Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Disk at 100% constantly. Malware?

Virus Disk Windows 100 Task Manager

  • Please log in to reply

#1
MrMatoke

MrMatoke

    Member

  • Member
  • PipPip
  • 32 posts

Hello everyone.

The problem is that the disk at the task manager is regularly at 100%. I play a lot of games and my pc IS built for them (i7 proccessor, gtx 1050 gpu, 8 gb ram, and so on). However, even when I use google chrome the disk reaches 100% and therefore makes everything slow. Bottom line is: I don't know why, but the disk is constantly at 100% and makes the performance so much worse. I tried some solutions I saw on Google but got nowhere. Thoughts? Here's the FRST.txt and the Addition.txt (I know someone will ask for those surely) 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 4-08-2019
Ran by Matoke (administrator) on DESKTOP-4LAFI5B (04-08-2019 21:58:17)
Running from C:\Users\amd\Downloads
Loaded Profiles: Matoke (Available Profiles: Matoke & Otros)
Platform: Windows 10 Pro Version 1803 17134.885 (X64) Language: Español (México)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.50.38.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19051.16210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() [File not signed] C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_1.16.1012.0_x64__8wekyb3d8bbwe\GameBar.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(alch) [File not signed] C:\Program Files (x86)\ClamWin\bin\ClamTray.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\UnrealCEFSubProcess.exe
(Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(GoPro Media, Inc. -> ) C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.50.38.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\NisSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [598200 2018-09-28] (Razer USA Ltd. -> Razer Inc.)
HKLM-x32\...\Run: [ClamWin] => C:\Program Files (x86)\ClamWin\bin\ClamTray.exe [86016 2018-03-03] (alch) [File not signed]
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2622520 2019-05-19] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3148576 2019-06-17] (Valve -> Valve Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Discord] => C:\Users\amd\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35808144 2019-07-22] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [18666984 2018-12-14] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe [23913464 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [53646912 2019-06-20] (Skype Software Sarl -> Skype Technologies S.A.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe [2019-07-16] (Google LLC -> Google LLC)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00F4F76B-A514-46C8-9041-AC8F1F0C5C9B} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0EB188D4-899C-4085-A2BF-6893B1A7308B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27351864 2019-07-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {1ED78B5C-3A99-4E5F-8E27-F003DF678504} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-23] (Google Inc -> Google Inc.)
Task: {2F50A520-DCAC-4D6B-9269-3CFDD60B7573} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1447064 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {40FA51BE-AEAA-4CA1-B73B-97530A85869B} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {430F00B1-AB5F-40E8-9870-BC01732DFEBB} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1447064 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {4599A762-E0B5-4246-8CDF-74B64E7AA6EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {485416D2-BC05-48E7-9A3D-3B9FFCE7BBBC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-23] (Google Inc -> Google Inc.)
Task: {4D328107-ED1C-4530-BD4C-F433198AC403} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1830811996-1437030023-4132568959-1004 => C:\Users\amd\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {59483DF7-535D-4BAB-8FCB-CC65784B66EF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [114736 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {61D39848-674B-46A5-8268-3445EA823DBA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4519576 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {6635DC11-B66B-4F5C-9FDA-6C665A941ED1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6DE9B58E-2767-484C-AFDE-10FC1F0EE760} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6F4F7FCB-0456-45E7-B3E9-CF8B9A376106} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4519576 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487F195-19CA-48A1-9358-C9DF5F516FF4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9E89DC01-5E7B-401E-B422-E5CEE8BCE7E3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27351864 2019-07-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF137F09-55AC-49AD-A05A-EC79B4F65130} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B82B48CC-E9E4-480D-A8AC-DB6FADE86FAE} - System32\Tasks\AdobeGCInvoker-1.0-DESKTOP-4LAFI5B-Matoke => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {BEC3D44E-57AF-4C07-8783-0D41C08FE14E} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C1219263-DB86-48BC-A6CF-AD87E24D39D7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [114736 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF526D79-AAE9-456A-A1DA-8DF6F79EB36F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CF7A22FF-51C6-4EFE-9E03-A8EFE14BF099} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D1957C35-1B5A-483C-9745-24693D6FBF4A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D4D624E7-4B22-4A16-B776-874A63CCFFE6} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3788144 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D55632DC-FAF3-4AD6-A362-6BE33B0A7831} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D5C93072-60ED-4351-9C65-BC314006E5C5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2047368 2019-07-30] (AVAST Software s.r.o. -> AVAST Software)
Task: {F49AE5A7-D544-43AF-A12C-20339E432107} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (All) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [54784 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [64000 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [24064 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 12 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9 13 C:\WINDOWS\SysWOW64\mswsock.dll [341920 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5-x64 01 C:\Windows\system32\napinsp.dll [67072 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5-x64 02 C:\Windows\system32\pnrpnsp.dll [84992 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5-x64 03 C:\Windows\system32\pnrpnsp.dll [84992 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5-x64 04 C:\Windows\system32\NLAapi.dll [80896 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5-x64 05 C:\Windows\System32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog5-x64 06 C:\Windows\System32\winrnr.dll [31232 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 01 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 02 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 03 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 04 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 05 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 06 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 07 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 08 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 09 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 10 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 11 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 12 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Winsock: Catalog9-x64 13 C:\Windows\system32\mswsock.dll [401968 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{54e2108c-8637-4bb9-95c6-a60275ec1987}: [DhcpNameServer] 208.67.220.220 208.67.222.222
Tcpip\..\Interfaces\{641c23af-61d5-46a6-a811-c61f189b2b88}: [NameServer] 8.8.8.8,8.8.4.4
ManualProxies: 
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHhI8J8aInErgE7xdslq-PtG7be0E1PeUZSAqkGnzX2fKYuNPJVwuxmFa_2ljjAKqYTs0__ceWtT-R6P1LcWVhKWRC1r3SchMfrR1r6e9gaYZukVYY0-V8bYUqylE-BJTBFHftuXCFMrzVQD-F2EPQITHgiufaNPCmL7DWKc8mQR&q={searchTerms}
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHhI8J8aInErgE7xdslq-PtG7be0E1PeUZSAqkGnzX2fKYuNPJVwuxmFa_2ljjAKqYTs0__ceWtT-R6P1LcWVhKWRC1r3SchMfrR1r6e9gaYZukVYY0-V8bYUqylE-BJTBFHftuXCFMrzVQD-F2EPQITHgiufaNPCmL7DWKc8mQR&q={searchTerms}
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
URLSearchHook: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Windows -> Microsoft Corporation)
URLSearchHook: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001 - Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Windows -> Microsoft Corporation)
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
SearchScopes: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHhI8J8aInErgE7xdslq-PtG7be0E1PeUZSAqkGnzX2fKYuNPJVwuxmFa_2ljjAKqYTs0__ceWtT-R6P1LcWVhKWRC1r3SchMfrR1r6e9gaYZukVYY0-V8bYUqylE-BJTBFHftuXCFMrzVQD-F2EPQITHgiufaNPCmL7DWKc8mQR&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
SearchScopes: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHhI8J8aInErgE7xdslq-PtG7be0E1PeUZSAqkGnzX2fKYuNPJVwuxmFa_2ljjAKqYTs0__ceWtT-R6P1LcWVhKWRC1r3SchMfrR1r6e9gaYZukVYY0-V8bYUqylE-BJTBFHftuXCFMrzVQD-F2EPQITHgiufaNPCmL7DWKc8mQR&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\msvidctl.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2019-01-09] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll [2019-01-09] (Microsoft Windows -> Microsoft Corporation)
Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll [2018-09-08] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll [2018-09-08] (Microsoft Windows -> Microsoft Corporation)
Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll [2019-05-17] (Microsoft Windows -> Microsoft Corporation)
Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll [2019-01-09] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll [2019-01-09] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2018-06-08] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2018-06-08] (Microsoft Windows -> Microsoft Corporation)
Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\msvidctl.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll [2019-07-04] (Microsoft Windows -> Microsoft Corporation)
Handler: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll [2018-06-08] (Microsoft Windows -> Microsoft Corporation)
Handler-x32: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll [2018-06-08] (Microsoft Windows -> Microsoft Corporation)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWOW64\mscoree.dll [2018-04-11] (Microsoft Windows -> Microsoft Corporation)
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Filter-x32: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe
 
Edge: 
======
Edge Extension: (AutoFormFill) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [2018-04-11]
Edge Extension: (LearningTools) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [2018-04-11]
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.mystartsearch.com/?type=hp&ts=1425245053&from=tugs&uid=WDCXWD5000LPVX-60V0TT0_WD-WX91A743J2453J245
CHR StartupUrls: Default -> "hxxp://www.mystartsearch.com/?type=hp&ts=1425245053&from=tugs&uid=WDCXWD5000LPVX-60V0TT0_WD-WX91A743J2453J245","hxxp://www.mystartsearch.com/?type=hppp&ts=1425245075&from=tugs&uid=WDCXWD5000LPVX-60V0TT0_WD-WX91A743J2453J245"
CHR DefaultSearchURL: Default -> hxxps://defaultsearch.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> Adaware Secure
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default [2019-08-04]
CHR Extension: (Presentaciones) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-07-21]
CHR Extension: (Documentos) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-07-21]
CHR Extension: (Google Drive) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-17]
CHR Extension: (YouTube) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-07-21]
CHR Extension: (Hojas de cálculo) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-07-21]
CHR Extension: (Cablevisión Flow) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfbnbmbkemlokfckhdoaakhjogffkinc [2018-07-21]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-10]
CHR Extension: (AdBlock) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-07-31]
CHR Extension: (Hola Free VPN Proxy Unblocker) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2019-07-31]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-07-21]
CHR Extension: (Gmail) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-21]
CHR Extension: (Chrome Media Router) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-06-21]
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-02-23]
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\System Profile [2019-02-23]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
CHR crx: C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\default_apps\docs.crx [2019-07-12]
CHR crx: C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\default_apps\drive.crx [2019-07-12]
CHR crx: C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\default_apps\gmail.crx [2019-07-12]
CHR crx: C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\default_apps\youtube.crx [2019-07-12]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [816184 2019-05-19] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3117648 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2888272 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-03-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11469920 2019-07-26] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-12-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 GoProDeviceDetectionService; C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe [38328 2018-04-26] (GoPro Media, Inc. -> )
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2247144 2018-12-14] (Plex, Inc -> Plex, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5073792 2019-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11660528 2018-12-07] (TeamViewer GmbH -> TeamViewer GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 Ds3Service; "C:\Users\amd\Desktop\Driver ps3\Drivers PS3 By Haniel\ScpServer\bin\ScpService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [34696 2018-05-11] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33144 2018-05-11] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [31592 2018-04-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [137104 2018-05-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-05-13] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-05-13] (Disc Soft Ltd -> Disc Soft Ltd)
R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvpcdi.inf_amd64_400a42b4e8d4c1e9\nvlddmkm.sys [21854352 2019-07-04] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-06-13] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [75600 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation -> Corel Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [680416 2018-10-24] (Realtek Semiconductor Corp. -> Realtek )
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5707264 2018-04-11] (Microsoft Windows -> Realtek Semiconductor Corporation )
R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [51728 2016-08-05] (Razer USA Ltd. -> Razer Inc)
R3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [43536 2016-08-05] (Razer USA Ltd. -> Razer Inc)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [344288 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
S3 dufetyu; \??\C:\WINDOWS\system32\dufetyu.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-04 21:58 - 2019-08-04 21:58 - 000000000 ____D C:\Users\amd\Downloads\FRST-OlderVersion
2019-08-02 15:17 - 2019-08-02 15:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Herramientas de Microsoft Office
2019-08-02 15:16 - 2019-08-03 01:06 - 000212992 _____ C:\WINDOWS\system32\ClickToRun_Pipeline16
2019-07-31 19:38 - 2019-07-31 19:38 - 001028376 _____ C:\Users\amd\Downloads\Blockhouse.zip
2019-07-31 18:39 - 2019-07-31 18:39 - 000000000 ____D C:\Users\amd\AppData\Roaming\NVIDIA
2019-07-30 16:26 - 2019-07-30 16:26 - 000124674 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-06-25 at 1.19.28 PM (1).jpeg
2019-07-30 16:26 - 2019-07-30 16:26 - 000104282 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-06-25 at 1.19.29 PM (1).jpeg
2019-07-29 16:07 - 2019-07-29 16:07 - 000000000 ____D C:\Users\amd\Documents\This War of Mine
2019-07-29 16:07 - 2019-07-29 16:07 - 000000000 ____D C:\Users\amd\AppData\Roaming\11bitstudios
2019-07-29 14:53 - 2019-07-29 14:53 - 000000000 ____D C:\Users\amd\Desktop\CKScanner
2019-07-29 14:46 - 2019-07-29 14:46 - 000004443 _____ C:\Users\amd\Downloads\ckfiles.txt
2019-07-24 23:46 - 2019-07-24 23:48 - 000058664 _____ C:\Users\amd\Downloads\Addition.txt
2019-07-24 23:42 - 2019-08-04 21:59 - 000047431 _____ C:\Users\amd\Downloads\FRST.txt
2019-07-24 23:42 - 2019-08-04 21:58 - 002096640 _____ (Farbar) C:\Users\amd\Downloads\FRST64.exe
2019-07-24 22:58 - 2019-07-29 14:53 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2019-07-24 22:57 - 2019-07-24 22:58 - 047441489 _____ C:\Users\amd\Downloads\MSIAfterburnerSetup.zip
2019-07-24 22:50 - 2019-07-24 22:50 - 000001447 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2019-07-24 22:45 - 2019-07-03 06:10 - 005435376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 002637168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 001767464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000651248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000450416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000124784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000082984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-07-24 22:45 - 2019-07-03 06:09 - 008628422 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-07-24 22:45 - 2019-03-06 01:33 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-07-24 22:42 - 2019-07-24 22:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2019-07-24 22:33 - 2019-07-24 22:37 - 123477920 _____ (NVIDIA Corporation New) C:\Users\amd\Downloads\GeForce_Experience_v3.19.0.107.exe
2019-07-24 21:22 - 2019-07-23 15:19 - 000000000 ____D C:\Users\amd\Desktop\MAINCRENZIE
2019-07-24 20:48 - 2019-07-24 20:49 - 250287771 _____ C:\Users\amd\Downloads\MAINCRENZIE.rar
2019-07-24 19:55 - 2019-07-24 19:55 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2019-07-24 19:46 - 2019-07-24 19:46 - 005193376 _____ (Husdawg, LLC) C:\Users\amd\Downloads\Detection (2).exe
2019-07-21 12:39 - 2019-07-21 12:39 - 000000000 ____D C:\Users\amd\AppData\LocalLow\Oracle
2019-07-13 19:18 - 2019-07-04 15:07 - 005085096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-07-13 19:18 - 2019-07-04 15:07 - 004340664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 001006792 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 001006792 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000870088 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000870088 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000552136 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000456448 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000286408 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-07-13 19:18 - 2019-07-04 12:13 - 000286408 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-07-13 19:18 - 2019-07-04 12:13 - 000260296 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-07-13 19:18 - 2019-07-04 12:13 - 000260296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-07-13 19:18 - 2019-07-04 12:12 - 011059128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-07-13 19:18 - 2019-07-04 12:12 - 009492224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 020190592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 005422464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 004759240 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 002040192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001722056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443136.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001542016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001470904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001467832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443136.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001162168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001134464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000912072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000821176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000808832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000675224 _____ C:\WINDOWS\system32\nvofapi64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000654720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000631712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000542296 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000521872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-07-13 19:18 - 2019-07-04 12:10 - 040412360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-07-13 19:18 - 2019-07-04 12:10 - 035270016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-07-13 19:18 - 2019-07-04 12:10 - 017467592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-07-13 19:18 - 2019-07-03 10:56 - 000052446 _____ C:\WINDOWS\system32\nvinfo.pb
2019-07-10 15:40 - 2019-07-10 15:40 - 011150138 _____ C:\Users\amd\Downloads\Barthes, R. - La cámara lúcida.pdf
2019-07-09 19:26 - 2019-07-04 01:56 - 007519896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-09 19:26 - 2019-07-04 01:42 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-09 19:26 - 2019-07-04 01:37 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-09 19:26 - 2019-07-04 01:29 - 022717440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-09 19:25 - 2019-07-04 06:45 - 001786680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-09 19:25 - 2019-07-04 06:43 - 000094008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2019-07-09 19:25 - 2019-07-04 06:41 - 000304144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-09 19:25 - 2019-07-04 06:40 - 021390504 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-09 19:25 - 2019-07-04 06:40 - 001631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-09 19:25 - 2019-07-04 06:40 - 001616840 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-09 19:25 - 2019-07-04 06:40 - 000790416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-09 19:25 - 2019-07-04 06:22 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-09 19:25 - 2019-07-04 06:22 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-09 19:25 - 2019-07-04 06:21 - 008627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-09 19:25 - 2019-07-04 06:20 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-09 19:25 - 2019-07-04 06:19 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-09 19:25 - 2019-07-04 06:18 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-09 19:25 - 2019-07-04 06:18 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-09 19:25 - 2019-07-04 05:56 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-09 19:25 - 2019-07-04 05:54 - 000662352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-09 19:25 - 2019-07-04 05:51 - 020384128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-09 19:25 - 2019-07-04 05:41 - 007990784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-09 19:25 - 2019-07-04 05:37 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-09 19:25 - 2019-07-04 05:36 - 001471488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-09 19:25 - 2019-07-04 02:00 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-09 19:25 - 2019-07-04 01:58 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-09 19:25 - 2019-07-04 01:58 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-09 19:25 - 2019-07-04 01:58 - 000416312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-09 19:25 - 2019-07-04 01:58 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-09 19:25 - 2019-07-04 01:57 - 003292152 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000986128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000776784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000723728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000708696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-09 19:25 - 2019-07-04 01:57 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000362264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000209424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000194360 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000137656 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000091776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-09 19:25 - 2019-07-04 01:56 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 007436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-09 19:25 - 2019-07-04 01:56 - 002571640 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 001566520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 001459120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-09 19:25 - 2019-07-04 01:56 - 001260776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 001141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-09 19:25 - 2019-07-04 01:56 - 000983936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 000767536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000734952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000713272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 000493752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000115512 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000832016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-09 19:25 - 2019-07-04 01:43 - 000665440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000328696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000287376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000191800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-09 19:25 - 2019-07-04 01:42 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 002479176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 001980984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 000356312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 000097272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2019-07-09 19:25 - 2019-07-04 01:41 - 000559328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-09 19:25 - 2019-07-04 01:33 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-09 19:25 - 2019-07-04 01:26 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-09 19:25 - 2019-07-04 01:26 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-09 19:25 - 2019-07-04 01:26 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 007589888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 003401216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-09 19:25 - 2019-07-04 01:24 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-09 19:25 - 2019-07-04 01:24 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-09 19:25 - 2019-07-04 01:24 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-09 19:25 - 2019-07-04 01:24 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-09 19:25 - 2019-07-04 01:23 - 001765888 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-09 19:25 - 2019-07-04 01:23 - 001217536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-09 19:25 - 2019-07-04 01:23 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 003707904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 002587648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 001175552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 005784064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 003202560 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 002166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-09 19:25 - 2019-07-04 01:21 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 001156608 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-09 19:25 - 2019-07-04 01:19 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-09 19:25 - 2019-07-04 01:19 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 002602496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 000953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-09 19:25 - 2019-07-04 01:17 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-09 19:25 - 2019-07-04 00:01 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2019-07-09 19:25 - 2019-06-21 05:50 - 000280584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-07-09 19:25 - 2019-06-13 09:15 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-09 19:25 - 2019-06-13 09:12 - 002871848 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-09 19:25 - 2019-06-13 09:05 - 000810296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-09 19:25 - 2019-06-13 09:04 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-09 19:25 - 2019-06-13 09:00 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-09 19:25 - 2019-06-13 08:59 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-09 19:25 - 2019-06-13 08:58 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-09 19:25 - 2019-06-13 08:58 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-09 19:25 - 2019-06-13 08:56 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-09 19:25 - 2019-06-13 08:43 - 001427984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-09 19:25 - 2019-06-13 08:43 - 001048480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-09 19:25 - 2019-06-13 08:42 - 004038688 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-09 19:25 - 2019-06-13 08:42 - 002266936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-09 19:25 - 2019-06-13 08:42 - 000652088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-09 19:25 - 2019-06-13 08:42 - 000566536 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-09 19:25 - 2019-06-13 08:41 - 001626936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-09 19:25 - 2019-06-13 08:41 - 000830264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-09 19:25 - 2019-06-13 08:41 - 000825144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-09 19:25 - 2019-06-13 08:41 - 000670008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-09 19:25 - 2019-06-13 08:40 - 000749880 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-09 19:25 - 2019-06-13 08:40 - 000540984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-09 19:25 - 2019-06-13 08:40 - 000495416 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-09 19:25 - 2019-06-13 08:38 - 000766264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2019-07-09 19:25 - 2019-06-13 08:37 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-09 19:25 - 2019-06-13 08:36 - 000251000 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-09 19:25 - 2019-06-13 08:36 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2019-07-09 19:25 - 2019-06-13 08:35 - 001376688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-09 19:25 - 2019-06-13 08:34 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-09 19:25 - 2019-06-13 08:18 - 006586880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-09 19:25 - 2019-06-13 08:18 - 004847104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 012756992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2019-07-09 19:25 - 2019-06-13 08:17 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-09 19:25 - 2019-06-13 08:16 - 000767488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-09 19:25 - 2019-06-13 08:15 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-09 19:25 - 2019-06-13 08:15 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-09 19:25 - 2019-06-13 08:14 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2019-07-09 19:25 - 2019-06-13 08:14 - 000900096 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe
2019-07-09 19:25 - 2019-06-13 08:14 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-09 19:25 - 2019-06-13 08:14 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 002920448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 001339392 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2019-07-09 19:25 - 2019-06-13 08:12 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-09 19:25 - 2019-06-13 08:10 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2019-07-09 19:25 - 2019-06-13 07:11 - 001539896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-09 19:25 - 2019-06-13 07:07 - 001027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-09 19:25 - 2019-06-13 07:07 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2019-07-09 19:25 - 2019-06-13 07:07 - 000221232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2019-07-09 19:25 - 2019-06-13 07:05 - 003700160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-09 19:25 - 2019-06-13 06:55 - 005657088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-09 19:25 - 2019-06-13 06:54 - 011942912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-09 19:25 - 2019-06-13 06:54 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2019-07-09 19:25 - 2019-06-13 06:53 - 000089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-09 19:25 - 2019-06-13 06:51 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2019-07-09 19:25 - 2019-06-13 06:50 - 000896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2019-07-09 19:25 - 2019-06-13 06:49 - 002406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-09 19:25 - 2019-06-13 06:49 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-09 19:25 - 2019-06-13 04:48 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2019-07-09 19:25 - 2019-06-13 04:46 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-09 19:25 - 2019-06-13 04:01 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-09 19:25 - 2019-06-13 04:01 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-09 19:25 - 2019-06-13 04:01 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-09 19:25 - 2019-06-13 03:59 - 000785264 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-07-09 19:25 - 2019-06-13 03:47 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-09 19:25 - 2019-06-13 03:47 - 001063224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-09 19:25 - 2019-06-13 03:46 - 001076536 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2019-07-09 19:25 - 2019-06-13 03:46 - 000510296 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-07-09 19:25 - 2019-06-13 03:46 - 000093984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-09 19:25 - 2019-06-13 03:45 - 002421560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-09 19:25 - 2019-06-13 03:44 - 002769688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 002546704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 001098272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 001033696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 000607112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 000545808 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 000130624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-07-09 19:25 - 2019-06-13 03:17 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-09 19:25 - 2019-06-13 03:16 - 001626112 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-09 19:25 - 2019-06-13 03:16 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-07-09 19:25 - 2019-06-13 03:15 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-09 19:25 - 2019-06-13 03:15 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-09 19:25 - 2019-06-13 03:15 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-07-09 19:25 - 2019-06-13 03:15 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-09 19:25 - 2019-06-13 03:15 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\KdsCli.dll
2019-07-09 19:25 - 2019-06-13 03:14 - 003318784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-09 19:25 - 2019-06-13 03:14 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-09 19:25 - 2019-06-13 03:14 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-07-09 19:25 - 2019-06-13 03:14 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 004771840 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 002370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 000761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-07-09 19:25 - 2019-06-13 03:13 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-09 19:25 - 2019-06-13 03:11 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-09 19:25 - 2019-06-13 03:11 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2019-07-09 19:25 - 2019-06-13 03:11 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-09 19:25 - 2019-06-13 03:09 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-09 19:25 - 2019-06-13 03:09 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-07-09 19:25 - 2019-06-13 03:09 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-09 19:25 - 2019-06-13 03:08 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-09 19:25 - 2019-06-13 02:14 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-09 19:25 - 2019-06-13 02:08 - 000443632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-07-09 19:25 - 2019-06-13 02:07 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-07-09 19:25 - 2019-06-13 02:07 - 000080744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-09 19:25 - 2019-06-13 02:06 - 002256768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-09 19:25 - 2019-06-13 02:06 - 001130776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-09 19:25 - 2019-06-13 02:06 - 000581600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2019-07-09 19:25 - 2019-06-13 01:49 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-07-09 19:25 - 2019-06-13 01:47 - 003554304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2019-07-09 19:25 - 2019-06-13 01:47 - 002899456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-07-09 19:25 - 2019-06-13 01:47 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-09 19:25 - 2019-06-13 01:46 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-09 19:25 - 2019-06-13 01:46 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-09 19:25 - 2019-06-13 01:46 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2019-07-09 19:25 - 2019-06-13 01:45 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2019-07-09 19:25 - 2019-06-13 01:45 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-09 19:25 - 2019-06-13 01:43 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-07-09 19:25 - 2019-06-13 01:43 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 01:43 - 000445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-08 18:21 - 2019-07-08 18:21 - 000046911 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-03 at 8.48.35 PM (1).jpeg
2019-07-08 16:53 - 2019-07-08 16:53 - 000085744 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-03 at 8.57.01 PM.jpeg
2019-07-08 16:53 - 2019-07-08 16:53 - 000046911 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-03 at 8.48.35 PM.jpeg
2019-07-08 16:52 - 2019-07-08 16:52 - 000000000 ____D C:\Users\amd\AppData\Local\PackageStaging
2019-07-07 19:10 - 2019-07-07 19:10 - 000001383 _____ C:\Users\Public\Desktop\Skype.lnk
2019-07-07 19:10 - 2019-07-07 19:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-07-07 19:08 - 2019-07-07 19:09 - 063471184 _____ (Skype Technologies S.A.) C:\Users\amd\Downloads\Skype-8.48.0.51.exe
2019-07-07 19:02 - 2019-07-07 19:10 - 000000000 ____D C:\Users\amd\AppData\Roaming\Skype
2019-07-07 17:18 - 2019-07-07 17:18 - 000000759 _____ C:\Users\amd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programas y características - Acceso directo.lnk
2019-07-07 15:55 - 2019-07-21 12:41 - 000110064 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2019-07-07 15:55 - 2019-07-21 12:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2019-07-07 15:55 - 2019-07-21 12:41 - 000000000 ____D C:\Program Files\Java
2019-07-07 15:55 - 2019-07-07 15:55 - 000000000 ____D C:\Users\amd\AppData\Roaming\Sun
2019-07-07 15:50 - 2019-07-07 15:51 - 079721824 _____ (Oracle Corporation) C:\Users\amd\Downloads\jre-8u211-windows-x64.exe
2019-07-07 15:47 - 2019-07-07 15:47 - 002043232 _____ (Oracle Corporation) C:\Users\amd\Downloads\jre-8u211-windows-i586-iftw.exe
2019-07-07 15:41 - 2019-07-07 15:41 - 002260992 _____ C:\Users\amd\Downloads\MinecraftInstaller (3).msi
2019-07-07 15:40 - 2019-07-07 15:40 - 001340256 _____ C:\Users\amd\Downloads\Minecraft.dmg
2019-07-07 15:39 - 2019-07-07 15:39 - 002260992 _____ C:\Users\amd\Downloads\MinecraftInstaller (2).msi
2019-07-07 15:30 - 2019-07-07 15:30 - 002043232 _____ (Oracle Corporation) C:\Users\amd\Downloads\JavaSetup8u211 (1).exe
2019-07-06 00:56 - 2019-07-24 22:45 - 000000000 ____D C:\Users\amd\AppData\Local\LogMeIn Hamachi
2019-07-05 18:15 - 2019-07-05 18:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2019-07-05 18:15 - 2019-07-05 18:15 - 000000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2019-07-05 18:12 - 2019-07-05 18:13 - 009142272 _____ C:\Users\amd\Downloads\hamachi (1).msi
2019-07-05 17:55 - 2019-07-05 17:57 - 035952401 _____ C:\Users\amd\Downloads\server (1).jar
2019-07-05 17:47 - 2019-07-05 18:12 - 000000000 ____D C:\Users\amd\Desktop\MC Server
2019-07-05 17:47 - 2019-07-05 17:50 - 035952401 _____ C:\Users\amd\Downloads\server.jar
2019-07-05 13:56 - 2019-07-05 13:56 - 000071190 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-05 at 12.31.28 PM.jpeg
2019-07-05 13:56 - 2019-07-05 13:56 - 000070671 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-05 at 12.32.47 PM.jpeg
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-04 21:58 - 2018-07-24 15:06 - 000000000 ____D C:\FRST
2019-08-04 21:51 - 2018-05-10 16:18 - 000000000 ____D C:\ProgramData\NVIDIA
2019-08-04 21:26 - 2018-04-11 20:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-08-04 19:29 - 2019-03-13 21:44 - 000000000 ____D C:\Users\amd\Documents\Remedy
2019-08-03 01:17 - 2018-05-14 20:23 - 000000000 ____D C:\Program Files\Epic Games
2019-08-03 01:07 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-08-03 01:06 - 2018-12-19 18:02 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-08-03 01:06 - 2018-06-10 20:03 - 005101640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-08-03 01:05 - 2018-06-10 20:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-08-02 15:21 - 2018-04-11 18:04 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2019-08-02 15:17 - 2019-06-30 15:46 - 000002580 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Empresarial.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002531 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002512 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002485 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002439 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-08-02 15:16 - 2018-05-13 22:05 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-08-02 15:12 - 2018-04-11 20:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-02 15:10 - 2018-11-17 00:38 - 000000000 ____D C:\Program Files\rempl
2019-08-02 15:04 - 2018-06-10 20:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-07-31 21:00 - 2018-05-14 20:36 - 000000000 ____D C:\Users\amd\Desktop\MIS COSAS
2019-07-31 18:45 - 2018-06-10 20:24 - 000000000 ____D C:\Users\amd\AppData\Local\D3DSCache
2019-07-31 18:38 - 2018-05-10 16:19 - 000000000 ____D C:\Users\amd\AppData\Local\NVIDIA
2019-07-30 18:52 - 2018-07-20 02:36 - 000000000 ____D C:\Users\amd\AppData\Local\CrashDumps
2019-07-30 15:44 - 2018-06-10 20:07 - 000000000 ___HD C:\Users\amd
2019-07-30 01:59 - 2018-05-16 21:18 - 000000000 ____D C:\Users\amd\AppData\Roaming\vlc
2019-07-26 16:44 - 2018-12-02 20:13 - 000000000 ____D C:\WINDOWS\Minidump
2019-07-26 16:22 - 2018-05-10 18:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-07-24 22:50 - 2018-07-16 21:09 - 000003976 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:50 - 2018-07-16 21:09 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:50 - 2018-05-10 16:16 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-07-16 21:08 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-07-16 21:08 - 000004106 _____ C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-06-10 20:18 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-06-10 20:18 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-05-10 16:17 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-07-24 22:49 - 2018-05-10 16:15 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-07-24 22:49 - 2018-04-11 20:36 - 000000000 ____D C:\WINDOWS\INF
2019-07-24 22:46 - 2018-07-30 02:44 - 000000000 ____D C:\temp
2019-07-24 22:45 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\Help
2019-07-24 21:59 - 2019-05-27 00:47 - 000000000 ____D C:\Users\amd\AppData\Roaming\.minecraft
2019-07-24 21:50 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-07-24 20:50 - 2019-05-27 00:45 - 000000000 ____D C:\Program Files (x86)\Minecraft Launcher
2019-07-23 18:00 - 2018-06-16 23:43 - 000000000 ____D C:\Users\amd\AppData\Roaming\discord
2019-07-22 13:35 - 2018-06-10 20:18 - 001762872 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-22 13:35 - 2018-04-12 13:21 - 000781218 _____ C:\WINDOWS\system32\perfh00A.dat
2019-07-22 13:35 - 2018-04-12 13:21 - 000152030 _____ C:\WINDOWS\system32\perfc00A.dat
2019-07-16 07:18 - 2019-02-23 16:19 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-16 07:18 - 2019-02-23 16:19 - 000002258 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-13 18:03 - 2019-04-21 03:53 - 000000000 ____D C:\Users\amd\AppData\Local\Ubisoft Game Launcher
2019-07-11 08:25 - 2018-05-10 15:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-11 08:25 - 2018-05-10 15:33 - 000000000 ___RD C:\Users\amd\3D Objects
2019-07-11 08:20 - 2018-04-12 13:26 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-11 08:20 - 2018-04-11 18:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-07-09 19:39 - 2018-04-11 20:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-09 19:12 - 2018-05-10 17:44 - 000741432 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-08 16:52 - 2018-05-10 15:33 - 000000000 ____D C:\Users\amd\AppData\Local\Packages
2019-07-07 19:10 - 2018-05-10 16:19 - 000000000 ____D C:\Users\amd\AppData\Local\PlaceholderTileLogoFolder
 
==================== Files in the root of some directories ================
 
2019-06-20 23:11 - 2019-06-20 23:11 - 000000000 _____ () C:\Users\amd\AppData\Local\oobelibMkey.log
2018-08-09 20:09 - 2018-08-16 23:40 - 000007620 _____ () C:\Users\amd\AppData\Local\Resmon.ResmonCfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
 
 
 
..........................................................................................................
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 4-08-2019
Ran by Matoke (04-08-2019 22:01:36)
Running from C:\Users\amd\Downloads
Windows 10 Pro Version 1803 17134.885 (X64) (2018-06-10 23:19:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrador (S-1-5-21-1830811996-1437030023-4132568959-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1830811996-1437030023-4132568959-503 - Limited - Disabled)
Invitado (S-1-5-21-1830811996-1437030023-4132568959-501 - Limited - Disabled)
matia (S-1-5-21-1830811996-1437030023-4132568959-1002 - Limited - Disabled)
Matoke (S-1-5-21-1830811996-1437030023-4132568959-1001 - Administrator - Enabled) => C:\Users\amd
Otros (S-1-5-21-1830811996-1437030023-4132568959-1004 - Limited - Enabled) => C:\Users\Otros
WDAGUtilityAccount (S-1-5-21-1830811996-1437030023-4132568959-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\uTorrent) (Version: 3.5.5.45271 - BitTorrent Inc.)
Actualización de NVIDIA 37.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 37.0.0.0 - NVIDIA Corporation) Hidden
Adobe After Effects 2019 (HKLM-x32\...\AEFT_16_1_1) (Version: 16.1.1 - Adobe Systems Incorporated)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated)
Adobe Animate CC 2015 (HKLM-x32\...\{8CEBC11D-C52F-11E5-A0D6-D44AB5E81A82}) (Version: 15.1 - Adobe Systems Incorporated)
Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.8.2.476 - Adobe Systems Incorporated)
Adobe Encore CS6 (HKLM-x32\...\{46251F95-B2F8-484A-9B5B-8C0E5A43A202}) (Version: 6.0.0 - Adobe Systems Incorporated)
Adobe Illustrator CC 2015 (HKLM-x32\...\{5680D629-B263-49CC-821E-3CEBD4507B51}) (Version: 19.0 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.0.0 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 17.7 - Advanced Micro Devices, Inc.)
AmericasCardroom (HKLM-x32\...\296836EA-EF3A-4C36-8C13-3A6C1DB2D4BE) (Version: 16.6 - IGSoft)
Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.0.0.4 - Electronic Arts, Inc.)
Balanced (HKLM-x32\...\{EFD0705E-598B-46D4-8D5B-4539431764B8}) (Version: 2.02.0000 - Nombre de su organización) Hidden
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
ClamWin Free Antivirus 0.99.4 (HKLM-x32\...\ClamWin Free Antivirus_is1) (Version:  - alch)
DaVinci Resolve (HKLM\...\{EA907964-FDE2-48E5-A8E4-41F2B4342FA8}) (Version: 16.0.0033 - Blackmagic Design)
DaVinci Resolve Panels (HKLM\...\{B1782967-E600-4BBD-B2F1-AEF3F2FE0A12}) (Version: 1.2.1.0 - Blackmagic Design)
Discord (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
DMMultiView (HKLM-x32\...\{8EEBAD15-F3B7-468B-917F-97BBF6B1004B}) (Version:  - )
Epic Games Launcher (HKLM-x32\...\{79F5479A-BF71-4F4C-9C49-9D616AF923DE}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
GeoVision MJPG (HKLM-x32\...\Codec_MJPG) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.142 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
GoPro Quik (HKLM\...\{855E73D9-1EC0-4914-98D1-FD1FC7E93870}) (Version: 0.1.780 - GoPro, Inc.) Hidden
GoPro Quik (HKLM-x32\...\{e2b0610c-a7ad-4330-87ba-c30a14ff17e7}) (Version: 2.6.1.780 - GoPro, Inc.)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Java 8 Update 221 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180221F0}) (Version: 8.0.2210.11 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}) (Version: 2.2.0.633 - LogMeIn, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.633 - LogMeIn, Inc.)
Microsoft Office Profesional Plus 2016 - es-es (HKLM\...\ProPlusRetail - es-es) (Version: 16.0.11901.20176 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{ab058666-66d5-445f-bef6-76a4ab200ef1}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{449EFED6-5F86-4428-8EB2-3DA1F6E67CE4}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{E154B2C8-2F3E-4763-B3D5-E7D34AE39C6B}) (Version: 1.0.0.0 - Mojang)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.15 - NVIDIA Corporation) Hidden
NVIDIA Controlador de audio HD 1.3.38.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.16 - NVIDIA Corporation)
NVIDIA Controlador de gráficos 431.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 431.36 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.19.0.107 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.19.0.107 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Panel de control de NVIDIA 431.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 431.36 - NVIDIA Corporation) Hidden
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Plex Media Server (HKLM-x32\...\{049535F6-B56E-4F73-B5A5-06369B94ED2E}) (Version: 1.14.1488 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{0a25946e-e061-47a7-9da4-d055bb78571d}) (Version: 1.14.1.5488 - Plex, Inc.)
Popcorn-Time (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Popcorn-Time) (Version: 0.3.10 - Popcorn Time)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.)
Skype versión 8.48 (HKLM-x32\...\Skype_is1) (Version: 8.48 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stopping Plex (HKLM-x32\...\{A21C244F-E5E9-498C-90FB-CDBA86BA89CC}) (Version: 1.14.1488 - Plex, Inc.) Hidden
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.1.3399 - TeamViewer)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 85.1 - Ubisoft)
Vegas Pro 13.0 (64-bit) (HKLM\...\{3934F12E-091D-11E4-A0AD-F04DA23A5C58}) (Version: 13.0.373 - Sony)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.7 - VideoLAN)
WinDirStat 1.1.2 (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\WinDirStat) (Version:  - )
WinRAR 5.60 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
 
Packages:
=========
Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11901.20184.0_x64__8wekyb3d8bbwe [2019-08-02] (Microsoft Corporation) [MS Ad]
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.520.0_x64__rz1tebttyb220 [2019-03-13] (Dolby Laboratories)
Extensión de video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2018-10-12] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_100.1.581.0_x64__v10z8vjag6ke6 [2019-07-20] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Noticias -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad]
MSN El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0 [2019-08-02] (Spotify AB)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8999FA35C723} -> [Creative Cloud Files] => C:\Users\amd\Creative Cloud Files [2019-06-20 23:01]
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\amd\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\amd\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\amd\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [ClamWin] -> {65713842-C410-4f44-8383-BFE01A398C90} => C:\Program Files (x86)\ClamWin\bin\ExpShell64.dll [2008-04-19] () [File not signed]
ContextMenuHandlers1: [TVCShellExt] -> {4E33A7F5-8083-4C08-9D45-C5CED88F5C04} => C:\PROGRA~2\TOTALV~1\TVCSHE~2.DLL -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-07-03] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers6: [ClamWin] -> {65713842-C410-4f44-8383-BFE01A398C90} => C:\Program Files (x86)\ClamWin\bin\ExpShell64.dll [2008-04-19] () [File not signed]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2019-01-17 19:06 - 2005-02-08 17:23 - 000979005 _____ () [File not signed] C:\Program Files (x86)\ClamWin\bin\python23.dll
2019-01-17 19:06 - 2004-05-25 21:17 - 000622651 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_bsddb.pyd
2019-01-17 19:06 - 2004-01-15 14:45 - 000061440 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_ctypes.pyd
2019-01-17 19:06 - 2004-05-25 21:18 - 000049212 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_socket.pyd
2019-01-17 19:06 - 2004-05-25 21:18 - 000057401 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_sre.pyd
2019-01-17 19:06 - 2004-05-25 21:18 - 000495616 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_ssl.pyd
2019-01-17 19:06 - 2004-05-25 21:20 - 000036864 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_winreg.pyd
2019-01-17 19:06 - 2004-05-25 21:19 - 000045117 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\datetime.pyd
2019-01-17 19:06 - 2003-08-10 09:14 - 000061440 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\mxDateTime.pyd
2019-01-17 19:06 - 2004-10-11 20:22 - 000315392 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\pythoncom23.dll
2019-01-17 19:06 - 2004-10-11 20:21 - 000094208 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\pywintypes23.dll
2019-01-17 19:06 - 2004-11-20 03:27 - 000106496 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\shell.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000069632 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32api.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000024576 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32event.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000077824 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32file.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000086016 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32gui.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000024576 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32pipe.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000036864 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32process.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000065536 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32security.pyd
2019-01-17 19:06 - 2003-10-01 13:40 - 002240512 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\wxc.pyd
2019-01-17 19:06 - 2003-10-01 11:43 - 003239936 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\wxmsw24h.dll
2018-05-14 20:21 - 2018-05-14 20:21 - 098275328 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libcef.dll
2018-05-14 20:21 - 2018-05-14 20:21 - 000092672 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libEGL.dll
2018-05-14 20:21 - 2018-05-14 20:21 - 003922432 _____ () [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\libGLESv2.dll
2019-01-17 19:06 - 2018-03-03 22:42 - 000086016 _____ (alch) [File not signed] C:\Program Files (x86)\ClamWin\bin\ClamTray.exe
2018-05-13 22:05 - 2018-05-13 22:05 - 000000000 ____L (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\AppVIsvSubsystems32.dll
2018-05-13 22:05 - 2018-05-13 22:05 - 000000000 ____L (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\c2r32.dll
2018-05-14 20:21 - 2018-05-14 20:21 - 000547840 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\ThirdParty\CEF3\Win64\chrome_elf.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:E0EFB096 [141]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [474]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\localhost -> localhost
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-09-29 10:46 - 2019-01-04 18:42 - 000055801 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 mydownloaddomain.com
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 texttotalk.org
127.0.0.1 gambling577.xyz
127.0.0.1 htagdownload.space
127.0.0.1 mybcnmonetize.com
127.0.0.1 360devtraking.website
127.0.0.1 dscdn.pw
127.0.0.1 bcnmonetize.go2affise.com
127.0.0.1 beautifllink.xyz
5.149.252.98 www.google-analytics.com
5.149.252.98 adservice.google.com
 
2018-05-20 17:09 - 2018-05-20 17:09 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Control Panel\Desktop\\Wallpaper -> c:\users\amd\desktop\mis cosas\fotos\eclipse-solar-desde-espacio-5303c998cd1c9.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run32: => "Razer Synapse"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_75BED9BC4FE28DE71792C715C05373CF"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Plex Media Server"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Lync"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{88E3E29D-109F-46CA-8ABB-4FAC74DE9764}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{232BF066-6AFA-4FB6-8B8C-258FD2AA095C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{B298653C-6BAB-4CCA-B65C-37F519AEFE6D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{E2D48BAC-D002-4319-9A43-B7D6B9C52F95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [UDP Query User{46C1F681-5175-4812-A704-0A018D087A0F}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [TCP Query User{CB8558D1-FF69-4771-986A-C2983A7D5446}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [{A4D6B4EE-7047-43BC-909B-5FF1F4911A6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{D015CD49-13BE-4A89-BA7C-828AFA56A527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{5DAFBFA5-8A8F-4773-BF75-7B6D123C593D}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe (GoPro Media, Inc. -> )
FirewallRules: [{C9725F0F-0625-4FA0-85EB-FBF7A38DCE1E}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe (GoPro Media, Inc. -> )
FirewallRules: [{41A40A2A-E44C-44AD-A93A-4446FB8E4CA9}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe (GoPro Media, Inc. -> )
FirewallRules: [{CE208CB7-FEB1-4606-A637-A1C014A852E8}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro Quik.exe (GoPro Media, Inc. -> )
FirewallRules: [UDP Query User{C0A02348-D406-4393-8DAB-A47F8250E9BF}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{212AADF3-0D7A-4B97-BD5E-D558EFAA8095}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1986FD76-61B9-48EB-90E8-50AB87B518ED}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{C7410143-03D1-4CB0-B8BE-5CF6D10EA1C9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{BFE94E1D-B42B-4799-B60B-6336E3F01D1F}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{14BC1D4B-28B3-4AD0-A3EA-97B954B29A81}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{881E906A-2F74-49C0-AAA0-5BE6EF13ABD7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{BDE08CFB-A8A7-4776-B108-37791A672AEB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{D3BC73DD-4794-4CA4-B22F-4FEF12DC5665}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{CC017309-7C26-4359-A151-1AE1D766CC4D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{378DBA21-D185-4130-9A42-F11651F8C453}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{B074AF06-8527-4F30-BDCE-8D9CE60A0D53}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CB3F23E2-5A54-40B3-BAF2-DCBC60FD273E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D57043B8-7AB8-49A0-8243-ADF770A2B30C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{53837B31-8D2F-466C-8E38-1069A3E1C37D}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe No File
FirewallRules: [{45B402DD-CE34-43F1-830C-D0C80FF226B7}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe No File
FirewallRules: [{F5EBA397-3D6C-4658-9923-9C1FCFEB8134}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E7D76357-97B3-491B-B6B2-C135A6ACEF96}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D8382B40-5C53-468C-A007-635FC233849F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{D43A96E2-F383-4917-BA90-431A11A42CFA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [TCP Query User{E06DD89F-C2D8-48C5-BB31-21157FD16FBE}C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed]
FirewallRules: [UDP Query User{041C8811-C93D-4C37-8098-CCD179390CB1}C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed]
FirewallRules: [{9EA637D9-F5E4-41D8-9848-FBCD05793038}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{54E1A440-155B-4F00-90C5-88FC53B5DDAC}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{50308C51-107C-4B7D-9079-B6EF5170E396}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Town of Salem\TownOfSalem.exe () [File not signed]
FirewallRules: [{2A4AEF8E-C153-4052-90CA-269D568F821E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Town of Salem\TownOfSalem.exe () [File not signed]
FirewallRules: [{21AEFB78-DA26-4A84-8140-C02C95C4A30A}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{609ABCE4-9708-429A-A26F-40AFE31FEF37}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{5BECCA37-B0AC-4558-8118-39BE3AA0AACC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E4AF5CF5-AF77-427F-848F-68E9EA9B55C1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{3EDB7FBE-1516-4B06-A430-4074E85DA702}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{DD83AE20-1140-49BA-9760-1AA24D2968F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{D4DE269D-82ED-4781-9BF4-16674762D66C}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{ADD5AE4F-87C9-4370-9190-B39738090812}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{65922F68-02C0-4FF3-95F3-7D093F8B1283}] => (Allow) C:\Users\amd\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{88999D04-27E0-4E0C-B247-59A51236CBC5}] => (Allow) C:\Users\amd\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{C5521E59-5090-4F95-A302-A3219269926B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ring of Elysium\SLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{E0C3C56D-995E-49C9-968A-B2D52B3A6DB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ring of Elysium\SLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{C3EC1744-1DC4-4E0C-9D8D-B0333C188CCD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{9EAACC06-4304-45E6-9BA1-4F2F0F1447AF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{381B9BC2-805C-454B-B7FC-8699684D2E89}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{C81F32D9-96BA-4D98-8B82-C17CD10ED9BA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [TCP Query User{13361F34-2D40-4372-9EA8-4B675F765DE2}C:\program files\epic games\subnautica\subnautica.exe] => (Allow) C:\program files\epic games\subnautica\subnautica.exe () [File not signed]
FirewallRules: [UDP Query User{94F26278-01EC-4A69-9450-F7168943E058}C:\program files\epic games\subnautica\subnautica.exe] => (Allow) C:\program files\epic games\subnautica\subnautica.exe () [File not signed]
FirewallRules: [{80E3F48E-EFC3-419D-BCEF-E28AE2CD6550}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [{E8562E62-FE35-4E65-83F4-56D0383FF1F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [TCP Query User{E999B8F4-2717-4915-BA23-0E390665D14F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [UDP Query User{AA8257FA-4E74-4CD8-AB50-FCB9201ADCCF}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [TCP Query User{706521BE-B3C4-432D-8359-908201175E6D}C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe No File
FirewallRules: [UDP Query User{EFADB801-A1F2-4014-A2FF-13290243BFDE}C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe No File
FirewallRules: [{33A53120-D49A-4FE5-9819-DB194B121DC5}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{001BB55E-C9F3-45D8-BE44-B73CDAD38EC0}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{AEB573C4-19A5-4CA7-8D82-E59649FCA00F}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{C7DC833A-D8BA-47F3-8660-49CB63B90E03}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{C6DBD3F6-EB35-46C3-A64C-4430DEB5D042}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{8B7C3E07-989F-419D-A2F8-ECED19B56BD5}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> Plex)
FirewallRules: [{D0892972-8796-4E5F-9655-04DCD277FA88}] => (Allow) C:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{892528D0-600B-4F09-94BB-9F90EF29D7EB}] => (Allow) C:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{2A95D321-66A4-4E56-AF4B-5B45515B5335}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alan Wake\AlanWake.exe No File
FirewallRules: [{188F6E2E-8A5B-4EDB-BB95-DEE071026A99}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alan Wake\AlanWake.exe No File
FirewallRules: [{BC2198CF-F58B-417C-AB36-3F61B09FB61E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8D82FA1A-A146-4272-9F5B-C5B36019D936}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{56D45FB2-91E6-4FB7-99E5-77CC3F74C338}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe () [File not signed]
FirewallRules: [{2875CEA6-1A6B-44D1-8F30-EBE1E01062E1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe () [File not signed]
FirewallRules: [TCP Query User{4917E636-7D06-41FD-8533-5404D48A47E1}C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe] => (Allow) C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe (Phoenix Labs -> Phoenix Labs)
FirewallRules: [UDP Query User{9BD7052E-3BF6-475C-87EB-028DB1487797}C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe] => (Allow) C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe (Phoenix Labs -> Phoenix Labs)
FirewallRules: [TCP Query User{000B4821-E27A-423A-A2BE-985653130CEC}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [UDP Query User{411E6683-1433-47F0-8503-93F164167388}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [{5E44AAC1-EE7A-4916-9A4E-8AEF4556D61D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5171F884-236E-43C6-A707-FF09451739E6}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{E6E69058-2D38-45D7-834C-7401FF0EC505}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe () [File not signed]
FirewallRules: [{6DC35D5D-6DA7-4B30-83A5-CE0D80B9E568}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe () [File not signed]
FirewallRules: [{0DE95936-2723-4D63-8FD0-BA92507FFD9A}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe () [File not signed]
FirewallRules: [{15999344-A2AA-4561-9E13-3AA2AF6F29DD}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe () [File not signed]
FirewallRules: [{9346FA6F-421C-42F7-AB99-5A48F9171945}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe () [File not signed]
FirewallRules: [{F01C84E7-CBB6-400A-9183-02F53C744F1C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe No File
FirewallRules: [{9D0A1C8A-4DFE-45E0-A50C-E25879423B4A}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\OxygenPanelDaemon.exe No File
FirewallRules: [{10D314F3-B88D-4402-B028-1B1A286BA038}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DPDecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{69D13C4D-495C-428D-9874-EC75AD9778D7}] => (Allow) C:\ProgramData\Blackmagic Design\DaVinci Resolve\Support\QtDecoder\QTDecoder.exe No File
FirewallRules: [TCP Query User{5E419FAA-AF43-4F55-A3C4-0F3724FE90BF}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty. Ltd.) [File not signed]
FirewallRules: [UDP Query User{4A10943A-912F-4BDB-8DE9-63847AA072B1}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty. Ltd.) [File not signed]
FirewallRules: [TCP Query User{032D82B7-EF25-4785-963A-F8E75D125A89}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{93198204-5E41-4B68-AB18-9CF5F0D3994E}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [{B0ACB74F-7E77-42DD-98B9-4AA3DBDF481E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8277AC0B-3734-4B56-8AC5-BB5F40D0B93F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{6A74A575-1142-4777-BB6C-9AF4B8AFC7C9}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{EA67E5DF-8299-450B-84C1-AF802314D9F5}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [{D721A274-8454-42BD-9A3F-2FA1674FBD56}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{69C3820F-E1F1-405F-82E1-A3AEA78ED024}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2463FF76-1F92-42F9-BF80-524149A2E97D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{F3EE1434-034A-459D-A5BE-14C746720EB5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E489F6C2-2F42-4E5A-9362-556A05FE68EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{3B4286C8-3725-4AFF-A825-8C9DADF61CB7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{8DC007D8-7E55-4C55-A932-003715013E01}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{092F635E-34FA-4792-9F4F-84825A47B075}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{23143A09-F11A-4E34-A967-AF548264026C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{AA4AFF4A-4BD0-4A2E-89B5-6E52C4B749A9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A7A3A1C0-05E0-4657-86C6-AE915C795B05}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E917715A-3C66-484F-9E58-A45244A7DA20}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{CD89FAE0-DBA3-4509-9F34-8F3E72444AF0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FE9F6753-D516-4AAB-9CE1-043A6CE06D2B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{638CDB27-8527-464C-916C-1FC2C8D013AB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
 
==================== Restore Points =========================
 
20-07-2019 15:07:21 Punto de control programado
30-07-2019 20:35:10 Punto de control programado
 
==================== Faulty Device Manager Devices =============
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/04/2019 04:19:42 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/04/2019 04:19:14 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=TimerEvent
 
Error: (08/03/2019 01:08:05 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/03/2019 01:07:57 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (08/02/2019 03:06:09 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/02/2019 03:06:01 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=TimerEvent
 
Error: (07/31/2019 03:59:34 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (07/31/2019 03:59:26 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
 
System errors:
=============
Error: (08/04/2019 10:03:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 10:01:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 09:59:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 09:57:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 09:55:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 09:53:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {E48EDA45-43C6-48E0-9323-A7B2067D9CD5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 09:51:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/04/2019 09:49:22 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
 
Windows Defender:
===================================
Date: 2019-08-04 21:26:07.363
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {1A895F26-A4A9-4D4B-B8EA-0268E00ED617}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-04 19:26:56.395
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {58A28F52-BC8A-4021-B24F-DA6543D23F43}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-02 15:20:15.918
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {BD190ADD-B41A-4C9B-A9E4-BD4E400A01B0}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-02 15:04:57.784
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {5D7C8D14-0A85-404D-9441-22A5CA1F48C7}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-07-31 20:39:52.614
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {CE55CA55-C17D-486C-B14C-7E5BF6C46201}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-06-22 15:23:30.095
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.295.1256.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16000.6
Código de error: 0x80240016
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulta Ayuda y soporte técnico. 
 
Date: 2019-06-15 17:13:51.052
Description: 
Antivirus de Windows Defender encontró un error al intentar actualizar las firmas.
Nueva versión de firma: 
Versión de firma anterior: 1.295.787.0
Origen de actualización: Servidor de Microsoft Update
Tipo de firma: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión de motor actual: 
Versión de motor anterior: 1.1.16000.6
Código de error: 0x80240016
Descripción del error: Se produjo un problema inesperado mientras se buscaban actualizaciones. Para obtener más información sobre cómo instalar o solucionar problemas en las actualizaciones, consulta Ayuda y soporte técnico. 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 4011 04/19/2018
Motherboard: ASUSTeK COMPUTER INC. PRIME B350M-A
Processor: AMD Ryzen 7 1700 Eight-Core Processor 
Percentage of memory in use: 54%
Total physical RAM: 8124 MB
Available physical RAM: 3687.33 MB
Total Virtual: 10940 MB
Available Virtual: 4709.23 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.91 GB) (Free:322.96 GB) NTFS
 
\\?\Volume{232ffcd7-c3e0-4d2a-87fa-f0a4133550f4}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.1 GB) NTFS
\\?\Volume{48d798ba-c390-4088-a209-866139d7c711}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: EA3C124C)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
 
 
 
 
 
 
 
 

 


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Did you install LogMeIn?  If not uninstall it.

 

In Chrome, go to chrome://extensions/

 

Turn off all but the Chrome Apps by moving the blue spot to the left.  Delete the one called

Hola Free VPN Proxy Unblocker

 

Now Go to

chrome://settings/

 

Find:

On Startup

 Click on

Open The New Tab Page.

 

Find:

Search engine
Search engine used in the address bar - change to Google

 

Click on Manage search engines

For each search engine except Google under Default Search Engines, click on the three bars and select Remove From List.

 

 

 

Scroll to the bottom and click on Advanced.

 

Now scroll to where it says System and turn off

 

Continue running background apps when Google Chrome is closed
 

Under

Privacy and security

 

turn off:

 

Preload pages for faster browsing and searching

 

That should cut down the number of Chrome.exe programs running.  Restart Chrome so that the changes take effect.

 

I see one other sign of infection so let's run a fixlist to remove it:

 

 

Download the attached fixlist.txt to the same location as FRST

Attached File  fixlist.txt   5.48KB   241 downloads

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.

 

If things have improved, go back into  chrome://extensions/ and turn on about 1/2 of the things you turned off, restart Chrome and check to see if the problem returns.  If not try the rest.

 

 

 

 

 

 

 


  • 0

#3
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Did you install LogMeIn?  If not uninstall it.

 

In Chrome, go to chrome://extensions/

 

Turn off all but the Chrome Apps by moving the blue spot to the left.  Delete the one called

Hola Free VPN Proxy Unblocker

 

Now Go to

chrome://settings/

 

Find:

On Startup

 Click on

Open The New Tab Page.

 

Find:

Search engine
Search engine used in the address bar - change to Google

 

Click on Manage search engines

For each search engine except Google under Default Search Engines, click on the three bars and select Remove From List.

 

 

 

Scroll to the bottom and click on Advanced.

 

Now scroll to where it says System and turn off

 

Continue running background apps when Google Chrome is closed
 

Under

Privacy and security

 

turn off:

 

Preload pages for faster browsing and searching

 

That should cut down the number of Chrome.exe programs running.  Restart Chrome so that the changes take effect.

 

I see one other sign of infection so let's run a fixlist to remove it:

 

 

Download the attached fixlist.txt to the same location as FRST

.send(a))}}},s=function(){var b={},d=document.getElementsByTagName("IMG");if(0==d.length)return{};var a=d[0];if(!("naturalWidth"in a&&"naturalHeight"in a))return{};for(var c= 0;a=d[c];++c){var e=a.getAttribute("pagespeed_url_hash");e&&(!(e in b)&&0=b[e].k&&a.height>=b[e].j)&&(b[e]={rw:a.width,rh:a.height,ow:a.naturalWidth,oh:a.naturalHeight})}return b},t="";h("pagespeed.CriticalImages.getBeaconData",function(){return t});h("pagespeed.CriticalImages.Run",function(b,d,a,c,e,f){var k=new p(b,d,a,e,f);n=k;c&&m(function(){window.setTimeout(function(){r(k)},0)})});})(); pagespeed.CriticalImages.Run('/mod_pagespeed_beacon','http://www.geekstogo.com/forum/index.php?s=9769a852f51c0c893aa574a3f8a9b0f2&app=forums&module=ajax§ion=topics&do=quote&t=373542&p=2639735&md5check=8c67515ccad2456205527671ea1ba586&isRte=1,mKmPV3o1Px,true,true,r_El5qt1siQ');//]]></script>

Run FRST and press Fix
A fix log will be generated please post that

Reboot if the fix doesn't reboot it for you

Run FRST again as before.  Make sure Addition.txt is checked and hit Scan.  Post both logs.&&0

 

If things have improved, go back into  chrome://extensions/ and turn on about 1/2 of the things you turned off, restart Chrome and check to see if the problem returns.  If not try the rest.

 

 

 

 

 

 

 

Thanks for the help again.

The thing is that when I play games (for which my PC is supposedly built for) I always get a bad performance. When I started looking, I realized that the disk at the task manager was constantly working at 100%. Even when I closed the game in frustration, the disk still maxed out making everything slower for some time. I naturaly thought that the disk was the cause of the poor performance. That is the reason why I made the post. If you think of anything that could cause this, I'm all ears. 

 

 

Here are the .txt:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-08-2019
Ran by Matoke (administrator) on DESKTOP-4LAFI5B (05-08-2019 22:43:41)
Running from C:\Users\amd\Downloads
Loaded Profiles: Matoke (Available Profiles: Matoke & Otros)
Platform: Windows 10 Pro Version 1803 17134.885 (X64) Language: Español (México)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.50.38.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(alch) [File not signed] C:\Program Files (x86)\ClamWin\bin\ClamTray.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google) C:\Users\amd\AppData\Local\Google\Chrome\User Data\SwReporter\43.210.200.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\amd\AppData\Local\Google\Chrome\User Data\SwReporter\43.210.200.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\amd\AppData\Local\Google\Chrome\User Data\SwReporter\43.210.200.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\amd\AppData\Local\Google\Chrome\User Data\SwReporter\43.210.200.3\software_reporter_tool.exe
(GoPro Media, Inc. -> ) C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) [File not signed] C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.50.38.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.17134.881_none_eada7c8e1d8131a8\TiWorker.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\NisSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [598200 2018-09-28] (Razer USA Ltd. -> Razer Inc.)
HKLM-x32\...\Run: [ClamWin] => C:\Program Files (x86)\ClamWin\bin\ClamTray.exe [86016 2018-03-03] (alch) [File not signed]
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2622520 2019-05-19] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3148576 2019-06-17] (Valve -> Valve Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Discord] => C:\Users\amd\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35809680 2019-08-05] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [18666984 2018-12-14] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe [23913464 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [53646912 2019-06-20] (Skype Software Sarl -> Skype Technologies S.A.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\75.0.3770.142\Installer\chrmstp.exe [2019-07-16] (Google LLC -> Google LLC)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00F4F76B-A514-46C8-9041-AC8F1F0C5C9B} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0EB188D4-899C-4085-A2BF-6893B1A7308B} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27351864 2019-07-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {1ED78B5C-3A99-4E5F-8E27-F003DF678504} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-23] (Google Inc -> Google Inc.)
Task: {2F50A520-DCAC-4D6B-9269-3CFDD60B7573} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1447064 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {40FA51BE-AEAA-4CA1-B73B-97530A85869B} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {430F00B1-AB5F-40E8-9870-BC01732DFEBB} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1447064 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {4599A762-E0B5-4246-8CDF-74B64E7AA6EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {485416D2-BC05-48E7-9A3D-3B9FFCE7BBBC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-23] (Google Inc -> Google Inc.)
Task: {4D328107-ED1C-4530-BD4C-F433198AC403} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1830811996-1437030023-4132568959-1004 => C:\Users\amd\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {59483DF7-535D-4BAB-8FCB-CC65784B66EF} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [114736 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {61D39848-674B-46A5-8268-3445EA823DBA} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4519576 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {6635DC11-B66B-4F5C-9FDA-6C665A941ED1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6DE9B58E-2767-484C-AFDE-10FC1F0EE760} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6F4F7FCB-0456-45E7-B3E9-CF8B9A376106} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4519576 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487F195-19CA-48A1-9358-C9DF5F516FF4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9E89DC01-5E7B-401E-B422-E5CEE8BCE7E3} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27351864 2019-07-26] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF137F09-55AC-49AD-A05A-EC79B4F65130} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B82B48CC-E9E4-480D-A8AC-DB6FADE86FAE} - System32\Tasks\AdobeGCInvoker-1.0-DESKTOP-4LAFI5B-Matoke => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {BEC3D44E-57AF-4C07-8783-0D41C08FE14E} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C1219263-DB86-48BC-A6CF-AD87E24D39D7} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [114736 2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF526D79-AAE9-456A-A1DA-8DF6F79EB36F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CF7A22FF-51C6-4EFE-9E03-A8EFE14BF099} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D1957C35-1B5A-483C-9745-24693D6FBF4A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D4D624E7-4B22-4A16-B776-874A63CCFFE6} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3788144 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D55632DC-FAF3-4AD6-A362-6BE33B0A7831} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D5C93072-60ED-4351-9C65-BC314006E5C5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2047368 2019-07-30] (AVAST Software s.r.o. -> AVAST Software)
Task: {F49AE5A7-D544-43AF-A12C-20339E432107} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{54e2108c-8637-4bb9-95c6-a60275ec1987}: [DhcpNameServer] 208.67.220.220 208.67.222.222
Tcpip\..\Interfaces\{641c23af-61d5-46a6-a811-c61f189b2b88}: [NameServer] 8.8.8.8,8.8.4.4
ManualProxies: 
 
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR DefaultSearchURL: Default -> hxxps://defaultsearch.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> Adaware Secure
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default [2019-08-05]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-08-05]
CHR Extension: (Chrome Media Router) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-05]
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-02-23]
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\System Profile [2019-02-23]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [816184 2019-05-19] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3117648 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2888272 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-03-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11469920 2019-07-26] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-12-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 GoProDeviceDetectionService; C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe [38328 2018-04-26] (GoPro Media, Inc. -> )
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2247144 2018-12-14] (Plex, Inc -> Plex, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5073792 2019-07-04] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11660528 2018-12-07] (TeamViewer GmbH -> TeamViewer GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 Ds3Service; "C:\Users\amd\Desktop\Driver ps3\Drivers PS3 By Haniel\ScpServer\bin\ScpService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [34696 2018-05-11] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33144 2018-05-11] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [31592 2018-04-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [137104 2018-05-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-05-13] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-05-13] (Disc Soft Ltd -> Disc Soft Ltd)
R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvpcdi.inf_amd64_400a42b4e8d4c1e9\nvlddmkm.sys [21854352 2019-07-04] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-06-13] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [75600 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation -> Corel Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [680416 2018-10-24] (Realtek Semiconductor Corp. -> Realtek )
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5707264 2018-04-11] (Microsoft Windows -> Realtek Semiconductor Corporation )
R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [51728 2016-08-05] (Razer USA Ltd. -> Razer Inc)
R3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [43536 2016-08-05] (Razer USA Ltd. -> Razer Inc)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [344288 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-05 22:33 - 2019-08-05 22:35 - 000005705 _____ C:\Users\amd\Downloads\Fixlog.txt
2019-08-05 19:52 - 2019-08-05 19:52 - 003997227 _____ C:\Users\amd\Downloads\Historia del cine 2 - 2019 - completo - resumen (3).pdf
2019-08-04 21:58 - 2019-08-05 22:33 - 000000000 ____D C:\Users\amd\Downloads\FRST-OlderVersion
2019-08-02 15:17 - 2019-08-02 15:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Herramientas de Microsoft Office
2019-08-02 15:16 - 2019-08-05 22:40 - 000212992 _____ C:\WINDOWS\system32\ClickToRun_Pipeline16
2019-07-31 19:38 - 2019-07-31 19:38 - 001028376 _____ C:\Users\amd\Downloads\Blockhouse.zip
2019-07-31 18:39 - 2019-07-31 18:39 - 000000000 ____D C:\Users\amd\AppData\Roaming\NVIDIA
2019-07-30 16:26 - 2019-07-30 16:26 - 000124674 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-06-25 at 1.19.28 PM (1).jpeg
2019-07-30 16:26 - 2019-07-30 16:26 - 000104282 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-06-25 at 1.19.29 PM (1).jpeg
2019-07-29 16:07 - 2019-07-29 16:07 - 000000000 ____D C:\Users\amd\Documents\This War of Mine
2019-07-29 16:07 - 2019-07-29 16:07 - 000000000 ____D C:\Users\amd\AppData\Roaming\11bitstudios
2019-07-29 14:53 - 2019-07-29 14:53 - 000000000 ____D C:\Users\amd\Desktop\CKScanner
2019-07-29 14:46 - 2019-07-29 14:46 - 000004443 _____ C:\Users\amd\Downloads\ckfiles.txt
2019-07-24 23:46 - 2019-08-04 22:03 - 000057086 _____ C:\Users\amd\Downloads\Addition.txt
2019-07-24 23:42 - 2019-08-05 22:45 - 000027389 _____ C:\Users\amd\Downloads\FRST.txt
2019-07-24 23:42 - 2019-08-05 22:33 - 002096640 _____ (Farbar) C:\Users\amd\Downloads\FRST64.exe
2019-07-24 22:58 - 2019-07-29 14:53 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2019-07-24 22:57 - 2019-07-24 22:58 - 047441489 _____ C:\Users\amd\Downloads\MSIAfterburnerSetup.zip
2019-07-24 22:50 - 2019-07-24 22:50 - 000001447 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2019-07-24 22:45 - 2019-07-03 06:10 - 005435376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 002637168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 001767464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000651248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000450416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000124784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-07-24 22:45 - 2019-07-03 06:10 - 000082984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-07-24 22:45 - 2019-07-03 06:09 - 008628422 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-07-24 22:45 - 2019-03-06 01:33 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-07-24 22:42 - 2019-07-24 22:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2019-07-24 22:33 - 2019-07-24 22:37 - 123477920 _____ (NVIDIA Corporation New) C:\Users\amd\Downloads\GeForce_Experience_v3.19.0.107.exe
2019-07-24 21:22 - 2019-07-23 15:19 - 000000000 ____D C:\Users\amd\Desktop\MAINCRENZIE
2019-07-24 20:48 - 2019-07-24 20:49 - 250287771 _____ C:\Users\amd\Downloads\MAINCRENZIE.rar
2019-07-24 19:55 - 2019-07-24 19:55 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2019-07-24 19:46 - 2019-07-24 19:46 - 005193376 _____ (Husdawg, LLC) C:\Users\amd\Downloads\Detection (2).exe
2019-07-21 12:39 - 2019-07-21 12:39 - 000000000 ____D C:\Users\amd\AppData\LocalLow\Oracle
2019-07-13 19:18 - 2019-07-04 15:07 - 005085096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-07-13 19:18 - 2019-07-04 15:07 - 004340664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 001006792 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 001006792 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000870088 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000870088 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000552136 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000456448 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-07-13 19:18 - 2019-07-04 12:13 - 000286408 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-07-13 19:18 - 2019-07-04 12:13 - 000286408 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-07-13 19:18 - 2019-07-04 12:13 - 000260296 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-07-13 19:18 - 2019-07-04 12:13 - 000260296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-07-13 19:18 - 2019-07-04 12:12 - 011059128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-07-13 19:18 - 2019-07-04 12:12 - 009492224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 020190592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 005422464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 004759240 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 002040192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001722056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443136.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001542016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001470904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001467832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443136.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001162168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 001134464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000912072 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000821176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000808832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000675224 _____ C:\WINDOWS\system32\nvofapi64.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000654720 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000631712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000542296 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2019-07-13 19:18 - 2019-07-04 12:11 - 000521872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-07-13 19:18 - 2019-07-04 12:10 - 040412360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-07-13 19:18 - 2019-07-04 12:10 - 035270016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-07-13 19:18 - 2019-07-04 12:10 - 017467592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-07-13 19:18 - 2019-07-03 10:56 - 000052446 _____ C:\WINDOWS\system32\nvinfo.pb
2019-07-10 15:40 - 2019-07-10 15:40 - 011150138 _____ C:\Users\amd\Downloads\Barthes, R. - La cámara lúcida.pdf
2019-07-09 19:26 - 2019-07-04 01:56 - 007519896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-07-09 19:26 - 2019-07-04 01:42 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-07-09 19:26 - 2019-07-04 01:37 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-07-09 19:26 - 2019-07-04 01:29 - 022717440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-07-09 19:25 - 2019-07-04 06:45 - 001786680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-07-09 19:25 - 2019-07-04 06:43 - 000094008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2019-07-09 19:25 - 2019-07-04 06:41 - 000304144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-07-09 19:25 - 2019-07-04 06:40 - 021390504 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-07-09 19:25 - 2019-07-04 06:40 - 001631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-07-09 19:25 - 2019-07-04 06:40 - 001616840 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-07-09 19:25 - 2019-07-04 06:40 - 000790416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-07-09 19:25 - 2019-07-04 06:22 - 000131072 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-07-09 19:25 - 2019-07-04 06:22 - 000128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2019-07-09 19:25 - 2019-07-04 06:21 - 008627200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-07-09 19:25 - 2019-07-04 06:20 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2019-07-09 19:25 - 2019-07-04 06:19 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpclip.exe
2019-07-09 19:25 - 2019-07-04 06:18 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-07-09 19:25 - 2019-07-04 06:18 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-07-09 19:25 - 2019-07-04 05:56 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-07-09 19:25 - 2019-07-04 05:54 - 000662352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-07-09 19:25 - 2019-07-04 05:51 - 020384128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-07-09 19:25 - 2019-07-04 05:41 - 007990784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-07-09 19:25 - 2019-07-04 05:37 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-07-09 19:25 - 2019-07-04 05:36 - 001471488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-07-09 19:25 - 2019-07-04 02:00 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-07-09 19:25 - 2019-07-04 01:58 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-07-09 19:25 - 2019-07-04 01:58 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-07-09 19:25 - 2019-07-04 01:58 - 000416312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2019-07-09 19:25 - 2019-07-04 01:58 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-07-09 19:25 - 2019-07-04 01:57 - 003292152 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000986128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000776784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000723728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000708696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-07-09 19:25 - 2019-07-04 01:57 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000362264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000209424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-07-09 19:25 - 2019-07-04 01:57 - 000194360 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000137656 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-07-09 19:25 - 2019-07-04 01:57 - 000091776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-07-09 19:25 - 2019-07-04 01:56 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 007436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-07-09 19:25 - 2019-07-04 01:56 - 002571640 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 001566520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 001459120 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-07-09 19:25 - 2019-07-04 01:56 - 001260776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 001141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-07-09 19:25 - 2019-07-04 01:56 - 000983936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 000767536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000734952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000713272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000604984 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-07-09 19:25 - 2019-07-04 01:56 - 000493752 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-07-09 19:25 - 2019-07-04 01:56 - 000115512 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000832016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2019-07-09 19:25 - 2019-07-04 01:43 - 000665440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000328696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000287376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2019-07-09 19:25 - 2019-07-04 01:43 - 000191800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-07-09 19:25 - 2019-07-04 01:42 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 002479176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 001980984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 000356312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-07-09 19:25 - 2019-07-04 01:42 - 000097272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2019-07-09 19:25 - 2019-07-04 01:41 - 000559328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2019-07-09 19:25 - 2019-07-04 01:33 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-07-09 19:25 - 2019-07-04 01:26 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-07-09 19:25 - 2019-07-04 01:26 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-07-09 19:25 - 2019-07-04 01:26 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 007589888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 003401216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2019-07-09 19:25 - 2019-07-04 01:25 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-07-09 19:25 - 2019-07-04 01:24 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-07-09 19:25 - 2019-07-04 01:24 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-07-09 19:25 - 2019-07-04 01:24 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-07-09 19:25 - 2019-07-04 01:24 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-07-09 19:25 - 2019-07-04 01:23 - 001765888 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-07-09 19:25 - 2019-07-04 01:23 - 001217536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2019-07-09 19:25 - 2019-07-04 01:23 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 003707904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 002587648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 001175552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2019-07-09 19:25 - 2019-07-04 01:22 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 005784064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 003202560 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 002166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-07-09 19:25 - 2019-07-04 01:21 - 001920000 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2019-07-09 19:25 - 2019-07-04 01:21 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 001156608 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-07-09 19:25 - 2019-07-04 01:20 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-07-09 19:25 - 2019-07-04 01:19 - 000886272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-07-09 19:25 - 2019-07-04 01:19 - 000230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 002602496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 001076224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 000953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2019-07-09 19:25 - 2019-07-04 01:18 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-07-09 19:25 - 2019-07-04 01:17 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-07-09 19:25 - 2019-07-04 00:01 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2019-07-09 19:25 - 2019-06-21 05:50 - 000280584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2019-07-09 19:25 - 2019-06-13 09:15 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-07-09 19:25 - 2019-06-13 09:12 - 002871848 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2019-07-09 19:25 - 2019-06-13 09:05 - 000810296 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2019-07-09 19:25 - 2019-06-13 09:04 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-07-09 19:25 - 2019-06-13 09:00 - 000464696 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2019-07-09 19:25 - 2019-06-13 08:59 - 000740664 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2019-07-09 19:25 - 2019-06-13 08:58 - 000637752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2019-07-09 19:25 - 2019-06-13 08:58 - 000071480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-07-09 19:25 - 2019-06-13 08:56 - 000164152 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-07-09 19:25 - 2019-06-13 08:43 - 001427984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-07-09 19:25 - 2019-06-13 08:43 - 001048480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2019-07-09 19:25 - 2019-06-13 08:42 - 004038688 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-07-09 19:25 - 2019-06-13 08:42 - 002266936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2019-07-09 19:25 - 2019-06-13 08:42 - 000652088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-07-09 19:25 - 2019-06-13 08:42 - 000566536 _____ (Microsoft Corporation) C:\WINDOWS\system32\phoneactivate.exe
2019-07-09 19:25 - 2019-06-13 08:41 - 001626936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-07-09 19:25 - 2019-06-13 08:41 - 000830264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-07-09 19:25 - 2019-06-13 08:41 - 000825144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-07-09 19:25 - 2019-06-13 08:41 - 000670008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-07-09 19:25 - 2019-06-13 08:40 - 000749880 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-07-09 19:25 - 2019-06-13 08:40 - 000540984 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2019-07-09 19:25 - 2019-06-13 08:40 - 000495416 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-07-09 19:25 - 2019-06-13 08:38 - 000766264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2019-07-09 19:25 - 2019-06-13 08:37 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\system32\changepk.exe
2019-07-09 19:25 - 2019-06-13 08:36 - 000251000 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2019-07-09 19:25 - 2019-06-13 08:36 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2019-07-09 19:25 - 2019-06-13 08:35 - 001376688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2019-07-09 19:25 - 2019-06-13 08:34 - 000146888 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingUI.exe
2019-07-09 19:25 - 2019-06-13 08:18 - 006586880 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-07-09 19:25 - 2019-06-13 08:18 - 004847104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 012756992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2019-07-09 19:25 - 2019-06-13 08:17 - 000109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2019-07-09 19:25 - 2019-06-13 08:17 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2019-07-09 19:25 - 2019-06-13 08:16 - 000767488 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcommdlg.dll
2019-07-09 19:25 - 2019-06-13 08:15 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-07-09 19:25 - 2019-06-13 08:15 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpgradeResultsUI.exe
2019-07-09 19:25 - 2019-06-13 08:14 - 001127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2019-07-09 19:25 - 2019-06-13 08:14 - 000900096 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe
2019-07-09 19:25 - 2019-06-13 08:14 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2019-07-09 19:25 - 2019-06-13 08:14 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\DesktopSwitcherDataModel.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 002920448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 001339392 _____ (Microsoft Corporation) C:\WINDOWS\system32\TaskFlowDataEngine.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2019-07-09 19:25 - 2019-06-13 08:13 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2019-07-09 19:25 - 2019-06-13 08:12 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2019-07-09 19:25 - 2019-06-13 08:10 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2019-07-09 19:25 - 2019-06-13 07:11 - 001539896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2019-07-09 19:25 - 2019-06-13 07:07 - 001027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2019-07-09 19:25 - 2019-06-13 07:07 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2019-07-09 19:25 - 2019-06-13 07:07 - 000221232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2019-07-09 19:25 - 2019-06-13 07:05 - 003700160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-07-09 19:25 - 2019-06-13 06:55 - 005657088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-07-09 19:25 - 2019-06-13 06:54 - 011942912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-07-09 19:25 - 2019-06-13 06:54 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2019-07-09 19:25 - 2019-06-13 06:53 - 000089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2019-07-09 19:25 - 2019-06-13 06:51 - 000622080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2019-07-09 19:25 - 2019-06-13 06:50 - 000896512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2019-07-09 19:25 - 2019-06-13 06:49 - 002406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2019-07-09 19:25 - 2019-06-13 06:49 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2019-07-09 19:25 - 2019-06-13 04:48 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2019-07-09 19:25 - 2019-06-13 04:46 - 000713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedRealitySvc.dll
2019-07-09 19:25 - 2019-06-13 04:01 - 000513336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2019-07-09 19:25 - 2019-06-13 04:01 - 000511288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2019-07-09 19:25 - 2019-06-13 04:01 - 000036152 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-07-09 19:25 - 2019-06-13 03:59 - 000785264 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-07-09 19:25 - 2019-06-13 03:47 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-07-09 19:25 - 2019-06-13 03:47 - 001063224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2019-07-09 19:25 - 2019-06-13 03:46 - 001076536 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2019-07-09 19:25 - 2019-06-13 03:46 - 000510296 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-07-09 19:25 - 2019-06-13 03:46 - 000093984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-07-09 19:25 - 2019-06-13 03:45 - 002421560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-07-09 19:25 - 2019-06-13 03:44 - 002769688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 002546704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 001098272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 001033696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 000607112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 000545808 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-07-09 19:25 - 2019-06-13 03:44 - 000130624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-07-09 19:25 - 2019-06-13 03:17 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-07-09 19:25 - 2019-06-13 03:16 - 001626112 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-07-09 19:25 - 2019-06-13 03:16 - 000140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-07-09 19:25 - 2019-06-13 03:15 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2019-07-09 19:25 - 2019-06-13 03:15 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-07-09 19:25 - 2019-06-13 03:15 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-07-09 19:25 - 2019-06-13 03:15 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2019-07-09 19:25 - 2019-06-13 03:15 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\KdsCli.dll
2019-07-09 19:25 - 2019-06-13 03:14 - 003318784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-07-09 19:25 - 2019-06-13 03:14 - 000409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2019-07-09 19:25 - 2019-06-13 03:14 - 000361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-07-09 19:25 - 2019-06-13 03:14 - 000302080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CXHProvisioningServer.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 004771840 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 002370048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 000761344 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2019-07-09 19:25 - 2019-06-13 03:13 - 000322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-07-09 19:25 - 2019-06-13 03:13 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-07-09 19:25 - 2019-06-13 03:12 - 000501248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2019-07-09 19:25 - 2019-06-13 03:11 - 000508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-07-09 19:25 - 2019-06-13 03:11 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2019-07-09 19:25 - 2019-06-13 03:11 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 001215488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 03:10 - 000523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-07-09 19:25 - 2019-06-13 03:09 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-07-09 19:25 - 2019-06-13 03:09 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-07-09 19:25 - 2019-06-13 03:09 - 000755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2019-07-09 19:25 - 2019-06-13 03:08 - 000506368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2019-07-09 19:25 - 2019-06-13 02:14 - 000415544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2019-07-09 19:25 - 2019-06-13 02:08 - 000443632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-07-09 19:25 - 2019-06-13 02:07 - 000101192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-07-09 19:25 - 2019-06-13 02:07 - 000080744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-07-09 19:25 - 2019-06-13 02:06 - 002256768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-07-09 19:25 - 2019-06-13 02:06 - 001130776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-07-09 19:25 - 2019-06-13 02:06 - 000581600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll
2019-07-09 19:25 - 2019-06-13 01:49 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-07-09 19:25 - 2019-06-13 01:47 - 003554304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2019-07-09 19:25 - 2019-06-13 01:47 - 002899456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2019-07-09 19:25 - 2019-06-13 01:47 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2019-07-09 19:25 - 2019-06-13 01:46 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-07-09 19:25 - 2019-06-13 01:46 - 000331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2019-07-09 19:25 - 2019-06-13 01:46 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2019-07-09 19:25 - 2019-06-13 01:45 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2019-07-09 19:25 - 2019-06-13 01:45 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2019-07-09 19:25 - 2019-06-13 01:44 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2019-07-09 19:25 - 2019-06-13 01:43 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-07-09 19:25 - 2019-06-13 01:43 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2019-07-09 19:25 - 2019-06-13 01:43 - 000445952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-07-08 18:21 - 2019-07-08 18:21 - 000046911 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-03 at 8.48.35 PM (1).jpeg
2019-07-08 16:53 - 2019-07-08 16:53 - 000085744 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-03 at 8.57.01 PM.jpeg
2019-07-08 16:53 - 2019-07-08 16:53 - 000046911 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-07-03 at 8.48.35 PM.jpeg
2019-07-08 16:52 - 2019-07-08 16:52 - 000000000 ____D C:\Users\amd\AppData\Local\PackageStaging
2019-07-07 19:10 - 2019-07-07 19:10 - 000001383 _____ C:\Users\Public\Desktop\Skype.lnk
2019-07-07 19:10 - 2019-07-07 19:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2019-07-07 19:08 - 2019-07-07 19:09 - 063471184 _____ (Skype Technologies S.A.) C:\Users\amd\Downloads\Skype-8.48.0.51.exe
2019-07-07 19:02 - 2019-07-07 19:10 - 000000000 ____D C:\Users\amd\AppData\Roaming\Skype
2019-07-07 17:18 - 2019-07-07 17:18 - 000000759 _____ C:\Users\amd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programas y características - Acceso directo.lnk
2019-07-07 15:55 - 2019-07-21 12:41 - 000110064 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2019-07-07 15:55 - 2019-07-21 12:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2019-07-07 15:55 - 2019-07-21 12:41 - 000000000 ____D C:\Program Files\Java
2019-07-07 15:55 - 2019-07-07 15:55 - 000000000 ____D C:\Users\amd\AppData\Roaming\Sun
2019-07-07 15:50 - 2019-07-07 15:51 - 079721824 _____ (Oracle Corporation) C:\Users\amd\Downloads\jre-8u211-windows-x64.exe
2019-07-07 15:47 - 2019-07-07 15:47 - 002043232 _____ (Oracle Corporation) C:\Users\amd\Downloads\jre-8u211-windows-i586-iftw.exe
2019-07-07 15:41 - 2019-07-07 15:41 - 002260992 _____ C:\Users\amd\Downloads\MinecraftInstaller (3).msi
2019-07-07 15:40 - 2019-07-07 15:40 - 001340256 _____ C:\Users\amd\Downloads\Minecraft.dmg
2019-07-07 15:39 - 2019-07-07 15:39 - 002260992 _____ C:\Users\amd\Downloads\MinecraftInstaller (2).msi
2019-07-07 15:30 - 2019-07-07 15:30 - 002043232 _____ (Oracle Corporation) C:\Users\amd\Downloads\JavaSetup8u211 (1).exe
2019-07-06 00:56 - 2019-07-24 22:45 - 000000000 ____D C:\Users\amd\AppData\Local\LogMeIn Hamachi
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-05 22:43 - 2018-07-24 15:06 - 000000000 ____D C:\FRST
2019-08-05 22:43 - 2018-05-10 16:18 - 000000000 ____D C:\ProgramData\NVIDIA
2019-08-05 22:41 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-08-05 22:40 - 2018-12-19 18:02 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-08-05 22:40 - 2018-06-10 20:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-08-05 22:40 - 2018-04-11 20:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-08-05 22:39 - 2018-04-11 18:04 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2019-08-05 22:22 - 2018-06-10 20:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-08-05 21:30 - 2018-04-11 20:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-05 19:57 - 2018-05-10 15:33 - 000000000 ____D C:\Users\amd\AppData\Local\Packages
2019-08-04 19:29 - 2019-03-13 21:44 - 000000000 ____D C:\Users\amd\Documents\Remedy
2019-08-03 01:17 - 2018-05-14 20:23 - 000000000 ____D C:\Program Files\Epic Games
2019-08-03 01:06 - 2018-06-10 20:03 - 005101640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-08-02 15:17 - 2019-06-30 15:46 - 000002580 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Empresarial.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002531 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002512 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002485 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-08-02 15:17 - 2019-06-30 15:46 - 000002439 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-08-02 15:16 - 2018-05-13 22:05 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-08-02 15:10 - 2018-11-17 00:38 - 000000000 ____D C:\Program Files\rempl
2019-07-31 21:00 - 2018-05-14 20:36 - 000000000 ____D C:\Users\amd\Desktop\MIS COSAS
2019-07-31 18:45 - 2018-06-10 20:24 - 000000000 ____D C:\Users\amd\AppData\Local\D3DSCache
2019-07-31 18:38 - 2018-05-10 16:19 - 000000000 ____D C:\Users\amd\AppData\Local\NVIDIA
2019-07-30 18:52 - 2018-07-20 02:36 - 000000000 ____D C:\Users\amd\AppData\Local\CrashDumps
2019-07-30 15:44 - 2018-06-10 20:07 - 000000000 ___HD C:\Users\amd
2019-07-30 01:59 - 2018-05-16 21:18 - 000000000 ____D C:\Users\amd\AppData\Roaming\vlc
2019-07-26 16:44 - 2018-12-02 20:13 - 000000000 ____D C:\WINDOWS\Minidump
2019-07-26 16:22 - 2018-05-10 18:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-07-24 22:50 - 2018-07-16 21:09 - 000003976 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:50 - 2018-07-16 21:09 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:50 - 2018-05-10 16:16 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-07-16 21:08 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-07-16 21:08 - 000004106 _____ C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-06-10 20:18 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-06-10 20:18 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-05-10 16:17 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-07-24 22:49 - 2018-05-10 16:15 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-07-24 22:49 - 2018-04-11 20:36 - 000000000 ____D C:\WINDOWS\INF
2019-07-24 22:46 - 2018-07-30 02:44 - 000000000 ____D C:\temp
2019-07-24 22:45 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\Help
2019-07-24 21:59 - 2019-05-27 00:47 - 000000000 ____D C:\Users\amd\AppData\Roaming\.minecraft
2019-07-24 21:50 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-07-24 20:50 - 2019-05-27 00:45 - 000000000 ____D C:\Program Files (x86)\Minecraft Launcher
2019-07-23 18:00 - 2018-06-16 23:43 - 000000000 ____D C:\Users\amd\AppData\Roaming\discord
2019-07-22 13:35 - 2018-06-10 20:18 - 001762872 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-22 13:35 - 2018-04-12 13:21 - 000781218 _____ C:\WINDOWS\system32\perfh00A.dat
2019-07-22 13:35 - 2018-04-12 13:21 - 000152030 _____ C:\WINDOWS\system32\perfc00A.dat
2019-07-16 07:18 - 2019-02-23 16:19 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-07-16 07:18 - 2019-02-23 16:19 - 000002258 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-07-13 18:03 - 2019-04-21 03:53 - 000000000 ____D C:\Users\amd\AppData\Local\Ubisoft Game Launcher
2019-07-11 08:25 - 2018-05-10 15:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-07-11 08:25 - 2018-05-10 15:33 - 000000000 ___RD C:\Users\amd\3D Objects
2019-07-11 08:20 - 2018-04-12 13:26 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-07-11 08:20 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-07-11 08:20 - 2018-04-11 18:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-07-09 19:39 - 2018-04-11 20:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-07-09 19:12 - 2018-05-10 17:44 - 000741432 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-07-07 19:10 - 2018-05-10 16:19 - 000000000 ____D C:\Users\amd\AppData\Local\PlaceholderTileLogoFolder
 
==================== Files in the root of some directories ================
 
2019-06-20 23:11 - 2019-06-20 23:11 - 000000000 _____ () C:\Users\amd\AppData\Local\oobelibMkey.log
2018-08-09 20:09 - 2018-08-16 23:40 - 000007620 _____ () C:\Users\amd\AppData\Local\Resmon.ResmonCfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-08-2019
Ran by Matoke (05-08-2019 22:47:18)
Running from C:\Users\amd\Downloads
Windows 10 Pro Version 1803 17134.885 (X64) (2018-06-10 23:19:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrador (S-1-5-21-1830811996-1437030023-4132568959-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1830811996-1437030023-4132568959-503 - Limited - Disabled)
Invitado (S-1-5-21-1830811996-1437030023-4132568959-501 - Limited - Disabled)
matia (S-1-5-21-1830811996-1437030023-4132568959-1002 - Limited - Disabled)
Matoke (S-1-5-21-1830811996-1437030023-4132568959-1001 - Administrator - Enabled) => C:\Users\amd
Otros (S-1-5-21-1830811996-1437030023-4132568959-1004 - Limited - Enabled) => C:\Users\Otros
WDAGUtilityAccount (S-1-5-21-1830811996-1437030023-4132568959-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\uTorrent) (Version: 3.5.5.45271 - BitTorrent Inc.)
Actualización de NVIDIA 37.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 37.0.0.0 - NVIDIA Corporation) Hidden
Adobe After Effects 2019 (HKLM-x32\...\AEFT_16_1_1) (Version: 16.1.1 - Adobe Systems Incorporated)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated)
Adobe Animate CC 2015 (HKLM-x32\...\{8CEBC11D-C52F-11E5-A0D6-D44AB5E81A82}) (Version: 15.1 - Adobe Systems Incorporated)
Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.8.2.476 - Adobe Systems Incorporated)
Adobe Encore CS6 (HKLM-x32\...\{46251F95-B2F8-484A-9B5B-8C0E5A43A202}) (Version: 6.0.0 - Adobe Systems Incorporated)
Adobe Illustrator CC 2015 (HKLM-x32\...\{5680D629-B263-49CC-821E-3CEBD4507B51}) (Version: 19.0 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.0.0 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 17.7 - Advanced Micro Devices, Inc.)
AmericasCardroom (HKLM-x32\...\296836EA-EF3A-4C36-8C13-3A6C1DB2D4BE) (Version: 16.6 - IGSoft)
Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.0.0.4 - Electronic Arts, Inc.)
Balanced (HKLM-x32\...\{EFD0705E-598B-46D4-8D5B-4539431764B8}) (Version: 2.02.0000 - Nombre de su organización) Hidden
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
ClamWin Free Antivirus 0.99.4 (HKLM-x32\...\ClamWin Free Antivirus_is1) (Version:  - alch)
DaVinci Resolve (HKLM\...\{EA907964-FDE2-48E5-A8E4-41F2B4342FA8}) (Version: 16.0.0033 - Blackmagic Design)
DaVinci Resolve Panels (HKLM\...\{B1782967-E600-4BBD-B2F1-AEF3F2FE0A12}) (Version: 1.2.1.0 - Blackmagic Design)
Discord (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
DMMultiView (HKLM-x32\...\{8EEBAD15-F3B7-468B-917F-97BBF6B1004B}) (Version:  - )
Epic Games Launcher (HKLM-x32\...\{79F5479A-BF71-4F4C-9C49-9D616AF923DE}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
GeoVision MJPG (HKLM-x32\...\Codec_MJPG) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 75.0.3770.142 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
GoPro Quik (HKLM\...\{855E73D9-1EC0-4914-98D1-FD1FC7E93870}) (Version: 0.1.780 - GoPro, Inc.) Hidden
GoPro Quik (HKLM-x32\...\{e2b0610c-a7ad-4330-87ba-c30a14ff17e7}) (Version: 2.6.1.780 - GoPro, Inc.)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Java 8 Update 221 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180221F0}) (Version: 8.0.2210.11 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}) (Version: 2.2.0.633 - LogMeIn, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.633 - LogMeIn, Inc.)
Microsoft Office Profesional Plus 2016 - es-es (HKLM\...\ProPlusRetail - es-es) (Version: 16.0.11901.20176 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{ab058666-66d5-445f-bef6-76a4ab200ef1}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{449EFED6-5F86-4428-8EB2-3DA1F6E67CE4}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{E154B2C8-2F3E-4763-B3D5-E7D34AE39C6B}) (Version: 1.0.0.0 - Mojang)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.15 - NVIDIA Corporation) Hidden
NVIDIA Controlador de audio HD 1.3.38.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.16 - NVIDIA Corporation)
NVIDIA Controlador de gráficos 431.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 431.36 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.19.0.107 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.19.0.107 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11901.20176 - Microsoft Corporation) Hidden
Panel de control de NVIDIA 431.36 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 431.36 - NVIDIA Corporation) Hidden
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
Plex Media Server (HKLM-x32\...\{049535F6-B56E-4F73-B5A5-06369B94ED2E}) (Version: 1.14.1488 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{0a25946e-e061-47a7-9da4-d055bb78571d}) (Version: 1.14.1.5488 - Plex, Inc.)
Popcorn-Time (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Popcorn-Time) (Version: 0.3.10 - Popcorn Time)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.)
Skype versión 8.48 (HKLM-x32\...\Skype_is1) (Version: 8.48 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stopping Plex (HKLM-x32\...\{A21C244F-E5E9-498C-90FB-CDBA86BA89CC}) (Version: 1.14.1488 - Plex, Inc.) Hidden
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.1.3399 - TeamViewer)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 85.1 - Ubisoft)
Vegas Pro 13.0 (64-bit) (HKLM\...\{3934F12E-091D-11E4-A0AD-F04DA23A5C58}) (Version: 13.0.373 - Sony)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.7 - VideoLAN)
WinDirStat 1.1.2 (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\WinDirStat) (Version:  - )
WinRAR 5.60 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
 
Packages:
=========
Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11901.20184.0_x64__8wekyb3d8bbwe [2019-08-02] (Microsoft Corporation) [MS Ad]
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.520.0_x64__rz1tebttyb220 [2019-03-13] (Dolby Laboratories)
Extensión de video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2018-10-12] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_100.1.581.0_x64__v10z8vjag6ke6 [2019-07-20] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Noticias -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad]
MSN El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0 [2019-08-02] (Spotify AB)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8999FA35C723} -> [Creative Cloud Files] => C:\Users\amd\Creative Cloud Files [2019-06-20 23:01]
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [ClamWin] -> {65713842-C410-4f44-8383-BFE01A398C90} => C:\Program Files (x86)\ClamWin\bin\ExpShell64.dll [2008-04-19] () [File not signed]
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-07-03] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers6: [ClamWin] -> {65713842-C410-4f44-8383-BFE01A398C90} => C:\Program Files (x86)\ClamWin\bin\ExpShell64.dll [2008-04-19] () [File not signed]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2019-01-17 19:06 - 2005-02-08 17:23 - 000979005 _____ () [File not signed] C:\Program Files (x86)\ClamWin\bin\python23.dll
2019-01-17 19:06 - 2004-05-25 21:17 - 000622651 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_bsddb.pyd
2019-01-17 19:06 - 2004-01-15 14:45 - 000061440 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_ctypes.pyd
2019-01-17 19:06 - 2004-05-25 21:18 - 000049212 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_socket.pyd
2019-01-17 19:06 - 2004-05-25 21:18 - 000057401 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_sre.pyd
2019-01-17 19:06 - 2004-05-25 21:18 - 000495616 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_ssl.pyd
2019-01-17 19:06 - 2004-05-25 21:20 - 000036864 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\_winreg.pyd
2019-01-17 19:06 - 2004-05-25 21:19 - 000045117 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\datetime.pyd
2019-01-17 19:06 - 2003-08-10 09:14 - 000061440 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\mxDateTime.pyd
2019-01-17 19:06 - 2004-10-11 20:22 - 000315392 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\pythoncom23.dll
2019-01-17 19:06 - 2004-10-11 20:21 - 000094208 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\pywintypes23.dll
2019-01-17 19:06 - 2004-11-20 03:27 - 000106496 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\shell.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000069632 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32api.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000024576 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32event.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000077824 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32file.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000086016 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32gui.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000024576 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32pipe.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000036864 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32process.pyd
2019-01-17 19:06 - 2004-11-20 03:27 - 000065536 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\win32security.pyd
2019-01-17 19:06 - 2003-10-01 13:40 - 002240512 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\wxc.pyd
2019-01-17 19:06 - 2003-10-01 11:43 - 003239936 _____ () [File not signed] C:\Program Files (x86)\ClamWin\lib\wxmsw24h.dll
2019-01-17 19:06 - 2018-03-03 22:42 - 000086016 _____ (alch) [File not signed] C:\Program Files (x86)\ClamWin\bin\ClamTray.exe
2019-08-05 22:32 - 2019-08-05 22:43 - 000478720 _____ (ESET) [File not signed] c:\users\amd\appdata\local\google\chrome\user data\swreporter\43.210.200.3\edls_64.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\localhost -> localhost
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-09-29 10:46 - 2019-01-04 18:42 - 000055801 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 mydownloaddomain.com
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 texttotalk.org
127.0.0.1 gambling577.xyz
127.0.0.1 htagdownload.space
127.0.0.1 mybcnmonetize.com
127.0.0.1 360devtraking.website
127.0.0.1 dscdn.pw
127.0.0.1 bcnmonetize.go2affise.com
127.0.0.1 beautifllink.xyz
5.149.252.98 www.google-analytics.com
5.149.252.98 adservice.google.com
 
2018-05-20 17:09 - 2018-05-20 17:09 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Control Panel\Desktop\\Wallpaper -> c:\users\amd\desktop\mis cosas\fotos\eclipse-solar-desde-espacio-5303c998cd1c9.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run32: => "Razer Synapse"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_75BED9BC4FE28DE71792C715C05373CF"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Plex Media Server"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Lync"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{88E3E29D-109F-46CA-8ABB-4FAC74DE9764}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{232BF066-6AFA-4FB6-8B8C-258FD2AA095C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{B298653C-6BAB-4CCA-B65C-37F519AEFE6D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{E2D48BAC-D002-4319-9A43-B7D6B9C52F95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [UDP Query User{46C1F681-5175-4812-A704-0A018D087A0F}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [TCP Query User{CB8558D1-FF69-4771-986A-C2983A7D5446}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [{A4D6B4EE-7047-43BC-909B-5FF1F4911A6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{D015CD49-13BE-4A89-BA7C-828AFA56A527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{5DAFBFA5-8A8F-4773-BF75-7B6D123C593D}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe (GoPro Media, Inc. -> )
FirewallRules: [{C9725F0F-0625-4FA0-85EB-FBF7A38DCE1E}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe (GoPro Media, Inc. -> )
FirewallRules: [{41A40A2A-E44C-44AD-A93A-4446FB8E4CA9}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe (GoPro Media, Inc. -> )
FirewallRules: [{CE208CB7-FEB1-4606-A637-A1C014A852E8}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro Quik.exe (GoPro Media, Inc. -> )
FirewallRules: [UDP Query User{C0A02348-D406-4393-8DAB-A47F8250E9BF}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{212AADF3-0D7A-4B97-BD5E-D558EFAA8095}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1986FD76-61B9-48EB-90E8-50AB87B518ED}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{C7410143-03D1-4CB0-B8BE-5CF6D10EA1C9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{BFE94E1D-B42B-4799-B60B-6336E3F01D1F}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{14BC1D4B-28B3-4AD0-A3EA-97B954B29A81}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{881E906A-2F74-49C0-AAA0-5BE6EF13ABD7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{BDE08CFB-A8A7-4776-B108-37791A672AEB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{D3BC73DD-4794-4CA4-B22F-4FEF12DC5665}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{CC017309-7C26-4359-A151-1AE1D766CC4D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{378DBA21-D185-4130-9A42-F11651F8C453}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{B074AF06-8527-4F30-BDCE-8D9CE60A0D53}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CB3F23E2-5A54-40B3-BAF2-DCBC60FD273E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D57043B8-7AB8-49A0-8243-ADF770A2B30C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{53837B31-8D2F-466C-8E38-1069A3E1C37D}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe No File
FirewallRules: [{45B402DD-CE34-43F1-830C-D0C80FF226B7}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe No File
FirewallRules: [{F5EBA397-3D6C-4658-9923-9C1FCFEB8134}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E7D76357-97B3-491B-B6B2-C135A6ACEF96}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D8382B40-5C53-468C-A007-635FC233849F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{D43A96E2-F383-4917-BA90-431A11A42CFA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [TCP Query User{E06DD89F-C2D8-48C5-BB31-21157FD16FBE}C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed]
FirewallRules: [UDP Query User{041C8811-C93D-4C37-8098-CCD179390CB1}C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed]
FirewallRules: [{9EA637D9-F5E4-41D8-9848-FBCD05793038}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{54E1A440-155B-4F00-90C5-88FC53B5DDAC}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{50308C51-107C-4B7D-9079-B6EF5170E396}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Town of Salem\TownOfSalem.exe () [File not signed]
FirewallRules: [{2A4AEF8E-C153-4052-90CA-269D568F821E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Town of Salem\TownOfSalem.exe () [File not signed]
FirewallRules: [{21AEFB78-DA26-4A84-8140-C02C95C4A30A}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{609ABCE4-9708-429A-A26F-40AFE31FEF37}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{5BECCA37-B0AC-4558-8118-39BE3AA0AACC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E4AF5CF5-AF77-427F-848F-68E9EA9B55C1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{3EDB7FBE-1516-4B06-A430-4074E85DA702}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{DD83AE20-1140-49BA-9760-1AA24D2968F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{D4DE269D-82ED-4781-9BF4-16674762D66C}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{ADD5AE4F-87C9-4370-9190-B39738090812}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{65922F68-02C0-4FF3-95F3-7D093F8B1283}] => (Allow) C:\Users\amd\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{88999D04-27E0-4E0C-B247-59A51236CBC5}] => (Allow) C:\Users\amd\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{C5521E59-5090-4F95-A302-A3219269926B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ring of Elysium\SLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{E0C3C56D-995E-49C9-968A-B2D52B3A6DB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ring of Elysium\SLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{C3EC1744-1DC4-4E0C-9D8D-B0333C188CCD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{9EAACC06-4304-45E6-9BA1-4F2F0F1447AF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{381B9BC2-805C-454B-B7FC-8699684D2E89}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{C81F32D9-96BA-4D98-8B82-C17CD10ED9BA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [TCP Query User{13361F34-2D40-4372-9EA8-4B675F765DE2}C:\program files\epic games\subnautica\subnautica.exe] => (Allow) C:\program files\epic games\subnautica\subnautica.exe () [File not signed]
FirewallRules: [UDP Query User{94F26278-01EC-4A69-9450-F7168943E058}C:\program files\epic games\subnautica\subnautica.exe] => (Allow) C:\program files\epic games\subnautica\subnautica.exe () [File not signed]
FirewallRules: [{80E3F48E-EFC3-419D-BCEF-E28AE2CD6550}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [{E8562E62-FE35-4E65-83F4-56D0383FF1F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [TCP Query User{E999B8F4-2717-4915-BA23-0E390665D14F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [UDP Query User{AA8257FA-4E74-4CD8-AB50-FCB9201ADCCF}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [TCP Query User{706521BE-B3C4-432D-8359-908201175E6D}C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe No File
FirewallRules: [UDP Query User{EFADB801-A1F2-4014-A2FF-13290243BFDE}C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe No File
FirewallRules: [{33A53120-D49A-4FE5-9819-DB194B121DC5}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{001BB55E-C9F3-45D8-BE44-B73CDAD38EC0}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{AEB573C4-19A5-4CA7-8D82-E59649FCA00F}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{C7DC833A-D8BA-47F3-8660-49CB63B90E03}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{C6DBD3F6-EB35-46C3-A64C-4430DEB5D042}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{8B7C3E07-989F-419D-A2F8-ECED19B56BD5}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> Plex)
FirewallRules: [{D0892972-8796-4E5F-9655-04DCD277FA88}] => (Allow) C:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{892528D0-600B-4F09-94BB-9F90EF29D7EB}] => (Allow) C:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{2A95D321-66A4-4E56-AF4B-5B45515B5335}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alan Wake\AlanWake.exe No File
FirewallRules: [{188F6E2E-8A5B-4EDB-BB95-DEE071026A99}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alan Wake\AlanWake.exe No File
FirewallRules: [{BC2198CF-F58B-417C-AB36-3F61B09FB61E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8D82FA1A-A146-4272-9F5B-C5B36019D936}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{56D45FB2-91E6-4FB7-99E5-77CC3F74C338}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe () [File not signed]
FirewallRules: [{2875CEA6-1A6B-44D1-8F30-EBE1E01062E1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe () [File not signed]
FirewallRules: [TCP Query User{4917E636-7D06-41FD-8533-5404D48A47E1}C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe] => (Allow) C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe (Phoenix Labs -> Phoenix Labs)
FirewallRules: [UDP Query User{9BD7052E-3BF6-475C-87EB-028DB1487797}C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe] => (Allow) C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe (Phoenix Labs -> Phoenix Labs)
FirewallRules: [TCP Query User{000B4821-E27A-423A-A2BE-985653130CEC}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [UDP Query User{411E6683-1433-47F0-8503-93F164167388}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [{5E44AAC1-EE7A-4916-9A4E-8AEF4556D61D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5171F884-236E-43C6-A707-FF09451739E6}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{E6E69058-2D38-45D7-834C-7401FF0EC505}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe () [File not signed]
FirewallRules: [{6DC35D5D-6DA7-4B30-83A5-CE0D80B9E568}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe () [File not signed]
FirewallRules: [{0DE95936-2723-4D63-8FD0-BA92507FFD9A}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe () [File not signed]
FirewallRules: [{15999344-A2AA-4561-9E13-3AA2AF6F29DD}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe () [File not signed]
FirewallRules: [{9346FA6F-421C-42F7-AB99-5A48F9171945}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe () [File not signed]
FirewallRules: [{F01C84E7-CBB6-400A-9183-02F53C744F1C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe No File
FirewallRules: [{9D0A1C8A-4DFE-45E0-A50C-E25879423B4A}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\OxygenPanelDaemon.exe No File
FirewallRules: [{10D314F3-B88D-4402-B028-1B1A286BA038}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DPDecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{69D13C4D-495C-428D-9874-EC75AD9778D7}] => (Allow) C:\ProgramData\Blackmagic Design\DaVinci Resolve\Support\QtDecoder\QTDecoder.exe No File
FirewallRules: [TCP Query User{5E419FAA-AF43-4F55-A3C4-0F3724FE90BF}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty. Ltd.) [File not signed]
FirewallRules: [UDP Query User{4A10943A-912F-4BDB-8DE9-63847AA072B1}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty. Ltd.) [File not signed]
FirewallRules: [TCP Query User{032D82B7-EF25-4785-963A-F8E75D125A89}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{93198204-5E41-4B68-AB18-9CF5F0D3994E}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [{B0ACB74F-7E77-42DD-98B9-4AA3DBDF481E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8277AC0B-3734-4B56-8AC5-BB5F40D0B93F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{6A74A575-1142-4777-BB6C-9AF4B8AFC7C9}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{EA67E5DF-8299-450B-84C1-AF802314D9F5}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [{D721A274-8454-42BD-9A3F-2FA1674FBD56}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{69C3820F-E1F1-405F-82E1-A3AEA78ED024}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2463FF76-1F92-42F9-BF80-524149A2E97D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{F3EE1434-034A-459D-A5BE-14C746720EB5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E489F6C2-2F42-4E5A-9362-556A05FE68EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{3B4286C8-3725-4AFF-A825-8C9DADF61CB7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{8DC007D8-7E55-4C55-A932-003715013E01}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{092F635E-34FA-4792-9F4F-84825A47B075}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{23143A09-F11A-4E34-A967-AF548264026C}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{AA4AFF4A-4BD0-4A2E-89B5-6E52C4B749A9}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A7A3A1C0-05E0-4657-86C6-AE915C795B05}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E917715A-3C66-484F-9E58-A45244A7DA20}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{CD89FAE0-DBA3-4509-9F34-8F3E72444AF0}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FE9F6753-D516-4AAB-9CE1-043A6CE06D2B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{638CDB27-8527-464C-916C-1FC2C8D013AB}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.449.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
 
==================== Restore Points =========================
 
20-07-2019 15:07:21 Punto de control programado
30-07-2019 20:35:10 Punto de control programado
 
==================== Faulty Device Manager Devices =============
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/05/2019 10:43:12 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/05/2019 10:43:04 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
 
System errors:
=============
Error: (08/05/2019 10:49:04 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/05/2019 10:47:04 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/05/2019 10:45:04 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {B52D54BB-4818-4EB9-AA80-F9EACD371DF8} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/05/2019 10:43:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID 
Windows.SecurityCenter.WscDataProtection
 y APPID 
No disponible
 al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
 
Error: (08/05/2019 10:43:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: La configuración de permisos específico de la aplicación no concede el permiso Iniciar Local para la aplicación de servidor COM con CLSID 
Windows.SecurityCenter.WscBrokerManager
 y APPID 
No disponible
 al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
 
Error: (08/05/2019 10:43:04 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/05/2019 10:42:50 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-4LAFI5B)
Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 y APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 al usuario DESKTOP-4LAFI5B\Matoke con SID (S-1-5-21-1830811996-1437030023-4132568959-1001) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.
 
Error: (08/05/2019 10:40:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: El servicio Ds3Service no pudo iniciarse debido al siguiente error: 
El sistema no puede encontrar el archivo especificado.
 
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 4011 04/19/2018
Motherboard: ASUSTeK COMPUTER INC. PRIME B350M-A
Processor: AMD Ryzen 7 1700 Eight-Core Processor 
Percentage of memory in use: 41%
Total physical RAM: 8124 MB
Available physical RAM: 4778.11 MB
Total Virtual: 10940 MB
Available Virtual: 6808.89 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.91 GB) (Free:318.38 GB) NTFS
 
\\?\Volume{232ffcd7-c3e0-4d2a-87fa-f0a4133550f4}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.1 GB) NTFS
\\?\Volume{48d798ba-c390-4088-a209-866139d7c711}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: EA3C124C)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.

 

Let's try Latency Monitor:

Go to

http://www.resplendence.com/downloads

Scroll down to

System Monitoring Tools

and then find

LatencyMon 6.70 (or it may be a higher number if they update)

Click on Download free home edition

Save it then right click and Run As Admin.  It will install and then start the program.  
It will tell you to click on the Start button but there isn't one.  
Instead click on the green arrowhead (looks like a Play button).   Let it run for at least 20 seconds.  Then hit the red box to stop it.

Edit, Copy Report text to Clipboard then move to a REPLY and Ctrl + v to paste the text into a reply. 


 


  • 0

#5
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.

 

Let's try Latency Monitor:

Go to

http://www.resplendence.com/downloads

Scroll down to

System Monitoring Tools

and then find

LatencyMon 6.70 (or it may be a higher number if they update)

Click on Download free home edition

Save it then right click and Run As Admin.  It will install and then start the program.  
It will tell you to click on the Start button but there isn't one.  
Instead click on the green arrowhead (looks like a Play button).   Let it run for at least 20 seconds.  Then hit the red box to stop it.

Edit, Copy Report text to Clipboard then move to a REPLY and Ctrl + v to paste the text into a reply. 


 

Sorry for the delay. Here's everything you asked for (I didn't delete Hamachi since I use it sometimes): 

 

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer

System Idle Process 98.18 52 K 8 K 0
procexp (1)64.exe 0.78 46.392 K 81.696 K 5712 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
Interrupts 0.23 0 K 0 K n/a Hardware Interrupts and DPCs
WmiPrvSE.exe 0.15 9.304 K 14.540 K 5392 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
EpicGamesLauncher.exe 0.12 176.816 K 138.504 K 11244 EpicGamesLauncher Epic Games, Inc. (Verified) Epic Games Inc.
dwm.exe 0.12 67.888 K 37.624 K 1200 Administrador de ventanas de escritorio Microsoft Corporation (Verified) Microsoft Windows
System 0.09 248 K 28.532 K 4
csrss.exe 0.07 2.620 K 2.704 K 820 Proceso en tiempo de ejecución del cliente-servidor Microsoft Corporation (Verified) Microsoft Windows Publisher
NVIDIA Share.exe 0.05 47.800 K 42.564 K 10688 NVIDIA Share NVIDIA Corporation (Verified) NVIDIA Corporation
MsMpEng.exe 0.05 209.152 K 177.516 K 3496 Antimalware Service Executable Microsoft Corporation (Verified) Microsoft Windows Publisher
ctfmon.exe 0.04 5.588 K 9.292 K 7520 Cargador de CTF Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 0.04 22.492 K 39.268 K 2396 Google Chrome Google LLC (Verified) Google LLC
svchost.exe 0.02 9.444 K 14.360 K 3544 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
nvsphelper64.exe 0.01 2.852 K 3.644 K 10028 NVIDIA ShadowPlay Helper NVIDIA Corporation (Verified) NVIDIA Corporation
nvcontainer.exe 0.01 12.952 K 19.064 K 3400 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
explorer.exe 0.01 89.824 K 110.656 K 7776 Explorador de Windows Microsoft Corporation (Verified) Microsoft Windows
nvcontainer.exe < 0.01 12.708 K 19.224 K 5304 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
chrome.exe < 0.01 98.624 K 144.152 K 11384 Google Chrome Google LLC (Verified) Google LLC
chrome.exe < 0.01 154.824 K 157.816 K 11804 Google Chrome Google LLC (Verified) Google LLC
chrome.exe < 0.01 22.296 K 29.868 K 3184 Google Chrome Google LLC (Verified) Google LLC
svchost.exe < 0.01 4.848 K 11.676 K 10852 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 9.796 K 12.192 K 1092 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 15.764 K 15.024 K 1628 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe < 0.01 62.776 K 94.348 K 5188 Google Chrome Google LLC (Verified) Google LLC
svchost.exe < 0.01 5.568 K 9.368 K 2980 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
hamachi-2.exe < 0.01 3.912 K 8.944 K 4400 Hamachi Client Tunneling Engine LogMeIn Inc. (Verified) LogMeIn, Inc.
svchost.exe < 0.01 12.904 K 17.276 K 736 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 8.972 K 20.372 K 6580 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
TeamViewer_Service.exe < 0.01 7.792 K 8.468 K 3592 TeamViewer 14 TeamViewer GmbH (Verified) TeamViewer GmbH
lsass.exe < 0.01 7.112 K 12.400 K 992 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
services.exe < 0.01 5.760 K 7.736 K 972 Aplicación de servicios y controlador Microsoft Corporation (Verified) Microsoft Windows Publisher
AGMService.exe < 0.01 2.484 K 3.944 K 3480 Adobe Genuine Software Service Adobe Systems, Incorporated (Verified) Adobe Inc.
svchost.exe < 0.01 4.004 K 7.228 K 2880 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 21.728 K 25.228 K 1724 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 4.120 K 6.632 K 2216 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
chrome.exe < 0.01 197.156 K 141.520 K 5184 Google Chrome Google LLC (Verified) Google LLC
ClamTray.exe < 0.01 16.456 K 17.788 K 9432 ClamWin Antivirus alch (No hay ninguna firma presente en el sujeto) alch
NVIDIA Web Helper.exe < 0.01 33.740 K 15.032 K 9580 NVIDIA Web Helper Service Node.js (Verified) NVIDIA Corporation
svchost.exe < 0.01 5.720 K 16.072 K 3512 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe < 0.01 39.560 K 40.832 K 3208 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
GameBar.exe < 0.01 25.924 K 15.936 K 9524 (No hay ninguna firma presente en el sujeto)
RuntimeBroker.exe < 0.01 10.024 K 23.976 K 11256 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
NVDisplay.Container.exe < 0.01 30.856 K 36.632 K 2236 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
AdobeUpdateService.exe < 0.01 1.432 K 1.220 K 3504 Adobe Update Service Adobe Inc. (Verified) Adobe Inc.
UnrealCEFSubProcess.exe < 0.01 77.380 K 64.504 K 7928 UnrealCEFSubProcess Epic Games, Inc. (Verified) Epic Games Inc.
NvTelemetryContainer.exe < 0.01 5.660 K 11.152 K 3408 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
chrome.exe < 0.01 23.160 K 40.692 K 2132 Google Chrome Google LLC (Verified) Google LLC
NVIDIA Share.exe < 0.01 72.576 K 51.068 K 10568 NVIDIA Share NVIDIA Corporation (Verified) NVIDIA Corporation
svchost.exe < 0.01 4.020 K 5.668 K 2660 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
LMIGuardianSvc.exe < 0.01 2.184 K 2.800 K 3428 LMIGuardianSvc LogMeIn, Inc. (Verified) LogMeIn, Inc.
WmiPrvSE.exe 15.420 K 16.688 K 12124 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
winlogon.exe 2.660 K 6.072 K 928 Aplicación de inicio de sesión de Windows Microsoft Corporation (Verified) Microsoft Windows
wininit.exe 1.400 K 1.700 K 848 Aplicación de inicio de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
unsecapp.exe 1.544 K 2.700 K 5312 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
taskhostw.exe 6.500 K 8.948 K 7188 Proceso de host para tareas de Windows Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 5.956 K 9.500 K 2088 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 8.784 K 22.148 K 5456 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5.284 K 11.984 K 7816 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5.460 K 16.648 K 5092 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.976 K 4.188 K 1916 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.264 K 5.036 K 4704 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.944 K 4.280 K 1136 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.504 K 3.512 K 2800 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.572 K 9.324 K 6792 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 7.812 K 10.312 K 1544 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 11.792 K 14.668 K 3516 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.816 K 10.792 K 6840 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.448 K 5.592 K 11980 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.888 K 2.104 K 3976 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.712 K 6.904 K 12216 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.588 K 7.344 K 2372 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.508 K 4.520 K 2728 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.072 K 4.476 K 1908 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.184 K 3.456 K 3264 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.256 K 3.572 K 5288 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.732 K 6.920 K 8444 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.328 K 5.084 K 6424 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5.976 K 10.000 K 2512 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 6.440 K 11.344 K 11176 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.316 K 4.684 K 1364 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.784 K 4.936 K 1764 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.256 K 4.096 K 1208 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 3.728 K 11.328 K 10360 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.068 K 5.220 K 2020 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4.040 K 6.416 K 4648 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.420 K 3.664 K 4372 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4.448 K 8.204 K 4364 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.656 K 2.016 K 4132 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.320 K 1.376 K 3576 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4.428 K 9.764 K 3560 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.892 K 3.308 K 3564 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.824 K 3.588 K 3548 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.640 K 2.052 K 3524 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.172 K 3.792 K 3536 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.888 K 5.908 K 7472 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.720 K 4.100 K 3024 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4.616 K 14.632 K 2924 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.224 K 3.544 K 1132 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.792 K 3.384 K 1184 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.360 K 1.624 K 1900 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 5.468 K 6.160 K 1788 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.736 K 5.820 K 1536 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.600 K 2.492 K 1436 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 2.380 K 5.112 K 1276 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.976 K 2.740 K 11604 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.004 K 1.020 K 660 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.640 K 2.604 K 7436 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 4.052 K 7.072 K 2848 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.436 K 3.164 K 1608 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe 1.668 K 7.372 K 7116 Proceso host para los servicios de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
spoolsv.exe 6.072 K 7.704 K 2536 Aplicación de subsistema de cola Microsoft Corporation (Verified) Microsoft Windows
smss.exe 488 K 356 K 552 Administrador de sesión de Windows Microsoft Corporation (Verified) Microsoft Windows Publisher
SkypeBackgroundHost.exe Suspended 2.052 K 3.552 K 8676 Microsoft Skype Microsoft Corporation (No hay ninguna firma presente en el sujeto) Microsoft Corporation
SkypeApp.exe Suspended 226.104 K 175.400 K 8668 SkypeApp Microsoft Corporation (No hay ninguna firma presente en el sujeto) Microsoft Corporation
sihost.exe 8.376 K 15.716 K 6472 Shell Infrastructure Host Microsoft Corporation (Verified) Microsoft Windows
ShellExperienceHost.exe Suspended 39.816 K 4.960 K 3724 Windows Shell Experience Host Microsoft Corporation (Verified) Microsoft Windows
SgrmBroker.exe 2.396 K 2.924 K 1640 Servicio Agente de supervisión en tiempo de ejecución de Protección del sistema Microsoft Corporation (Verified) Microsoft Windows Publisher
SettingSyncHost.exe 11.464 K 22.260 K 8940 Host Process for Setting Synchronization Microsoft Corporation (Verified) Microsoft Windows
sedsvc.exe 2.252 K 2.360 K 10596 sedsvc Microsoft Corporation (Verified) Microsoft Windows
SecurityHealthService.exe 4.528 K 7.428 K 3856 Windows Security Health Service Microsoft Corporation (Verified) Microsoft Windows Publisher
SearchUI.exe Suspended 79.420 K 78.248 K 6708 Search and Cortana application Microsoft Corporation (Verified) Microsoft Windows
SearchIndexer.exe 2.000 K 3.116 K 5656 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 3.800 K 9.608 K 12068 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5.008 K 12.808 K 3880 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 6.504 K 16.768 K 7484 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5.512 K 15.488 K 8876 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5.948 K 12.904 K 8592 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 4.620 K 5.972 K 3216 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
RuntimeBroker.exe 5.864 K 5.700 K 4220 Runtime Broker Microsoft Corporation (Verified) Microsoft Windows
rundll32.exe 1.732 K 1.984 K 5464 Proceso host de Windows (Rundll32) Microsoft Corporation (Verified) Microsoft Windows
Registry 5.084 K 17.696 K 168
procexp (1).exe 3.332 K 10.980 K 4256 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
Plex Update Service.exe 1.856 K 1.448 K 3444 Plex Update Service Plex, Inc. (Verified) Plex, Inc
OfficeClickToRun.exe 39.544 K 46.868 K 3392 Microsoft Office Click-to-Run (SxS) Microsoft Corporation (Verified) Microsoft Corporation
NVIDIA Share.exe 56.924 K 55.040 K 11020 NVIDIA Share NVIDIA Corporation (Verified) NVIDIA Corporation
NVDisplay.Container.exe 3.492 K 6.324 K 1756 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
nvcontainer.exe 34.960 K 49.060 K 6492 NVIDIA Container NVIDIA Corporation (Verified) NVIDIA Corporation
NisSrv.exe 5.428 K 6.140 K 7460 Microsoft Network Realtime Inspection Service Microsoft Corporation (Verified) Microsoft Windows Publisher
MSASCuiL.exe 2.164 K 3.248 K 7220 Windows Defender notification icon Microsoft Corporation (Verified) Microsoft Windows
Microsoft.Photos.exe Suspended 48.824 K 18.152 K 1960 (No hay ninguna firma presente en el sujeto)
LockApp.exe Suspended 27.688 K 33.620 K 6176 LockApp.exe Microsoft Corporation (Verified) Microsoft Windows
jusched.exe 1.468 K 1.216 K 9500 Java Update Scheduler Oracle Corporation (Verified) Oracle America, Inc.
GoProDeviceDetection.exe 19.596 K 16.888 K 10324 (Verified) GoPro Media, Inc.
GoogleCrashHandler64.exe 1.692 K 1.080 K 9788 Google Crash Handler Google LLC (Verified) Google Inc
GoogleCrashHandler.exe 1.760 K 724 K 9744 Google Crash Handler Google LLC (Verified) Google Inc
fontdrvhost.exe 12.652 K 13.152 K 492 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
fontdrvhost.exe 10.780 K 10.624 K 688 Usermode Font Driver Host Microsoft Corporation (Verified) Microsoft Windows
dllhost.exe 4.020 K 5.536 K 6184 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
dasHost.exe 8.912 K 15.652 K 4384 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
csrss.exe 2.068 K 2.724 K 732 Proceso en tiempo de ejecución del cliente-servidor Microsoft Corporation (Verified) Microsoft Windows Publisher
conhost.exe 5.448 K 1.032 K 9604 Host de ventana de consola Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 25.808 K 17.576 K 11600 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 6.932 K 6.708 K 11740 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 19.768 K 35.308 K 304 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 35.520 K 60.148 K 896 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 13.452 K 22.924 K 12716 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 2.112 K 2.952 K 6680 Google Chrome Google LLC (Verified) Google LLC
chrome.exe 1.996 K 2.580 K 656 Google Chrome Google LLC (Verified) Google LLC
backgroundTaskHost.exe 12.944 K 17.168 K 11772 Background Task Host Microsoft Corporation (Verified) Microsoft Windows
AGSService.exe 1.916 K 1.676 K 3436 Adobe Genuine Software Integrity Service Adobe Systems, Incorporated (Verified) Adobe Inc.
 
 
 
.......................................................................
 
 
 
 
Nombre de imagen               PID Servicios                                    
========================= ======== =============================================
System Idle Process              0 N/D                                          
System                           4 N/D                                          
Registry                       168 N/D                                          
smss.exe                       552 N/D                                          
csrss.exe                      732 N/D                                          
csrss.exe                      820 N/D                                          
wininit.exe                    848 N/D                                          
winlogon.exe                   928 N/D                                          
services.exe                   972 N/D                                          
lsass.exe                      992 KeyIso, SamSs, VaultSvc                      
svchost.exe                    660 PlugPlay                                     
svchost.exe                    736 BrokerInfrastructure, DcomLaunch, Power,     
                                   SystemEventsBroker                           
fontdrvhost.exe                688 N/D                                          
fontdrvhost.exe                492 N/D                                          
svchost.exe                   1092 RpcEptMapper, RpcSs                          
svchost.exe                   1136 LSM                                          
dwm.exe                       1200 N/D                                          
svchost.exe                   1276 NcbService                                   
svchost.exe                   1364 TimeBrokerSvc                                
svchost.exe                   1436 hidserv                                      
svchost.exe                   1536 ProfSvc                                      
svchost.exe                   1544 Schedule                                     
svchost.exe                   1628 EventLog                                     
svchost.exe                   1724 BFE, CoreMessagingRegistrar, mpssvc          
NVDisplay.Container.exe       1756 NVDisplay.ContainerLocalSystem               
svchost.exe                   1764 UserManager                                  
svchost.exe                   1788 nsi                                          
svchost.exe                   1900 Themes                                       
svchost.exe                   1908 Dhcp                                         
svchost.exe                   1916 EventSystem                                  
svchost.exe                   2020 SENS                                         
svchost.exe                   1132 AudioEndpointBuilder                         
svchost.exe                   1184 FontCache                                    
svchost.exe                   2088 NlaSvc                                       
svchost.exe                   2216 netprofm                                     
NVDisplay.Container.exe       2236 N/D                                          
svchost.exe                   2372 Audiosrv                                     
svchost.exe                   2512 StateRepository                              
svchost.exe                   2660 Dnscache                                     
svchost.exe                   2728 WinHttpAutoProxySvc                          
svchost.exe                   2800 DusmSvc                                      
svchost.exe                   2880 Wcmsvc                                       
svchost.exe                   2924 LicenseManager                               
svchost.exe                   2980 WlanSvc                                      
svchost.exe                   3024 ShellHWDetection                             
spoolsv.exe                   2536 Spooler                                      
svchost.exe                   3208 UsoSvc, wuauserv                             
svchost.exe                   3264 LanmanWorkstation                            
OfficeClickToRun.exe          3392 ClickToRunSvc                                
nvcontainer.exe               3400 NvContainerLocalSystem                       
NvTelemetryContainer.exe      3408 NvTelemetryContainer                         
LMIGuardianSvc.exe            3428 LMIGuardianSvc                               
AGSService.exe                3436 AGSService                                   
Plex Update Service.exe       3444 PlexUpdateService                            
AGMService.exe                3480 AGMService                                   
MsMpEng.exe                   3496 WinDefend                                    
AdobeUpdateService.exe        3504 AdobeUpdateService                           
svchost.exe                   3512 WpnService                                   
svchost.exe                   3516 DPS                                          
svchost.exe                   3524 SstpSvc                                      
svchost.exe                   3536 stisvc                                       
svchost.exe                   3548 IKEEXT                                       
svchost.exe                   3544 Winmgmt                                      
svchost.exe                   3560 CryptSvc                                     
svchost.exe                   3564 DeviceAssociationService                     
svchost.exe                   3576 TrkWks                                       
TeamViewer_Service.exe        3592 TeamViewer                                   
SecurityHealthService.exe     3856 SecurityHealthService                        
svchost.exe                   3976 TapiSrv                                      
svchost.exe                   4132 WdiServiceHost                               
svchost.exe                   4364 iphlpsvc                                     
svchost.exe                   4372 LanmanServer                                 
dasHost.exe                   4384 N/D                                          
hamachi-2.exe                 4400 Hamachi2Svc                                  
svchost.exe                   4648 RasMan                                       
svchost.exe                   4704 SSDPSRV                                      
unsecapp.exe                  5312 N/D                                          
WmiPrvSE.exe                  5392 N/D                                          
rundll32.exe                  5464 N/D                                          
SearchIndexer.exe             5656 WSearch                                      
dllhost.exe                   6184 N/D                                          
svchost.exe                   6424 NcdAutoSetup                                 
svchost.exe                   6792 lfsvc                                        
svchost.exe                   6840 TokenBroker                                  
nvcontainer.exe               5304 N/D                                          
sihost.exe                    6472 N/D                                          
nvcontainer.exe               6492 N/D                                          
svchost.exe                   5456 CDPUserSvc_6d733                             
svchost.exe                   6580 WpnUserService_6d733                         
taskhostw.exe                 7188 N/D                                          
svchost.exe                   7436 TabletInputService                           
NisSrv.exe                    7460 WdNisSvc                                     
ctfmon.exe                    7520 N/D                                          
explorer.exe                  7776 N/D                                          
svchost.exe                   7816 CDPSvc                                       
svchost.exe                   2848 PcaSvc                                       
ShellExperienceHost.exe       3724 N/D                                          
SearchUI.exe                  6708 N/D                                          
RuntimeBroker.exe             4220 N/D                                          
RuntimeBroker.exe             8592 N/D                                          
SkypeApp.exe                  8668 N/D                                          
SkypeBackgroundHost.exe       8676 N/D                                          
RuntimeBroker.exe             8876 N/D                                          
SettingSyncHost.exe           8940 N/D                                          
RuntimeBroker.exe             3880 N/D                                          
MSASCuiL.exe                  7220 N/D                                          
ClamTray.exe                  9432 N/D                                          
jusched.exe                   9500 N/D                                          
NVIDIA Web Helper.exe         9580 N/D                                          
conhost.exe                   9604 N/D                                          
GoogleCrashHandler.exe        9744 N/D                                          
GoogleCrashHandler64.exe      9788 N/D                                          
svchost.exe                  10852 DoSvc                                        
GoProDeviceDetection.exe     10324 GoProDeviceDetectionService                  
svchost.exe                  11176 OneSyncSvc_6d733,                            
                                   PimIndexMaintenanceSvc_6d733,                
                                   UnistoreSvc_6d733, UserDataSvc_6d733         
sedsvc.exe                   10596 sedsvc                                       
SgrmBroker.exe                1640 SgrmBroker                                   
svchost.exe                   1208 wscsvc                                       
svchost.exe                   1608 Appinfo                                      
nvsphelper64.exe             10028 N/D                                          
NVIDIA Share.exe             10688 N/D                                          
NVIDIA Share.exe             10568 N/D                                          
NVIDIA Share.exe             11020 N/D                                          
svchost.exe                   5288 StorSvc                                      
EpicGamesLauncher.exe        11244 N/D                                          
UnrealCEFSubProcess.exe       7928 N/D                                          
GameBar.exe                   9524 N/D                                          
RuntimeBroker.exe             3216 N/D                                          
Microsoft.Photos.exe          1960 N/D                                          
RuntimeBroker.exe            12068 N/D                                          
chrome.exe                   11384 N/D                                          
chrome.exe                    6680 N/D                                          
chrome.exe                     656 N/D                                          
chrome.exe                    5184 N/D                                          
chrome.exe                    3184 N/D                                          
WmiPrvSE.exe                 12124 N/D                                          
chrome.exe                   11740 N/D                                          
chrome.exe                   11804 N/D                                          
chrome.exe                   11600 N/D                                          
svchost.exe                  11604 BthAvctpSvc                                  
backgroundTaskHost.exe       11772 N/D                                          
RuntimeBroker.exe             7484 N/D                                          
LockApp.exe                   6176 N/D                                          
RuntimeBroker.exe            11256 N/D                                          
svchost.exe                   8444 Browser                                      
svchost.exe                   5092 wlidsvc                                      
svchost.exe                  12216 NgcCtnrSvc                                   
svchost.exe                  11980 lmhosts                                      
chrome.exe                    5188 N/D                                          
svchost.exe                  10360 AppXSvc                                      
chrome.exe                     304 N/D                                          
chrome.exe                    2396 N/D                                          
chrome.exe                    2132 N/D                                          
chrome.exe                     896 N/D                                          
svchost.exe                   7472 WdiSystemHost                                
svchost.exe                   7116 camsvc                                       
svchost.exe                  10448 NgcSvc                                       
svchost.exe                   7588 BITS                                         
audiodg.exe                   1388 N/D                                          
powershell.exe               10740 N/D                                          
conhost.exe                  10012 N/D                                          
chrome.exe                    8304 N/D                                          
svchost.exe                  12088 gpsvc                                        
dllhost.exe                   5884 N/D                                          
smartscreen.exe               3648 N/D                                          
tasklist.exe                 12444 N/D                                          
 

...........................................................

 

 

_________________________________________________________________________________________________________
CONCLUSION
_________________________________________________________________________________________________________
Your system appears to be suitable for handling real-time audio and other tasks without dropouts. 
LatencyMon has been analyzing your system for  0:00:21  (h:mm:ss) on all processors.
 
 
_________________________________________________________________________________________________________
SYSTEM INFORMATION
_________________________________________________________________________________________________________
Computer name:                                        DESKTOP-4LAFI5B
OS version:                                           Windows 10 , 10.0, version 1803, build: 17134 (x64)
Hardware:                                             ASUSTeK COMPUTER INC., PRIME B350M-A
CPU:                                                  AuthenticAMD AMD Ryzen 7 1700 Eight-Core Processor 
Logical processors:                                   16
Processor groups:                                     1
RAM:                                                  8123 MB total
 
 
_________________________________________________________________________________________________________
CPU SPEED
_________________________________________________________________________________________________________
Reported CPU speed:                                   2994 MHz
 
Note: reported execution times may be calculated based on a fixed reported CPU speed. Disable variable speed settings like Intel Speed Step and AMD Cool N Quiet in the BIOS setup for more accurate results.
 
 
_________________________________________________________________________________________________________
MEASURED INTERRUPT TO USER PROCESS LATENCIES
_________________________________________________________________________________________________________
The interrupt to process latency reflects the measured interval that a usermode process needed to respond to a hardware request from the moment the interrupt service routine started execution. This includes the scheduling and execution of a DPC routine, the signaling of an event and the waking up of a usermode thread from an idle wait state in response to that event.
 
Highest measured interrupt to process latency (µs):   532,795294
Average measured interrupt to process latency (µs):   6,161289
 
Highest measured interrupt to DPC latency (µs):       530,059503
Average measured interrupt to DPC latency (µs):       2,080615
 
 
_________________________________________________________________________________________________________
 REPORTED ISRs
_________________________________________________________________________________________________________
Interrupt service routines are routines installed by the OS and device drivers that execute in response to a hardware interrupt signal.
 
Highest ISR routine execution time (µs):              233,016032
Driver with highest ISR routine execution time:       dxgkrnl.sys - DirectX Graphics Kernel, Microsoft Corporation
 
Highest reported total ISR routine time (%):          0,018297
Driver with highest ISR total time:                   dxgkrnl.sys - DirectX Graphics Kernel, Microsoft Corporation
 
Total time spent in ISRs (%)                          0,020092
 
ISR count (execution time <250 µs):                   6480
ISR count (execution time 250-500 µs):                0
ISR count (execution time 500-999 µs):                0
ISR count (execution time 1000-1999 µs):              0
ISR count (execution time 2000-3999 µs):              0
ISR count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
REPORTED DPCs
_________________________________________________________________________________________________________
DPC routines are part of the interrupt servicing dispatch mechanism and disable the possibility for a process to utilize the CPU while it is interrupted until the DPC has finished execution.
 
Highest DPC routine execution time (µs):              485,070140
Driver with highest DPC routine execution time:       Wdf01000.sys - Motor en tiempo de ejecución del marco de controlador en modo kernel, Microsoft Corporation
 
Highest reported total DPC routine time (%):          0,036924
Driver with highest DPC total execution time:         Wdf01000.sys - Motor en tiempo de ejecución del marco de controlador en modo kernel, Microsoft Corporation
 
Total time spent in DPCs (%)                          0,069102
 
DPC count (execution time <250 µs):                   39664
DPC count (execution time 250-500 µs):                0
DPC count (execution time 500-999 µs):                8
DPC count (execution time 1000-1999 µs):              0
DPC count (execution time 2000-3999 µs):              0
DPC count (execution time >=4000 µs):                 0
 
 
_________________________________________________________________________________________________________
 REPORTED HARD PAGEFAULTS
_________________________________________________________________________________________________________
Hard pagefaults are events that get triggered by making use of virtual memory that is not resident in RAM but backed by a memory mapped file on disk. The process of resolving the hard pagefault requires reading in the memory from disk while the process is interrupted and blocked from execution.
 
NOTE: some processes were hit by hard pagefaults. If these were programs producing audio, they are likely to interrupt the audio stream resulting in dropouts, clicks and pops. Check the Processes tab to see which programs were hit.
 
Process with highest pagefault count:                 adobeupdateservice.exe
 
Total number of hard pagefaults                       2
Hard pagefault count of hardest hit process:          2
Number of processes hit:                              1
 
 
_________________________________________________________________________________________________________
 PER CPU DATA
_________________________________________________________________________________________________________
CPU 0 Interrupt cycle time (s):                       0,802775
CPU 0 ISR highest execution time (µs):                233,016032
CPU 0 ISR total execution time (s):                   0,066733
CPU 0 ISR count:                                      5642
CPU 0 DPC highest execution time (µs):                485,070140
CPU 0 DPC total execution time (s):                   0,222738
CPU 0 DPC count:                                      38416
_________________________________________________________________________________________________________
CPU 1 Interrupt cycle time (s):                       0,311782
CPU 1 ISR highest execution time (µs):                1,823647
CPU 1 ISR total execution time (s):                   0,000125
CPU 1 ISR count:                                      105
CPU 1 DPC highest execution time (µs):                169,238477
CPU 1 DPC total execution time (s):                   0,002454
CPU 1 DPC count:                                      309
_________________________________________________________________________________________________________
CPU 2 Interrupt cycle time (s):                       0,250142
CPU 2 ISR highest execution time (µs):                0,0
CPU 2 ISR total execution time (s):                   0,0
CPU 2 ISR count:                                      0
CPU 2 DPC highest execution time (µs):                15,521042
CPU 2 DPC total execution time (s):                   0,000404
CPU 2 DPC count:                                      78
_________________________________________________________________________________________________________
CPU 3 Interrupt cycle time (s):                       0,300792
CPU 3 ISR highest execution time (µs):                0,0
CPU 3 ISR total execution time (s):                   0,0
CPU 3 ISR count:                                      0
CPU 3 DPC highest execution time (µs):                47,645291
CPU 3 DPC total execution time (s):                   0,000141
CPU 3 DPC count:                                      21
_________________________________________________________________________________________________________
CPU 4 Interrupt cycle time (s):                       0,244298
CPU 4 ISR highest execution time (µs):                0,0
CPU 4 ISR total execution time (s):                   0,0
CPU 4 ISR count:                                      0
CPU 4 DPC highest execution time (µs):                31,803607
CPU 4 DPC total execution time (s):                   0,000464
CPU 4 DPC count:                                      68
_________________________________________________________________________________________________________
CPU 5 Interrupt cycle time (s):                       0,277668
CPU 5 ISR highest execution time (µs):                0,0
CPU 5 ISR total execution time (s):                   0,0
CPU 5 ISR count:                                      0
CPU 5 DPC highest execution time (µs):                2,134269
CPU 5 DPC total execution time (s):                   0,000003
CPU 5 DPC count:                                      2
_________________________________________________________________________________________________________
CPU 6 Interrupt cycle time (s):                       0,263264
CPU 6 ISR highest execution time (µs):                0,0
CPU 6 ISR total execution time (s):                   0,0
CPU 6 ISR count:                                      0
CPU 6 DPC highest execution time (µs):                200,270541
CPU 6 DPC total execution time (s):                   0,000630
CPU 6 DPC count:                                      80
_________________________________________________________________________________________________________
CPU 7 Interrupt cycle time (s):                       0,272654
CPU 7 ISR highest execution time (µs):                0,0
CPU 7 ISR total execution time (s):                   0,0
CPU 7 ISR count:                                      0
CPU 7 DPC highest execution time (µs):                23,657315
CPU 7 DPC total execution time (s):                   0,000081
CPU 7 DPC count:                                      15
_________________________________________________________________________________________________________
CPU 8 Interrupt cycle time (s):                       0,376175
CPU 8 ISR highest execution time (µs):                0,0
CPU 8 ISR total execution time (s):                   0,0
CPU 8 ISR count:                                      0
CPU 8 DPC highest execution time (µs):                128,336673
CPU 8 DPC total execution time (s):                   0,002054
CPU 8 DPC count:                                      286
_________________________________________________________________________________________________________
CPU 9 Interrupt cycle time (s):                       0,420806
CPU 9 ISR highest execution time (µs):                0,0
CPU 9 ISR total execution time (s):                   0,0
CPU 9 ISR count:                                      0
CPU 9 DPC highest execution time (µs):                191,993988
CPU 9 DPC total execution time (s):                   0,001111
CPU 9 DPC count:                                      99
_________________________________________________________________________________________________________
CPU 10 Interrupt cycle time (s):                       0,297237
CPU 10 ISR highest execution time (µs):                0,0
CPU 10 ISR total execution time (s):                   0,0
CPU 10 ISR count:                                      0
CPU 10 DPC highest execution time (µs):                46,603206
CPU 10 DPC total execution time (s):                   0,000263
CPU 10 DPC count:                                      41
_________________________________________________________________________________________________________
CPU 11 Interrupt cycle time (s):                       0,362347
CPU 11 ISR highest execution time (µs):                0,0
CPU 11 ISR total execution time (s):                   0,0
CPU 11 ISR count:                                      0
CPU 11 DPC highest execution time (µs):                38,106212
CPU 11 DPC total execution time (s):                   0,000716
CPU 11 DPC count:                                      104
_________________________________________________________________________________________________________
CPU 12 Interrupt cycle time (s):                       0,261096
CPU 12 ISR highest execution time (µs):                1,983968
CPU 12 ISR total execution time (s):                   0,000372
CPU 12 ISR count:                                      402
CPU 12 DPC highest execution time (µs):                90,110220
CPU 12 DPC total execution time (s):                   0,000606
CPU 12 DPC count:                                      68
_________________________________________________________________________________________________________
CPU 13 Interrupt cycle time (s):                       0,302477
CPU 13 ISR highest execution time (µs):                1,523046
CPU 13 ISR total execution time (s):                   0,000006
CPU 13 ISR count:                                      5
CPU 13 DPC highest execution time (µs):                4,468938
CPU 13 DPC total execution time (s):                   0,000004
CPU 13 DPC count:                                      1
_________________________________________________________________________________________________________
CPU 14 Interrupt cycle time (s):                       0,276556
CPU 14 ISR highest execution time (µs):                1,593186
CPU 14 ISR total execution time (s):                   0,000065
CPU 14 ISR count:                                      73
CPU 14 DPC highest execution time (µs):                32,945892
CPU 14 DPC total execution time (s):                   0,000391
CPU 14 DPC count:                                      51
_________________________________________________________________________________________________________
CPU 15 Interrupt cycle time (s):                       0,310336
CPU 15 ISR highest execution time (µs):                1,973948
CPU 15 ISR total execution time (s):                   0,000258
CPU 15 ISR count:                                      253
CPU 15 DPC highest execution time (µs):                39,979960
CPU 15 DPC total execution time (s):                   0,000298
CPU 15 DPC count:                                      33
_________________________________________________________________________________________________________

Attached Files


  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Don't use the Reply button in the top right.  Just start typing in the window at the bottom where it says Reply to this topic.  That way it won't copy everything I say.

 

Uninstall Clam Win Antivirus.  It should have turned off Windows Defender when it was installed but it didn't.  Windows Defender is actually a decent antivirus so you can let it run by itself for a while.

 

Open an elevated command prompt:
 
 
If you open an elevated command prompt it will by default open in c:\Windows\system32
 
Once you have an elevated command prompt:
 
Type:
 
 DISM  /Online  /Cleanup-Image  /RestoreHealth
 
 (I use two spaces so you can be sure to see where one space goes.)
Hit Enter.  This will take a while (10-20 minutes) to complete.  Once the prompt returns:
 
Reboot.  Open an elevated Command Prompt again and type (with an Enter after the line):
 
sfc  /scannow
 
 
 
This will also take a few minutes.  
 
When it finishes it will say one of the following:
 
Windows did not find any integrity violations (a good thing)
Windows Resource Protection found corrupt files and repaired them (a good thing)
Windows Resource Protection found corrupt files but was unable to fix some (or all) of them (not a good thing)
 
If you get the last result then type:
 
findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  \junk.txt 
 
Hit Enter.  Then type::
 
 
notepad  \junk.txt 
 
Hit Enter. 
 
 Copy the text from notepad and paste it into a reply.
 
 
After you finish SFC, regardless of the result:
 
 
 
1. Please download the Event Viewer Tool by Vino Rosso
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:
 
* System
4. Under 'Select type to list', select:
* Error
* Warning
 
 
Then use the 'Number of events' as follows:
 
 
1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.
 
 
Please post the Output log in your next reply then repeat but select Application.  (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)
 

 

Speccy is unable to read the SMART info on your hard drive.  Let's try HD Sentinel:

 

https://www.hdsentin...om/download.php

 

Download and Save the third one:  (Hard Disk Sentinel (standard) v5.50 (ZIP))

 

Right click on the downloaded file and extract all.  Extract. Then right click on the exe and Run As Admin.  Close the window that wants you to upgrade.

 

Click on Report then Save Txt Report

 

Copy and paste the report to a reply.

 

If it can't read it try Western Digital's Data Lifeguard Diagnostic for Windows

https://support.wdc....ds.aspx?lang=en

 

It's a zip so you have to save and extract then run as admin.  Have it do the extended test.  Takes hours.


  • 0

#7
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Hi. I was out of the country for a few days. 

I did everything you said. The sfc  /scannow found the files and fixed them without any problem. Now, the Event Viewer Tool by Vino Rosso didn't allow me to run it. A window popped up that said that it wasn't coded in my language (spanish) therefore it wouldn't run. 

Apart from that, everything went well. 

Here's the report from HD Sentinel: 

 

 

 
  -- General Information --
 
    Application Information
   -------------------------
    Installed Version  . . . . . . . . . . . . . . . : Hard Disk Sentinel 5.50
    Registered To  . . . . . . . . . . . . . . . . . : Unregistered version, please register.
    Current Date And Time  . . . . . . . . . . . . . : 11/8/2019 20:01:41
    Health Calculation Method  . . . . . . . . . . . : Analyse data field (default)
 
    Computer Information
   ----------------------
    Computer Name  . . . . . . . . . . . . . . . . . : DESKTOP-4LAFI5B
    User Name  . . . . . . . . . . . . . . . . . . . : Matoke
    Computer Type  . . . . . . . . . . . . . . . . . : Desktop
    IP Address . . . . . . . . . . . . . . . . . . . : 25.19.217.192,192.168.0.101
    MAC Address  . . . . . . . . . . . . . . . . . . : 7A-79-19-13-D9-C0
    System Uptime  . . . . . . . . . . . . . . . . . : 0 days, 0 hours, 31 minutes, 37 seconds
    System Idle Time . . . . . . . . . . . . . . . . : 0 days, 0 hours, 0 minutes, 0 seconds
    System Up Since  . . . . . . . . . . . . . . . . : 11/8/2019 19:30:04
    CPU Usage  . . . . . . . . . . . . . . . . . . . : CPU #1: 4 %, CPU #2: 1 %, CPU #3: 4 %, CPU #4: 1 %, CPU #5: 4 %, CPU #6: 1 %, CPU #7: 1 %, CPU #8: 15 %, CPU #9: 1 %, CPU #10: 1 %, CPU #11: 4 %, CPU #12: 1 %, CPU #13: 1 %, CPU #14: 1 %, CPU #15: 7 %, CPU #16: 1 %
    Virtual Memory . . . . . . . . . . . . . . . . . : 10939 MB, Used: 4310 MB (39 %)
 
    System Information
   --------------------
    Windows Version  . . . . . . . . . . . . . . . . : Windows 10 Pro 
    CPU Type & Speed #1  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #2  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #3  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #4  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #5  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #6  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #7  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #8  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #9  . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #10 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #11 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #12 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #13 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #14 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #15 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    CPU Type & Speed #16 . . . . . . . . . . . . . . : AMD Ryzen 7 1700 Eight-Core Processor, 2994 MHz
    BIOS Manufacturer  . . . . . . . . . . . . . . . : AMI
    Physical Memory Size . . . . . . . . . . . . . . : 8124 MB, Used: 3170 MB (39 %)
    Display Adapter  . . . . . . . . . . . . . . . . : NVIDIA GeForce GTX 1050
    Display Resolution . . . . . . . . . . . . . . . : 1920 x 1080 (32 bit)
    Printer #1 . . . . . . . . . . . . . . . . . . . : Fax
    Printer #2 . . . . . . . . . . . . . . . . . . . : HP543555 (HP Deskjet 3540 series)
    Printer #3 . . . . . . . . . . . . . . . . . . . : Microsoft Print to PDF
    Printer #4 . . . . . . . . . . . . . . . . . . . : Microsoft XPS Document Writer
    Printer #5 . . . . . . . . . . . . . . . . . . . : S-1-5-21-1830811996-1437030023-4132568959-1004:OneNote
    Printer #6 . . . . . . . . . . . . . . . . . . . : Send To OneNote 2016
    Network Controller . . . . . . . . . . . . . . . : Realtek PCIe GbE Family Controller
    Optical Drive
 
    PCI Device Information
   ------------------------
    PCI Bus 0; Device 1; Function 3  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 0; Device 3; Function 1  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 0; Device 7; Function 1  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 0; Device 8; Function 1  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 1; Device 0; Function 0  . . . . . . . . : %1 USB %2 eXtensible Host Controller - %3 (Microsoft);(AMD,3.10,1.10)
    PCI Bus 1; Device 0; Function 1  . . . . . . . . : Standard SATA AHCI Controller
    PCI Bus 1; Device 0; Function 2  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 2; Device 0; Function 0  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 2; Device 4; Function 0  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 2; Device 5; Function 0  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 2; Device 6; Function 0  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 2; Device 7; Function 0  . . . . . . . . : PCI-to-PCI Bridge
    PCI Bus 3; Device 0; Function 0  . . . . . . . . : ASMedia USB3.1 eXtensible Host Controller (ASM1143)
    PCI Bus 6; Device 0; Function 0  . . . . . . . . : Realtek PCIe GbE Family Controller
    PCI Bus 8; Device 0; Function 0  . . . . . . . . : NVIDIA GeForce GTX 1050
    PCI Bus 8; Device 0; Function 1  . . . . . . . . : High Definition Audio Controller
    PCI Bus 9; Device 0; Function 2  . . . . . . . . : AMD PSP 3.0 Device
    PCI Bus 9; Device 0; Function 3  . . . . . . . . : %1 USB %2 eXtensible Host Controller - %3 (Microsoft);(AMD,3.0,1.0)
    PCI Bus 10; Device 0; Function 2 . . . . . . . . : Standard SATA AHCI Controller
    PCI Bus 10; Device 0; Function 3 . . . . . . . . : High Definition Audio Controller
 
 
 
  -- Physical Disk Information - Disk: #0: WDC WD10EZEX-08WN4A0 --
 
    Hard Disk Summary
   -------------------
    Hard Disk Number . . . . . . . . . . . . . . . . : 0
    Interface  . . . . . . . . . . . . . . . . . . . : S-ATA Gen3, 6 Gbps
    Disk Controller  . . . . . . . . . . . . . . . . : Controladora SATA AHCI estándar (AHCI) [VEN: 1022, DEV: 43B7] Version: 10.0.17134.1, 6-21-2006
    Disk Location  . . . . . . . . . . . . . . . . . : Bus Number 0, Target Id 0, LUN 0
    Hard Disk Model ID . . . . . . . . . . . . . . . : WDC WD10EZEX-08WN4A0
    Firmware Revision  . . . . . . . . . . . . . . . : 02.01A02
    Hard Disk Serial Number  . . . . . . . . . . . . : WD-WCC6Y1VLZNPT
    Total Size . . . . . . . . . . . . . . . . . . . : 953867 MB
    Power State  . . . . . . . . . . . . . . . . . . : Active
    Logical Drive(s) . . . . . . . . . . . . . . . . : C: [] 
    Current Temperature  . . . . . . . . . . . . . . : 27 °C
    Power On Time  . . . . . . . . . . . . . . . . . : 89 days, 19 hours
    Estimated Remaining Lifetime . . . . . . . . . . : more than 1000 days
    Health . . . . . . . . . . . . . . . . . . . . . : #################### 100 % (Excellent)
    Performance  . . . . . . . . . . . . . . . . . . : #################### 100 % (Excellent)
 
    The hard disk status is PERFECT. Problematic or weak sectors were not found and there are no spin up or data transfer errors. 
      No actions needed.
 
    ATA Information
   -----------------
    Hard Disk Cylinders  . . . . . . . . . . . . . . : 1938021
    Hard Disk Heads  . . . . . . . . . . . . . . . . : 16
    Hard Disk Sectors  . . . . . . . . . . . . . . . : 63
    ATA Revision . . . . . . . . . . . . . . . . . . : ACS-3 Revision 3b
    Transport Version  . . . . . . . . . . . . . . . : SATA Rev 3.1
    Total Sectors  . . . . . . . . . . . . . . . . . : 244190646
    Bytes Per Sector . . . . . . . . . . . . . . . . : 4096 [Advanced Format]
    Multiple Sectors . . . . . . . . . . . . . . . . : 16
    Error Correction Bytes . . . . . . . . . . . . . : 0
    Unformatted Capacity . . . . . . . . . . . . . . : 953870 MB
    Maximum PIO Mode . . . . . . . . . . . . . . . . : 4
    Maximum Multiword DMA Mode . . . . . . . . . . . : 2
    Highest Possible Transfer Rate . . . . . . . . . : S-ATA Gen3 Signaling Speed (6 Gps)
    Negotiated Transfer Rate . . . . . . . . . . . . : S-ATA Gen3 Signaling Speed (6 Gps)
    Minimum Multiword DMA Transfer Time  . . . . . . : 120 ns
    Recommended Multiword DMA Transfer Time  . . . . : 120 ns
    Minimum PIO Transfer Time Without IORDY  . . . . : 120 ns
    Minimum PIO Transfer Time With IORDY . . . . . . : 120 ns
    ATA Control Byte . . . . . . . . . . . . . . . . : Valid
    ATA Checksum Value . . . . . . . . . . . . . . . : Valid
 
    Acoustic Management Configuration
   -----------------------------------
    Acoustic Management  . . . . . . . . . . . . . . : Not supported
    Acoustic Management  . . . . . . . . . . . . . . : Disabled
    Current Acoustic Level . . . . . . . . . . . . . : Default (00h)
    Recommended Acoustic Level . . . . . . . . . . . : Default (00h)
 
    ATA Features
   --------------
    Read Ahead Buffer  . . . . . . . . . . . . . . . : Supported, Enabled
    DMA  . . . . . . . . . . . . . . . . . . . . . . : Supported
    Ultra DMA  . . . . . . . . . . . . . . . . . . . : Supported
    S.M.A.R.T. . . . . . . . . . . . . . . . . . . . : Supported
    Power Management . . . . . . . . . . . . . . . . : Supported
    Write Cache  . . . . . . . . . . . . . . . . . . : Supported
    Host Protected Area  . . . . . . . . . . . . . . : Supported
    HPA Security Extensions  . . . . . . . . . . . . : Supported
    Advanced Power Management  . . . . . . . . . . . : Supported, Enabled
    Advanced Power Management Level  . . . . . . . . : Minimum power consumption without standby (128)
    Extended Power Management  . . . . . . . . . . . : Not supported
    Power Up In Standby  . . . . . . . . . . . . . . : Not supported
    48-Bit LBA Addressing  . . . . . . . . . . . . . : Supported
    Device Configuration Overlay . . . . . . . . . . : Supported
    IORDY Support  . . . . . . . . . . . . . . . . . : Supported
    Read/Write DMA Queue . . . . . . . . . . . . . . : Not supported
    NOP Command  . . . . . . . . . . . . . . . . . . : Not supported
    Trusted Computing  . . . . . . . . . . . . . . . : Not supported
    64-Bit World Wide ID . . . . . . . . . . . . . . : 50014EE2BA588718
    Streaming  . . . . . . . . . . . . . . . . . . . : Not supported
    Media Card Pass Through  . . . . . . . . . . . . : Not supported
    General Purpose Logging  . . . . . . . . . . . . : Supported
    Error Logging  . . . . . . . . . . . . . . . . . : Supported
    CFA Feature Set  . . . . . . . . . . . . . . . . : Not supported
    CFast Device . . . . . . . . . . . . . . . . . . : Not supported
    Long Physical Sectors (8)  . . . . . . . . . . . : Supported
    Long Logical Sectors . . . . . . . . . . . . . . : Not supported
    Write-Read-Verify  . . . . . . . . . . . . . . . : Not supported
    NV Cache Feature . . . . . . . . . . . . . . . . : Not supported
    NV Cache Power Mode  . . . . . . . . . . . . . . : Not supported
    NV Cache Size  . . . . . . . . . . . . . . . . . : Not supported
    Free-fall Control  . . . . . . . . . . . . . . . : Not supported
    Free-fall Control Sensitivity  . . . . . . . . . : Not supported
    Service Interrupt  . . . . . . . . . . . . . . . : Not supported
    IDLE IMMEDIATE Command With UNLOAD Feature . . . : Supported
    Nominal Media Rotation Rate  . . . . . . . . . . : 7200 RPM
    Nominal Form Factor  . . . . . . . . . . . . . . : 3.5 inch
 
    SSD Features
   --------------
    Data Set Management  . . . . . . . . . . . . . . : Not supported
    TRIM Command . . . . . . . . . . . . . . . . . . : Not supported
    Deterministic Read After TRIM  . . . . . . . . . : Not supported
    Read Zeroes After TRIM . . . . . . . . . . . . . : Not supported
 
    S.M.A.R.T. Details
   --------------------
    Off-line Data Collection Status  . . . . . . . . : Successfully Completed
    Self Test Execution Status . . . . . . . . . . . : Successfully Completed
    Total Time To Complete Off-line Data Collection  : 10740 seconds
    Execute Off-line Immediate . . . . . . . . . . . : Supported
    Abort/restart Off-line By Host . . . . . . . . . : Not supported
    Off-line Read Scanning . . . . . . . . . . . . . : Supported
    Short Self-test  . . . . . . . . . . . . . . . . : Supported
    Extended Self-test . . . . . . . . . . . . . . . : Supported
    Conveyance Self-test . . . . . . . . . . . . . . : Supported
    Selective Self-Test  . . . . . . . . . . . . . . : Supported
    Save Data Before/After Power Saving Mode . . . . : Supported
    Enable/Disable Attribute Autosave  . . . . . . . : Supported
    Error Logging Capability . . . . . . . . . . . . : Supported
    Short Self-test Estimated Time . . . . . . . . . : 2 minutes
    Extended Self-test Estimated Time  . . . . . . . : 112 minutes
    Conveyance Self-test Estimated Time  . . . . . . : 5 minutes
    Last Short Self-test Result  . . . . . . . . . . : Never Started
    Last Short Self-test Date  . . . . . . . . . . . : Never Started
    Last Extended Self-test Result . . . . . . . . . : Never Started
    Last Extended Self-test Date . . . . . . . . . . : Never Started
    Last Conveyance Self-test Result . . . . . . . . : Never Started
    Last Conveyance Self-test Date . . . . . . . . . : Never Started
 
    Security Mode
   ---------------
    Security Mode  . . . . . . . . . . . . . . . . . : Supported
    Security Erase . . . . . . . . . . . . . . . . . : Supported
    Security Erase Time  . . . . . . . . . . . . . . : 118 minutes
    Security Enhanced Erase Feature  . . . . . . . . : Supported
    Security Enhanced Erase Time . . . . . . . . . . : 118 minutes
    Security Enabled . . . . . . . . . . . . . . . . : No
    Security Locked  . . . . . . . . . . . . . . . . : No
    Security Frozen  . . . . . . . . . . . . . . . . : Yes
    Security Counter Expired . . . . . . . . . . . . : No
    Security Level . . . . . . . . . . . . . . . . . : High
    Device Encrypts All User Data  . . . . . . . . . : No
    Sanitize . . . . . . . . . . . . . . . . . . . . : Not supported
    Overwrite  . . . . . . . . . . . . . . . . . . . : Not supported
    Crypto Scramble  . . . . . . . . . . . . . . . . : Not supported
    Block Erase  . . . . . . . . . . . . . . . . . . : Not supported
    Sanitize Antifreeze Lock . . . . . . . . . . . . : Not supported
    ACS-3 Commands Allowed By Sanitize . . . . . . . : No
 
    Serial ATA Features
   ---------------------
    S-ATA Compliance . . . . . . . . . . . . . . . . : Yes
    S-ATA I Signaling Speed (1.5 Gps)  . . . . . . . : Supported
    S-ATA II Signaling Speed (3 Gps) . . . . . . . . : Supported
    S-ATA Gen3 Signaling Speed (6 Gps) . . . . . . . : Supported
    Receipt Of Power Management Requests From Host . : Not supported
    PHY Event Counters . . . . . . . . . . . . . . . : Supported
    Non-Zero Buffer Offsets In DMA Setup FIS . . . . : Not supported
    DMA Setup Auto-Activate Optimization . . . . . . : Supported, Disabled
    Device Initiating Interface Power Management . . : Supported, Disabled
    In-Order Data Delivery . . . . . . . . . . . . . : Not supported
    Asynchronous Notification  . . . . . . . . . . . : Not supported
    Software Settings Preservation . . . . . . . . . : Supported, Enabled
    Native Command Queuing (NCQ) . . . . . . . . . . : Supported
    Queue Length . . . . . . . . . . . . . . . . . . : 32
    NCQ Streaming  . . . . . . . . . . . . . . . . . : Not supported
    NCQ Autosense  . . . . . . . . . . . . . . . . . : Not supported
    Automatic Partial To Slumber Translations  . . . : Not supported
    Rebuild Assist . . . . . . . . . . . . . . . . . : Not supported
    Hybrid Information . . . . . . . . . . . . . . . : Not supported
    Device Sleep (DevSleep)  . . . . . . . . . . . . : Not supported
    DevSleep To ReducedPwrState  . . . . . . . . . . : Not supported
 
    Disk Information
   ------------------
    Disk Family  . . . . . . . . . . . . . . . . . . : Caviar Blue
    Form Factor  . . . . . . . . . . . . . . . . . . : 3.5" 
    Capacity . . . . . . . . . . . . . . . . . . . . : 1 TB (1 x 1.000.000.000.000 bytes)
    Number Of Disks  . . . . . . . . . . . . . . . . : ?
    Number Of Heads  . . . . . . . . . . . . . . . . : ?
    Rotational Speed . . . . . . . . . . . . . . . . : 7200 RPM
    Rotation Time  . . . . . . . . . . . . . . . . . : 8,33 ms
    Average Rotational Latency . . . . . . . . . . . : 4,17 ms
    Disk Interface . . . . . . . . . . . . . . . . . : Serial-ATA/600
    Buffer-Host Max. Rate  . . . . . . . . . . . . . : 600 MB/seconds
    Buffer Size  . . . . . . . . . . . . . . . . . . : 65536 KB
    Drive Ready Time (Typical) . . . . . . . . . . . : ? seconds
    Average Seek Time  . . . . . . . . . . . . . . . : ? ms
    Track To Track Seek Time . . . . . . . . . . . . : ? ms
    Full Stroke Seek Time  . . . . . . . . . . . . . : ? ms
    Width  . . . . . . . . . . . . . . . . . . . . . : 101,6 mm (4,0 inch)
    Depth  . . . . . . . . . . . . . . . . . . . . . : 147,0 mm (5,8 inch)
    Height . . . . . . . . . . . . . . . . . . . . . : 25,4 mm (1,0 inch)
    Weight . . . . . . . . . . . . . . . . . . . . . : 440 grams (1,0 pounds)
    Required Power For Spinup  . . . . . . . . . . . : ? mA
    Power Required (Seek)  . . . . . . . . . . . . . : ? W
    Power Required (Idle)  . . . . . . . . . . . . . : ? W
    Power Required (Standby) . . . . . . . . . . . . : ? W
    Manufacturer . . . . . . . . . . . . . . . . . . : Western Digital Corporation
    Manufacturer Website . . . . . . . . . . . . . . : http://www.westerndi...com/en/products
 
    S.M.A.R.T.
   ------------
No.  Attribute                Thre.. Value  Worst  Data                Status                   Flags                                                  
1    Raw Read Error Rate      51     200    200    000000000000        OK                       Self Preserving, Error-Rate, Performance, Statistica.. 
3    Spin Up Time             21     169    166    0000000009F6        OK                       Self Preserving, Performance, Statistical, Critical    
4    Start/Stop Count         0      100    100    000000000328        OK (Always passing)      Self Preserving, Event Count, Statistical              
5    Reallocated Sectors Co.. 140    200    200    000000000000        OK                       Self Preserving, Event Count, Statistical, Critical    
7    Seek Error Rate          0      200    200    000000000000        OK (Always passing)      Self Preserving, Error-Rate, Performance, Statistical  
9    Power On Time Count      0      98     98     00000000086B        OK (Always passing)      Self Preserving, Event Count, Statistical              
10   Spin Retry Count         0      100    100    000000000000        OK (Always passing)      Self Preserving, Event Count, Statistical              
11   Drive Calibration Retr.. 0      100    100    000000000000        OK (Always passing)      Self Preserving, Event Count, Statistical              
12   Drive Power Cycle Count  0      100    100    000000000322        OK (Always passing)      Self Preserving, Event Count, Statistical              
192  Power off Retract Cycl.. 0      200    200    000000000030        OK (Always passing)      Self Preserving, Event Count, Statistical              
193  Load/Unload Cycle Count  0      200    200    000000000301        OK (Always passing)      Self Preserving, Event Count, Statistical              
194  Disk Temperature         0      116    98     00000000001B        OK (Always passing)      Self Preserving, Statistical                           
196  Reallocation Event Count 0      200    200    000000000000        OK (Always passing)      Self Preserving, Event Count, Statistical              
197  Current Pending Sector.. 0      200    200    000000000000        OK (Always passing)      Self Preserving, Event Count, Statistical              
198  Off-Line Uncorrectable.. 0      200    200    000000000000        OK (Always passing)      Self Preserving, Event Count                           
199  Ultra ATA CRC Error Co.. 0      200    200    000000000000        OK (Always passing)      Self Preserving, Event Count, Statistical              
200  Write Error Rate         0      200    200    000000000000        OK (Always passing)      Error-Rate                                             
 
    Transfer Rate Information
   ---------------------------
    Total Data Read  . . . . . . . . . . . . . . . . : 17 MB,  17 MB since installation  (11/8/2019)
    Total Data Write . . . . . . . . . . . . . . . . : 1 MB,  1 MB since installation
    Average Reads Per Day  . . . . . . . . . . . . . : 17,00 MB
    Average Writes Per Day . . . . . . . . . . . . . : 1,00 MB
    Current Transfer Rate  . . . . . . . . . . . . . : 0 KB/s
    Maximum Transfer Rate  . . . . . . . . . . . . . : 3343 KB/s
    Current Read Rate  . . . . . . . . . . . . . . . : 0 KB/s
    Current Write Rate . . . . . . . . . . . . . . . : 0 KB/s
    Current Disk Activity  . . . . . . . . . . . . . : 0 %
 
 
 
  -- Partition Information --
 
Logical Drive                           Total Space         Free Space          Free Space               Used Space
C: (Disk: #0)                           930,9 GB            316,3 GB             34 %                    #############-------

  • 0

#8
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Delays are no problem.  I do not keep track and I am on a trip this week too.

 

Hard drive appears to be in good shape.  You can uninstall HD Sentinel.

 

Sorry about VEW.  Try FullEventLogView.

 

https://www.nirsoft....t_log_view.html

 

Download is near the bottom of the page.  Says:  Download FullEventLogView (64-bit version)

 

(We do not need the Spanish language overlay)

 

Save, Right click and Extract All Extract then right click on the exe and Run AS Admin.  Once it runs you can hit Stop then Option then Advanced Options.  Under Event Levels:

 

 

UNCHECK  Information and Verbose 

Change the number of days to 1  if you have restarted today.  Otherwise use the number of days since your last restart.then OK.  It will take a few seconds to process.  When the Stop goes away it is done.  Click on Ctrl + a to select all events then File, Save Selected Events, (to your desktop), call it Events.  OK.  Open Events.txt and copy and paste to a reply.


  • 0

#9
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Hi, here's the txt.

I was wondering if you could help me with reimage plus as well (the pop up page that appears sometimes when you are browsing) since we are in spirit of solving problems. It's been bothering for some time and I wasn't able to solve it. I understand though if you don't want to. There are other things more important, plus we are not finished with the main issue.

Anyway, here's what you asked for (attached as a file since it wouldn't let me paste it). 

 

 

 

 

Attached Files


  • 0

#10
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Generally the reimage ads come from some software you installed.  Looking at your FRST installed software list I see two that are hidden that do not have a good rep.

 

bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden

ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden

 

You should be able to uninstall them with an elevated command prompt:

 

Open an elevated command prompt:

http://www.howtogeek...-in-windows-10/

(If you open an elevated Command Prompt properly it will say Administrator: Command Prompt in the margin at the top of the window)


Once you have an elevated command prompt:

Type (or copy and paste):

MsiExec.exe /x {2A075BB4-E976-4278-BF3F-E5C6945D84C0}

then hit Enter.  Repeat for:

MsiExec.exe /x {185F9795-9663-4F13-9EF9-307A282ADB5A}

Then run a new FRST scan to verify that both are gone.


  • 0

Advertisements


#11
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Did as you said.

 

Here is the FRST,txt and the Addition.txt: 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-08-2019

Ran by Matoke (administrator) on DESKTOP-4LAFI5B (21-08-2019 10:26:21)
Running from C:\Users\amd\Desktop\Kit salva compu
Loaded Profiles: Matoke (Available Profiles: Matoke & Otros)
Platform: Windows 10 Pro Version 1803 17134.950 (X64) Language: Español (México)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\IPCBox\AdobeIPCBroker.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler.exe
(Google Inc -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.34.11\GoogleCrashHandler64.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(GoPro Media, Inc. -> ) C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe
(LogMeIn, Inc. -> LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19051.16210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\NisSrv.exe
(Node.js Foundation -> Node.js) C:\Program Files (x86)\Common Files\Adobe\Creative Cloud Libraries\libs\node.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Plex, Inc -> Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.51.72.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.51.72.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation -> Microsoft Corporation)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [598200 2018-09-28] (Razer USA Ltd. -> Razer Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2622520 2019-05-19] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5890504 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3148576 2019-06-17] (Valve -> Valve Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Discord] => C:\Users\amd\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [35826064 2019-08-08] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [18666984 2018-12-14] (Plex, Inc -> Plex, Inc.)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe [23913464 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Run: [Skype for Desktop] => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe [53646912 2019-06-20] (Skype Software Sarl -> Skype Technologies S.A.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00F4F76B-A514-46C8-9041-AC8F1F0C5C9B} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {0B46341C-A7E7-40F9-80B0-9D1B8921E0E5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27351656 2019-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {1ED78B5C-3A99-4E5F-8E27-F003DF678504} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-23] (Google Inc -> Google Inc.)
Task: {3739E659-3D9C-4A55-821E-D017128D0A87} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1447512 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {40FA51BE-AEAA-4CA1-B73B-97530A85869B} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4599A762-E0B5-4246-8CDF-74B64E7AA6EF} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {485416D2-BC05-48E7-9A3D-3B9FFCE7BBBC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-23] (Google Inc -> Google Inc.)
Task: {4D328107-ED1C-4530-BD4C-F433198AC403} - System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1830811996-1437030023-4132568959-1004 => C:\Users\amd\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {5B102A4B-0616-4F2D-B1A4-A45D0BA2A7CA} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [1447512 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {6165886F-17B6-4723-A645-BCDC886E0776} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [114736 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {6635DC11-B66B-4F5C-9FDA-6C665A941ED1} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {6DE9B58E-2767-484C-AFDE-10FC1F0EE760} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {74641703-D788-4113-BBD2-DB0BFE834925} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4519576 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {8487F195-19CA-48A1-9358-C9DF5F516FF4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {8BC84566-CC39-4CBE-8C36-D777FB571A3E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16835256 2019-07-11] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A06075E6-3777-4563-B86C-539113003152} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-07-11] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A944E701-F2C4-4351-80EC-D289880AF00A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [4519576 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF137F09-55AC-49AD-A05A-EC79B4F65130} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B82B48CC-E9E4-480D-A8AC-DB6FADE86FAE} - System32\Tasks\AdobeGCInvoker-1.0-DESKTOP-4LAFI5B-Matoke => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {BEC3D44E-57AF-4C07-8783-0D41C08FE14E} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CD096D00-209C-4C05-8429-1544AB9CFACC} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [114736 2019-08-19] (Microsoft Corporation -> Microsoft Corporation)
Task: {CF526D79-AAE9-456A-A1DA-8DF6F79EB36F} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CF7A22FF-51C6-4EFE-9E03-A8EFE14BF099} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {D1957C35-1B5A-483C-9745-24693D6FBF4A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D486A95A-E997-4DDB-B662-EBC4307EB521} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27351656 2019-08-07] (Microsoft Corporation -> Microsoft Corporation)
Task: {D4D624E7-4B22-4A16-B776-874A63CCFFE6} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3788144 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D55632DC-FAF3-4AD6-A362-6BE33B0A7831} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D5C93072-60ED-4351-9C65-BC314006E5C5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2045832 2019-08-19] (AVAST Software s.r.o. -> AVAST Software)
Task: {F49AE5A7-D544-43AF-A12C-20339E432107} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{54e2108c-8637-4bb9-95c6-a60275ec1987}: [DhcpNameServer] 208.67.220.220 208.67.222.222
Tcpip\..\Interfaces\{641c23af-61d5-46a6-a811-c61f189b2b88}: [NameServer] 8.8.8.8,8.8.4.4
ManualProxies: 
 
Internet Explorer:
==================
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-06-26] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-02] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-07-21] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-04-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2019-05-19] (Adobe Inc. -> Adobe Systems)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR DefaultSearchURL: Default -> hxxps://defaultsearch.co/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> Adaware Secure
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default [2019-08-21]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-08-05]
CHR Extension: (Chrome Media Router) - C:\Users\amd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-11]
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-02-23]
CHR Profile: C:\Users\amd\AppData\Local\Google\Chrome\User Data\System Profile [2019-02-23]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [816184 2019-05-19] (Adobe Inc. -> Adobe Inc.)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3117648 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2888272 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8473200 2019-03-27] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11469920 2019-08-08] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2018-12-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 GoProDeviceDetectionService; C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe [38328 2018-04-26] (GoPro Media, Inc. -> )
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3361736 2019-04-02] (LogMeIn, Inc. -> LogMeIn Inc.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc. -> LogMeIn, Inc.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PlexUpdateService; C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe [2247144 2018-12-14] (Plex, Inc -> Plex, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5074128 2019-08-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11660528 2018-12-07] (TeamViewer GmbH -> TeamViewer GmbH)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 Ds3Service; "C:\Users\amd\Desktop\Driver ps3\Drivers PS3 By Haniel\ScpServer\bin\ScpService.exe" [X]
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 amdgpio2; C:\WINDOWS\System32\drivers\amdgpio2.sys [34696 2018-05-11] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc)
R3 amdgpio3; C:\WINDOWS\System32\drivers\amdgpio3.sys [33144 2018-05-11] (AMD PMP-PE CB Code Signer v20160415 -> Advanced Micro Devices, Inc)
R3 AMDPCIDev; C:\WINDOWS\System32\drivers\AMDPCIDev.sys [31592 2018-04-25] (Advanced Micro Devices Inc. -> Advanced Micro Devices)
R0 amdpsp; C:\WINDOWS\System32\drivers\amdpsp.sys [137104 2018-05-11] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc. )
S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-05-13] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-05-13] (Disc Soft Ltd -> Disc Soft Ltd)
R3 Hamachi; C:\WINDOWS\system32\DRIVERS\Hamdrv.sys [45680 2019-04-02] (Microsoft Windows Hardware Compatibility Publisher -> LogMeIn Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvpcdi.inf_amd64_3f2e864e30bb9e15\nvlddmkm.sys [21858904 2019-07-18] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-06-13] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [75600 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
S3 rspLLL; C:\WINDOWS\System32\DRIVERS\rspLLL64.sys [26368 2015-07-13] (Daniel Terhell -> Resplendence Software Projects Sp.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [680416 2018-10-24] (Realtek Semiconductor Corp. -> Realtek )
R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [5707264 2018-04-11] (Microsoft Windows -> Realtek Semiconductor Corporation )
R3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [51728 2016-08-05] (Razer USA Ltd. -> Razer Inc)
R3 rzvkeyboard; C:\WINDOWS\System32\drivers\rzvkeyboard.sys [43536 2016-08-05] (Razer USA Ltd. -> Razer Inc)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [344288 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
R4 PxHlpa64; System32\Drivers\PxHlpa64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-19 14:26 - 2019-08-19 14:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Herramientas de Microsoft Office
2019-08-16 15:42 - 2019-08-16 15:42 - 000103338 _____ C:\Users\amd\Downloads\fulleventlogview-x64.zip
2019-08-14 16:43 - 2019-08-07 10:18 - 001786680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2019-08-14 16:43 - 2019-08-07 10:18 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2019-08-14 16:43 - 2019-08-07 10:13 - 021389776 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-08-14 16:43 - 2019-08-07 10:13 - 001632112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-08-14 16:43 - 2019-08-07 10:13 - 001515904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-08-14 16:43 - 2019-08-07 09:55 - 008626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-08-14 16:43 - 2019-08-07 09:54 - 004783104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2019-08-14 16:43 - 2019-08-07 09:53 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-08-14 16:43 - 2019-08-07 09:52 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-08-14 16:43 - 2019-08-07 09:43 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-08-14 16:43 - 2019-08-07 09:41 - 001322688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-08-14 16:43 - 2019-08-07 09:40 - 020384344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-08-14 16:43 - 2019-08-07 09:27 - 007990272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-08-14 16:43 - 2019-08-07 09:24 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-08-14 16:43 - 2019-08-07 09:24 - 001472000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-08-14 16:43 - 2019-08-07 05:09 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-08-14 16:43 - 2019-08-07 05:09 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-08-14 16:43 - 2019-08-07 05:08 - 007435720 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-08-14 16:43 - 2019-08-07 05:08 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-08-14 16:43 - 2019-08-07 05:08 - 002470648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-08-14 16:43 - 2019-08-07 05:08 - 001566736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-08-14 16:43 - 2019-08-07 05:08 - 000710232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-08-14 16:43 - 2019-08-07 05:08 - 000494992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-08-14 16:43 - 2019-08-07 05:07 - 009084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-08-14 16:43 - 2019-08-07 05:07 - 007520112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-08-14 16:43 - 2019-08-07 05:07 - 002719240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-08-14 16:43 - 2019-08-07 05:07 - 001459328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-08-14 16:43 - 2019-08-07 05:07 - 001260992 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-08-14 16:43 - 2019-08-07 05:07 - 000786288 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-08-14 16:43 - 2019-08-07 04:56 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-08-14 16:43 - 2019-08-07 04:56 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-08-14 16:43 - 2019-08-07 04:56 - 001993344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-08-14 16:43 - 2019-08-07 04:56 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-08-14 16:43 - 2019-08-07 04:55 - 000603792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-08-14 16:43 - 2019-08-07 04:49 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-08-14 16:43 - 2019-08-07 04:47 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-08-14 16:43 - 2019-08-07 04:44 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-08-14 16:43 - 2019-08-07 04:42 - 022717952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-08-14 16:43 - 2019-08-07 04:39 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-08-14 16:43 - 2019-08-07 04:38 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-08-14 16:43 - 2019-08-07 04:38 - 004385792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-08-14 16:43 - 2019-08-07 04:36 - 007572480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-08-14 16:43 - 2019-08-07 04:35 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-08-14 16:43 - 2019-08-07 04:35 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-08-14 16:43 - 2019-08-07 04:34 - 005769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-08-14 16:43 - 2019-08-07 04:34 - 001826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-08-14 16:43 - 2019-08-07 04:34 - 001680384 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-08-14 16:43 - 2019-08-07 04:34 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-08-14 16:43 - 2019-08-07 04:32 - 004938240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-08-14 16:43 - 2019-08-07 04:32 - 004516864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-08-14 16:43 - 2019-08-07 04:32 - 002165760 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-08-14 16:43 - 2019-08-07 04:32 - 001154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-08-14 16:43 - 2019-08-07 04:32 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-08-14 16:43 - 2019-08-07 04:31 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-08-14 16:43 - 2019-08-07 04:31 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-08-14 16:43 - 2019-08-07 04:31 - 000793088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-08-14 16:43 - 2019-08-07 04:31 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-08-14 16:43 - 2019-08-07 04:31 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-08-14 16:43 - 2019-07-10 22:30 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-08-14 16:43 - 2019-07-09 05:07 - 001627664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2019-08-14 16:43 - 2019-07-09 05:07 - 000827920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2019-08-14 16:43 - 2019-07-09 05:01 - 004527792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-08-14 16:43 - 2019-07-09 05:00 - 001616824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-08-14 16:43 - 2019-07-09 04:44 - 012757504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-08-14 16:43 - 2019-07-09 04:43 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-08-14 16:43 - 2019-07-09 04:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-08-14 16:43 - 2019-07-09 03:42 - 011943424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-08-14 16:43 - 2019-07-09 00:23 - 001213264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-08-14 16:43 - 2019-07-09 00:23 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-08-14 16:43 - 2019-07-09 00:21 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-08-14 16:43 - 2019-07-09 00:19 - 002769472 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-08-14 16:43 - 2019-07-09 00:19 - 002371504 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-08-14 16:43 - 2019-07-09 00:19 - 001674216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-08-14 16:43 - 2019-07-09 00:19 - 000799248 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2019-08-14 16:43 - 2019-07-09 00:19 - 000767232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-08-14 16:43 - 2019-07-09 00:12 - 002331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-08-14 16:43 - 2019-07-09 00:12 - 001286528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-08-14 16:43 - 2019-07-09 00:12 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-08-14 16:43 - 2019-07-09 00:11 - 002257336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-08-14 16:43 - 2019-07-08 23:55 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-08-14 16:43 - 2019-07-08 23:53 - 003708416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-08-14 16:43 - 2019-07-08 23:52 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-08-14 16:43 - 2019-07-08 23:50 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-08-14 16:43 - 2019-07-08 23:50 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-08-14 16:43 - 2019-07-08 23:50 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-08-14 16:43 - 2019-07-08 23:49 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-08-14 16:43 - 2019-07-08 23:49 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-08-14 16:43 - 2019-07-08 23:48 - 003402240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-08-14 16:43 - 2019-07-08 23:47 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-08-14 16:43 - 2019-07-08 23:47 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-08-14 16:43 - 2019-07-08 23:47 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-08-14 16:43 - 2019-07-08 23:47 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-08-14 16:43 - 2019-07-08 23:47 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-08-14 16:43 - 2019-07-08 23:47 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-08-14 16:43 - 2019-07-08 23:46 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-08-14 16:43 - 2019-07-08 23:46 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-08-14 16:43 - 2019-07-08 23:45 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-08-14 16:43 - 2019-07-08 23:45 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-08-14 16:43 - 2019-07-08 23:45 - 000510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-08-14 16:43 - 2019-07-08 23:44 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-08-14 16:43 - 2019-07-08 23:44 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-08-14 16:43 - 2019-07-08 23:44 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-08-14 16:43 - 2019-07-08 23:43 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-08-14 16:43 - 2019-07-08 23:43 - 001398272 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2019-08-14 16:43 - 2019-07-08 23:43 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-08-14 16:42 - 2019-08-07 10:14 - 000303928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mssecflt.sys
2019-08-14 16:42 - 2019-08-07 10:13 - 000790208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-08-14 16:42 - 2019-08-07 09:58 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-08-14 16:42 - 2019-08-07 09:58 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-08-14 16:42 - 2019-08-07 09:55 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2PGraph.dll
2019-08-14 16:42 - 2019-08-07 09:55 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2019-08-14 16:42 - 2019-08-07 09:53 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2019-08-14 16:42 - 2019-08-07 09:53 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2pnetsh.dll
2019-08-14 16:42 - 2019-08-07 09:51 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2019-08-14 16:42 - 2019-08-07 09:41 - 000662112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-08-14 16:42 - 2019-08-07 09:30 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-08-14 16:42 - 2019-08-07 09:30 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-08-14 16:42 - 2019-08-07 09:26 - 000366592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2PGraph.dll
2019-08-14 16:42 - 2019-08-07 09:26 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2019-08-14 16:42 - 2019-08-07 09:25 - 004175360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2019-08-14 16:42 - 2019-08-07 09:24 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\p2pnetsh.dll
2019-08-14 16:42 - 2019-08-07 06:40 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-08-14 16:42 - 2019-08-07 05:09 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-08-14 16:42 - 2019-08-07 05:09 - 001098064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-08-14 16:42 - 2019-08-07 05:09 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-08-14 16:42 - 2019-08-07 05:09 - 000194352 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-08-14 16:42 - 2019-08-07 05:09 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-08-14 16:42 - 2019-08-07 05:09 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-08-14 16:42 - 2019-08-07 05:09 - 000095008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-08-14 16:42 - 2019-08-07 05:08 - 001141712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-08-14 16:42 - 2019-08-07 05:08 - 000723216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-08-14 16:42 - 2019-08-07 05:08 - 000227744 _____ (Microsoft Corporation) C:\WINDOWS\system32\xmllite.dll
2019-08-14 16:42 - 2019-08-07 05:08 - 000170296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-08-14 16:42 - 2019-08-07 05:08 - 000130840 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-08-14 16:42 - 2019-08-07 05:08 - 000091568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-08-14 16:42 - 2019-08-07 05:07 - 001031696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2019-08-14 16:42 - 2019-08-07 05:07 - 000984152 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-08-14 16:42 - 2019-08-07 05:07 - 000115728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-08-14 16:42 - 2019-08-07 04:57 - 000081256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-08-14 16:42 - 2019-08-07 04:56 - 000357336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-08-14 16:42 - 2019-08-07 04:56 - 000192608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xmllite.dll
2019-08-14 16:42 - 2019-08-07 04:56 - 000101400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-08-14 16:42 - 2019-08-07 04:38 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-08-14 16:42 - 2019-08-07 04:38 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-08-14 16:42 - 2019-08-07 04:37 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2019-08-14 16:42 - 2019-08-07 04:37 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2019-08-14 16:42 - 2019-08-07 04:37 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-08-14 16:42 - 2019-08-07 04:36 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-08-14 16:42 - 2019-08-07 04:36 - 000354816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2019-08-14 16:42 - 2019-08-07 04:36 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2019-08-14 16:42 - 2019-08-07 04:36 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2019-08-14 16:42 - 2019-08-07 04:36 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2019-08-14 16:42 - 2019-08-07 04:36 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-08-14 16:42 - 2019-08-07 04:35 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2019-08-14 16:42 - 2019-08-07 04:35 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-08-14 16:42 - 2019-08-07 04:35 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2019-08-14 16:42 - 2019-08-07 04:35 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2019-08-14 16:42 - 2019-08-07 04:35 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2019-08-14 16:42 - 2019-08-07 04:34 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-08-14 16:42 - 2019-08-07 04:34 - 000521216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2019-08-14 16:42 - 2019-08-07 04:34 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-08-14 16:42 - 2019-08-07 04:34 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-08-14 16:42 - 2019-08-07 04:34 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-08-14 16:42 - 2019-08-07 04:33 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-08-14 16:42 - 2019-08-07 04:33 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpsrv.dll
2019-08-14 16:42 - 2019-08-07 04:33 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-08-14 16:42 - 2019-08-07 04:32 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2019-08-14 16:42 - 2019-08-07 04:32 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-08-14 16:42 - 2019-08-07 04:32 - 000318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2019-08-14 16:42 - 2019-08-07 04:32 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-08-14 16:42 - 2019-08-07 04:32 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-08-14 16:42 - 2019-08-07 04:31 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2019-08-14 16:42 - 2019-08-07 04:31 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-08-14 16:42 - 2019-08-07 04:31 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-08-14 16:42 - 2019-08-07 04:31 - 000367616 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2019-08-14 16:42 - 2019-08-07 03:15 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2019-08-14 16:42 - 2019-07-11 03:48 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-08-14 16:42 - 2019-07-10 22:30 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-08-14 16:42 - 2019-07-10 22:30 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 001038352 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPolicy.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000954384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVManifest.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000830480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000825360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000750096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000670224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000652304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000506088 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-08-14 16:42 - 2019-07-09 05:07 - 000495632 _____ (Microsoft Corporation) C:\WINDOWS\system32\TransportDSA.dll
2019-08-14 16:42 - 2019-07-09 05:07 - 000400696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2019-08-14 16:42 - 2019-07-09 05:04 - 000348664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-08-14 16:42 - 2019-07-09 04:44 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsUpdateElevatedInstaller.exe
2019-08-14 16:42 - 2019-07-09 04:43 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2019-08-14 16:42 - 2019-07-09 04:43 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2019-08-14 16:42 - 2019-07-09 04:40 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-08-14 16:42 - 2019-07-09 04:39 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2019-08-14 16:42 - 2019-07-09 04:39 - 001193472 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2019-08-14 16:42 - 2019-07-09 04:39 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2019-08-14 16:42 - 2019-07-09 04:38 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-08-14 16:42 - 2019-07-09 04:37 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-08-14 16:42 - 2019-07-09 04:37 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2019-08-14 16:42 - 2019-07-09 04:37 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-08-14 16:42 - 2019-07-09 04:37 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2019-08-14 16:42 - 2019-07-09 03:59 - 000022840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hvsicontainerservice.dll
2019-08-14 16:42 - 2019-07-09 03:38 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2019-08-14 16:42 - 2019-07-09 03:37 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2019-08-14 16:42 - 2019-07-09 00:29 - 000375312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-08-14 16:42 - 2019-07-09 00:29 - 000230200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2019-08-14 16:42 - 2019-07-09 00:29 - 000031032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2019-08-14 16:42 - 2019-07-09 00:21 - 000133136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2019-08-14 16:42 - 2019-07-09 00:20 - 000500536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-08-14 16:42 - 2019-07-09 00:20 - 000275512 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2019-08-14 16:42 - 2019-07-09 00:20 - 000227640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-08-14 16:42 - 2019-07-09 00:19 - 000713488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-08-14 16:42 - 2019-07-09 00:19 - 000152104 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-08-14 16:42 - 2019-07-09 00:19 - 000142352 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2019-08-14 16:42 - 2019-07-09 00:19 - 000046608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\werkernel.sys
2019-08-14 16:42 - 2019-07-09 00:12 - 000125504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-08-14 16:42 - 2019-07-09 00:11 - 000576528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2019-08-14 16:42 - 2019-07-09 00:11 - 000108560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2019-08-14 16:42 - 2019-07-08 23:56 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2019-08-14 16:42 - 2019-07-08 23:56 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2019-08-14 16:42 - 2019-07-08 23:55 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetDriverInstall.dll
2019-08-14 16:42 - 2019-07-08 23:55 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-08-14 16:42 - 2019-07-08 23:53 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-08-14 16:42 - 2019-07-08 23:52 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DuCsps.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2019-08-14 16:42 - 2019-07-08 23:51 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-08-14 16:42 - 2019-07-08 23:50 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-08-14 16:42 - 2019-07-08 23:50 - 000659456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-08-14 16:42 - 2019-07-08 23:50 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-08-14 16:42 - 2019-07-08 23:50 - 000141312 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2019-08-14 16:42 - 2019-07-08 23:50 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2019-08-14 16:42 - 2019-07-08 23:50 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdcpw.dll
2019-08-14 16:42 - 2019-07-08 23:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-08-14 16:42 - 2019-07-08 23:49 - 000856576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-08-14 16:42 - 2019-07-08 23:49 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-08-14 16:42 - 2019-07-08 23:49 - 000372736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2019-08-14 16:42 - 2019-07-08 23:49 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-08-14 16:42 - 2019-07-08 23:49 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-08-14 16:42 - 2019-07-08 23:49 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetDriverInstall.dll
2019-08-14 16:42 - 2019-07-08 23:48 - 000697344 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-08-14 16:42 - 2019-07-08 23:48 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-08-14 16:42 - 2019-07-08 23:48 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2019-08-14 16:42 - 2019-07-08 23:48 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-08-14 16:42 - 2019-07-08 23:48 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-08-14 16:42 - 2019-07-08 23:48 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2019-08-14 16:42 - 2019-07-08 23:47 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-08-14 16:42 - 2019-07-08 23:46 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-08-14 16:42 - 2019-07-08 23:46 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-08-14 16:42 - 2019-07-08 23:45 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-08-14 16:42 - 2019-07-08 23:45 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2019-08-14 16:42 - 2019-07-08 23:44 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-08-14 16:42 - 2019-07-08 23:44 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-08-14 16:42 - 2019-07-08 23:44 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-08-14 16:42 - 2019-07-08 23:44 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-08-14 16:42 - 2019-07-08 23:43 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2019-08-14 16:42 - 2019-06-19 23:21 - 000058882 _____ C:\WINDOWS\system32\srms.dat
2019-08-11 20:10 - 2019-08-11 20:10 - 000019680 _____ (EasyAntiCheat Oy) C:\WINDOWS\system32\eac_usermode_7238258728122.dll
2019-08-11 20:01 - 2019-08-11 20:01 - 000000000 ____D C:\Users\amd\AppData\Roaming\Hard Disk Sentinel
2019-08-11 19:12 - 2019-08-16 15:42 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2019-08-11 18:53 - 2019-08-11 18:53 - 000061440 _____ ( ) C:\Users\amd\Downloads\VEW.exe
2019-08-06 21:33 - 2019-07-18 16:15 - 001006800 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-08-06 21:33 - 2019-07-18 16:15 - 001006800 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-08-06 21:33 - 2019-07-18 16:15 - 000870096 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-08-06 21:33 - 2019-07-18 16:15 - 000870096 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-08-06 21:33 - 2019-07-18 16:15 - 000552144 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-08-06 21:33 - 2019-07-18 16:15 - 000456912 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-08-06 21:33 - 2019-07-18 16:15 - 000286416 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-08-06 21:33 - 2019-07-18 16:15 - 000286416 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-08-06 21:33 - 2019-07-18 16:15 - 000260304 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-08-06 21:33 - 2019-07-18 16:15 - 000260304 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-08-06 21:33 - 2019-07-18 16:14 - 011059408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-08-06 21:33 - 2019-07-18 16:14 - 009492680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 040411904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 035269568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 020193184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 017470416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 005426104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 004767912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 002042272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 001721816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443160.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 001543824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 001472600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 001468320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443160.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 001164376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 001136024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000914520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000822016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000810912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000677256 _____ C:\WINDOWS\system32\nvofapi64.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000656792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000633488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000543944 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2019-08-06 21:33 - 2019-07-18 16:13 - 000523920 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-08-06 20:27 - 2019-08-06 20:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LatencyMon
2019-08-06 20:27 - 2019-08-06 20:27 - 000000000 ____D C:\Program Files\LatencyMon
2019-08-06 20:27 - 2015-07-13 11:16 - 000026368 _____ (Resplendence Software Projects Sp.) C:\WINDOWS\system32\Drivers\rspLLL64.sys
2019-08-06 20:26 - 2019-08-06 20:26 - 002323432 _____ (Resplendence Software Projects Sp. ) C:\Users\amd\Downloads\LatencyMon (1).exe
2019-08-06 20:22 - 2019-08-06 20:22 - 000003936 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-08-06 20:22 - 2019-08-06 20:22 - 000002890 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2019-08-06 20:22 - 2019-08-06 20:22 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-08-06 20:22 - 2019-08-06 20:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-08-06 20:21 - 2019-08-06 20:22 - 000000000 ____D C:\Program Files\CCleaner
2019-08-06 20:21 - 2019-08-06 20:21 - 000000000 ____D C:\Program Files\Speccy
2019-08-06 20:20 - 2019-08-06 20:21 - 006889184 _____ (Piriform Ltd) C:\Users\amd\Downloads\spsetup132 (1).exe
2019-08-05 22:33 - 2019-08-05 22:35 - 000005705 _____ C:\Users\amd\Downloads\Fixlog.txt
2019-08-05 19:52 - 2019-08-05 19:52 - 003997227 _____ C:\Users\amd\Downloads\Historia del cine 2 - 2019 - completo - resumen (3).pdf
2019-08-04 21:58 - 2019-08-05 22:33 - 000000000 ____D C:\Users\amd\Downloads\FRST-OlderVersion
2019-08-02 15:16 - 2019-08-19 14:25 - 000212992 _____ C:\WINDOWS\system32\ClickToRun_Pipeline16
2019-07-31 19:38 - 2019-07-31 19:38 - 001028376 _____ C:\Users\amd\Downloads\Blockhouse.zip
2019-07-31 18:39 - 2019-07-31 18:39 - 000000000 ____D C:\Users\amd\AppData\Roaming\NVIDIA
2019-07-30 16:26 - 2019-07-30 16:26 - 000124674 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-06-25 at 1.19.28 PM (1).jpeg
2019-07-30 16:26 - 2019-07-30 16:26 - 000104282 _____ C:\Users\amd\Downloads\WhatsApp Image 2019-06-25 at 1.19.29 PM (1).jpeg
2019-07-29 16:07 - 2019-07-29 16:07 - 000000000 ____D C:\Users\amd\Documents\This War of Mine
2019-07-29 16:07 - 2019-07-29 16:07 - 000000000 ____D C:\Users\amd\AppData\Roaming\11bitstudios
2019-07-29 14:53 - 2019-08-21 10:26 - 000000000 ____D C:\Users\amd\Desktop\Kit salva compu
2019-07-29 14:46 - 2019-07-29 14:46 - 000004443 _____ C:\Users\amd\Downloads\ckfiles.txt
2019-07-24 23:46 - 2019-08-05 22:49 - 000050913 _____ C:\Users\amd\Downloads\Addition.txt
2019-07-24 23:42 - 2019-08-05 22:49 - 000075155 _____ C:\Users\amd\Downloads\FRST.txt
2019-07-24 22:58 - 2019-07-29 14:53 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2019-07-24 22:57 - 2019-07-24 22:58 - 047441489 _____ C:\Users\amd\Downloads\MSIAfterburnerSetup.zip
2019-07-24 22:50 - 2019-07-24 22:50 - 000001447 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2019-07-24 22:45 - 2019-07-17 18:10 - 005435192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-07-24 22:45 - 2019-07-17 18:10 - 002637352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-07-24 22:45 - 2019-07-17 18:10 - 001767920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-07-24 22:45 - 2019-07-17 18:10 - 000650608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-07-24 22:45 - 2019-07-17 18:10 - 000451056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-07-24 22:45 - 2019-07-17 18:10 - 000125424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-07-24 22:45 - 2019-07-17 18:10 - 000083440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-07-24 22:45 - 2019-07-16 05:18 - 008642772 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-07-24 22:45 - 2019-03-24 13:54 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-07-24 22:42 - 2019-07-24 22:42 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2019-07-24 22:33 - 2019-07-24 22:37 - 123477920 _____ (NVIDIA Corporation New) C:\Users\amd\Downloads\GeForce_Experience_v3.19.0.107.exe
2019-07-24 20:48 - 2019-07-24 20:49 - 250287771 _____ C:\Users\amd\Downloads\MAINCRENZIE.rar
2019-07-24 19:46 - 2019-07-24 19:46 - 005193376 _____ (Husdawg, LLC) C:\Users\amd\Downloads\Detection (2).exe
 
==================== One month (modified) ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2019-08-21 10:26 - 2018-07-24 15:06 - 000000000 ____D C:\FRST
2019-08-21 10:25 - 2018-04-11 20:36 - 000000000 ____D C:\WINDOWS\INF
2019-08-21 10:21 - 2018-04-11 20:38 - 000000000 ___HD C:\Program Files\WindowsApps
2019-08-21 10:21 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-08-21 10:20 - 2018-05-10 16:18 - 000000000 ____D C:\ProgramData\NVIDIA
2019-08-21 10:17 - 2018-04-11 20:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-08-19 15:32 - 2018-05-14 20:36 - 000000000 ____D C:\Users\amd\Desktop\MIS COSAS
2019-08-19 14:47 - 2018-05-10 16:19 - 000000000 ____D C:\Users\amd\AppData\Local\NVIDIA
2019-08-19 14:26 - 2019-06-30 15:46 - 000002580 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype Empresarial.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002531 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002512 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002485 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002443 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-08-19 14:26 - 2019-06-30 15:46 - 000002439 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-08-19 14:25 - 2018-05-13 22:05 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2019-08-16 17:22 - 2018-06-10 20:03 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-08-16 15:16 - 2018-05-10 15:33 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-08-16 15:16 - 2018-05-10 15:33 - 000000000 ___RD C:\Users\amd\3D Objects
2019-08-16 15:15 - 2018-12-19 18:02 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-08-16 15:15 - 2018-06-10 20:03 - 005101640 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-08-16 15:14 - 2018-06-10 20:18 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-08-14 17:26 - 2018-04-12 13:26 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2019-08-14 17:26 - 2018-04-12 13:21 - 000000000 ____D C:\WINDOWS\system32\Drivers\es-MX
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ___SD C:\WINDOWS\system32\UNP
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-08-14 17:26 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-08-14 17:26 - 2018-04-11 18:04 - 001310720 _____ C:\WINDOWS\system32\config\BBI
2019-08-14 16:50 - 2018-04-11 20:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-08-12 00:29 - 2018-07-20 02:36 - 000000000 ____D C:\Users\amd\AppData\Local\CrashDumps
2019-08-11 20:25 - 2018-06-10 20:07 - 000000000 ___HD C:\Users\amd
2019-08-08 18:53 - 2018-05-10 15:33 - 000000000 ____D C:\Users\amd\AppData\Local\Packages
2019-08-07 21:30 - 2019-02-23 16:19 - 000002299 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 21:30 - 2019-02-23 16:19 - 000002258 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-08-07 00:30 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-08-06 21:37 - 2018-07-30 02:44 - 000000000 ____D C:\temp
2019-08-06 21:37 - 2018-05-10 16:15 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-08-06 20:17 - 2018-07-25 01:36 - 000028050 _____ C:\junk.txt
2019-08-06 20:10 - 2018-07-25 01:45 - 000043192 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-08-05 23:07 - 2018-07-13 00:01 - 000000000 ___HD C:\Users\Public\Shared Files
2019-08-04 19:29 - 2019-03-13 21:44 - 000000000 ____D C:\Users\amd\Documents\Remedy
2019-08-03 01:17 - 2018-05-14 20:23 - 000000000 ____D C:\Program Files\Epic Games
2019-08-02 15:10 - 2018-11-17 00:38 - 000000000 ____D C:\Program Files\rempl
2019-07-31 18:45 - 2018-06-10 20:24 - 000000000 ____D C:\Users\amd\AppData\Local\D3DSCache
2019-07-30 01:59 - 2018-05-16 21:18 - 000000000 ____D C:\Users\amd\AppData\Roaming\vlc
2019-07-26 16:44 - 2018-12-02 20:13 - 000000000 ____D C:\WINDOWS\Minidump
2019-07-26 16:22 - 2018-05-10 18:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-07-24 22:50 - 2018-07-16 21:09 - 000003976 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:50 - 2018-07-16 21:09 - 000003940 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:50 - 2018-05-10 16:16 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2019-05-29 19:16 - 000003858 _____ C:\WINDOWS\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-07-16 21:08 - 000004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-07-16 21:08 - 000004106 _____ C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-06-10 20:18 - 000003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-06-10 20:18 - 000003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2019-07-24 22:49 - 2018-05-10 16:17 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-07-24 22:45 - 2019-07-06 00:56 - 000000000 ____D C:\Users\amd\AppData\Local\LogMeIn Hamachi
2019-07-24 22:45 - 2018-04-11 20:38 - 000000000 ____D C:\WINDOWS\Help
2019-07-24 21:59 - 2019-05-27 00:47 - 000000000 ____D C:\Users\amd\AppData\Roaming\.minecraft
2019-07-24 20:50 - 2019-05-27 00:45 - 000000000 ____D C:\Program Files (x86)\Minecraft Launcher
2019-07-23 18:00 - 2018-06-16 23:43 - 000000000 ____D C:\Users\amd\AppData\Roaming\discord
2019-07-22 13:35 - 2018-06-10 20:18 - 001762872 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-07-22 13:35 - 2018-04-12 13:21 - 000781218 _____ C:\WINDOWS\system32\perfh00A.dat
2019-07-22 13:35 - 2018-04-12 13:21 - 000152030 _____ C:\WINDOWS\system32\perfc00A.dat
 
==================== Files in the root of some directories ================
 
2019-06-20 23:11 - 2019-06-20 23:11 - 000000000 _____ () C:\Users\amd\AppData\Local\oobelibMkey.log
2018-08-09 20:09 - 2018-08-16 23:40 - 000007620 _____ () C:\Users\amd\AppData\Local\Resmon.ResmonCfg
 
==================== SigCheck ===============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ============================
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-08-2019
Ran by Matoke (21-08-2019 10:29:42)
Running from C:\Users\amd\Desktop\Kit salva compu
Windows 10 Pro Version 1803 17134.950 (X64) (2018-06-10 23:19:43)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrador (S-1-5-21-1830811996-1437030023-4132568959-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1830811996-1437030023-4132568959-503 - Limited - Disabled)
Invitado (S-1-5-21-1830811996-1437030023-4132568959-501 - Limited - Disabled)
matia (S-1-5-21-1830811996-1437030023-4132568959-1002 - Limited - Disabled)
Matoke (S-1-5-21-1830811996-1437030023-4132568959-1001 - Administrator - Enabled) => C:\Users\amd
Otros (S-1-5-21-1830811996-1437030023-4132568959-1004 - Limited - Enabled) => C:\Users\Otros
WDAGUtilityAccount (S-1-5-21-1830811996-1437030023-4132568959-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\uTorrent) (Version: 3.5.5.45271 - BitTorrent Inc.)
Actualización de NVIDIA 37.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 37.0.0.0 - NVIDIA Corporation) Hidden
Adobe After Effects 2019 (HKLM-x32\...\AEFT_16_1_1) (Version: 16.1.1 - Adobe Systems Incorporated)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated)
Adobe Animate CC 2015 (HKLM-x32\...\{8CEBC11D-C52F-11E5-A0D6-D44AB5E81A82}) (Version: 15.1 - Adobe Systems Incorporated)
Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.8.2.476 - Adobe Systems Incorporated)
Adobe Encore CS6 (HKLM-x32\...\{46251F95-B2F8-484A-9B5B-8C0E5A43A202}) (Version: 6.0.0 - Adobe Systems Incorporated)
Adobe Illustrator CC 2015 (HKLM-x32\...\{5680D629-B263-49CC-821E-3CEBD4507B51}) (Version: 19.0 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2015 (HKLM-x32\...\{38C72D42-0672-43B1-9E05-E7631684F9A1}) (Version: 9.0.0 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 17.7 - Advanced Micro Devices, Inc.)
AmericasCardroom (HKLM-x32\...\296836EA-EF3A-4C36-8C13-3A6C1DB2D4BE) (Version: 16.6 - IGSoft)
Apex Legends (HKLM-x32\...\{D7FBF176-382D-484E-863A-DFD1124A2A1C}) (Version: 1.0.0.4 - Electronic Arts, Inc.)
Balanced (HKLM-x32\...\{EFD0705E-598B-46D4-8D5B-4539431764B8}) (Version: 2.02.0000 - Nombre de su organización) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.60 - Piriform)
DaVinci Resolve (HKLM\...\{EA907964-FDE2-48E5-A8E4-41F2B4342FA8}) (Version: 16.0.0033 - Blackmagic Design)
DaVinci Resolve Panels (HKLM\...\{B1782967-E600-4BBD-B2F1-AEF3F2FE0A12}) (Version: 1.2.1.0 - Blackmagic Design)
Discord (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
DMMultiView (HKLM-x32\...\{8EEBAD15-F3B7-468B-917F-97BBF6B1004B}) (Version:  - )
Epic Games Launcher (HKLM-x32\...\{79F5479A-BF71-4F4C-9C49-9D616AF923DE}) (Version: 1.1.151.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
GeoVision MJPG (HKLM-x32\...\Codec_MJPG) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 76.0.3809.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
GoPro Quik (HKLM\...\{855E73D9-1EC0-4914-98D1-FD1FC7E93870}) (Version: 0.1.780 - GoPro, Inc.) Hidden
GoPro Quik (HKLM-x32\...\{e2b0610c-a7ad-4330-87ba-c30a14ff17e7}) (Version: 2.6.1.780 - GoPro, Inc.)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Java 8 Update 221 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180221F0}) (Version: 8.0.2210.11 - Oracle Corporation)
LatencyMon 6.71 (HKLM\...\LatencyMon_is1) (Version:  - Resplendence Software Projects Sp.)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\{ECC0FA07-863E-44BC-8B1D-DA22F96E5FB7}) (Version: 2.2.0.633 - LogMeIn, Inc.) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.633 - LogMeIn, Inc.)
Microsoft Office Profesional Plus 2016 - es-es (HKLM\...\ProPlusRetail - es-es) (Version: 16.0.11901.20218 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{ab058666-66d5-445f-bef6-76a4ab200ef1}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{449EFED6-5F86-4428-8EB2-3DA1F6E67CE4}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Minecraft Launcher (HKLM-x32\...\{E154B2C8-2F3E-4763-B3D5-E7D34AE39C6B}) (Version: 1.0.0.0 - Mojang)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.15 - NVIDIA Corporation) Hidden
NVIDIA Controlador de audio HD 1.3.38.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.16 - NVIDIA Corporation)
NVIDIA Controlador de gráficos 431.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 431.60 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.19.0.107 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.19.0.107 - NVIDIA Corporation)
NVIDIA Software del sistema PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11901.20218 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11901.20218 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11901.20218 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0C0A-0000-0000000FF1CE}) (Version: 16.0.11901.20218 - Microsoft Corporation) Hidden
Panel de control de NVIDIA 431.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 431.60 - NVIDIA Corporation) Hidden
Plex Media Server (HKLM-x32\...\{049535F6-B56E-4F73-B5A5-06369B94ED2E}) (Version: 1.14.1488 - Plex, Inc.) Hidden
Plex Media Server (HKLM-x32\...\{0a25946e-e061-47a7-9da4-d055bb78571d}) (Version: 1.14.1.5488 - Plex, Inc.)
Popcorn-Time (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\Popcorn-Time) (Version: 0.3.10 - Popcorn Time)
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.21.21.1 - Razer Inc.)
Skype versión 8.48 (HKLM-x32\...\Skype_is1) (Version: 8.48 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Stopping Plex (HKLM-x32\...\{A21C244F-E5E9-498C-90FB-CDBA86BA89CC}) (Version: 1.14.1488 - Plex, Inc.) Hidden
TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.1.3399 - TeamViewer)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 85.1 - Ubisoft)
Vegas Pro 13.0 (64-bit) (HKLM\...\{3934F12E-091D-11E4-A0AD-F04DA23A5C58}) (Version: 13.0.373 - Sony)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.7 - VideoLAN)
WinDirStat 1.1.2 (HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\WinDirStat) (Version:  - )
WinRAR 5.60 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
 
Packages:
=========
Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11901.20184.0_x64__8wekyb3d8bbwe [2019-08-02] (Microsoft Corporation) [MS Ad]
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_2.4.520.0_x64__rz1tebttyb220 [2019-03-13] (Dolby Laboratories)
Extensión de video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2018-10-12] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_100.1.581.0_x64__v10z8vjag6ke6 [2019-07-20] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Noticias -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.31.12124.0_x64__8wekyb3d8bbwe [2019-08-07] (Microsoft Corporation) [MS Ad]
MSN El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.31.11905.0_x64__8wekyb3d8bbwe [2019-07-20] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0 [2019-08-16] (Spotify AB)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-8999FA35C723} -> [Creative Cloud Files] => C:\Users\amd\Creative Cloud Files [2019-06-20 23:01]
CustomCLSID: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems)
ShellIconOverlayIdentifiers: [   AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ShellIconOverlayIdentifiers: [   AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-07-17] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> )
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\localhost -> localhost
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2017-09-29 10:46 - 2019-01-04 18:42 - 000055801 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 mydownloaddomain.com
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 texttotalk.org
127.0.0.1 gambling577.xyz
127.0.0.1 htagdownload.space
127.0.0.1 mybcnmonetize.com
127.0.0.1 360devtraking.website
127.0.0.1 dscdn.pw
127.0.0.1 bcnmonetize.go2affise.com
127.0.0.1 beautifllink.xyz
5.149.252.98 www.google-analytics.com
5.149.252.98 adservice.google.com
 
2018-05-20 17:09 - 2018-05-20 17:09 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\Control Panel\Desktop\\Wallpaper -> c:\users\amd\desktop\mis cosas\fotos\eclipse-solar-desde-espacio-5303c998cd1c9.jpg
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
If an entry is included in the fixlist, it will be removed.
 
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "XboxStat"
HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0"
HKLM\...\StartupApproved\Run32: => "Razer Synapse"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "LogMeIn Hamachi Ui"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Discord"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "EpicGamesLauncher"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_75BED9BC4FE28DE71792C715C05373CF"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Plex Media Server"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Skype for Desktop"
HKU\S-1-5-21-1830811996-1437030023-4132568959-1001\...\StartupApproved\Run: => "Lync"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{88E3E29D-109F-46CA-8ABB-4FAC74DE9764}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{232BF066-6AFA-4FB6-8B8C-258FD2AA095C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{B298653C-6BAB-4CCA-B65C-37F519AEFE6D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [{E2D48BAC-D002-4319-9A43-B7D6B9C52F95}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForestVR.exe () [File not signed]
FirewallRules: [UDP Query User{46C1F681-5175-4812-A704-0A018D087A0F}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [TCP Query User{CB8558D1-FF69-4771-986A-C2983A7D5446}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [{A4D6B4EE-7047-43BC-909B-5FF1F4911A6E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{D015CD49-13BE-4A89-BA7C-828AFA56A527}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\The Forest\TheForest.exe () [File not signed]
FirewallRules: [{5DAFBFA5-8A8F-4773-BF75-7B6D123C593D}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe (GoPro Media, Inc. -> )
FirewallRules: [{C9725F0F-0625-4FA0-85EB-FBF7A38DCE1E}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe (GoPro Media, Inc. -> )
FirewallRules: [{41A40A2A-E44C-44AD-A93A-4446FB8E4CA9}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe (GoPro Media, Inc. -> )
FirewallRules: [{CE208CB7-FEB1-4606-A637-A1C014A852E8}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro Quik.exe (GoPro Media, Inc. -> )
FirewallRules: [UDP Query User{C0A02348-D406-4393-8DAB-A47F8250E9BF}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{212AADF3-0D7A-4B97-BD5E-D558EFAA8095}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{1986FD76-61B9-48EB-90E8-50AB87B518ED}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{C7410143-03D1-4CB0-B8BE-5CF6D10EA1C9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{BFE94E1D-B42B-4799-B60B-6336E3F01D1F}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{14BC1D4B-28B3-4AD0-A3EA-97B954B29A81}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{881E906A-2F74-49C0-AAA0-5BE6EF13ABD7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{BDE08CFB-A8A7-4776-B108-37791A672AEB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{D3BC73DD-4794-4CA4-B22F-4FEF12DC5665}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{CC017309-7C26-4359-A151-1AE1D766CC4D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{378DBA21-D185-4130-9A42-F11651F8C453}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{B074AF06-8527-4F30-BDCE-8D9CE60A0D53}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{CB3F23E2-5A54-40B3-BAF2-DCBC60FD273E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D57043B8-7AB8-49A0-8243-ADF770A2B30C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{53837B31-8D2F-466C-8E38-1069A3E1C37D}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{45B402DD-CE34-43F1-830C-D0C80FF226B7}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{F5EBA397-3D6C-4658-9923-9C1FCFEB8134}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{E7D76357-97B3-491B-B6B2-C135A6ACEF96}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D8382B40-5C53-468C-A007-635FC233849F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{D43A96E2-F383-4917-BA90-431A11A42CFA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [TCP Query User{E06DD89F-C2D8-48C5-BB31-21157FD16FBE}C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed]
FirewallRules: [UDP Query User{041C8811-C93D-4C37-8098-CCD179390CB1}C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe] => (Allow) C:\users\amd\appdata\local\popcorn-time\popcorn-time.exe (The NWJS Community) [File not signed]
FirewallRules: [{9EA637D9-F5E4-41D8-9848-FBCD05793038}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{54E1A440-155B-4F00-90C5-88FC53B5DDAC}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{50308C51-107C-4B7D-9079-B6EF5170E396}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Town of Salem\TownOfSalem.exe () [File not signed]
FirewallRules: [{2A4AEF8E-C153-4052-90CA-269D568F821E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Town of Salem\TownOfSalem.exe () [File not signed]
FirewallRules: [{21AEFB78-DA26-4A84-8140-C02C95C4A30A}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{609ABCE4-9708-429A-A26F-40AFE31FEF37}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{5BECCA37-B0AC-4558-8118-39BE3AA0AACC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E4AF5CF5-AF77-427F-848F-68E9EA9B55C1}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{3EDB7FBE-1516-4B06-A430-4074E85DA702}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{DD83AE20-1140-49BA-9760-1AA24D2968F5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TheLongDark\tld.exe () [File not signed]
FirewallRules: [{D4DE269D-82ED-4781-9BF4-16674762D66C}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{ADD5AE4F-87C9-4370-9190-B39738090812}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{65922F68-02C0-4FF3-95F3-7D093F8B1283}] => (Allow) C:\Users\amd\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{88999D04-27E0-4E0C-B247-59A51236CBC5}] => (Allow) C:\Users\amd\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{C5521E59-5090-4F95-A302-A3219269926B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ring of Elysium\SLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{E0C3C56D-995E-49C9-968A-B2D52B3A6DB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ring of Elysium\SLauncher.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{C3EC1744-1DC4-4E0C-9D8D-B0333C188CCD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{9EAACC06-4304-45E6-9BA1-4F2F0F1447AF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{381B9BC2-805C-454B-B7FC-8699684D2E89}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [{C81F32D9-96BA-4D98-8B82-C17CD10ED9BA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH)
FirewallRules: [TCP Query User{13361F34-2D40-4372-9EA8-4B675F765DE2}C:\program files\epic games\subnautica\subnautica.exe] => (Allow) C:\program files\epic games\subnautica\subnautica.exe () [File not signed]
FirewallRules: [UDP Query User{94F26278-01EC-4A69-9450-F7168943E058}C:\program files\epic games\subnautica\subnautica.exe] => (Allow) C:\program files\epic games\subnautica\subnautica.exe () [File not signed]
FirewallRules: [{80E3F48E-EFC3-419D-BCEF-E28AE2CD6550}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [{E8562E62-FE35-4E65-83F4-56D0383FF1F7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe () [File not signed]
FirewallRules: [TCP Query User{E999B8F4-2717-4915-BA23-0E390665D14F}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [UDP Query User{AA8257FA-4E74-4CD8-AB50-FCB9201ADCCF}C:\program files (x86)\origin games\apex\r5apex.exe] => (Allow) C:\program files (x86)\origin games\apex\r5apex.exe (Electronic Arts, Inc. -> Respawn Entertainment)
FirewallRules: [TCP Query User{706521BE-B3C4-432D-8359-908201175E6D}C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe No File
FirewallRules: [UDP Query User{EFADB801-A1F2-4014-A2FF-13290243BFDE}C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\obduction\obduction\binaries\win64\obduction-win64-shipping.exe No File
FirewallRules: [{33A53120-D49A-4FE5-9819-DB194B121DC5}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{001BB55E-C9F3-45D8-BE44-B73CDAD38EC0}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{AEB573C4-19A5-4CA7-8D82-E59649FCA00F}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{C7DC833A-D8BA-47F3-8660-49CB63B90E03}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe (Plex, Inc -> Python Software Foundation)
FirewallRules: [{C6DBD3F6-EB35-46C3-A64C-4430DEB5D042}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex DLNA Server.exe (Plex, Inc -> Plex, Inc.)
FirewallRules: [{8B7C3E07-989F-419D-A2F8-ECED19B56BD5}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Tuner Service.exe (Plex, Inc -> Plex)
FirewallRules: [{D0892972-8796-4E5F-9655-04DCD277FA88}] => (Allow) C:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{892528D0-600B-4F09-94BB-9F90EF29D7EB}] => (Allow) C:\Program Files (x86)\Origin Games\Apex\EasyAntiCheat_launcher.exe (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
FirewallRules: [{2A95D321-66A4-4E56-AF4B-5B45515B5335}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alan Wake\AlanWake.exe No File
FirewallRules: [{188F6E2E-8A5B-4EDB-BB95-DEE071026A99}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Alan Wake\AlanWake.exe No File
FirewallRules: [{BC2198CF-F58B-417C-AB36-3F61B09FB61E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8D82FA1A-A146-4272-9F5B-C5B36019D936}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{56D45FB2-91E6-4FB7-99E5-77CC3F74C338}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe () [File not signed]
FirewallRules: [{2875CEA6-1A6B-44D1-8F30-EBE1E01062E1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe () [File not signed]
FirewallRules: [TCP Query User{4917E636-7D06-41FD-8533-5404D48A47E1}C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe] => (Allow) C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe (Phoenix Labs -> Phoenix Labs)
FirewallRules: [UDP Query User{9BD7052E-3BF6-475C-87EB-028DB1487797}C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe] => (Allow) C:\program files\epic games\dauntless\archon\binaries\win64\dauntless-win64-shipping.exe (Phoenix Labs -> Phoenix Labs)
FirewallRules: [TCP Query User{000B4821-E27A-423A-A2BE-985653130CEC}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [UDP Query User{411E6683-1433-47F0-8503-93F164167388}C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft launcher\runtime\jre-x64\bin\javaw.exe
FirewallRules: [{5E44AAC1-EE7A-4916-9A4E-8AEF4556D61D}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5171F884-236E-43C6-A707-FF09451739E6}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty Ltd -> Blackmagic Design Pty. Ltd.)
FirewallRules: [{E6E69058-2D38-45D7-834C-7401FF0EC505}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\bmdpaneld.exe () [File not signed]
FirewallRules: [{6DC35D5D-6DA7-4B30-83A5-CE0D80B9E568}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DaVinciPanelDaemon.exe () [File not signed]
FirewallRules: [{0DE95936-2723-4D63-8FD0-BA92507FFD9A}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\JLCooperPanelDaemon.exe () [File not signed]
FirewallRules: [{15999344-A2AA-4561-9E13-3AA2AF6F29DD}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\EuphonixPanelDaemon.exe () [File not signed]
FirewallRules: [{9346FA6F-421C-42F7-AB99-5A48F9171945}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\TangentPanelDaemon.exe () [File not signed]
FirewallRules: [{F01C84E7-CBB6-400A-9183-02F53C744F1C}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe No File
FirewallRules: [{9D0A1C8A-4DFE-45E0-A50C-E25879423B4A}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\OxygenPanelDaemon.exe No File
FirewallRules: [{10D314F3-B88D-4402-B028-1B1A286BA038}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\DPDecoder.exe (Blackmagic Design Pty Ltd -> )
FirewallRules: [{69D13C4D-495C-428D-9874-EC75AD9778D7}] => (Allow) C:\ProgramData\Blackmagic Design\DaVinci Resolve\Support\QtDecoder\QTDecoder.exe No File
FirewallRules: [TCP Query User{5E419FAA-AF43-4F55-A3C4-0F3724FE90BF}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty. Ltd.) [File not signed]
FirewallRules: [UDP Query User{4A10943A-912F-4BDB-8DE9-63847AA072B1}C:\program files\blackmagic design\davinci resolve\fuscript.exe] => (Allow) C:\program files\blackmagic design\davinci resolve\fuscript.exe (Blackmagic Design Pty. Ltd.) [File not signed]
FirewallRules: [TCP Query User{032D82B7-EF25-4785-963A-F8E75D125A89}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{93198204-5E41-4B68-AB18-9CF5F0D3994E}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [{B0ACB74F-7E77-42DD-98B9-4AA3DBDF481E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{8277AC0B-3734-4B56-8AC5-BB5F40D0B93F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{6A74A575-1142-4777-BB6C-9AF4B8AFC7C9}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{EA67E5DF-8299-450B-84C1-AF802314D9F5}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [{D721A274-8454-42BD-9A3F-2FA1674FBD56}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{69C3820F-E1F1-405F-82E1-A3AEA78ED024}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F3EE1434-034A-459D-A5BE-14C746720EB5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E489F6C2-2F42-4E5A-9362-556A05FE68EE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{3B4286C8-3725-4AFF-A825-8C9DADF61CB7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{8DC007D8-7E55-4C55-A932-003715013E01}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{E04AC00A-28D7-4E41-A780-2E13E00991D0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{4A5085D5-3C04-4ACF-B2B5-0ED576A3A3CE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{5B275472-A2AA-46A9-A5A8-333EA9B8D0BE}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3BF2CFB2-A6A3-41D4-B35D-B89F6F5E18B6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{9C0C19C9-ED56-4895-8905-972945BE4682}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{E0CC7645-30F0-41AC-922B-D1AFD3EC2B07}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{78993ACC-F998-476D-AA34-D0DD355FCB55}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{44B7B91D-8617-4528-BBFE-DFFFEA6DEEFC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{B9C27A11-157F-44F7-8891-306339A886A6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.112.451.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
 
==================== Restore Points =========================
 
30-07-2019 20:35:10 Punto de control programado
11-08-2019 23:29:27 Punto de control programado
21-08-2019 10:24:26 Removed bl.
21-08-2019 10:25:08 Removed ph.
 
==================== Faulty Device Manager Devices =============
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/21/2019 10:18:39 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/21/2019 10:18:30 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=TimerEvent
 
Error: (08/19/2019 02:18:11 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
 
Error: (08/19/2019 02:18:11 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/19/2019 02:17:47 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=TimerEvent
 
Error: (08/16/2019 03:16:56 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (08/16/2019 03:16:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x8007139F
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (08/16/2019 03:16:05 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x8007139F
Argumentos de línea de comandos:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=TimerEvent
 
 
System errors:
=============
Error: (08/21/2019 10:31:17 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:30:46 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:30:15 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {9E175B68-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:29:44 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {9E175B68-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:29:13 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {9E175B68-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:28:42 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: El servidor {9E175B68-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:28:11 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (08/21/2019 10:27:40 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4LAFI5B)
Description: El servidor {9E175B6D-F52A-11D8-B9A5-505054503030} no se registró con DCOM dentro del tiempo de espera requerido.
 
 
Windows Defender:
===================================
Date: 2019-08-08 20:04:20.814
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {D1BA9E96-21D5-4C35-B6BF-6E7C3D6320AC}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-08 00:24:39.889
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {8C27F9AC-A9A3-4DA4-A73A-922CB7B00B73}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-08 00:08:31.379
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {94C32086-1556-4628-A39D-AED0C798D3EA}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-07 22:14:35.420
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {56CE0074-AD0A-4527-8D86-90CA3A4D1C7A}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2019-08-07 21:44:29.813
Description: 
El examen de Antivirus de Windows Defender se detuvo antes de completarse.
Id. de examen: {08782F55-87E1-4492-ACCB-C91382B2CCA9}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
==================== Memory info =========================== 
 
BIOS: American Megatrends Inc. 4011 04/19/2018
Motherboard: ASUSTeK COMPUTER INC. PRIME B350M-A
Processor: AMD Ryzen 7 1700 Eight-Core Processor 
Percentage of memory in use: 47%
Total physical RAM: 8124 MB
Available physical RAM: 4268.96 MB
Total Virtual: 10940 MB
Available Virtual: 5842.52 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.91 GB) (Free:320.77 GB) NTFS
 
\\?\Volume{232ffcd7-c3e0-4d2a-87fa-f0a4133550f4}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.1 GB) NTFS
\\?\Volume{48d798ba-c390-4088-a209-866139d7c711}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: EA3C124C)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

  • 0

#12
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Did that help with reimage plus?

 

Are you getting a warning that your copy of Windows is not valid?


  • 0

#13
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Regarding Reimage, no; it didn't help. It still pops up.

As for windows, it runs with no problems. No warnings. 


  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Did you modify your hosts file?  The last two entries seem a bit odd.  We can reset it with a fixlist:

Download the attached fixlist.txt to the same location as FRST

 

Attached File  fixlist.txt   5.53KB   153 downloads


Run FRST and press Fix
A fix log will be generated please post that

 

Try running ESET's free online scan.  takes a few hours:

 

https://www.eset.com/us/home/online-scanner/ See if it finds anything.

 

Also try MBAR:

 

https://www.malwareb...om/antirootkit/

 

 

 

 


  • 0

#15
MrMatoke

MrMatoke

    Member

  • Topic Starter
  • Member
  • PipPip
  • 32 posts

Hi, sorry for the extreme delay. I had to deal with some personal issues... The ESET's free online scan had it's page taken down. As for the MBAR, it detected 10 malwares and cleaned them all up.  Here's the fixlog:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 30-09-2019

Ran by Matoke (02-10-2019 00:58:50) Run:5
Running from C:\Users\amd\Desktop\Kit salva compu
Loaded Profiles: Matoke (Available Profiles: Matoke & Otros)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
S2 Ds3Service; "C:\Users\amd\Desktop\Driver ps3\Drivers PS3 By Haniel\ScpServer\bin\ScpService.exe" [X]
R4 PxHlpa64; System32\Drivers\PxHlpa64.sys [X]
Task: {D5C93072-60ED-4351-9C65-BC314006E5C5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2045832 2019-08-19] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>  -> No File
FirewallRules: [UDP Query User{46C1F681-5175-4812-A704-0A018D087A0F}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [TCP Query User{CB8558D1-FF69-4771-986A-C2983A7D5446}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe] => (Allow) C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe No File
FirewallRules: [{881E906A-2F74-49C0-AAA0-5BE6EF13ABD7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{BDE08CFB-A8A7-4776-B108-37791A672AEB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{9EA637D9-F5E4-41D8-9848-FBCD05793038}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{54E1A440-155B-4F00-90C5-88FC53B5DDAC}] => (Allow) C:\Users\amd\AppData\Roaming\BitTorrent\BitTorrent.exe No File
FirewallRules: [{21AEFB78-DA26-4A84-8140-C02C95C4A30A}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{609ABCE4-9708-429A-A26F-40AFE31FEF37}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{D4DE269D-82ED-4781-9BF4-16674762D66C}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [{ADD5AE4F-87C9-4370-9190-B39738090812}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File
FirewallRules: [TCP Query User{032D82B7-EF25-4785-963A-F8E75D125A89}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [UDP Query User{93198204-5E41-4B68-AB18-9CF5F0D3994E}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe No File
FirewallRules: [TCP Query User{6A74A575-1142-4777-BB6C-9AF4B8AFC7C9}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe No File
hosts:
CMD: FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i"
Reboot:
 
 
 
 
 
 
 
*****************
 
Ds3Service => service not found.
PxHlpa64 => service not found.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{D5C93072-60ED-4351-9C65-BC314006E5C5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D5C93072-60ED-4351-9C65-BC314006E5C5}" => removed successfully
C:\WINDOWS\System32\Tasks\Avast Software\Overseer => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => removed successfully
"HKU\\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
"HKU\\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
"HKU\\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{46C1F681-5175-4812-A704-0A018D087A0F}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{CB8558D1-FF69-4771-986A-C2983A7D5446}C:\users\amd\appdata\roaming\bittorrent\bittorrent.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{881E906A-2F74-49C0-AAA0-5BE6EF13ABD7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BDE08CFB-A8A7-4776-B108-37791A672AEB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9EA637D9-F5E4-41D8-9848-FBCD05793038}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{54E1A440-155B-4F00-90C5-88FC53B5DDAC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{21AEFB78-DA26-4A84-8140-C02C95C4A30A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{609ABCE4-9708-429A-A26F-40AFE31FEF37}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D4DE269D-82ED-4781-9BF4-16674762D66C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ADD5AE4F-87C9-4370-9190-B39738090812}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{032D82B7-EF25-4785-963A-F8E75D125A89}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{93198204-5E41-4B68-AB18-9CF5F0D3994E}C:\program files (x86)\java\jre1.8.0_211\bin\javaw.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6A74A575-1142-4777-BB6C-9AF4B8AFC7C9}C:\program files\java\jre1.8.0_211\bin\javaw.exe" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= FOR /F "usebackq delims==" %i IN (`wevtutil el`) DO wevtutil cl "%i" =========
 
Error al borrar el registro Microsoft-Windows-LiveId/Analytic.
Acceso denegado.
Error al borrar el registro Microsoft-Windows-LiveId/Operational.
Acceso denegado.
Error al borrar el registro Microsoft-Windows-USBVideo/Analytic.
Un proveedor de datos WMI no reconoce como válido el nombre de instancia pasado.
 
========= End of CMD: =========
 
 
 
The system needed a reboot.
 
==== End of Fixlog 01:02:33 ====

  • 0






Similar Topics


Also tagged with one or more of these keywords: Virus, Disk, Windows, 100, Task Manager

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP