Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-06-2019 Ran by igna_ (administrator) on DESKTOP-0IQOHNG (Dell Inc. Inspiron 5459) (30-06-2019 22:08:23) Running from C:\Users\igna_\Downloads Loaded Profiles: igna_ (Available Profiles: igna_) Platform: Windows 10 Home Single Language Version 1809 17763.557 (X64) Language: Español (España, internacional) Default browser: Chrome Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) () [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe () [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe () [File not signed] C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (CyberLink Corp. -> ) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe (Dell Inc -> Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe (Dell Inc -> Dell) C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe (Dell Inc -> Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe (Dell Inc -> Dell) C:\Program Files\Dell\Dell Product Registration\PRSvc.exe (Dell Inc. -> Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe (Dell Inc. -> Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127176.inf_amd64_86c658cabfb17c9c\igfxCUIService.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127176.inf_amd64_86c658cabfb17c9c\igfxEM.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127176.inf_amd64_86c658cabfb17c9c\IntelCpHDCPSvc.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127176.inf_amd64_86c658cabfb17c9c\IntelCpHeciSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeApp.exe (Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.48.51.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe (Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.WindowsStore_11905.1001.4.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1905.4-0\MsMpEng.exe (Panda Security S.L -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe (Panda Security S.L -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (Panda Security S.L -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe (Panda Security S.L. -> Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe (Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe (Waves Inc -> Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8848640 2016-02-05] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-02-05] (Realtek Semiconductor Corp -> Realtek Semiconductor) HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5786576 2015-06-24] (Compal electronic ,inc -> Dell Inc.) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322120 2016-04-28] (Intel(R) Rapid Storage Technology -> Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [301880 2018-10-22] (Apple Inc. -> Apple Inc.) HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [611248 2015-05-26] (Waves Inc -> Waves Audio Ltd.) HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [109824 2016-08-05] (Panda Security S.L -> Panda Security, S.L.) HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-1024775671-315252889-1402477582-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2018-10-01] (Apple Inc. -> Apple Inc.) HKU\S-1-5-21-1024775671-315252889-1402477582-1001\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [356664 2018-10-01] (Apple Inc. -> Apple Inc.) HKU\S-1-5-21-1024775671-315252889-1402477582-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22695280 2019-06-18] (Piriform Software Ltd -> Piriform Software Ltd) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.100\Installer\chrmstp.exe [2019-06-21] (Google LLC -> Google LLC) GroupPolicyScripts: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0251D447-ECC9-4902-B1CC-1C8EDC7256C1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {08669B1F-968C-4C4D-8F92-2DCD03548230} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\igna_\Downloads\esetonlinescanner_esn.exe [7982616 2019-06-29] (ESET, spol. s r.o. -> ESET spol. s r.o.) Task: {0E8C852F-293F-4091-B107-D1DA13DF56C0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {0F087D2C-895C-4670-BE7A-86DA394DE3CF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16667424 2019-06-18] (Piriform Software Ltd -> Piriform Software Ltd) Task: {1E6F3E2A-59D1-4CB6-8842-D5E751C75B7D} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {3A041AD6-7E26-4DD8-9B0A-52CC83BADB78} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [340440 2015-01-28] (CyberLink Corp. -> CyberLink Corp.) Task: {47856552-9F27-499D-A329-AA43D072090D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {4949445E-576B-49AA-BBD4-97144E3E971F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {86E037C2-B7B4-4F77-9721-AA59E93C3424} - no filepath Task: {9BAAD9D7-A26E-438D-8D82-A53F5BB6B340} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MpCmdRun.exe [469960 2019-06-02] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {A4DEA616-17E5-4F48-A2C2-7701FD102755} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [416432 2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Task: {B6878290-B2C5-4E8A-BD1E-2FF8C9084FF4} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [110008 2015-08-19] (CyberLink Corp. -> CyberLink) Task: {C4A24894-C1F7-46C3-B876-7BB3DF687701} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.) Task: {C71098FB-498D-4D34-BFD5-5CD9E6C5DE3D} - no filepath Task: {CA579A0A-5BA5-415B-96EC-D91E72A1F550} - System32\Tasks\{F43539F2-AF2B-4F4D-B591-54F15E4C0C55} => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe [82032 2016-08-01] (Panda Security S.L -> Panda Security, S.L.) Task: {CB326C3A-DCA0-487A-8106-11652D7F5019} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-05-23] (Google Inc -> Google LLC) Task: {D9E71BA4-08A7-4143-9365-CB0781FE409A} - no filepath Task: {E7DD184D-4767-453C-8D1D-2F0A18F1C3EE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-06-18] (Piriform Software Ltd -> Piriform Software Ltd) Task: {F4CC94F3-412B-4117-AD53-8F0B563379B5} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\igna_\Downloads\esetonlinescanner_esn.exe [7982616 2019-06-29] (ESET, spol. s r.o. -> ESET spol. s r.o.) Task: {F75FBD2B-7472-4E7B-A54F-FC6A3B9B1A3E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-05-23] (Google Inc -> Google LLC) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\RunDFS.job => cmd /c sc start Dell Foundation ServicesWORKGROUP DESKTOP 0IQOHNG 06 Task: C:\WINDOWS\Tasks\RunDLC.job => cmd c sc start Dell Help SupportWORKGROUP DESKTOP 0IQOHNG 07 Task: C:\WINDOWS\Tasks\{F43539F2-AF2B-4F4D-B591-54F15E4C0C55}.job => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: 0.0.0.0 telemetry.malwarebytes.com Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{aed91d49-b366-4fc4-8a27-dab64e9900e1}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKU\S-1-5-21-1024775671-315252889-1402477582-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell15.msn.com/?pc=DCTE HKU\S-1-5-21-1024775671-315252889-1402477582-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) FireFox: ======== FF DefaultProfile: xk8ujm9c.default-1549042999832 FF ProfilePath: C:\Users\igna_\AppData\Roaming\Mozilla\Firefox\Profiles\xk8ujm9c.default-1549042999832 [2019-06-30] FF Extension: (AdBlock) - C:\Users\igna_\AppData\Roaming\Mozilla\Firefox\Profiles\xk8ujm9c.default-1549042999832\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2019-05-16] FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-24] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-24] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-23] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-23] (Google Inc -> Google LLC) FF Plugin-x32: @videolan.org/vlc,version=3.0.0-git -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-11-21] (VideoLAN) [File not signed] FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-01-31] (Adobe Systems, Incorporated -> Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> hxxps://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.com.ar/" CHR Profile: C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default [2019-06-30] CHR Extension: (Presentaciones) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-28] CHR Extension: (Documentos) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-28] CHR Extension: (Google Drive) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-16] CHR Extension: (YouTube) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-11-28] CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-05-20] CHR Extension: (Hojas de cálculo) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-28] CHR Extension: (Cablevisión Flow) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfbnbmbkemlokfckhdoaakhjogffkinc [2017-12-02] CHR Extension: (Documentos de Google sin conexión) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-15] CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-02] CHR Extension: (Gmail) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-23] CHR Extension: (Chrome Media Router) - C:\Users\igna_\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-22] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [85304 2018-10-16] (Apple Inc. -> Apple Inc.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2017-12-20] (BattlEye Innovations e.K. -> ) R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208760 2017-07-27] (Dell Inc -> Dell Inc.) R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294584 2017-07-27] (Dell Inc -> Dell Inc.) R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-07-27] (Dell Inc -> Dell Inc.) R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [137968 2015-09-22] (Dell Inc. -> Dell Inc.) R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell Inc -> Dell) R2 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [40976 2017-09-18] (Dell Inc -> Dell Inc.) R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [184064 2017-02-02] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel® Trusted Connect Service -> Intel(R) Corporation) S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed] R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-10-16] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6562472 2019-02-01] (Malwarebytes Corporation -> Malwarebytes) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-03-21] (Intel Corporation-Wireless Connectivity Solutions -> ) R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [153096 2016-08-04] (Panda Security S.L -> Panda Security, S.L.) R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [84176 2019-02-19] (Panda Security S.L. -> Panda Security, S.L.) R2 Product Registration; C:\Program Files\Dell\Dell Product Registration\PRSvc.exe [47144 2017-04-06] (Dell Inc -> Dell) R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [47096 2017-04-26] (Panda Security S.L. -> Panda Security, S.L.) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2014-04-14] (CyberLink Corp. -> ) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-05] (Realtek Semiconductor Corp -> Realtek Semiconductor) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [53208 2017-09-22] (Dell Inc. -> Dell Inc.) R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [564144 2015-05-26] (Waves Inc -> Waves Audio Ltd.) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\NisSrv.exe [2433136 2019-06-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1905.4-0\MsMpEng.exe [109896 2019-06-02] (Microsoft Windows Publisher -> Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3750304 2017-03-21] (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2017-11-16] (AnchorFree Inc -> The OpenVPN Project) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.) R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [32960 2017-07-27] (Techporch Incorporated -> Dell Inc.) R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [32568 2017-07-27] (Techporch Incorporated -> Dell Computer Corporation) R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-08] (Microsoft Windows Hardware Compatibility Publisher -> OSR Open Systems Resources, Inc.) S3 iaLPSS2_GPIO2; C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys [84264 2015-06-16] (Intel Corporation - Client Components Group -> Intel Corporation) R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [230656 2017-02-02] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-02-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-06-29] (Malwarebytes Corporation -> Malwarebytes) R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3517696 2017-04-13] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation) R1 NNSALPC; C:\WINDOWS\system32\DRIVERS\NNSALPC.sys [103856 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [210864 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [120240 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [120240 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [58616 2015-06-19] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [112560 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPIHSW; C:\WINDOWS\system32\DRIVERS\NNSPIHSW.sys [82864 2016-03-17] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [133552 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [309680 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [179632 2016-02-18] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [122800 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [267184 2016-02-18] (Panda Security S.L. -> Panda Security, S.L.) R1 NNSTLSC; C:\WINDOWS\system32\DRIVERS\NNSTLSC.sys [115632 2015-12-10] (Panda Security S.L. -> Panda Security, S.L.) S0 PsBoot; C:\WINDOWS\System32\Drivers\PsBoot.sys [52104 2018-01-30] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [174000 2016-08-09] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [129456 2016-08-09] (Panda Security S.L. -> Panda Security, S.L.) R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [207712 2018-03-08] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [133544 2016-08-09] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [146864 2016-08-09] (Panda Security S.L. -> Panda Security, S.L.) R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [117168 2016-08-09] (Panda Security S.L. -> Panda Security, S.L.) R3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72112 2016-08-09] (Panda Security S.L. -> Panda Security, S.L.) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek Semiconductor Corp -> Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation) S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2017-02-02] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2017-02-02] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2017-02-02] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640 2017-01-31] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated) S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2017-02-02] (DEVGURU CO LTD -> DEVGURU Co., LTD.) S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2017-02-02] (DEVGURU CO LTD -> DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2017-02-02] (DEVGURU CO LTD -> DEVGURU Co., LTD.) S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (OpenVPN Technologies, Inc. -> The OpenVPN Project) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-06-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [337632 2019-06-02] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-06-02] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-06-30 22:08 - 2019-06-30 22:10 - 000030199 _____ C:\Users\igna_\Downloads\FRST.txt 2019-06-30 22:07 - 2019-06-30 22:08 - 000000000 ____D C:\FRST 2019-06-30 22:06 - 2018-01-30 06:22 - 000052104 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PsBoot.sys 2019-06-30 22:05 - 2019-06-30 22:05 - 002419200 ____N (Farbar) C:\Users\igna_\Downloads\FRST64.exe 2019-06-30 16:18 - 2019-06-30 16:31 - 000000000 ____D C:\Users\igna_\AppData\Roaming\ZHP 2019-06-30 16:18 - 2019-06-30 16:18 - 000000877 _____ C:\Users\igna_\Desktop\ZHPCleaner.lnk 2019-06-30 16:18 - 2019-06-30 16:18 - 000000000 ____D C:\Users\igna_\AppData\Local\ZHP 2019-06-30 16:13 - 2019-06-30 16:13 - 003147648 _____ (Nicolas Coolman) C:\Users\igna_\Downloads\ZHPCleaner.exe 2019-06-29 16:08 - 2019-06-29 16:08 - 000003812 _____ C:\WINDOWS\System32\Tasks\EOSv3 Scheduler onLogOn 2019-06-29 16:08 - 2019-06-29 16:08 - 000003370 _____ C:\WINDOWS\System32\Tasks\EOSv3 Scheduler onTime 2019-06-29 12:46 - 2019-06-29 12:46 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2019-06-29 02:20 - 2019-06-30 16:07 - 000000000 ____D C:\Users\igna_\AppData\Local\ESET 2019-06-29 02:20 - 2019-06-29 12:46 - 000000672 _____ C:\Users\igna_\Desktop\ESET Online Scanner.lnk 2019-06-29 02:20 - 2019-06-29 02:20 - 007982616 _____ (ESET spol. s r.o.) C:\Users\igna_\Downloads\esetonlinescanner_esn.exe 2019-06-29 02:20 - 2019-06-29 02:20 - 000000771 _____ C:\Users\igna_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk 2019-06-29 02:09 - 2019-06-29 02:09 - 000976896 _____ (Bleeping Computer, LLC) C:\Users\igna_\Downloads\rkill-unsigned64.exe 2019-06-29 02:08 - 2019-06-29 02:08 - 001780224 _____ (Bleeping Computer, LLC) C:\Users\igna_\Downloads\rkill-unsigned.exe 2019-06-29 01:24 - 2019-06-29 01:25 - 007025360 _____ (Malwarebytes) C:\Users\igna_\Downloads\adwcleaner_7.3.exe 2019-06-29 01:20 - 2019-06-29 01:20 - 000000000 ____D C:\Users\igna_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer 2019-06-29 01:12 - 2019-06-29 01:20 - 000000000 ____D C:\Users\igna_\Desktop\gta 2019-06-29 01:01 - 2019-06-29 13:00 - 000007601 _____ C:\Users\igna_\AppData\Local\Resmon.ResmonCfg 2019-06-28 19:28 - 2019-06-28 19:28 - 000000000 ____D C:\Users\igna_\Documents\GTA San Andreas User Files 2019-06-28 19:26 - 2019-06-28 19:27 - 016278985 _____ C:\Users\igna_\Downloads\Samp_By Scour Flow XD.zip 2019-06-28 19:17 - 2019-06-28 19:19 - 557604222 _____ C:\Users\igna_\Downloads\GTA San Andreas 2.8.rar 2019-06-25 23:39 - 2019-06-25 23:39 - 020650160 _____ (Piriform Software Ltd) C:\Users\igna_\Downloads\ccsetup559.exe 2019-06-23 18:59 - 2019-06-25 23:41 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update 2019-06-23 18:59 - 2019-06-25 23:40 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk 2019-06-23 18:59 - 2019-06-23 18:59 - 000002888 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2019-06-23 18:59 - 2019-06-23 18:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2019-06-23 18:56 - 2019-06-23 18:57 - 020638704 _____ (Piriform Software Ltd) C:\Users\igna_\Downloads\ccsetup558.exe 2019-06-19 12:01 - 2019-06-19 12:01 - 000004115 _____ C:\Users\igna_\Downloads\transferencia.pdf 2019-06-18 22:04 - 2019-06-18 22:05 - 000079840 _____ C:\Users\igna_\Downloads\NO-2019-53374851-APN-DNHFYSF%23MSYDS.pdf 2019-06-18 15:48 - 2019-06-18 15:48 - 000000000 ____D C:\Program Files\UNP 2019-06-13 16:24 - 2019-06-13 16:24 - 007724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 005112792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 002469440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 001260048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2019-06-13 16:24 - 2019-06-13 16:24 - 001223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 000898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll 2019-06-13 16:24 - 2019-06-13 16:24 - 000311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 026808320 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 023438336 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 020816384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 018999296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 015221248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 012869120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 012162048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 007875072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 006547144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 006441472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 006309256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 006068224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 005764608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 005588184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 005210904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 004883968 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 004661760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 004627456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 003906560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 003743744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 003426816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 002276192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 002096128 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2019-06-13 16:23 - 2019-06-13 16:23 - 002017280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2019-06-13 16:23 - 2019-06-13 16:23 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001761280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001750016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001618944 ____R (The ICU Project) C:\WINDOWS\SysWOW64\icuin.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001466496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001254912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001098136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001072640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 001000448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000833024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000791040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000553664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000540720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000451104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000427688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe 2019-06-13 16:23 - 2019-06-13 16:23 - 000362496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskcomp.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe 2019-06-13 16:23 - 2019-06-13 16:23 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000351744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000345600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esentutl.exe 2019-06-13 16:23 - 2019-06-13 16:23 - 000287912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2019-06-13 16:23 - 2019-06-13 16:23 - 000280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2019-06-13 16:23 - 2019-06-13 16:23 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\spacebridge.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000122680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000091424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000087864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll 2019-06-13 16:23 - 2019-06-13 16:23 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll 2019-06-13 16:22 - 2019-06-13 16:23 - 002690048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 022114960 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 017484800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 009682744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 007884288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 007645392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 006926336 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 005297152 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 005086208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 004588544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 003983872 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 003637248 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 003385344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 003363640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 003344896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 003091968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 002999808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 002926096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 002777736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 002638336 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 002627600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 002422272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 002189312 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 002085168 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001929216 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001903616 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001860608 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001860096 ____R (The ICU Project) C:\WINDOWS\system32\icuin.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001701888 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001700312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-06-13 16:22 - 2019-06-13 16:22 - 001670840 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001644544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001616384 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001605120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001483872 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001471040 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001342904 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2019-06-13 16:22 - 2019-06-13 16:22 - 001331536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001315328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001256448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001180184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 001054712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 001005056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000924160 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000887808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000863544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000850760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000769536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000758688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000730592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000699392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000651576 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000615440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000604344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000586040 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000555232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000522752 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000515152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000513904 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000506192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000495616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000478720 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000474936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2019-06-13 16:22 - 2019-06-13 16:22 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000430904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SDDS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000419368 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmicmiplugin.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000404792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000398208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingASDS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000375544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000282424 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000262160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys 2019-06-13 16:22 - 2019-06-13 16:22 - 000257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000247608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000244224 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpnServiceDS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdigest.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSrv.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000152896 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000152400 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000137056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000114648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingFilterDS.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe 2019-06-13 16:22 - 2019-06-13 16:22 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin 2019-06-13 16:22 - 2019-06-13 16:22 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin 2019-06-13 16:21 - 2019-06-13 16:22 - 007687576 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 004997096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 002928640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 002707968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 002653696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 001298952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 001253688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-06-13 16:21 - 2019-06-13 16:21 - 001229824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 001219424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 001048592 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-06-13 16:21 - 2019-06-13 16:21 - 000853504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000773632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000752144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000676048 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000651064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000386576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000292664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000196920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spacebridge.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000156984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000125528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000101176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000090424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000080400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2019-06-13 16:21 - 2019-06-13 16:21 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll 2019-06-13 16:21 - 2019-06-13 16:21 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2019-06-12 11:30 - 2019-06-12 11:30 - 001993528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll 2019-06-02 17:05 - 2019-06-02 17:05 - 000505138 _____ C:\Users\igna_\Downloads\fa_consolidación_1_2017.pdf 2019-06-01 13:54 - 2019-06-01 13:55 - 013496408 _____ C:\Users\igna_\Downloads\Cyberfoot 2019 v2.100.rar ==================== One month (modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-06-30 21:59 - 2019-03-15 18:19 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-06-30 21:59 - 2019-03-15 17:55 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-06-30 21:59 - 2018-09-15 04:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-06-30 21:59 - 2017-01-18 21:48 - 000000000 __SHD C:\Users\igna_\IntelGraphicsProfiles 2019-06-30 16:16 - 2018-09-15 04:31 - 000000000 ____D C:\WINDOWS\INF 2019-06-30 16:15 - 2018-09-15 04:33 - 000000000 ___HD C:\Program Files\WindowsApps 2019-06-30 16:15 - 2018-09-15 04:33 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-06-29 13:08 - 2018-09-15 04:33 - 000000000 ____D C:\WINDOWS\ServiceState 2019-06-29 12:45 - 2018-09-15 03:09 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2019-06-29 01:50 - 2017-11-23 15:28 - 000000000 ____D C:\AdwCleaner 2019-06-28 23:46 - 2017-12-20 20:38 - 000000000 ____D C:\Users\igna_\AppData\Roaming\Skype 2019-06-28 19:47 - 2018-09-15 04:23 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-06-28 19:43 - 2018-07-20 16:09 - 000000000 ____D C:\Users\igna_\AppData\Local\D3DSCache 2019-06-28 19:20 - 2018-07-20 10:50 - 000000000 ____D C:\ProgramData\Packages 2019-06-25 23:39 - 2017-12-03 14:17 - 000000000 ____D C:\Users\igna_\AppData\Local\Spotify 2019-06-25 23:30 - 2017-12-03 14:16 - 000000000 ____D C:\Users\igna_\AppData\Roaming\Spotify 2019-06-23 18:59 - 2017-11-30 13:48 - 000000000 ____D C:\Program Files\CCleaner 2019-06-23 18:53 - 2017-12-02 16:04 - 000000000 ____D C:\Users\igna_\AppData\Roaming\uTorrent 2019-06-23 18:52 - 2018-09-15 04:33 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2019-06-21 21:31 - 2019-05-23 16:50 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-06-21 21:31 - 2019-05-23 16:50 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2019-06-13 21:06 - 2019-03-15 17:55 - 000494944 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-06-13 21:03 - 2018-09-15 04:33 - 000000000 ___RD C:\Program Files\Windows Defender 2019-06-13 21:03 - 2018-09-15 04:33 - 000000000 ____D C:\WINDOWS\system32\migwiz 2019-06-13 21:03 - 2018-09-15 04:33 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-06-12 11:35 - 2018-09-15 04:36 - 000835688 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2019-06-12 11:35 - 2018-09-15 04:36 - 000179816 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2019-06-12 11:35 - 2017-11-28 20:06 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-06-12 11:31 - 2017-11-28 20:05 - 135349160 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-06-11 11:57 - 2017-03-06 21:40 - 000000000 ____D C:\Users\igna_\Downloads\Cyberfoot 2007 2019-06-02 11:46 - 2018-09-15 04:33 - 000000000 ____D C:\WINDOWS\system32\NDF 2019-06-02 11:38 - 2018-06-11 22:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-06-01 18:21 - 2017-12-14 17:07 - 000000000 ____D C:\Users\igna_\Desktop\CyberFoot 2017 SARAYLI BURAK Edition v1 ==================== Files in the root of some directories ================ 2019-06-29 01:01 - 2019-06-29 13:00 - 000007601 _____ () C:\Users\igna_\AppData\Local\Resmon.ResmonCfg ==================== SigCheck =============================== (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ============================