Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-11-2019 Ran by Luis M (administrator) on PCLUISM (ASUSTeK Computer INC. V-P8H67E) (18-11-2019 19:30:26) Running from C:\Users\Luis M\Desktop Loaded Profiles: Luis M (Available Profiles: Luis M & DevToolsUser & Administrador) Platform: Windows 10 Pro Version 1903 18362.449 (X64) Language: Español (España, internacional) Default browser: Edge Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Inc. -> Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe (Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) C:\Program Files\WindowsApps\AppleInc.iTunes_12102.3.43028.0_x64__nzyj5cx40ttqa\AMDS64\AppleMobileDeviceProcess.exe (ASUSTeK Computer Inc. -> ) [File not signed] C:\Program Files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe (ASUSTeK Computer Inc. -> ) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe (ASUSTeK Computer Inc.) [File not signed] C:\Program Files (x86)\ASUS\AsusFanControlService\1.00.06\AsusFanControlService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [File not signed] C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe (Dropbox, Inc -> Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler.exe (Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.342\GoogleCrashHandler64.exe (Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (INNOVATIVE DIGITAL TECHNOLOGIES LLC -> Innovative Digital Technologies) C:\Users\Luis M\AppData\Roaming\ACEStream\engine\ace_engine.exe (INNOVATIVE DIGITAL TECHNOLOGIES LLC -> Innovative Digital Technologies) C:\Users\Luis M\AppData\Roaming\ACEStream\engine\ace_engine.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe (Lagerkvist Teknisk Radgivning i Boras HB -> Olof Lagerkvist) C:\Windows\System32\imdsksvc.exe (Mega Limited -> Mega Limited) C:\ProgramData\MEGAsync\MEGAsync.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe (Microsoft Windows -> ) C:\Windows\System32\OpenSSH\sshd.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\vds.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1910.4-0\MpCmdRun.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1910.4-0\MpCmdRun.exe (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1910.4-0\MsMpEng.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Shanghai Oriental Webcasting Co. Ltd. -> www.ejie.me) C:\Program Files (x86)\Clover\Clover.exe (TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Wondershare Technology Co.,Ltd -> Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9269352 2019-03-25] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [4884016 2019-10-16] (Adobe Inc. -> Adobe Systems Inc.) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [6260544 2019-11-15] (Dropbox, Inc -> Dropbox, Inc.) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133216 2017-03-23] (Wondershare Technology Co.,Ltd -> Wondershare) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645648 2019-10-05] (Oracle America, Inc. -> Oracle Corporation) HKU\S-1-5-21-1536180041-2647868905-2353555993-1000\...\Run: [Opera Browser Assistant] => C:\Users\Luis M\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [2771480 2019-11-15] (Opera Software AS -> Opera Software) HKU\S-1-5-21-1536180041-2647868905-2353555993-1000\...\Run: [AceStream] => C:\Users\Luis M\AppData\Roaming\ACEStream\engine\ace_engine.exe [27960 2018-08-23] (INNOVATIVE DIGITAL TECHNOLOGIES LLC -> Innovative Digital Technologies) HKU\S-1-5-21-1536180041-2647868905-2353555993-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1 HKU\S-1-5-18\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [25171944 2019-08-21] (Plex, Inc -> Plex, Inc.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.97\Installer\chrmstp.exe [2019-11-12] (Google LLC -> Google LLC) Lsa: [Authentication Packages] msv1_0 SshdPinAuthLsa Startup: C:\Users\Luis M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2019-07-13] ShortcutTarget: MEGAsync.lnk -> C:\ProgramData\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {00CA35EF-BB76-4ED2-8933-17FB5E9FD615} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-14] (Dropbox, Inc -> Dropbox, Inc.) Task: {058DEAE3-2DE7-4B2B-9CDA-79BF53D90918} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4427584 2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {06AADC22-6DC7-4292-91CD-B5A5C410707B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {0C27DB5B-CC17-4CAE-A27A-0479E867BA77} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_293_Plugin.exe [1457720 2019-11-13] (Adobe Inc. -> Adobe) Task: {0C367779-499F-4D8E-A7FA-E11523D187DC} - System32\Tasks\Trigger KMS Activation => C:\Users\Luis M\AppData\Local\Temp\RarSFX1\TriggerKMS.exe <==== ATTENTION Task: {101145F2-82C6-41FC-9D8F-E1DF0C222210} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114720 2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {240D517A-62DB-4FDF-87FA-2F4F324F85FE} - System32\Tasks\HPEA3JOBS => C:\Program [Argument = Files\HP\HP ePrint\hpeprint.exe /CheckJobs] Task: {3A10A3F5-680F-413B-B9DD-21AC1A8033D8} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27367496 2019-10-25] (Microsoft Corporation -> Microsoft Corporation) Task: {3D795BB9-C0B3-4324-967F-93C2BB0C57AE} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-1536180041-2647868905-2353555993-1000 => {201600D8-6EFF-48CE-B842-E14D37A0682D} C:\WINDOWS\System32\wpninprc.dll [24064 2019-03-19] (Microsoft Windows -> Microsoft Corporation) Task: {3E701786-61E7-42D3-BAE0-2399DB757CAA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27367496 2019-10-25] (Microsoft Corporation -> Microsoft Corporation) Task: {454BFACF-7BD7-4EC9-9347-C795B9B6352A} - System32\Tasks\Open URL by RoboForm => C:\WINDOWS\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/uninstall.html?aaa=KICMIMMMKMPMMMHMPMNMCNKJMJNJNMCNLMLMNMJMCNGMKJOJJMCNNJJJLJKJLMKMIMIMNMLJKMPMJNJICMHMCNKMCNIMFMOMOMCNMMIMGMCNOMIMIMJMMMFMPMCNPMCNOMIMIMJMMMCNNMJNPICMPMFMFMNMGMKMJNHICMEKMICNJJCKJNBJCMJNKJCMJNNICMJNDJCMKJMIJNMJCMPMFMPMFMPMJNFICMN (the data entry has 26 more characters). Task: {4A6F694A-8E4E-4F33-96FF-2F3DCBF6AC7C} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {5794AC49-F6D4-4704-B5EE-C3FE4A58C8ED} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-16] (Piriform Software Ltd -> Piriform Software Ltd) Task: {582F5177-629B-4F99-9249-2B9C01B114CF} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-laguados@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) Task: {89F9C506-7562-4DAE-BAA8-2007B0934FEE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-01-24] (Google Inc -> Google Inc.) Task: {94A30DFA-3A81-462E-960A-7357CF2282AE} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-1536180041-2647868905-2353555993-1000 => C:\ProgramData\MEGAsync\MEGAupdater.exe [615160 2019-09-16] (Mega Limited -> Mega Limited) Task: {97123C3A-1589-450D-8F6E-B34DE0CB30A9} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1423680 2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {978D7A90-D397-4CB1-8D0A-4C17A9B17A52} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-01-24] (Google Inc -> Google Inc.) Task: {9F9E017F-C8D2-4873-B45A-51C90E735091} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1423680 2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {A23A7CD4-AB54-427B-B0EF-FF52DC441E4F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {AC2013E9-6F8C-43A5-992F-285052EF23CB} - System32\Tasks\Opera scheduled assistant Autoupdate 1547387744 => C:\Users\Luis M\AppData\Local\Programs\Opera\launcher.exe [1534488 2019-11-05] (Opera Software AS -> Opera Software) Task: {B71FC731-7125-4561-B1BA-CB03C661BDD4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {BFAEAC4F-319D-4B68-BE20-9B8761939775} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.) Task: {CB013BA3-71D2-448F-907D-2C6BBC37E7B9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4427584 2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {CB239584-0DC6-4B9E-B6BD-73664B49D212} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems) Task: {CE1FF46C-CC70-4A53-8B3D-6CDA0A93391C} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\Office16\sdxhelper.exe [114720 2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Task: {D2E42ECA-9D82-47C3-8A79-604A629641AE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-16] (Piriform Software Ltd -> Piriform Ltd) Task: {D32B8C15-6B85-474C-A7CC-B4B9F3071FA7} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [645648 2019-10-05] (Oracle America, Inc. -> Oracle Corporation) Task: {D3A55E59-2765-4939-AF4F-65169F39F943} - System32\Tasks\Opera scheduled Autoupdate 1516736657 => C:\Users\Luis M\AppData\Local\Programs\Opera\launcher.exe [1534488 2019-11-05] (Opera Software AS -> Opera Software) Task: {E8ADB440-2938-42E7-B5DE-86EF0DC64074} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-14] (Dropbox, Inc -> Dropbox, Inc.) Task: {EE9DFA63-9738-44DB-96A1-87CBCB2B8FAD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MpCmdRun.exe [469928 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F8044A9E-8CDB-4DCA-88ED-D430CD92129D} - System32\Tasks\HPCustParticipation HP DeskJet 3700 series => C:\Program Files\HP\HP DeskJet 3700 series\Bin\HPCustPartic.exe [6439048 2018-04-06] (Hewlett Packard -> HP Inc.) Task: {F90A862C-8BE1-4625-A7A0-4EE052B922DB} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-11-13] (Adobe Inc. -> Adobe) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [S-1-5-21-1536180041-2647868905-2353555993-1000] => Proxy is enabled. ProxyServer: [S-1-5-21-1536180041-2647868905-2353555993-1000] => 127.0.0.1:8003 Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\..\Interfaces\{50a05a5f-1c19-47f1-9c06-e73837b1ea41}: [NameServer] 1.1.1.1,1.0.0.1 Tcpip\..\Interfaces\{d4f43c97-4b5d-452b-9f88-3dc451c12c56}: [DhcpNameServer] 8.8.8.8 8.8.4.4 Tcpip\..\Interfaces\{ff179712-d203-492b-89d4-5c41d3e09fd6}: [DhcpNameServer] 172.20.10.1 ManualProxies: 1127.0.0.1:8003 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1536180041-2647868905-2353555993-1000 -> DefaultScope {22DA3E47-2304-41ED-821B-24F0FEB19322} URL = SearchScopes: HKU\S-1-5-21-1536180041-2647868905-2353555993-1000 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-07-01] (Microsoft Corporation -> Microsoft Corporation) BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> C:\Program Files (x86)\Clover\TabHelper64.dll [2018-05-20] (Shanghai Oriental Webcasting Co. Ltd. -> EJIE Technology) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2019-04-05] (Microsoft Corporation -> Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\ssv.dll [2019-10-21] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\jp2ssv.dll [2019-10-21] (Oracle America, Inc. -> Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) BHO-x32: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> C:\Program Files (x86)\Clover\TabHelper32.dll [2018-05-20] (Shanghai Oriental Webcasting Co. Ltd. -> EJIE Technology) Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-1536180041-2647868905-2353555993-1000 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2017-11-27] (Adobe Systems, Incorporated -> Adobe Systems Incorporated) Toolbar: HKU\S-1-5-21-1536180041-2647868905-2353555993-1000 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - No File Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-11-03] (Microsoft Corporation -> Microsoft Corporation) Edge: ====== DownloadDir: C:\Users\Luis M\Downloads Edge HomeButtonPage: HKU\S-1-5-21-1536180041-2647868905-2353555993-1000 -> about:start Edge Notifications: HKU\S-1-5-21-1536180041-2647868905-2353555993-1000 -> hxxps://www.aliprice.com; hxxps://oko.sh; hxxps://www.mapfre.es; hxxps://iphonea2.com; hxxps://winphonemetro.com; hxxps://latestseoupdate.com; hxxps://techrogen.com FireFox: ======== FF DefaultProfile: a7q3uhys.default-1560367090125 FF ProfilePath: C:\Users\Luis M\AppData\Roaming\Mozilla\Firefox\Profiles\a7q3uhys.default-1560367090125 [2019-11-17] FF Homepage: Mozilla\Firefox\Profiles\a7q3uhys.default-1560367090125 -> hxxps://www.google.es/?gws_rd=ssl FF Session Restore: Mozilla\Firefox\Profiles\a7q3uhys.default-1560367090125 -> is enabled. FF ProfilePath: C:\Users\Luis M\AppData\Roaming\Flickr\Flickr Uploadr\Profiles\amvodndg.default [2018-01-26] FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2019-05-02] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF HKU\S-1-5-21-1536180041-2647868905-2353555993-1000\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Luis M\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi FF Extension: (Ace Script) - C:\Users\Luis M\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2018-11-26] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_293.dll [2019-11-13] (Adobe Inc. -> ) FF Plugin-x32: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-10-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files (x86)\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-10-21] (Oracle America, Inc. -> Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-05] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-05] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-05] (Google Inc -> Google LLC) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.342\npGoogleUpdate3.dll [2019-11-05] (Google Inc -> Google LLC) FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2019-10-16] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-16] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-01-23] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin HKU\S-1-5-21-1536180041-2647868905-2353555993-1000: @acestream.net/acestreamplugin,version=3.1.28 -> C:\Users\Luis M\AppData\Roaming\ACEStream\player\npace_plugin.dll [2017-01-13] (Innovative Digital Technologies -> Innovative Digital Technologies) FF Plugin HKU\S-1-5-21-1536180041-2647868905-2353555993-1000: @acestream.net/acestreamplugin,version=3.1.32 -> C:\Users\Luis M\AppData\Roaming\ACEStream\player\npace_plugin.dll [2017-01-13] (Innovative Digital Technologies -> Innovative Digital Technologies) FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\a.js [2019-11-05] Chrome: ======= CHR HomePage: Default -> hxxp://www.google.es/ CHR StartupUrls: Default -> "hxxps://www.google.com/?gws_rd=ssl" CHR Profile: C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default [2019-11-17] CHR Extension: (Presentaciones) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-24] CHR Extension: (Privacy Pass) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajhmfdgkijocedmfjonnpjfojldioehi [2019-11-02] CHR Extension: (h264ify) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2019-09-10] CHR Extension: (Documentos) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-24] CHR Extension: (Google Drive) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-24] CHR Extension: (MEGA) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2019-11-15] CHR Extension: (YouTube) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-24] CHR Extension: (uBlock Origin) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2019-10-28] CHR Extension: (Dropbox para Gmail) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2019-11-02] CHR Extension: (Adobe Acrobat) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2019-10-02] CHR Extension: (vGet Cast (DLNA Controller)) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjofnchpbfmnfbedalmbdlhbabiapi [2018-01-24] CHR Extension: (Hojas de cálculo) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-24] CHR Extension: (Favoritos de iCloud) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2019-11-03] CHR Extension: (Documentos de Google sin conexión) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-22] CHR Extension: (Hola Free VPN Proxy Unblocker) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2019-11-15] CHR Extension: (OSI: Servicio AntiBotnet) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhljghnmjahiaofikeljkjnhbeoiclbh [2018-02-13] CHR Extension: (vGet Extension (Video Downloader, DLNA)) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\hniladkejehjfchadikcbjmgjaogciic [2018-01-24] CHR Extension: (Cloud Browser) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmomimblkpkjeilfbkinoonalgiejlcl [2018-01-24] CHR Extension: (Picasa Extension (by Google)) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhhlohbbihddnfcehbijmlnpkafmmkfp [2018-01-24] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-01-26] CHR Extension: (Google Maps) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2018-01-24] CHR Extension: (Google Mail Checker) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-01-24] CHR Extension: (Ace Script) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2018-12-19] CHR Extension: (HTTP/2 and SPDY indicator) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpbpobfflnpcgagjijhmgnchggcjblin [2018-01-24] CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-10] CHR Extension: (Check My Links) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojkcdipcgfaekbeaelaapakgnjflfglf [2019-02-09] CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2019-11-16] CHR Extension: (Gmail) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-06-02] CHR Extension: (Chrome Media Router) - C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-11-02] CHR Profile: C:\Users\Luis M\AppData\Local\Google\Chrome\User Data\System Profile [2019-11-17] CHR HKU\S-1-5-21-1536180041-2647868905-2353555993-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] CHR HKU\S-1-5-21-1536180041-2647868905-2353555993-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3117648 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) S3 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2888272 2019-05-04] (Adobe Inc. -> Adobe Systems, Incorporated) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.18\atkexComSvc.exe [918448 2011-10-29] (ASUSTeK Computer Inc. -> ) [File not signed] R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2010-10-21] (ASUSTeK Computer Inc. -> ) R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.00.06\AsusFanControlService.exe [1399296 2011-09-02] (ASUSTeK Computer Inc.) [File not signed] R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11642744 2019-10-25] (Microsoft Corporation -> Microsoft Corporation) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-14] (Dropbox, Inc -> Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-12-14] (Dropbox, Inc -> Dropbox, Inc.) R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2019-11-15] (Dropbox, Inc -> Dropbox, Inc.) R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [40080 2018-08-14] (CHENGDU YIWO Tech Development Co., Ltd. -> CHENGDU YIWO Tech Development Co., Ltd) [File not signed] R2 ImDskSvc; C:\WINDOWS\system32\imdsksvc.exe [19552 2015-12-15] (Lagerkvist Teknisk Radgivning i Boras HB -> Olof Lagerkvist) S2 LxssManagerUser; C:\WINDOWS\system32\lxss\LxssManager.dll [631808 2019-07-09] (Microsoft Windows -> Microsoft Corporation) R2 LxssManagerUser_67de2; C:\WINDOWS\system32\svchost.exe [53744 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) R2 LxssManagerUser_67de2; C:\WINDOWS\SysWOW64\svchost.exe [45448 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2019-11-15] (Malwarebytes Inc -> Malwarebytes) R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2139112 2019-08-21] (Plex, Inc -> Plex, Inc.) R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5796168 2019-09-02] (Microsoft Windows Publisher -> Microsoft Corporation) R3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [974848 2019-05-30] (Microsoft Windows -> ) R3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [290816 2019-10-03] (Microsoft Windows -> Microsoft Corporation) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12054872 2019-10-10] (TeamViewer GmbH -> TeamViewer GmbH) S2 TrustedLogos; C:\WINDOWS\trustedlogos\TrustedLogos.exe [11328 2019-09-19] (Gelbe vom Ei GmbH -> ) S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd -> SHAREit Technologies Co.Ltd) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\NisSrv.exe [3201616 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1910.4-0\MsMpEng.exe [103168 2019-10-28] (Microsoft Windows Publisher -> Microsoft Corporation) S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.4.3.236\WsAppService.exe [495840 2018-01-26] (Wondershare Technology Co.,Ltd -> Wondershare) S2 wuauserv; C:\WINDOWS\system32\svchost.exe [53744 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL) S2 wuauserv; C:\WINDOWS\SysWOW64\svchost.exe [45448 2019-03-19] (Microsoft Windows Publisher -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AKCCID; C:\WINDOWS\System32\drivers\AKCCID.sys [65984 2019-06-05] (Alcor Micro, Corp. -> Generic) R3 AmUStor; C:\WINDOWS\system32\drivers\AmUStor.SYS [109504 2019-01-02] (Alcorlink Corp. -> ) S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2019-04-25] (WDKTestCert build,131474841775766162 -> Apple Inc.) S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2019-04-25] (WDKTestCert build,131474841775766162 -> Apple Inc.) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] (ASUSTeK Computer Inc. -> ) R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] (ASUSTeK Computer Inc. -> ) R2 AWEAlloc; C:\WINDOWS\system32\DRIVERS\awealloc.sys [21048 2015-12-15] (Lagerkvist Teknisk Radgivning i Boras HB -> Olof Lagerkvist) S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [34368 2018-01-16] (CHENGDU YIWO Tech Development Co., Ltd. -> ) R0 EPMVolFlt; C:\WINDOWS\System32\drivers\EPMVolFlt.sys [30280 2018-07-19] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider) R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [73328 2018-05-15] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd) R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [53360 2018-05-15] (Microsoft Windows Hardware Compatibility Publisher -> ) R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [22640 2018-05-15] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd) R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [341104 2018-07-28] (Microsoft Windows Hardware Compatibility Publisher -> CHENGDU YIWO Tech Development Co., Ltd) S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2016-07-11] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed] S3 HPEWSFXBULK; C:\WINDOWS\system32\drivers\hpfx64bulk.sys [20504 2016-12-04] (Hewlett-Packard Company -> Hewlett Packard) R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-01-26] (Martin Malik - REALiX -> REALiX(tm)) R2 ImDisk; C:\WINDOWS\system32\DRIVERS\imdisk.sys [48704 2015-12-15] (Lagerkvist Teknisk Radgivning i Boras HB -> Olof Lagerkvist) S3 lgmdbus; C:\WINDOWS\System32\drivers\lgmdbus.sys [115200 2008-07-08] (MCCI Corporation -> MCCI Corporation) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-11-15] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [278344 2019-11-16] (Malwarebytes Inc -> Malwarebytes) S3 netr28ux; C:\WINDOWS\System32\drivers\netr28ux.sys [2224128 2019-03-19] (Microsoft Windows -> MediaTek Inc.) R3 P9Rdr; C:\WINDOWS\System32\drivers\p9rdr.sys [88888 2019-08-14] (Microsoft Windows -> Microsoft Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1158944 2019-09-20] (Realtek Semiconductor Corp. -> Realtek ) R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [450152 2019-11-14] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation) R0 VMSNPXY; C:\WINDOWS\System32\drivers\VmsProxyHNic.sys [39952 2019-10-03] (Microsoft Windows -> Microsoft Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46472 2019-10-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [351968 2019-10-28] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [53984 2019-10-28] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-11-18 19:30 - 2019-11-18 19:32 - 000042552 _____ C:\Users\Luis M\Desktop\FRST.txt 2019-11-18 19:28 - 2019-11-18 19:27 - 002260480 _____ (Farbar) C:\Users\Luis M\Desktop\FRST64.exe 2019-11-17 22:06 - 2019-11-17 22:06 - 000000000 ___HD C:\$SysReset 2019-11-17 21:49 - 2019-11-17 21:49 - 000118862 _____ C:\WINDOWS\ntbtlog.txt 2019-11-17 21:49 - 2019-11-17 21:49 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2019-11-17 20:21 - 2019-11-17 20:21 - 015114618 _____ C:\Users\Luis M\Downloads\windows10.0-kb4521863-x64_a26672b0d37671b49d9306874bfab9db47007ddb.msu 2019-11-17 20:08 - 2019-11-17 20:08 - 000000000 ___HD C:\_acestream_cache_ 2019-11-17 20:04 - 2019-11-17 20:04 - 000004820 _____ C:\Users\Luis M\Desktop\AdwCleaner[C01].txt 2019-11-17 19:53 - 2019-11-17 19:53 - 000001542 _____ C:\Users\Luis M\Desktop\Informe Malwarebytes171119.txt 2019-11-16 21:02 - 2019-11-18 19:20 - 000000000 ____D C:\Users\Luis M\AppData\Roaming\.ACEStream 2019-11-16 21:00 - 2019-11-16 21:03 - 000000000 ____D C:\Users\Luis M\AppData\Roaming\ACEStream 2019-11-16 20:44 - 2019-11-16 20:44 - 000000000 ___HD C:\$Windows.~WS 2019-11-16 20:44 - 2019-11-16 20:44 - 000000000 ____D C:\$WINDOWS.~BT 2019-11-16 20:43 - 2019-11-16 20:43 - 000000751 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Asistente para actualización a Windows 10.lnk 2019-11-16 20:43 - 2019-11-16 20:43 - 000000739 _____ C:\Users\Luis M\Desktop\Asistente para actualización a Windows 10.lnk 2019-11-16 20:43 - 2019-11-16 20:43 - 000000000 ____D C:\Windows10Upgrade 2019-11-16 20:25 - 2019-11-16 20:25 - 000000656 _____ C:\Users\Luis M\Downloads\wu10.diagcab 2019-11-16 20:12 - 2019-11-16 20:12 - 000278344 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2019-11-15 23:06 - 2019-11-15 23:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2019-11-15 22:22 - 2019-11-15 22:22 - 000000000 ____D C:\Users\Luis M\AppData\Local\mbamtray 2019-11-15 22:22 - 2019-11-15 22:22 - 000000000 ____D C:\Users\Luis M\AppData\Local\mbam 2019-11-15 22:21 - 2019-11-15 22:20 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2019-11-15 22:21 - 2019-11-15 22:20 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys 2019-11-15 22:19 - 2019-11-15 22:19 - 000000000 ____D C:\Program Files\Malwarebytes 2019-11-15 22:18 - 2019-11-15 22:18 - 000004426 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1547387744 2019-11-15 21:58 - 2019-11-15 22:02 - 000000000 ____D C:\Users\Luis M\2274sj2u 2019-11-15 20:26 - 2019-11-15 20:26 - 007622344 _____ (Malwarebytes) C:\Users\Luis M\Desktop\adwcleaner_7.4.2.exe 2019-11-15 19:26 - 2019-11-15 19:26 - 000001986 _____ C:\Users\Luis M\Desktop\reparar.bat 2019-11-15 19:14 - 2019-11-15 19:14 - 325679072 _____ C:\Users\Luis M\Downloads\windows10.0-kb4524570-x64_bdd4583a9f921ceeb27dc8529aa8faa9023a8f98.msu 2019-11-15 19:00 - 2019-11-15 19:00 - 000313366 _____ C:\Users\Luis M\Downloads\WindowsUpdateDiagnostic.diagcab 2019-11-15 12:48 - 2019-11-15 12:48 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe 2019-11-15 12:48 - 2019-11-15 12:48 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys 2019-11-15 12:48 - 2019-11-15 12:48 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys 2019-11-15 12:48 - 2019-11-15 12:48 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys 2019-11-14 18:01 - 2019-11-14 18:01 - 009909000 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RsCRIcon.dll 2019-11-14 18:01 - 2019-11-14 18:01 - 000450152 _____ (Realsil Semiconductor Corporation) C:\WINDOWS\system32\Drivers\RtsUer.sys 2019-11-14 16:34 - 2019-11-14 16:34 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2019-11-14 13:07 - 2019-11-14 13:07 - 000002471 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk 2019-11-11 20:05 - 2019-11-11 20:36 - 000000000 ____D C:\Users\Luis M\Documents\Tejeras, 39 2019-11-10 21:45 - 2019-11-15 22:20 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-11-10 21:31 - 2019-11-10 21:45 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2019-11-10 21:29 - 2019-11-10 21:44 - 000109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2019-11-10 20:14 - 2019-11-10 20:14 - 000000000 ____D C:\Users\Luis M\polar 2019-11-10 20:14 - 2019-11-10 20:14 - 000000000 ____D C:\Program Files (x86)\Polar 2019-11-09 14:23 - 2019-11-09 14:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amlogic 2019-11-09 14:23 - 2019-11-09 14:23 - 000000000 ____D C:\Program Files (x86)\Amlogic 2019-11-07 19:35 - 2019-11-07 19:35 - 000004178 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1516736657 2019-11-07 19:35 - 2019-11-07 19:35 - 000001445 _____ C:\Users\Luis M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk 2019-11-05 20:47 - 2019-11-17 22:09 - 000000000 ____D C:\WINDOWS\trustedlogos 2019-11-04 21:43 - 2019-11-04 23:06 - 000016044 _____ C:\Users\Luis M\Desktop\Turnos Noviembre19-Marzo20.xlsx 2019-11-04 21:04 - 2019-11-04 21:04 - 000003366 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1536180041-2647868905-2353555993-1000 2019-11-04 21:04 - 2019-11-04 21:04 - 000002443 _____ C:\Users\Luis M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2019-11-03 18:34 - 2019-11-03 18:35 - 000000032 _____ C:\Users\Luis M\Desktop\contraseña adobe acrobat.txt 2019-11-03 13:36 - 2019-11-03 13:36 - 000000000 ____D C:\Users\Luis M\AppData\Roaming\PDAppFlex 2019-10-27 19:11 - 2019-10-25 21:58 - 000410822 __RSH C:\bootmgr 2019-10-27 19:11 - 2019-03-19 05:44 - 000000001 ___SH C:\BOOTNXT 2019-10-25 21:59 - 2019-10-25 21:59 - 025901056 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 022627840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 018020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 009711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 008011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 007015936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 006232576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 005501952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 004307968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 004129624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 002399232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 002369552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 002188808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 002158080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001718584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001659192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001616696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001495864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001387024 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001359872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebManagement.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 001185792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AgentService.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 001126912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 001059840 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 001047352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000960040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000827192 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000816952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000762880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.PrinterCustomActions.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000741376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2013CustomActions.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000666640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000637952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000512512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000494904 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CscUnpinTool.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 000396088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcLayers.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcLayers.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ManagedEventLogging.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ConfigWrapper.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000259384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVFileSystemMetadata.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000249856 _____ (Gracenote, Inc.) C:\WINDOWS\SysWOW64\gnsdk_fp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000230200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagSvc.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CmUtil.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcXtrnal.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl 2019-10-25 21:59 - 2019-10-25 21:59 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncController.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl 2019-10-25 21:59 - 2019-10-25 21:59 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CabUtil.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.EventLogMessages.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2010CustomActions.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAgentPolicyGenerator.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000030720 _____ C:\WINDOWS\system32\uwfservicingapi.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.WmiAccess.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppData.WinRT.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncCommon.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.WinRT.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.LocalSyncProvider.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcXtrnal.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernSync.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateConfigItemGenerator.exe 2019-10-25 21:59 - 2019-10-25 21:59 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SmbSyncProvider.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.MonitorSyncProvider.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncConditions.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx 2019-10-25 21:59 - 2019-10-25 21:59 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll 2019-10-25 21:59 - 2019-10-25 21:59 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL 2019-10-25 21:58 - 2019-10-25 21:58 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 009928208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 007600688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 007262456 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 006523552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 006435840 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 006166016 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 006082808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 005943296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 005763848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 005112320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 004150272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AI.MachineLearning.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 004047360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 003967920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 003791360 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 003752960 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 003742544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 003371928 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002988856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 002871848 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 002772272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002762504 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002703872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002698768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 002586816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002562048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002258848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001974824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 001916984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001856512 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2019-10-25 21:58 - 2019-10-25 21:58 - 001726480 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001691648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001664688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001394488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001189376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 001073168 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000982840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000822072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000811536 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000774672 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000768528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000747536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000700416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BTAGService.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000669352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000638264 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000632320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000586768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000522176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000514576 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000511000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000477712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS 2019-10-25 21:58 - 2019-10-25 21:58 - 000477184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000465208 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000453632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000354816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000324624 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000251512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\accessibilitycpl.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmd.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accessibilitycpl.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000164776 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000136536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Utilman.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000113160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Utilman.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AtBroker.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000071696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AtBroker.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nsiproxy.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000036368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winnsi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\posetup.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsisvc.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000028344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winnsi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000024792 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nsi.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\applockerfltr.sys 2019-10-25 21:58 - 2019-10-25 21:58 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe 2019-10-25 21:58 - 2019-10-25 21:58 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll 2019-10-25 21:58 - 2019-10-25 21:58 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll 2019-10-25 21:57 - 2019-10-25 21:58 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 017787904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 007904152 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 007849424 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 007278592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 006227624 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 005890048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AI.MachineLearning.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 004615616 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 003968512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tellib.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 003727872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 003703296 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 003591208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 003387392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 003105792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 002717184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 002284544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 002126112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001920512 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001656600 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001451520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 001428992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 001413912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001259416 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 001149928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 001094656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcRefreshTask.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\BTAGService.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001069064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000913920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000911824 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000874536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000849920 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntimewindows.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\agentactivationruntime.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000657424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000589592 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000552448 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000534528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000530944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000416016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000322504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000292664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000291256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmd.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcTok.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000204816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys 2019-10-25 21:57 - 2019-10-25 21:57 - 000105488 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS 2019-10-25 21:57 - 2019-10-25 21:57 - 000088568 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000065272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000047208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2019-10-25 21:57 - 2019-10-25 21:57 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS 2019-10-25 21:57 - 2019-10-25 21:57 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscisvif.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsilog.dll 2019-10-25 21:57 - 2019-10-25 21:57 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscadminui.exe 2019-10-25 21:28 - 2019-10-25 21:29 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2019-10-25 21:28 - 2019-10-25 21:29 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2019-10-24 21:50 - 2019-10-24 21:50 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll 2019-10-24 21:50 - 2019-10-24 21:50 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll 2019-10-24 21:50 - 2019-10-24 21:50 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnosticsTool.exe 2019-10-24 21:50 - 2019-10-24 21:50 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll 2019-10-24 21:50 - 2019-10-24 21:50 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll 2019-10-24 13:00 - 2019-10-24 13:00 - 000001044 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 14.lnk 2019-10-21 19:45 - 2019-10-21 19:43 - 000114232 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2019-10-21 19:26 - 2019-10-21 19:26 - 000001216 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mercedes-Benz Download Manager.lnk 2019-10-21 19:26 - 2019-10-21 19:26 - 000000000 ____D C:\Program Files (x86)\Mercedes-Benz Download Manager ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-11-18 19:31 - 2018-01-12 21:17 - 000000000 ____D C:\FRST 2019-11-18 19:24 - 2019-01-15 20:04 - 000000000 ____D C:\Users\Luis M\Downloads\opera autoupdate 2019-11-18 19:22 - 2019-03-25 20:09 - 000000000 ____D C:\Users\Luis M\AppData\Local\F961177B-09F3-4367-9FCE-C5FE491B9B29.aplzod 2019-11-18 19:18 - 2018-10-10 17:06 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2019-11-18 19:17 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-11-18 19:16 - 2019-05-30 20:44 - 000000000 ____D C:\Users\Luis M 2019-11-18 19:13 - 2019-05-30 21:17 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-11-18 19:13 - 2019-05-30 20:34 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-11-17 22:09 - 2019-06-13 17:34 - 000000000 ____D C:\ProgramData\ssh 2019-11-17 22:07 - 2019-03-19 05:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI 2019-11-17 21:45 - 2019-05-29 19:20 - 000000000 ___DC C:\WINDOWS\Panther 2019-11-17 21:28 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF 2019-11-17 21:05 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\USOPrivate 2019-11-17 20:18 - 2012-01-15 19:57 - 000000000 ____D C:\Users\Luis M\Documents\CCLEANER 2019-11-17 19:40 - 2013-12-30 13:19 - 000000000 ____D C:\Users\Luis M\Downloads\Antibichitos 2019-11-17 19:39 - 2018-05-20 12:55 - 000000000 ____D C:\Users\Luis M\AppData\LocalLow\Clover 2019-11-16 22:16 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-11-16 21:11 - 2017-05-08 21:09 - 000000000 ____D C:\ESD 2019-11-15 23:17 - 2019-05-16 19:37 - 000000000 ____D C:\ProgramData\playersclub 2019-11-15 23:17 - 2019-03-21 20:34 - 000000000 ____D C:\ProgramData\KMSAuto 2019-11-15 23:16 - 2017-12-28 18:23 - 000000000 ____D C:\Windat 2019-11-15 23:07 - 2018-12-14 20:22 - 000000000 ____D C:\Program Files (x86)\Dropbox 2019-11-15 22:22 - 2017-12-29 00:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-11-15 22:21 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2019-11-15 22:07 - 2019-06-13 17:34 - 000000000 ____D C:\Users\DevToolsUser\AppData\Roaming\IObit 2019-11-15 22:07 - 2018-09-13 13:26 - 000000000 ____D C:\Users\Luis M\AppData\Roaming\Hewlett-Packard 2019-11-15 22:07 - 2018-09-13 13:24 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard 2019-11-15 22:07 - 2018-05-14 23:32 - 000000000 ____D C:\Users\Luis M\AppData\Roaming\IObit 2019-11-15 22:07 - 2018-05-14 23:32 - 000000000 ____D C:\Users\Administrador.PCLUISM\AppData\Roaming\IObit 2019-11-15 22:07 - 2018-01-26 21:27 - 000000000 ____D C:\ProgramData\IObit 2019-11-15 22:07 - 2018-01-26 21:27 - 000000000 ____D C:\Program Files (x86)\IObit 2019-11-15 22:07 - 2014-03-31 20:26 - 000000000 ___HD C:\Users\Luis M\AppData\LocalLow\IObit 2019-11-15 22:02 - 2014-09-30 22:22 - 000000000 ____D C:\AdwCleaner 2019-11-15 20:15 - 2019-09-30 18:42 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update 2019-11-15 20:04 - 2018-04-27 19:01 - 000000000 ____D C:\WINDOWS\pss 2019-11-15 19:58 - 2019-07-01 21:33 - 000000000 ____D C:\WINDOWS\Minidump 2019-11-15 19:50 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\NDF 2019-11-15 19:28 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\AppLocker 2019-11-15 19:04 - 2018-01-23 21:30 - 000000000 ____D C:\Users\Luis M\AppData\Local\ElevatedDiagnostics 2019-11-15 19:03 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\catroot2.bak 2019-11-15 19:03 - 2018-01-22 21:13 - 000000000 ____D C:\WINDOWS\SoftwareDistribution.bak 2019-11-14 20:58 - 2018-01-25 14:35 - 000000000 ____D C:\Users\Luis M\AppData\Roaming\HpUpdate 2019-11-14 18:01 - 2018-01-25 18:50 - 000000000 ____D C:\ProgramData\Package Cache 2019-11-14 17:58 - 2018-01-26 21:28 - 000000000 ____D C:\ProgramData\ProductData 2019-11-13 19:47 - 2019-05-30 21:17 - 000004604 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player NPAPI Notifier 2019-11-13 19:47 - 2019-05-30 21:17 - 000004430 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater 2019-11-13 19:47 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-11-13 19:47 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-11-12 19:30 - 2018-01-24 21:12 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2019-11-10 21:30 - 2012-01-20 13:33 - 000000000 ____D C:\Temp 2019-11-10 21:27 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2019-11-09 18:37 - 2016-02-21 20:45 - 000000000 ____D C:\Users\Luis M\.android 2019-11-09 14:43 - 2019-06-26 19:19 - 000000000 ____D C:\Users\Luis M\Downloads\TV BOX 2019-11-09 14:23 - 2018-01-24 20:54 - 000000000 ____D C:\Program Files\DIFX 2019-11-08 20:25 - 2018-01-26 21:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google 2019-11-05 21:12 - 2019-06-13 17:34 - 000000000 ____D C:\Users\DevToolsUser 2019-11-05 21:12 - 2019-05-30 20:44 - 000000000 ____D C:\Users\Administrador.PCLUISM 2019-11-05 19:58 - 2019-05-30 21:17 - 000003622 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA 2019-11-05 19:58 - 2019-05-30 21:17 - 000003498 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore 2019-11-05 19:58 - 2015-07-17 20:16 - 000000000 ____D C:\Users\Luis M\Mercedes C220 d 2019-11-05 19:54 - 2017-10-07 21:55 - 000000000 ___RD C:\Users\Luis M\iCloudDrive 2019-11-05 19:53 - 2018-01-24 21:11 - 000000000 ____D C:\Program Files (x86)\Google 2019-11-04 22:51 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps 2019-11-04 22:51 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-11-04 22:51 - 2018-06-13 21:23 - 000000000 ____D C:\ProgramData\Packages 2019-11-04 21:05 - 2014-03-30 22:43 - 000000000 ___RD C:\Users\Luis M\OneDrive 2019-11-04 20:59 - 2018-01-25 14:51 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2019-11-04 20:52 - 2019-05-30 20:57 - 001773362 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-11-04 20:52 - 2019-03-19 12:59 - 000788406 _____ C:\WINDOWS\system32\perfh00A.dat 2019-11-04 20:52 - 2019-03-19 12:59 - 000155696 _____ C:\WINDOWS\system32\perfc00A.dat 2019-11-03 19:42 - 2015-08-31 23:27 - 000000000 ____D C:\Users\Luis M\Documents\MEGAsync Downloads 2019-11-03 14:17 - 2018-01-24 19:56 - 000000000 ____D C:\Users\Luis M\AppData\Local\Apple Inc 2019-10-31 20:14 - 2017-12-18 21:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2019-10-28 19:31 - 2018-03-01 19:27 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2019-10-27 19:16 - 2017-10-24 23:44 - 000000000 ___RD C:\Users\Luis M\3D Objects 2019-10-27 19:16 - 2015-09-10 06:29 - 000000000 __RHD C:\Users\Public\AccountPictures 2019-10-27 19:10 - 2019-05-30 20:34 - 000489048 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\appraiser 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellComponents 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\DiagTrack 2019-10-25 22:56 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-10-21 19:45 - 2018-01-24 21:27 - 000000000 ____D C:\Program Files (x86)\Java 2019-10-21 19:45 - 2015-10-05 12:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2019-10-19 15:04 - 2018-01-22 21:17 - 000000000 ____D C:\Users\Luis M\AppData\Local\Packages 2019-10-19 14:56 - 2018-01-26 20:22 - 000000000 ____D C:\Program Files\CCleaner ==================== Files in the root of some directories ======== 2018-01-24 21:35 - 2018-01-24 21:35 - 000000046 _____ () C:\Users\Luis M\AppData\Roaming\WB.CFG 2019-06-12 19:50 - 2019-06-12 19:50 - 000535552 _____ (Dirección General de la Policía) C:\Users\Luis M\AppData\Local\DNIeService.exe 2018-08-04 19:21 - 2018-08-04 19:21 - 000000001 _____ () C:\Users\Luis M\AppData\Local\llftool.4.12.agreement 2018-11-08 19:26 - 2018-11-08 19:26 - 000000000 _____ () C:\Users\Luis M\AppData\Local\oobelibMkey.log 2018-08-09 17:17 - 2019-06-26 17:47 - 000000600 _____ () C:\Users\Luis M\AppData\Local\PUTTY.RND 2018-02-01 19:40 - 2018-05-20 17:37 - 000007648 _____ () C:\Users\Luis M\AppData\Local\Resmon.ResmonCfg ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================