) Corel Graphics - Windows Shell Extension (HKLM\...\{4AB916EE-ABA8-4079-9889-745798B6D809}) (Version: 17.0.491 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 32 Bit (HKLM\...\{FD4A43CE-ABAE-4161-83AC-314A3C804F42}) (Version: 17.0.491 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Capture (x64) (HKLM\...\{2C91CB9D-323D-43E5-A433-229B71CFB773}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Common (x64) (HKLM\...\{9178F0A8-B6F6-4DA7-AD63-317CC4875F4B}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Connect (x64) (HKLM\...\{BD036E95-A9CD-4DED-B744-95AB1DCAFF0C}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Custom Data (x64) (HKLM\...\{5162E418-BB43-4C8F-ACD6-069645EF98C3}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Draw (x64) (HKLM\...\{2C0DDC74-5234-43DD-BB5A-0645B8FE5289}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - ES (x64) (HKLM\...\{65168D5C-A6DD-4C1B-BF5C-860A39CDD05E}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Filters (x64) (HKLM\...\{D10A5CFA-FE33-4F06-AE37-554604F00A52}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - FontNav (x64) (HKLM\...\{5406029B-67AD-4F8E-9F2D-F1959CD9CD86}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - IPM Content (x64) (HKLM\...\{EF44BCCD-13F9-4974-862C-CCFAF43EE082}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - IPM T (x64) (HKLM\...\{13179AB2-69FD-459B-800F-81865A501AD4}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - PHOTO-PAINT (x64) (HKLM\...\{C922F325-DD52-4E22-B204-431A06E63E51}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Photozoom Plugin (x64) (HKLM\...\{1A73168F-5983-46A6-AAAB-FD83BC231E02}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Redist (x64) (HKLM\...\{C57EDB5A-AC8E-4E03-9F1A-DC013A2BB9B2}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Setup Files (x64) (HKLM\...\{5CB73140-806C-42C6-A05A-1AFD0E92DEB5}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - VBA (x64) (HKLM\...\{5672E0DC-7489-4EAC-8CFD-E01B3868FCB5}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - VideoBrowser (x64) (HKLM\...\{966996DC-D67C-40E3-8BD4-31FA0F093571}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 - Writing Tools (x64) (HKLM\...\{D63404AC-C2F1-4B3D-96EA-9727AC9D994C}) (Version: 17.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X7 (64-Bit) (HKLM\...\_{5CB73140-806C-42C6-A05A-1AFD0E92DEB5}) (Version: 17.0.0.491 - Corel Corporation) CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd) Dell Customer Connect (HKLM-x32\...\{04A41EBC-AB30-4574-A14D-E0CDFE31AB70}) (Version: 1.5.1.0 - Dell Inc.) Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP) Dell Help & Support (HKLM\...\{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Hidden Dell Help & Support (HKLM-x32\...\InstallShield_{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Dell Product Registration (HKLM-x32\...\InstallShield_{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.2.6793.01 - Dell) Dell SupportAssist Remediation (HKLM\...\{2B2C47D2-F037-4C03-B599-07D7AFE8DD54}) (Version: 3.3.0.4943 - Dell Inc.) Hidden Dell SupportAssist Remediation (HKLM-x32\...\{8ce1a5ae-856e-4b8e-a0e8-27dd7a209276}) (Version: 3.3.0.4943 - Dell Inc.) Dell Update - SupportAssist Update Plugin (HKLM\...\{6DE68941-66DE-48DE-9C80-FE60C9DE0AD4}) (Version: 4.0.1.5857 - Dell Inc.) Hidden Dell Update - SupportAssist Update Plugin (HKLM-x32\...\{1dbe752f-b00e-4567-9276-141812b20d28}) (Version: 4.0.1.5857 - Dell Inc.) Dell Update (HKLM-x32\...\{D8AE5F9D-647C-49B4-A666-1C20B44EC0E1}) (Version: 2.1.3.0 - Dell Inc.) Dropbox 20 GB (HKLM-x32\...\{0867A88D-764F-366E-9E21-130DA8B472C3}) (Version: 3.1.18.0 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.141.1 - Dropbox, Inc.) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 69.0.3497.100 - Google Inc.) Google Earth Pro (HKLM-x32\...\{BF354C72-AC4C-4A87-8D42-B089862BAE58}) (Version: 7.3.2.5491 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden Grand Theft Auto V (HKLM-x32\...\Grand Theft Auto V_is1) (Version: - ) Hotspot Shield 7.12.1 (HKLM-x32\...\{09f8e8f3-99c4-49a2-961c-30be45d6392b}) (Version: 7.12.1.11056 - AnchorFree Inc.) Hotspot Shield 7.12.1 (HKLM-x32\...\{AF599C42-A2E5-4251-B7EE-4925C1E7BE53}) (Version: 7.12.1.11056 - AnchorFree Inc.) Hidden Hotspot Shield 7.12.1 (HKLM-x32\...\HotspotShield) (Version: 7.12.1 - AnchorFree Inc.) Hidden iCloud (HKLM\...\{82FCC407-A0E5-4B80-9241-5ABA78B61090}) (Version: 7.6.0.15 - Apple Inc.) Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4590 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation) Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{DC5673D2-228D-45BC-B9BB-9610CE67DFC0}) (Version: 17.1.1524.1353 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) iTools 3 (HKLM-x32\...\ThinkSky) (Version: - Shenzhen Thinksky Technology Co., Ltd.) iTunes (HKLM\...\{36F365B3-05C2-455D-9D96-B73829DE046D}) (Version: 12.8.0.150 - Apple Inc.) iVMS-4200(v2.6.1.2) (HKLM-x32\...\{7697245D-2E00-4B83-AD27-C051DE314D1F}) (Version: 2.06.01.02 - hikvision) Kodi (HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\Kodi) (Version: - XBMC-Foundation) Malwarebytes versión 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.9060.3 - Waves Audio Ltd.) Hidden MediaHuman YouTube to MP3 Converter 3.9.8.25 (HKLM-x32\...\MediaHuman YouTube to MP3 Converter_is1) (Version: 3.9.8.25 - MediaHuman) MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Excel 2007 Help Actualización (KB963678) (HKLM-x32\...\{90120000-0016-0C0A-0000-0000000FF1CE}_STANDARD_{59E09C3D-4878-47D9-87DB-6D0018026889}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Outlook 2007 Help Actualización (KB963677) (HKLM-x32\...\{90120000-001A-0C0A-0000-0000000FF1CE}_STANDARD_{59C244C2-0C37-4E85-8F7E-DBDD3958B694}) (Version: - Microsoft) Microsoft Office Powerpoint 2007 Help Actualización (KB963669) (HKLM-x32\...\{90120000-0018-0C0A-0000-0000000FF1CE}_STANDARD_{F318245D-05AE-4681-A749-A036CE44AF29}) (Version: - Microsoft) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation) Microsoft Office Standard 2007 (HKLM-x32\...\STANDARD) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Word 2007 Help Actualización (KB963665) (HKLM-x32\...\{90120000-001B-0C0A-0000-0000000FF1CE}_STANDARD_{377BA42A-1C84-45D6-94B8-6D00887D172D}) (Version: - Microsoft) Microsoft OneDrive (HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\OneDriveSetup.exe) (Version: 18.151.0729.0012 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3116818766-2193367744-924395030-1003\...\OneDriveSetup.exe) (Version: 18.151.0729.0012 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{56F27690-F6EA-3356-980A-02BA379506EE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{1b103cea-f037-4504-81de-956057b442c3}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2012 (HKLM-x32\...\{89ca2a32-2b52-4595-8dfd-6fe4757958d0}) (Version: 11.0.51108 - Microsoft Corporation) Mozilla Firefox 62.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 62.0.3 (x64 en-US)) (Version: 62.0.3 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0 - Mozilla) Need for Speed - Rivals (HKLM-x32\...\Need for Speed - Rivals_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) Need For Speed The Run version 1.4.0.0 (HKLM-x32\...\Need For Speed The Run_is1) (Version: 1.4.0.0 - Mr DJ) Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x64 Hosting Support - PTB (HKLM\...\{E237254B-36A1-3D27-815E-B37C13BE0796}) (Version: 11.0.51108 - Microsoft Corporation) Hidden Pacote de Idiomas do Microsoft Visual Studio Tools for Applications 2012 x86 Hosting Support - PTB (HKLM-x32\...\{03077B58-6ACF-32CA-B42A-EAA458C295A1}) (Version: 11.0.51108 - Microsoft Corporation) Hidden Panda Cloud Cleaner (HKLM-x32\...\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.1.10 - Panda Security) Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation) Popcorn Time (HKLM-x32\...\Popcorn Time_is1) (Version: 5.5.1.2 - Popcorn Time) <==== ATTENTION Product Registration (HKLM\...\{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Hidden Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.17.007 - Dell Inc.) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8142 - Realtek Semiconductor Corp.) Revo Uninstaller 2.0.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.5 - VS Revo Group, Ltd.) Skype™ 7.37 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.37.103 - Skype Technologies S.A.) Software Intel® PROSet/Wireless (HKLM-x32\...\{8431b7d7-59d1-4f45-8212-a2eac049528f}) (Version: 19.60.0 - Intel Corporation) Software para dispositivos de chipset Intel® (HKLM-x32\...\{60c073df-e736-4210-9c3a-5fc2b651cef3}) (Version: 10.1.1.7 - Intel(R) Corporation) Hidden Spotify (HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\Spotify) (Version: 1.0.90.268.ga8a0ceb4 - Spotify AB) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.95388 - TeamViewer) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Vulkan Run Time Libraries 1.0.33.0 (HKLM\...\VulkanRT1.0.33.0) (Version: 1.0.33.0 - LunarG, Inc.) Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden WhatsApp (HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\WhatsApp) (Version: 0.3.557 - WhatsApp) Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc) WinRAR 5.40 beta 3 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.3 - win.rar GmbH) Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x64) - RUS (HKLM\...\{25FB53C5-BE4C-3B6C-A0C9-D49A39227E1E}) (Version: 11.0.51108 - Microsoft Corporation) Hidden Языковой пакет для поддержки размещения набора средств Microsoft Visual Studio Tools для работы с приложениями 2012 (x86) - RUS (HKLM-x32\...\{68DC347D-C1C0-3DE2-A53E-CCC71DA53E57}) (Version: 11.0.51108 - Microsoft Corporation) Hidden ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-08-19] (Cyberlink) ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2018-06-26] (Apple Inc.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-07-02] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-07-02] (Alexander Roshal) ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-08-19] (Cyberlink) ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll [2017-10-18] () ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\ki127176.inf_amd64_86c658cabfb17c9c\igfxDTCM.dll [2018-03-22] (Intel Corporation) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-07-02] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-07-02] (Alexander Roshal) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0DC11472-AAF4-4909-A1FC-C76C5415EB9C} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2017-10-11] (Intel(R) Corporation) Task: {29A8BF60-D7E5-4EDD-9D2D-EC48C1BA0EFF} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [2015-08-18] (CyberLink) Task: {38E6F3F1-480C-408E-BE4A-6C6A4B869C0E} - System32\Tasks\iToolsDaemon => C:\Program Files (x86)\ThinkSky\iTools 3\iToolsDaemon.exe [2017-03-18] () Task: {4145ACEC-64F5-44AE-AC1C-DB2DB5664B7E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe [2018-09-25] (Microsoft Corporation) Task: {45C5CA0B-4FE3-4151-875F-AE32A9F5DFEC} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-3116818766-2193367744-924395030-1001 => C:\Users\chefcito\AppData\Local\MEGAsync\MEGAupdater.exe [2018-01-15] (Mega Limited) Task: {497B3EBA-C201-4776-A8C0-3C51C3B796BD} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2016-03-24] (PC-Doctor, Inc.) Task: {4BC0A23A-3F37-4E8E-A96D-160DA3267799} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2016-03-24] (PC-Doctor, Inc.) Task: {52393273-9B75-4E26-AFCF-6ED7CA4282C7} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_108_Plugin.exe [2018-09-26] (Adobe Systems Incorporated) Task: {530F92CD-34B5-493C-8B4F-6DF0DEAA6548} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe [2018-09-25] (Microsoft Corporation) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] () Task: {7A2DC757-A1C4-4BE1-BB59-46AD7BAE94A2} - System32\Tasks\{7E185169-EEBA-4B1F-B0C0-9F5EBDE0DCD3} => C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\Wondershare\New TunesGo\unins000.exe" -c /WAF Task: {7A5EA2B0-53F0-4AEB-9E1A-29AA9EBE41B9} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-09-19] (Piriform Ltd) Task: {7CD792E9-C233-49E8-94B2-815FABC7B4AC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-14] (Adobe Systems Incorporated) Task: {8251FE8B-3FFD-4EDE-8A02-0523A1D6E2C5} - System32\Tasks\RtHDVBg_PushButton => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2017-05-04] (Realtek Semiconductor) Task: {889DD04A-6D05-4612-81BC-79F3AABA9811} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {8A08B037-CF71-4D84-A653-01333AC52879} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2016-09-21] () Task: {9A764C3B-C17A-4CDE-9A03-3606F699AE18} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {A8395656-28D3-493E-9CEE-730EAB89A4EE} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe [2018-09-25] (Microsoft Corporation) Task: {A849FBCC-25DF-40A0-AA99-A1C916427641} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-30] (Google Inc.) Task: {AD675FD1-4632-451E-BA49-64C640C69993} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.) Task: {C01E739D-0F98-4B86-B8DD-9AD06C3903FD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-09-19] (Piriform Ltd) Task: {CD8AF87B-593C-4946-AF0B-DE01315B96EE} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-09-26] (Adobe Systems Incorporated) Task: {DFCC863E-962D-4CFD-859E-BB652799EA4E} - System32\Tasks\apagar pc => C:\Windows\System32\shutdown.exe [2018-04-11] (Microsoft Corporation) Task: {E40FB8D6-0A08-41F4-A424-D5FFC64128F2} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe [2018-09-25] (Microsoft Corporation) Task: {E661FB53-2C88-47FF-94E2-6A925AE13A02} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [2015-01-28] (CyberLink Corp.) Task: {F2E152BB-D652-40D6-9FC7-0E2974D2CFD1} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.) Task: {F4565002-D17E-47A4-8649-8E584F1F1BA8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-30] (Google Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\RunDLC.job => cmd c sc start Dell Help SupportWORKGROUP DESKTOP 24AAV6T ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-02-15 21:01 - 2016-02-15 21:01 - 000031256 _____ () C:\WINDOWS\System32\us008lm.dll 2015-12-28 10:49 - 2014-04-14 21:59 - 000253776 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2017-12-08 02:48 - 2017-12-08 02:48 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2018-08-22 22:18 - 2018-08-22 22:18 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2018-04-11 18:34 - 2018-04-11 18:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll 2018-04-11 18:34 - 2018-04-11 18:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-04-11 18:34 - 2018-04-11 18:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2018-09-16 14:02 - 2018-08-30 22:12 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-10-02 21:47 - 2018-10-02 21:47 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\ImagePipelineNative.dll 2018-10-02 21:47 - 2018-10-02 21:47 - 000058880 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\ChakraBridge.dll 2018-10-02 21:47 - 2018-10-02 21:48 - 000019456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\SkypeProxiesAndStubs.dll 2018-10-02 21:47 - 2018-10-02 21:47 - 010927104 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\LibWrapper.dll 2018-10-02 21:47 - 2018-10-02 21:48 - 002756096 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\skypert.dll 2018-10-02 21:47 - 2018-10-02 21:48 - 000683520 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-09-17 23:35 - 2018-07-06 02:00 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll 2018-09-17 23:35 - 2018-07-06 02:00 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll 2018-09-19 20:18 - 2018-09-15 03:26 - 005110616 _____ () C:\Program Files (x86)\Google\Chrome\Application\69.0.3497.100\libglesv2.dll 2018-09-19 20:18 - 2018-09-15 03:26 - 000116056 _____ () C:\Program Files (x86)\Google\Chrome\Application\69.0.3497.100\libegl.dll 2016-02-15 21:01 - 2016-02-15 21:01 - 001730400 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\us008du.dll 2018-10-02 21:47 - 2018-10-02 21:48 - 000181248 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.30.98.1000_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe 2017-10-18 16:51 - 2017-10-18 16:51 - 000598528 _____ () C:\Users\chefcito\AppData\Local\MEGAsync\ShellExtX64.dll 2018-09-29 16:32 - 2018-09-29 16:33 - 000199168 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11808.1001.10.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll 2018-07-31 14:10 - 2018-07-31 14:10 - 002447072 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11808.1001.10.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-09-15 19:01 - 2018-09-15 19:01 - 001685504 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11808.1001.10.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.dll 2018-09-29 16:32 - 2018-09-29 16:33 - 007618560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11808.1001.10.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2018-07-18 12:48 - 2018-06-14 23:41 - 005471232 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll 2018-07-18 12:47 - 2018-06-14 23:36 - 000047616 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll 2018-07-18 12:48 - 2018-06-14 23:40 - 005082112 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll 2015-12-28 10:47 - 2014-12-08 02:28 - 000627672 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMediaLibrary.dll 2014-12-08 18:28 - 2014-12-08 18:28 - 000016856 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvcPS.dll 2017-09-19 10:35 - 2017-09-19 10:35 - 000134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll 2018-03-27 13:41 - 2018-03-27 13:41 - 000134616 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll 2017-11-09 00:44 - 2017-11-09 00:44 - 001244304 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2010-01-09 21:18 - 2010-01-09 21:18 - 004254560 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf 2018-08-22 22:19 - 2018-08-22 22:19 - 001042232 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2017-12-08 02:49 - 2017-12-08 02:49 - 000076088 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2018-08-22 22:18 - 2018-08-22 22:18 - 000189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll 2018-09-15 18:31 - 2018-09-30 14:11 - 085383400 _____ () C:\Users\chefcito\AppData\Roaming\Spotify\libcef.dll 2018-09-15 18:31 - 2018-09-30 14:11 - 004078312 _____ () C:\Users\chefcito\AppData\Roaming\Spotify\libglesv2.dll 2018-09-15 18:31 - 2018-09-30 14:11 - 000097512 _____ () C:\Users\chefcito\AppData\Roaming\Spotify\libegl.dll 2018-03-18 20:57 - 2018-03-18 20:57 - 000021816 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleBMDAV.resources\es.lproj\AppleBMDAVLocalized.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\localhost -> localhost ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 06:04 - 2018-09-17 21:08 - 000336649 _____ C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 Suissa-ad.flycast.com 127.0.0.1 UGO.eu-adcenter.net 127.0.0.1 VNU.eu-adcenter.net 127.0.0.1 a32.g.a.yimg.com 127.0.0.1 ad-adex3.flycast.com 127.0.0.1 ad.adsmart.net 127.0.0.1 ad.ca.doubleclick.net 127.0.0.1 ad.de.doubleclick.net 127.0.0.1 ad.doubleclick.net 127.0.0.1 ad.fr.doubleclick.net 127.0.0.1 ad.jp.doubleclick.net 127.0.0.1 ad.linkexchange.com 127.0.0.1 ad.linksynergy.com 127.0.0.1 ad.nl.doubleclick.net 127.0.0.1 ad.no.doubleclick.net 127.0.0.1 ad.preferences.com 127.0.0.1 ad.sma.punto.net 127.0.0.1 ad.uk.doubleclick.net 127.0.0.1 ad.webprovider.com 127.0.0.1 ad08.focalink.com 127.0.0.1 adcontroller.unicast.com 127.0.0.1 adcreatives.imaginemedia.com 127.0.0.1 adex3.flycast.com 127.0.0.1 adforce.ads.imgis.com 127.0.0.1 adforce.imgis.com 127.0.0.1 adfu.blockstackers.com 127.0.0.1 adimage.blm.net 127.0.0.1 adimages.earthweb.com 127.0.0.1 adimg.egroups.com 127.0.0.1 admedia.xoom.com There are 10249 more lines. ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3116818766-2193367744-924395030-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\chefcito\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\stay_hungry_stay_foolish_2-wallpaper-1366x768.jpg HKU\S-1-5-21-3116818766-2193367744-924395030-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\anett\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run: => "Malwarebytes TrayApp" HKLM\...\StartupApproved\Run32: => "5KPlayer.exe" HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk" HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount" HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-3116818766-2193367744-924395030-1001\...\StartupApproved\Run: => "Spotify" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{3630993D-716D-4B31-A3C9-DEB21EBC11A7}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{7C27B354-7BD3-4359-BDAF-6C8850500803}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{113BD465-81B4-4CCE-8A57-758F7DFE0B58}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{1D307D7B-9093-49CA-A63E-EB5E3A41E2C3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{5435B01B-5091-4C4A-8B40-4853B6F6AF9B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{DC6E99B0-6F94-43E7-A259-61858A266563}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{535EA27B-C8A8-4798-9613-01DF52052648}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerManager\ApowerManagerCoreServices.exe FirewallRules: [{6B90212C-1006-4B6D-B026-79C6F17E4968}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerManager\ApowerManagerCoreServices.exe FirewallRules: [{84DD7CA8-B3C7-4FE3-9E38-8A7182C7BDF2}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerManager\ApowerManager.exe FirewallRules: [{9D42531E-9D82-4B88-AAB3-B4A21B264A1C}] => (Allow) C:\Program Files (x86)\Apowersoft\ApowerManager\ApowerManager.exe FirewallRules: [{697DEE0A-B637-479A-891D-123825CA8760}] => (Allow) C:\Games\Grand Theft Auto V\GTA5.exe FirewallRules: [{210C90CD-D573-4F97-85E4-AA10A0A7F171}] => (Allow) C:\Games\Grand Theft Auto V\GTA5.exe FirewallRules: [{31443FA0-D417-4F19-BA12-F5A6C77E5664}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [UDP Query User{DF788B1F-7FFD-4E57-ADAE-9693111CA252}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [TCP Query User{2162AC4F-1100-4A7E-8FE3-852FBE5D21AC}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Block) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [{DAF2C5F1-1538-4A52-BB25-7A2F705C8D3D}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [{8EE486C7-E65A-4250-ADA6-AC7B343FA454}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe FirewallRules: [UDP Query User{ECF22742-E913-41C2-9FC2-C1E181ECFD8A}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [TCP Query User{815BC73E-81BC-48E3-B313-381FD7FFAB25}C:\program files (x86)\dearmob\5kplayer\5kplayer.exe] => (Allow) C:\program files (x86)\dearmob\5kplayer\5kplayer.exe FirewallRules: [UDP Query User{B2D7E031-E782-428D-B42E-FB49B59620CE}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [TCP Query User{72E6EC01-499F-47EF-8EBF-101447133856}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe FirewallRules: [{202C2AAF-C31C-4BA2-94C7-86355D3CF3FE}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{454DA326-72EE-4384-9853-3BDFD346439B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{C04E9610-B677-40CA-B949-E4D1BC41F307}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{0B31DB4E-3B26-4EEB-ADEE-907BE54E1871}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{7E234787-5823-406B-8A16-7CADCD54E519}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe FirewallRules: [{B3E48AEC-0AEF-4718-8299-CF3BEE21770C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{16166AB1-B2B3-44BA-A25E-8B58A35B523E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{70244A18-935A-4409-A74C-8C20EC487306}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{B1EF1930-39FA-4D72-95E7-79ECD571692A}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C8D22712-0FFC-4F94-A4B9-C8F2EEA7E4FB}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{A173884C-2B09-4BD3-A825-E0CFF6C85944}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{4113F31D-D178-41C2-B73E-45FF6145671C}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C4B91DC2-36E2-4D09-94B1-0C3CDB20151D}] => (Allow) C:\Users\chefcito\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{FAEA6A51-F842-4954-8128-CC536F970D98}] => (Allow) C:\Program Files (x86)\Mr DJ\Need For Speed The Run\Need For Speed The Run.exe FirewallRules: [{4AB96C81-095F-4432-8608-98E4C23A44B8}] => (Allow) C:\Program Files (x86)\Mr DJ\Need For Speed The Run\Need For Speed The Run.exe FirewallRules: [TCP Query User{3997D094-765D-4469-9FA0-E52F56F58163}C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe] => (Allow) C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe FirewallRules: [UDP Query User{BEE40708-2EA7-4DB4-892B-3358A9900792}C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe] => (Allow) C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe FirewallRules: [{EC1F6BBB-E5FB-48FB-89A2-5EA5FCC2E9CE}] => (Block) c:\Program Files\Corel\CorelDRAW Graphics Suite X7\Programs64\CorelDrw.exe FirewallRules: [TCP Query User{299A4E8E-27D2-423B-B4BC-59A3C59E0F94}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{72E2298B-B495-4013-B238-9769C45E363B}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{96EA9230-3FF9-4B74-BF79-271CBE88D485}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{1FE24E06-3B57-475E-86E7-AA66AC63A990}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe FirewallRules: [TCP Query User{D0876698-3C33-4B09-8B14-DA147FDD1B3B}C:\users\chefcito\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\chefcito\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{1C8B9475-B98C-4C24-9B1F-419683A1997F}C:\users\chefcito\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\chefcito\appdata\roaming\spotify\spotify.exe FirewallRules: [{E5241812-C021-4DA3-9874-EA2A4DD446DE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{3A55B26E-3B9D-4842-BB6E-EC8D590472C9}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe FirewallRules: [{0DD74C31-DDDB-4E82-A490-60B026316659}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe ==================== Restore Points ========================= 21-09-2018 20:53:00 Instalador de Módulos de Windows 23-09-2018 19:18:33 Instalador de Módulos de Windows 25-09-2018 08:20:41 Instalador de Módulos de Windows 26-09-2018 14:31:25 Instalador de Módulos de Windows 28-09-2018 12:10:50 Instalador de Módulos de Windows 29-09-2018 17:36:54 Instalador de Módulos de Windows 30-09-2018 19:40:32 Instalador de Módulos de Windows 01-10-2018 21:39:12 Instalador de Módulos de Windows 03-10-2018 10:12:07 Instalador de Módulos de Windows 04-10-2018 13:58:28 Instalador de Módulos de Windows ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/04/2018 10:22:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Nombre del módulo con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Código de excepción: 0xc000041d Desplazamiento de errores: 0x00000000000041d0 Identificador del proceso con errores: 0x3790 Hora de inicio de la aplicación con errores: 0x01d45c5aabecbdbb Ruta de acceso de la aplicación con errores: C:\Program Files\Dell\QuickSet\quickset.exe Ruta de acceso del módulo con errores: C:\Program Files\Dell\QuickSet\quickset.exe Identificador del informe: 81623892-7968-4488-9886-a8eda3cbded5 Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 10:22:41 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Nombre del módulo con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Código de excepción: 0xc0000005 Desplazamiento de errores: 0x00000000000041d0 Identificador del proceso con errores: 0x3790 Hora de inicio de la aplicación con errores: 0x01d45c5aabecbdbb Ruta de acceso de la aplicación con errores: C:\Program Files\Dell\QuickSet\quickset.exe Ruta de acceso del módulo con errores: C:\Program Files\Dell\QuickSet\quickset.exe Identificador del informe: 6fa61b49-c153-49e8-b3f2-8568cc153842 Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 09:47:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Nombre del módulo con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Código de excepción: 0xc000041d Desplazamiento de errores: 0x00000000000041d0 Identificador del proceso con errores: 0x1744 Hora de inicio de la aplicación con errores: 0x01d45c55a708914d Ruta de acceso de la aplicación con errores: C:\Program Files\Dell\QuickSet\quickset.exe Ruta de acceso del módulo con errores: C:\Program Files\Dell\QuickSet\quickset.exe Identificador del informe: 7635a6f6-40e6-41dd-8188-63d7f99ebc80 Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 09:46:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Nombre del módulo con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Código de excepción: 0xc0000005 Desplazamiento de errores: 0x00000000000041d0 Identificador del proceso con errores: 0x1744 Hora de inicio de la aplicación con errores: 0x01d45c55a708914d Ruta de acceso de la aplicación con errores: C:\Program Files\Dell\QuickSet\quickset.exe Ruta de acceso del módulo con errores: C:\Program Files\Dell\QuickSet\quickset.exe Identificador del informe: 8c5a2c63-e9bf-47ae-aacd-0749440be981 Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 09:40:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: ZeroConfigService.exe, versión: 19.60.0.0, marca de tiempo: 0x58d16fa6 Nombre del módulo con errores: ZeroConfigService.exe, versión: 19.60.0.0, marca de tiempo: 0x58d16fa6 Código de excepción: 0xc0000409 Desplazamiento de errores: 0x000000000022af80 Identificador del proceso con errores: 0xf94 Hora de inicio de la aplicación con errores: 0x01d45be1c853aa09 Ruta de acceso de la aplicación con errores: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe Ruta de acceso del módulo con errores: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe Identificador del informe: 36a19af3-a3ac-423c-940d-574bede20863 Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 09:20:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Nombre del módulo con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Código de excepción: 0xc000041d Desplazamiento de errores: 0x00000000000041d0 Identificador del proceso con errores: 0x4d98 Hora de inicio de la aplicación con errores: 0x01d45c51f0e8c025 Ruta de acceso de la aplicación con errores: C:\Program Files\Dell\QuickSet\quickset.exe Ruta de acceso del módulo con errores: C:\Program Files\Dell\QuickSet\quickset.exe Identificador del informe: 332a3791-1f53-493e-bb4e-5b2a3c33d24d Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 09:20:11 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Nombre del módulo con errores: quickset.exe, versión: 10.17.7.3, marca de tiempo: 0x558a13bc Código de excepción: 0xc0000005 Desplazamiento de errores: 0x00000000000041d0 Identificador del proceso con errores: 0x4d98 Hora de inicio de la aplicación con errores: 0x01d45c51f0e8c025 Ruta de acceso de la aplicación con errores: C:\Program Files\Dell\QuickSet\quickset.exe Ruta de acceso del módulo con errores: C:\Program Files\Dell\QuickSet\quickset.exe Identificador del informe: fbedbfb4-95ea-467c-9afb-085421d85aa9 Nombre completo del paquete con errores: Identificador de aplicación relativa del paquete con errores: Error: (10/04/2018 03:03:20 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1969 System errors: ============= Error: (10/04/2018 10:22:56 PM) (Source: DCOM) (EventID: 10016) (User: CHEFCITO-PC) Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} y APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} al usuario CHEFCITO-PC\chefcito con SID (S-1-5-21-3116818766-2193367744-924395030-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 10:22:17 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} y APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 09:54:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} y APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} al usuario NT AUTHORITY\SERVICIO LOCAL con SID (S-1-5-19) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 09:48:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID Windows.SecurityCenter.WscDataProtection y APPID No disponible al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 09:48:34 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID Windows.SecurityCenter.WscBrokerManager y APPID No disponible al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 09:47:44 PM) (Source: DCOM) (EventID: 10016) (User: CHEFCITO-PC) Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID Windows.SecurityCenter.WscCloudBackupProvider y APPID No disponible al usuario CHEFCITO-PC\anett con SID (S-1-5-21-3116818766-2193367744-924395030-1003) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 09:47:37 PM) (Source: DCOM) (EventID: 10016) (User: CHEFCITO-PC) Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} y APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} al usuario CHEFCITO-PC\anett con SID (S-1-5-21-3116818766-2193367744-924395030-1003) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Error: (10/04/2018 09:47:03 PM) (Source: DCOM) (EventID: 10016) (User: CHEFCITO-PC) Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} y APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} al usuario CHEFCITO-PC\anett con SID (S-1-5-21-3116818766-2193367744-924395030-1003) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes. Windows Defender: =================================== Date: 2018-10-04 21:19:25.957 Description: El examen de Antivirus de Windows Defender se detuvo antes de completarse. Id. de examen: {4D36DE8A-08FD-47D1-A8F5-E255C6704D4E} Tipo de examen: Antimalware Parámetros de examen: Examen rápido Usuario: NT AUTHORITY\SYSTEM Date: 2018-10-04 14:41:50.907 Description: El examen de Antivirus de Windows Defender se detuvo antes de completarse. Id. de examen: {744CF8AD-4BC0-4CF6-B2CB-5F827EF08A15} Tipo de examen: Antimalware Parámetros de examen: Examen rápido Usuario: NT AUTHORITY\SYSTEM Date: 2018-10-04 08:49:25.531 Description: El examen de Antivirus de Windows Defender se detuvo antes de completarse. Id. de examen: {045E3646-A600-4DEB-BE12-6CCC341BFB61} Tipo de examen: Antimalware Parámetros de examen: Examen rápido Usuario: NT AUTHORITY\SYSTEM Date: 2018-10-04 08:40:23.825 Description: El examen de Antivirus de Windows Defender se detuvo antes de completarse. Id. de examen: {9733DDDA-187B-4A32-A801-6520A0FA0294} Tipo de examen: Antimalware Parámetros de examen: Examen rápido Usuario: NT AUTHORITY\SYSTEM Date: 2018-09-26 14:35:35.360 Description: El examen de Antivirus de Windows Defender se detuvo antes de completarse. Id. de examen: {CFBF8C49-536A-48A3-9927-4281F470DDDB} Tipo de examen: Antimalware Parámetros de examen: Examen rápido Usuario: NT AUTHORITY\SYSTEM Date: 2018-09-15 12:14:25.439 Description: Antivirus de Windows Defender encontró un error al intentar actualizar las firmas. Nueva versión de firma: Versión de firma anterior: 1.275.1090.0 Origen de actualización: Centro de protección contra malware de Microsoft Tipo de firma: AntiVirus Tipo de actualización: Completa Usuario: NT AUTHORITY\Servicio de red Versión de motor actual: Versión de motor anterior: 1.1.15200.1 Código de error: 0x80072ee7 Descripción del error: No se pudo resolver el nombre de servidor o su dirección Date: 2018-09-15 12:14:25.438 Description: Antivirus de Windows Defender encontró un error al intentar actualizar las firmas. Nueva versión de firma: Versión de firma anterior: 1.275.1090.0 Origen de actualización: Centro de protección contra malware de Microsoft Tipo de firma: AntiSpyware Tipo de actualización: Completa Usuario: NT AUTHORITY\Servicio de red Versión de motor actual: Versión de motor anterior: 1.1.15200.1 Código de error: 0x80072ee7 Descripción del error: No se pudo resolver el nombre de servidor o su dirección Date: 2018-09-15 12:14:25.438 Description: Antivirus de Windows Defender encontró un error al intentar actualizar las firmas. Nueva versión de firma: Versión de firma anterior: 1.275.1090.0 Origen de actualización: Centro de protección contra malware de Microsoft Tipo de firma: AntiVirus Tipo de actualización: Completa Usuario: NT AUTHORITY\Servicio de red Versión de motor actual: Versión de motor anterior: 1.1.15200.1 Código de error: 0x80072ee7 Descripción del error: No se pudo resolver el nombre de servidor o su dirección Date: 2018-09-15 12:14:25.427 Description: Antivirus de Windows Defender encontró un error al intentar actualizar las firmas. Nueva versión de firma: Versión de firma anterior: 1.275.1090.0 Origen de actualización: Centro de protección contra malware de Microsoft Tipo de firma: AntiVirus Tipo de actualización: Completa Usuario: NT AUTHORITY\Servicio de red Versión de motor actual: Versión de motor anterior: 1.1.15200.1 Código de error: 0x80072ee7 Descripción del error: No se pudo resolver el nombre de servidor o su dirección Date: 2018-09-15 12:14:25.427 Description: Antivirus de Windows Defender encontró un error al intentar actualizar las firmas. Nueva versión de firma: Versión de firma anterior: 1.275.1090.0 Origen de actualización: Centro de protección contra malware de Microsoft Tipo de firma: AntiSpyware Tipo de actualización: Completa Usuario: NT AUTHORITY\Servicio de red Versión de motor actual: Versión de motor anterior: 1.1.15200.1 Código de error: 0x80072ee7 Descripción del error: No se pudo resolver el nombre de servidor o su dirección CodeIntegrity: =================================== Date: 2018-08-16 21:33:19.576 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2018-07-05 07:54:33.578 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. Date: 2018-06-06 10:49:47.352 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz Percentage of memory in use: 69% Total physical RAM: 8083.9 MB Available physical RAM: 2484.8 MB Total Virtual: 11083.9 MB Available Virtual: 4507.55 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:918.16 GB) (Free:491.27 GB) NTFS Drive d: (LADICTADURAFASTERFTP) (CDROM) (Total:4.36 GB) (Free:0 GB) UDF \\?\Volume{237fd491-666e-4fba-9098-f9e8eba87de8}\ (WINRETOOLS) (Fixed) (Total:0.87 GB) (Free:0.47 GB) NTFS \\?\Volume{e2ce6c3d-1f09-4411-bba8-48d19f83a79b}\ (Image) (Fixed) (Total:11.87 GB) (Free:0.43 GB) NTFS \\?\Volume{f907e68b-117c-42fd-824c-c5719e6bbc4f}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.46 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 165AE242) Partition: GPT. ==================== End of Addition.txt ============================