• Registrarse
  • Iniciar sesión


  • Resultados 1 al 5 de 5

    Apertura de paginas de publicidad y problemas en chrome

    Hola a todos: Escribo este post porque se me abren muchas ventanas ventanas emergentes que me molestan a la hora de navegar. He leido otro post de este foro y parece que es lo mismo ...

    1. #1
      Usuario Avatar de jmirabel
      Registrado
      jun 2017
      Ubicación
      España
      Mensajes
      3

      Apertura de paginas de publicidad y problemas en chrome

      Hola a todos:

      Escribo este post porque se me abren muchas ventanas ventanas emergentes que me molestan a la hora de navegar.

      He leido otro post de este foro y parece que es lo mismo que me pasa a mi (http://www.forospyware.com/t528917.html). He realizado todo lo que pone en esa página pero el script final no creo que este adaptado a mi problema.

      ¿Me podéis ayudar? He pasado el malwarebytes y los demás programas y os adjunto el informe (Junkware Removal Tool, AdwCleaner | InfoSpyware en el escritorio, Farbar Recovery Scan Tool)

      Gracias por todo

      -------------------------------------Junkware Removal Tool --------------------------------------------------------------------------

      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Junkware Removal Tool (JRT) by Malwarebytes
      Version: 8.1.3 (04.10.2017)
      Operating System: Windows 10 Pro x64
      Ran by Johanna (Administrator) on 11/06/2017 at 17:31:01,74
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




      File System: 1

      Successfully deleted: C:\ProgramData\lavasoft\web companion (Folder)



      Registry: 3

      Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} (Registry Key)
      Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} (Registry Key)
      Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} (Registry Value)




      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Scan was completed on 11/06/2017 at 17:34:54,04
      End of JRT log
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~







      ------------------------------------------AdwCleaner | InfoSpyware en el escritorio.---------------------------------------

      # AdwCleaner v6.047 - Archivo de registro creado 11/06/2017 en 17:42:25
      # Actualizado en 19/05/2017 por Malwarebytes
      # Base de datos : 2017-06-10.1 [Servidor]
      # Sistema Operativo : Windows 10 Pro (X64)
      # Nombre de usuario : Johanna - JOHANNA-PC
      # Ejecutado desde : C:\Users\Johanna\Downloads\adwcleaner_6.047.exe
      # Modo: Limpiar
      # Soporte : https://www.malwarebytes.com/support



      ***** [ Servicios ] *****

      [-] Servicio eliminado: panda_url_filtering


      ***** [ Carpetas ] *****

      [-] Carpeta eliminada: C:\Users\Johanna\AppData\LocalLow\pandasecuritytb
      [#] Carpeta eliminada al reiniciar: C:\Program Files\Panda Security URL Filtering
      [-] Carpeta eliminada: C:\Program Files (x86)\pandasecuritytb
      [-] Carpeta eliminada: C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
      [-] Carpeta eliminada: C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\fagakgcelolinfnkfgekcnedpaklfcok
      [-] Carpeta eliminada: C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fagakgcelolinfnkfgekcnedpaklfcok


      ***** [ Archivos ] *****

      [-] Archivo eliminado: C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}.xpi


      ***** [ DLL ] *****



      ***** [ WMI ] *****



      ***** [ Accesos directos ] *****



      ***** [ Tareas programadas ] *****



      ***** [ Registro ] *****

      [-] Llave eliminada: HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
      [-] Llave eliminada: HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
      [-] Llave eliminada: HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
      [-] Llave eliminada: HKU\S-1-5-21-1477174034-2186171754-939287862-1001\Software\Vittalia
      [-] Llave eliminada: HKU\S-1-5-21-1477174034-2186171754-939287862-1001\Software\INSTALLPATH\STATUS
      [#] Llave eliminada al reiniciar: HKCU\Software\Vittalia
      [#] Llave eliminada al reiniciar: HKCU\Software\INSTALLPATH\STATUS
      [-] Llave eliminada: HKLM\SOFTWARE\Lavasoft\Web Companion
      [#] Llave eliminada al reiniciar: [x64] HKCU\Software\Vittalia
      [#] Llave eliminada al reiniciar: [x64] HKCU\Software\INSTALLPATH\STATUS
      [-] Llave eliminada: HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
      [#] Llave eliminada al reiniciar: [x64] HKCU\Software\Google\Chrome\Extensions\fcfenmboojpjinhpgggodefccipikbpd
      [-] Llave eliminada: HKLM\SOFTWARE\Google\Chrome\Extensions\fagakgcelolinfnkfgekcnedpaklfcok
      [-] Llave eliminada: [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\fagakgcelolinfnkfgekcnedpaklfcok


      ***** [ Navegadores ] *****

      [-] [C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default] [extension] Eliminado: fagakgcelolinfnkfgekcnedpaklfcok
      [-] [C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default] [extension] Eliminado: fcfenmboojpjinhpgggodefccipikbpd


      *************************

      :: Llaves "Tracing" eliminadas
      :: Se han borrado los ajustes de Winsock

      *************************

      C:\AdwCleaner\AdwCleaner[C0].txt - [3079 Bytes] - [11/06/2017 17:42:25]
      C:\AdwCleaner\AdwCleaner[S0].txt - [3515 Bytes] - [11/06/2017 17:41:03]

      ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3225 Bytes] ##########





      -------------------------------------------Farbar Recovery Scan Tool ------------------------------------------

      FRST.txt

      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-06-2017
      Ran by Johanna (administrator) on JOHANNA-PC (11-06-2017 17:50:24)
      Running from C:\Users\Johanna\Desktop
      Loaded Profiles: Johanna (Available Profiles: Johanna)
      Platform: Windows 10 Pro Version 1607 (X64) Language: Español (España, internacional)
      Internet Explorer Version 11 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: ***********************************************************************************************************

      ==================== Processes (Whitelisted) =================

      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

      (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
      (@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
      (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
      (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
      (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
      (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
      () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
      (Intel Corporation) C:\Windows\System32\igfxtray.exe
      (Intel Corporation) C:\Windows\System32\hkcmd.exe
      (Intel Corporation) C:\Windows\System32\igfxpers.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
      (Spotify Ltd) C:\Users\Johanna\AppData\Roaming\Spotify\SpotifyWebHelper.exe
      (© 2015 Microsoft Corporation) C:\Users\Johanna\AppData\Local\Microsoft\BingSvc\BingSvc.exe
      (Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
      (Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
      (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
      (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.1051_none_7f2bf7ea21d201b2\TiWorker.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe

      ==================== Registry (Whitelisted) ====================

      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

      HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-07] (ELAN Microelectronics Corp.)
      HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
      HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [141760 2017-02-22] (Panda Security, S.L.)
      Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
      HKLM\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4289728 2016-04-04] (Disc Soft Ltd)
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\Run: [Spotify Web Helper] => C:\Users\Johanna\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1449584 2017-05-30] (Spotify Ltd)
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\Run: [BingSvc] => C:\Users\Johanna\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9773272 2017-05-19] (Piriform Ltd)
      IFEO\notepad.exe: [Debugger] "C:\Program Files\Notepad2\Notepad2.exe" /z
      GroupPolicyScripts: Restriction <======= ATTENTION
      GroupPolicyScripts-x32: Restriction <======= ATTENTION

      ==================== Internet (Whitelisted) ====================

      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

      Hosts: 0.0.0.0 keystone.mwbsys.com
      Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
      Tcpip\..\Interfaces\{d874bc6b-5171-44eb-8bad-bf922bb8356e}: [DhcpNameServer] 80.58.61.250 80.58.61.254
      Tcpip\..\Interfaces\{fedc0634-ae31-4f60-8542-519ac3d4887b}: [DhcpNameServer] 192.168.1.1
      ManualProxies:

      Internet Explorer:
      ==================
      HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pclatino.*************/
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pclatino.*************/
      SearchScopes: HKU\.DEFAULT -> DefaultScope {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta=
      SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKU\.DEFAULT -> {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta=
      SearchScopes: HKU\S-1-5-21-1477174034-2186171754-939287862-1001 -> DefaultScope {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta=
      SearchScopes: HKU\S-1-5-21-1477174034-2186171754-939287862-1001 -> {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta=
      BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
      BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
      BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
      BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
      Toolbar: HKLM - No Name - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - No File
      Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
      Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
      Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
      Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)

      FireFox:
      ========
      FF DefaultProfile: ak96dsl9.default
      FF ProfilePath: C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default [2017-06-11]
      FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ak96dsl9.default -> Bing
      FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\ak96dsl9.default -> Bing
      FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ak96dsl9.default -> Bing
      FF Homepage: Mozilla\Firefox\Profiles\ak96dsl9.default -> hxxp://www.msn.com/?pc=SK216&ocid=SK216DHP&osmkt=es-es
      FF Keyword.URL: Mozilla\Firefox\Profiles\ak96dsl9.default -> hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
      FF Extension: (Bing Search) - C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\Extensions\[email protected] [2017-03-05]
      FF Extension: (signTextJS) - C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\Extensions\[email protected] [2017-05-28]
      FF Extension: (Follow-on Search Telemetry) - C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\features\{544d9ab7-3e9b-49fd-9b3a-fef97fa3edc3}\[email protected] [2017-06-06]
      FF SearchPlugin: C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\searchplugins\bing-.xml [2017-03-05]
      FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-05-26] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-26] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-26] (Google Inc.)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-1477174034-2186171754-939287862-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Johanna\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2017-06-07] (Citrix Online)

      Chrome:
      =======
      CHR StartupUrls: Default -> "hxxp://www.google.es/"
      CHR NewTab: Default -> Not-active:"chrome-extension://fcfenmboojpjinhpgggodefccipikbpd/newTab.html", Not-active:"chrome-extension://bnnelcjphpdfnliejknghmgjifnnkmoh/zlalwe.html", Not-active:"chrome-extension://mbjagikgfihlmlkbldaoklfikmcnjacb/newtab.html"
      CHR Profile: C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default [2017-06-11]
      CHR Extension: (Google Docs) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-24]
      CHR Extension: (Google Drive) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-24]
      CHR Extension: (YouTube) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-24]
      CHR Extension: (Maniya sites) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnnelcjphpdfnliejknghmgjifnnkmoh [2017-02-27]
      CHR Extension: (Adobe Acrobat) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-03]
      CHR Extension: (Documentos de Google sin conexión) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-24]
      CHR Extension: (Kolyan site) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbjagikgfihlmlkbldaoklfikmcnjacb [2017-02-12]
      CHR Extension: (Compose Hot Mail) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\moacggjajgoklflpminchmojpagdfnmi [2017-05-22]
      CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
      CHR Extension: (Gmail) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-24]
      CHR Extension: (Chrome Media Router) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-15]
      CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

      ==================== Services (Whitelisted) ====================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-14] (Microsoft Corporation)
      R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1443520 2016-04-04] (Disc Soft Ltd)
      R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-07] (ELAN Microelectronics Corp.)
      R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
      R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
      R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [110384 2017-02-14] (Panda Security, S.L.)
      R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
      R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [86104 2016-07-19] (Panda Security, S.L.)
      R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
      R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [47096 2017-04-26] (Panda Security, S.L.)
      S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
      R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [737984 2015-08-30] (@ByELDI) [File not signed]
      R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7757040 2017-04-06] (TeamViewer GmbH)
      R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
      R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)

      ===================== Drivers (Whitelisted) ======================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      S3 dot4; C:\WINDOWS\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
      S3 Dot4Print; C:\WINDOWS\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
      R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-04-24] (Disc Soft Ltd)
      R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-04-24] (Disc Soft Ltd)
      R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
      R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2017-06-11] (Malwarebytes)
      R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
      R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
      S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
      R3 NETJME; C:\WINDOWS\System32\drivers\NETJME.sys [137728 2016-07-16] (JMicron Technology Corp.)
      R1 NNSALPC; C:\WINDOWS\system32\DRIVERS\NNSALPC.sys [107488 2017-02-08] (Panda Security, S.L.)
      R1 NNSHTTP; C:\WINDOWS\system32\DRIVERS\NNSHTTP.sys [211376 2016-07-05] (Panda Security, S.L.)
      R1 NNSHTTPS; C:\WINDOWS\system32\DRIVERS\NNSHTTPS.sys [121312 2017-02-08] (Panda Security, S.L.)
      R1 NNSIDS; C:\WINDOWS\system32\DRIVERS\NNSIDS.sys [125872 2016-07-05] (Panda Security, S.L.)
      R1 NNSNAHSL; C:\WINDOWS\system32\DRIVERS\NNSNAHSL.sys [80152 2016-07-06] (Panda Security, S.L.)
      R1 NNSPICC; C:\WINDOWS\system32\DRIVERS\NNSPICC.sys [116656 2016-07-05] (Panda Security, S.L.)
      R1 NNSPIHSW; C:\WINDOWS\system32\DRIVERS\NNSPIHSW.sys [91104 2017-02-08] (Panda Security, S.L.)
      R1 NNSPOP3; C:\WINDOWS\system32\DRIVERS\NNSPOP3.sys [135088 2016-07-05] (Panda Security, S.L.)
      R1 NNSPROT; C:\WINDOWS\system32\DRIVERS\NNSPROT.sys [335792 2016-07-05] (Panda Security, S.L.)
      R1 NNSPRV; C:\WINDOWS\system32\DRIVERS\NNSPRV.sys [197600 2017-02-08] (Panda Security, S.L.)
      R1 NNSSMTP; C:\WINDOWS\system32\DRIVERS\NNSSMTP.sys [123312 2016-07-05] (Panda Security, S.L.)
      R1 NNSSTRM; C:\WINDOWS\system32\DRIVERS\NNSSTRM.sys [278960 2016-07-05] (Panda Security, S.L.)
      R1 NNSTLSC; C:\WINDOWS\system32\DRIVERS\NNSTLSC.sys [125360 2016-07-05] (Panda Security, S.L.)
      S3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
      R2 PSINAflt; C:\WINDOWS\system32\DRIVERS\PSINAflt.sys [177424 2017-02-12] (Panda Security, S.L.)
      R2 PSINFile; C:\WINDOWS\System32\DRIVERS\PSINFile.sys [129296 2017-02-12] (Panda Security, S.L.)
      R1 PSINKNC; C:\WINDOWS\system32\DRIVERS\PSINKNC.sys [205584 2017-02-20] (Panda Security, S.L.)
      R2 PSINProc; C:\WINDOWS\System32\DRIVERS\PSINProc.sys [131344 2017-02-12] (Panda Security, S.L.)
      R2 PSINProt; C:\WINDOWS\system32\DRIVERS\PSINProt.sys [144656 2017-02-12] (Panda Security, S.L.)
      R2 PSINReg; C:\WINDOWS\system32\DRIVERS\PSINReg.sys [114960 2017-02-12] (Panda Security, S.L.)
      U3 PSKMAD; C:\WINDOWS\System32\DRIVERS\PSKMAD.sys [72112 2016-08-09] (Panda Security, S.L.)
      S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
      R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
      R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

      ==================== NetSvcs (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


      ==================== One Month Created files and folders ========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2017-06-11 17:50 - 2017-06-11 17:50 - 00018718 _____ C:\Users\Johanna\Desktop\FRST.txt
      2017-06-11 17:49 - 2017-06-11 17:50 - 00000000 ____D C:\FRST
      2017-06-11 17:48 - 2017-06-11 17:48 - 02438656 _____ (Farbar) C:\Users\Johanna\Desktop\FRST64.exe
      2017-06-11 17:38 - 2017-06-11 17:38 - 04110280 _____ C:\Users\Johanna\Downloads\adwcleaner_6.047.exe
      2017-06-11 17:37 - 2017-06-11 17:42 - 00000000 ____D C:\AdwCleaner
      2017-06-11 17:34 - 2017-06-11 17:34 - 00001086 _____ C:\Users\Johanna\Desktop\JRT.txt
      2017-06-11 17:30 - 2017-06-11 17:30 - 01663672 _____ (Malwarebytes) C:\Users\Johanna\Downloads\JRT.exe
      2017-06-10 20:09 - 2017-06-11 17:41 - 00000000 ____D C:\Program Files\Panda Security URL Filtering
      2017-06-10 20:09 - 2017-06-10 20:09 - 00000000 ____D C:\ProgramData\panda_url_filtering
      2017-06-10 20:08 - 2017-06-10 20:09 - 00002298 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Protection.lnk
      2017-06-10 20:08 - 2017-06-10 20:09 - 00002281 _____ C:\Users\Public\Desktop\Panda Protection.lnk
      2017-06-10 20:08 - 2017-06-10 20:08 - 00000000 ____D C:\Users\Johanna\AppData\Roaming\Panda Security
      2017-06-10 20:08 - 2017-06-10 20:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Protection
      2017-06-10 20:08 - 2017-06-10 20:08 - 00000000 ____D C:\Program Files (x86)\Panda Security
      2017-06-10 20:08 - 2017-02-20 15:16 - 00205584 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINKNC.sys
      2017-06-10 20:08 - 2017-02-12 12:51 - 00144656 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINProt.sys
      2017-06-10 20:08 - 2017-02-12 12:46 - 00131344 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINProc.sys
      2017-06-10 20:08 - 2017-02-12 12:40 - 00114960 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINReg.sys
      2017-06-10 20:08 - 2017-02-12 12:33 - 00129296 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINFile.sys
      2017-06-10 20:08 - 2017-02-12 12:28 - 00177424 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSINAflt.sys
      2017-06-10 20:08 - 2016-08-09 22:17 - 00072112 _____ (Panda Security, S.L.) C:\WINDOWS\system32\Drivers\PSKMAD.sys
      2017-06-10 19:58 - 2017-06-10 20:08 - 00000000 ____D C:\ProgramData\Panda Security
      2017-06-10 19:57 - 2017-06-10 19:57 - 01980152 _____ (Panda Security, S.L.) C:\Users\Johanna\Downloads\PANDAFREEAV.exe
      2017-06-07 19:03 - 2017-06-11 17:43 - 00000692 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1477174034-2186171754-939287862-1001.job
      2017-06-07 19:03 - 2017-06-11 17:43 - 00000596 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1477174034-2186171754-939287862-1001.job
      2017-06-07 19:03 - 2017-06-09 15:46 - 00003854 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-1477174034-2186171754-939287862-1001
      2017-06-07 19:03 - 2017-06-09 15:46 - 00003758 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-1477174034-2186171754-939287862-1001
      2017-06-07 19:03 - 2017-06-07 19:03 - 00000000 ____D C:\Users\Johanna\AppData\Local\Citrix
      2017-06-07 18:52 - 2017-06-07 18:52 - 00000000 ____D C:\Users\Johanna\Documents\Camtasia Studio
      2017-06-07 18:52 - 2017-06-07 18:52 - 00000000 ____D C:\Users\Johanna\AppData\Roaming\TechSmith
      2017-06-07 18:52 - 2017-06-07 18:52 - 00000000 ____D C:\Users\Johanna\AppData\Local\TechSmith
      2017-06-07 18:51 - 2017-06-07 18:51 - 00001241 _____ C:\Users\Public\Desktop\Camtasia Studio 8.lnk
      2017-06-07 18:51 - 2017-06-07 18:51 - 00000000 ____D C:\ProgramData\TechSmith
      2017-06-07 18:51 - 2017-06-07 18:51 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
      2017-06-07 18:51 - 2017-06-07 18:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
      2017-06-07 18:51 - 2017-06-07 18:51 - 00000000 ____D C:\Program Files (x86)\TechSmith
      2017-06-07 18:51 - 2017-06-07 18:51 - 00000000 ____D C:\Program Files (x86)\QuickTime
      2017-06-07 18:38 - 2017-06-08 09:17 - 00000000 ____D C:\Users\Johanna\Downloads\Camtasia.Studio.v8.6.0.2079.Incl.Keygen-TSZ
      2017-06-06 23:44 - 2017-06-06 23:44 - 00000000 ____D C:\Users\Johanna\Documents\Plantillas personalizadas de Office
      2017-06-03 09:56 - 2017-06-03 09:56 - 00225756 _____ C:\Users\Johanna\Downloads\Mapa Parking-Hotel(1).pdf
      2017-06-03 09:55 - 2017-06-03 09:55 - 00225756 _____ C:\Users\Johanna\Downloads\Mapa Parking-Hotel.pdf
      2017-06-03 09:55 - 2017-06-03 09:55 - 00225575 _____ C:\Users\Johanna\Downloads\MAPA PARKING CACERES.pdf
      2017-05-30 11:00 - 2017-05-30 11:05 - 00000000 ____D C:\Users\Johanna\Desktop\Casas del Castañar
      2017-05-30 09:19 - 2017-05-30 09:19 - 03468560 _____ C:\Users\Johanna\Downloads\PGPF Orientacion para Afrontar los Conflictos Familiares.pdf
      2017-05-29 22:45 - 2017-06-11 17:45 - 00000000 ____D C:\Users\Johanna\AppData\LocalLow\Mozilla
      2017-05-29 00:20 - 2017-06-03 09:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
      2017-05-26 23:43 - 2017-05-26 23:44 - 00002342 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
      2017-05-26 23:43 - 2017-05-26 23:44 - 00002330 _____ C:\Users\Public\Desktop\Google Chrome.lnk
      2017-05-26 23:42 - 2017-05-26 23:42 - 00003618 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
      2017-05-26 23:42 - 2017-05-26 23:42 - 00003494 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
      2017-05-26 23:42 - 2017-05-26 23:42 - 00000000 ____D C:\Program Files (x86)\Google
      2017-05-26 23:39 - 2017-05-26 23:41 - 01130328 _____ (Google Inc.) C:\Users\Johanna\Downloads\ChromeSetup.exe
      2017-05-26 23:18 - 2017-06-11 17:43 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
      2017-05-26 23:17 - 2017-05-26 23:17 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
      2017-05-26 23:17 - 2017-05-26 23:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
      2017-05-26 23:16 - 2017-05-26 23:17 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
      2017-05-26 23:16 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
      2017-05-26 23:16 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
      2017-05-26 23:16 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
      2017-05-26 22:49 - 2016-03-19 00:35 - 00000000 ____D C:\Users\Johanna\Desktop\Malwarebytes.Anti-Malware.Premium.v2.2.1.1043.Multilingual.Final.Incl.Fix
      2017-05-26 22:32 - 2017-05-26 22:32 - 00002864 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
      2017-05-26 22:32 - 2017-05-26 22:32 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
      2017-05-26 22:32 - 2017-05-26 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
      2017-05-26 22:32 - 2017-05-26 22:32 - 00000000 ____D C:\Program Files\CCleaner
      2017-05-24 20:19 - 2017-05-24 20:19 - 00176373 _____ C:\Users\Johanna\Downloads\Dialnet-EvaluacionDelDesarrolloEnAtencionTemprana-3007812.pdf
      2017-05-24 18:05 - 2017-05-24 18:05 - 00603945 _____ C:\Users\Johanna\Downloads\161214121819_0001.pdf
      2017-05-24 18:05 - 2017-05-24 18:05 - 00584412 _____ C:\Users\Johanna\Downloads\161214121625_0001.pdf
      2017-05-24 18:05 - 2017-05-24 18:05 - 00523017 _____ C:\Users\Johanna\Downloads\161214121717_0001.pdf
      2017-05-24 18:04 - 2017-05-24 18:04 - 00634116 _____ C:\Users\Johanna\Downloads\161214121509_0001.pdf
      2017-05-24 18:03 - 2017-05-24 18:03 - 02055922 _____ C:\Users\Johanna\Downloads\TFM LAURA CABRERO MARTIN.pdf
      2017-05-24 18:03 - 2017-05-24 18:03 - 00174918 _____ C:\Users\Johanna\Downloads\disfagia.pdf
      2017-05-24 18:01 - 2017-05-24 18:01 - 00776029 _____ C:\Users\Johanna\Downloads\01_Disfagia_y_odinofagia.pdf
      2017-05-23 13:34 - 2017-05-23 13:34 - 01518080 _____ C:\Users\Johanna\Downloads\testdemaduracinsocialdevineland-estudioanio2003-120424105238-phpapp01.ppt
      2017-05-23 13:28 - 2017-05-23 13:28 - 00055063 _____ C:\Users\Johanna\Downloads\105728694-test-vineland-140401092237-phpapp02.pdf
      2017-05-23 13:25 - 2017-05-23 13:25 - 00251274 _____ C:\Users\Johanna\Downloads\escalamadurezsocialvineland-140427110204-phpapp02.pdf
      2017-05-23 10:15 - 2017-05-23 10:15 - 00210505 _____ C:\Users\Johanna\Downloads\CV Johanna xxxxxxxxxx.pdf
      2017-05-23 10:09 - 2017-05-23 10:09 - 00208929 _____ C:\Users\Johanna\Downloads\CV Completo (3).pdf
      2017-05-23 09:59 - 2017-05-23 09:59 - 00566183 _____ C:\Users\Johanna\Desktop\Bolsa-empleo-xxxxxxxxxxxxxx (1).pdf
      2017-05-22 19:35 - 2017-05-22 19:35 - 00371459 _____ C:\Users\Johanna\Downloads\Llevame a casa - Daniela Sacerdoti (2).epub
      2017-05-22 19:18 - 2017-05-22 19:18 - 00368849 _____ C:\Users\Johanna\Downloads\32118-818.epub
      2017-05-22 19:10 - 2017-05-22 19:10 - 00371708 _____ C:\Users\Johanna\Downloads\Elena Ferrante - La amiga estupendaR1 (1).epub
      2017-05-22 19:09 - 2017-05-22 19:09 - 00371708 _____ C:\Users\Johanna\Downloads\Elena Ferrante - La amiga estupendaR1.epub
      2017-05-20 23:40 - 2017-05-20 23:40 - 00013212 _____ C:\Users\Johanna\Downloads\PUNTUACIÓNTESTDECONNERS.pdf
      2017-05-20 23:40 - 2017-05-20 23:40 - 00008134 _____ C:\Users\Johanna\Downloads\INSTRUCCIONESTM..pdf
      2017-05-20 23:39 - 2017-05-20 23:39 - 00275483 _____ C:\Users\Johanna\Downloads\EVALUACIÓNDELCONOCIMIENTOMATEMÁTICO.pdf
      2017-05-20 23:39 - 2017-05-20 23:39 - 00038933 _____ C:\Users\Johanna\Downloads\TablaProtocoloBentonLuria.pdf
      2017-05-20 23:39 - 2017-05-20 23:39 - 00019631 _____ C:\Users\Johanna\Downloads\Hojadeanotación.pdf
      2017-05-20 23:38 - 2017-05-20 23:38 - 00036802 _____ C:\Users\Johanna\Downloads\EVALUACIÓNDELCONOCIMIENTOMATEMÁTICO4ºBÁSICO.pdf
      2017-05-20 23:37 - 2017-05-20 23:37 - 01032527 _____ C:\Users\Johanna\Downloads\DIBUJOYPERSONALIDAD.pdf
      2017-05-20 23:37 - 2017-05-20 23:37 - 00285128 _____ C:\Users\Johanna\Downloads\BENTONyLURIA(evaluaciondelconosimientomatematico).pdf
      2017-05-20 23:35 - 2017-05-20 23:35 - 00100047 _____ C:\Users\Johanna\Downloads\TESTDELAFIGURAHUMANADEKARENMMACHOVER.pdf
      2017-05-20 23:35 - 2017-05-20 23:35 - 00097743 _____ C:\Users\Johanna\Downloads\LAESCALADEINTELIGENCIADEF.GOODENOUGH.pdf
      2017-05-20 23:34 - 2017-05-20 23:34 - 00625592 _____ C:\Users\Johanna\Downloads\INDICADORESEMOCIONALESDELTESTDELDIBUJODELAFIGURAHUMANA.pdf
      2017-05-19 10:43 - 2017-05-19 10:43 - 01934391 _____ C:\Users\Johanna\Downloads\Tenemos que hablar. Acoso escolar, empatía, resolución de problemas y teoría de la mente (1).pdf
      2017-05-18 17:04 - 2017-05-18 17:04 - 00064682 _____ C:\Users\Johanna\Downloads\Yale-Brown.pdf
      2017-05-18 17:04 - 2017-05-18 17:04 - 00064682 _____ C:\Users\Johanna\Downloads\Yale-Brown (1).pdf
      2017-05-18 17:03 - 2017-05-18 17:03 - 00073248 _____ C:\Users\Johanna\Downloads\PT7_AnsHamilton (1).pdf
      2017-05-18 17:03 - 2017-05-18 17:03 - 00052316 _____ C:\Users\Johanna\Downloads\SDQvaloracion.pdf
      2017-05-18 17:03 - 2017-05-18 17:03 - 00049424 _____ C:\Users\Johanna\Downloads\Oviedo (2).pdf
      2017-05-18 17:03 - 2017-05-18 17:03 - 00049424 _____ C:\Users\Johanna\Downloads\Oviedo (1).pdf
      2017-05-18 17:03 - 2017-05-18 17:03 - 00034730 _____ C:\Users\Johanna\Downloads\m-chat.pdf
      2017-05-18 17:02 - 2017-05-18 17:02 - 00408944 _____ C:\Users\Johanna\Downloads\IDEA (1).pdf
      2017-05-18 17:02 - 2017-05-18 17:02 - 00150129 _____ C:\Users\Johanna\Downloads\Inventario-de-conductas-de-Conners.pdf
      2017-05-18 17:02 - 2017-05-18 17:02 - 00074988 _____ C:\Users\Johanna\Downloads\Inventario Ansiedad Estado-Rasgo.pdf
      2017-05-18 17:02 - 2017-05-18 17:02 - 00047910 _____ C:\Users\Johanna\Downloads\Impulsividad Barratt.pdf
      2017-05-18 17:01 - 2017-05-18 17:01 - 00408944 _____ C:\Users\Johanna\Downloads\IDEA.pdf
      2017-05-18 17:01 - 2017-05-18 17:01 - 00093551 _____ C:\Users\Johanna\Downloads\IDEA, INVENTARIO .PDF
      2017-05-18 17:01 - 2017-05-18 17:01 - 00065788 _____ C:\Users\Johanna\Downloads\EDI.pdf
      2017-05-18 17:01 - 2017-05-18 17:01 - 00051103 _____ C:\Users\Johanna\Downloads\EAT.pdf
      2017-05-18 17:01 - 2017-05-18 17:01 - 00041455 _____ C:\Users\Johanna\Downloads\haizea.pdf
      2017-05-18 17:00 - 2017-05-18 17:00 - 00090054 _____ C:\Users\Johanna\Downloads\BDI.pdf
      2017-05-18 17:00 - 2017-05-18 17:00 - 00073248 _____ C:\Users\Johanna\Downloads\PT7_AnsHamilton.pdf
      2017-05-18 17:00 - 2017-05-18 17:00 - 00055513 _____ C:\Users\Johanna\Downloads\BITE.pdf
      2017-05-18 17:00 - 2017-05-18 17:00 - 00049424 _____ C:\Users\Johanna\Downloads\Oviedo.pdf
      2017-05-17 10:08 - 2017-05-17 10:08 - 00208929 _____ C:\Users\Johanna\Downloads\CV Completo (2).pdf
      2017-05-17 10:08 - 2017-05-17 10:08 - 00207961 _____ C:\Users\Johanna\Downloads\CV Completo (1).pdf
      2017-05-17 10:01 - 2017-05-17 10:01 - 00207961 _____ C:\Users\Johanna\Downloads\CV Completo.pdf
      2017-05-13 18:40 - 2017-05-13 18:44 - 00000000 ____D C:\Users\Johanna\AppData\Local\0c85df
      2017-05-13 18:14 - 2017-05-26 23:07 - 00000000 ____D C:\Users\Johanna\AppData\Local\69c4
      2017-05-12 09:47 - 2017-05-12 09:47 - 00971534 _____ C:\Users\Johanna\Downloads\Gestión del tiempo (1).pptx
      2017-05-12 09:21 - 2017-05-12 09:45 - 01033847 _____ C:\Users\Johanna\Downloads\Gestión del tiempo.pptx

      ==================== One Month Modified files and folders ========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2017-06-11 17:49 - 2016-07-17 00:40 - 01658514 _____ C:\WINDOWS\system32\perfh00A.dat
      2017-06-11 17:49 - 2016-07-17 00:40 - 00421458 _____ C:\WINDOWS\system32\perfc00A.dat
      2017-06-11 17:49 - 2016-04-24 00:10 - 03586158 _____ C:\WINDOWS\system32\PerfStringBackup.INI
      2017-06-11 17:43 - 2016-09-14 15:39 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
      2017-06-11 17:43 - 2016-09-14 15:32 - 00000000 ____D C:\Users\Johanna
      2017-06-11 17:43 - 2016-09-14 15:30 - 00378240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
      2017-06-11 17:42 - 2016-07-16 08:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
      2017-06-11 17:31 - 2016-11-05 13:59 - 00000000 ____D C:\ProgramData\Lavasoft
      2017-06-11 01:35 - 2016-09-14 15:30 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
      2017-06-10 20:09 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
      2017-06-10 20:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
      2017-06-10 20:08 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
      2017-06-10 19:08 - 2016-04-26 20:41 - 00000000 ____D C:\Users\Johanna\Desktop\Imprimir
      2017-06-10 17:01 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
      2017-06-10 17:01 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
      2017-06-10 16:57 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
      2017-06-08 16:47 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
      2017-06-08 09:19 - 2016-04-23 13:16 - 00000000 ____D C:\Users\Johanna\AppData\Local\Packages
      2017-06-07 21:00 - 2016-04-24 15:08 - 00000000 ____D C:\Program Files (x86)\TeamViewer
      2017-06-07 19:27 - 2016-04-24 15:08 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
      2017-06-07 19:27 - 2016-04-24 15:08 - 00001028 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk
      2017-06-07 18:57 - 2016-04-24 14:30 - 00000000 ____D C:\Users\Johanna\AppData\Roaming\uTorrent
      2017-06-03 09:53 - 2016-11-11 13:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
      2017-05-31 23:45 - 2016-04-24 00:10 - 00000000 ____D C:\Users\Johanna\AppData\Local\Comms
      2017-05-31 09:10 - 2016-04-23 14:00 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
      2017-05-30 20:03 - 2016-04-24 15:10 - 00000000 ____D C:\Users\Johanna\AppData\Local\Spotify
      2017-05-30 19:31 - 2016-04-24 15:09 - 00000000 ____D C:\Users\Johanna\AppData\Roaming\Spotify
      2017-05-28 15:04 - 2016-11-10 20:38 - 00000000 ____D C:\WINDOWS\Minidump
      2017-05-28 15:03 - 2016-09-14 16:30 - 00000000 ___DC C:\WINDOWS\Panther
      2017-05-28 15:03 - 2016-04-24 15:08 - 00000000 ____D C:\Users\Johanna\AppData\Roaming\PhotoScape
      2017-05-28 15:03 - 2016-04-24 00:30 - 00000000 ____D C:\Users\Johanna\AppData\Roaming\DAEMON Tools Lite
      2017-05-26 23:09 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\PrintDialog
      2017-05-26 22:58 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
      2017-05-26 22:57 - 2016-04-24 00:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
      2017-05-23 19:43 - 2016-04-23 14:04 - 00000000 ____D C:\WINDOWS\system32\MRT
      2017-05-23 19:42 - 2016-04-23 14:04 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

      ==================== Files in the root of some directories =======

      2016-04-14 02:18 - 2016-04-14 02:18 - 0001422 _____ () C:\Users\Johanna\AppData\Roaming\DimorphWitPossumBileBarbarian
      2014-05-08 07:44 - 2014-05-08 07:44 - 0004137 _____ () C:\Users\Johanna\AppData\Roaming\estphon.env
      2013-10-02 04:54 - 2013-10-02 04:54 - 0000065 _____ () C:\Users\Johanna\AppData\Roaming\Kerguelen
      2016-04-14 02:18 - 2016-04-14 02:18 - 0050354 _____ () C:\Users\Johanna\AppData\Roaming\minus.image.xml
      2013-10-02 04:56 - 2013-10-02 04:56 - 0001603 _____ () C:\Users\Johanna\AppData\Roaming\preferred.mediaobject.role.xml
      2013-10-02 04:55 - 2013-10-02 04:55 - 0000246 _____ () C:\Users\Johanna\AppData\Roaming\rc-b-l-15-1body-2menu-3menu.png
      2015-05-20 03:14 - 2015-05-20 03:14 - 0001720 _____ () C:\Users\Johanna\AppData\Roaming\tweakNetworkingManual_pt-pt.p5p
      2017-03-30 13:34 - 2017-03-30 13:34 - 0000754 _____ () C:\Users\Johanna\AppData\Local\recently-used.xbel
      2016-06-05 11:48 - 2016-06-05 15:41 - 0012311 _____ () C:\ProgramData\hpzinstall.log

      Some files in TEMP:
      ====================
      2017-06-10 19:59 - 2017-06-10 20:07 - 58012600 _____ (Panda Security, S.L.) C:\Users\Johanna\AppData\Local\Temp\{60C285D3-FC45-4D0E-9AD3-29BEC394D49D}.exe

      ==================== Bamital & volsnap ======================

      (There is no automatic fix for files that do not pass verification.)

      C:\WINDOWS\system32\winlogon.exe => File is digitally signed
      C:\WINDOWS\system32\wininit.exe => File is digitally signed
      C:\WINDOWS\explorer.exe => File is digitally signed
      C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
      C:\WINDOWS\system32\svchost.exe => File is digitally signed
      C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
      C:\WINDOWS\system32\services.exe => File is digitally signed
      C:\WINDOWS\system32\User32.dll => File is digitally signed
      C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
      C:\WINDOWS\system32\userinit.exe => File is digitally signed
      C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
      C:\WINDOWS\system32\rpcss.dll => File is digitally signed
      C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
      C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
      C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

      LastRegBack: 2017-06-02 20:37

      ==================== End of FRST.txt ============================

    2. #2
      Usuario Avatar de jmirabel
      Registrado
      jun 2017
      Ubicación
      España
      Mensajes
      3

      Re: Apertura de paginas de publicidad y problemas en chrome

      Addition.txt


      Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-06-2017
      Ran by Johanna (11-06-2017 17:51:22)
      Running from C:\Users\Johanna\Desktop
      Windows 10 Pro Version 1607 (X64) (2016-09-14 13:42:11)
      Boot Mode: Normal
      ==========================================================


      ==================== Accounts: =============================

      Administrador (S-1-5-21-1477174034-2186171754-939287862-500 - Administrator - Disabled)
      DefaultAccount (S-1-5-21-1477174034-2186171754-939287862-503 - Limited - Disabled)
      HomeGroupUser$ (S-1-5-21-1477174034-2186171754-939287862-1003 - Limited - Enabled)
      Invitado (S-1-5-21-1477174034-2186171754-939287862-501 - Limited - Disabled)
      Johanna (S-1-5-21-1477174034-2186171754-939287862-1001 - Administrator - Enabled) => C:\Users\Johanna

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AV: Panda Protection (Disabled - Up to date) {46AEFD02-ACA3-E038-1FA5-4A15EFD361E0}
      AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: Panda Protection (Disabled - Up to date) {FDCF1CE6-8A99-EFB6-2515-716794542B5D}
      FW: Panda Firewall (Disabled) {7E957C27-E6CC-E160-34FA-E3201100269B}

      ==================== Installed Programs ======================

      (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      µTorrent (HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
      64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
      7-Zip (HKLM\...\7-Zip) (Version: 9.22 - 2011 Igor Pavlov)
      Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
      Ares (HKLM-x32\...\Ares) (Version: 2.4.2 - Ares)
      Camtasia Studio 8 (HKLM-x32\...\{AF33D0D2-2627-4AC8-8473-FDBB7892129C}) (Version: 8.6.0.2079 - TechSmith Corporation)
      CCleaner (HKLM\...\CCleaner) (Version: 5.30 - Piriform)
      Citrix Online Launcher (HKLM-x32\...\{97C200CA-BF24-41B9-B111-A7E47F8FD57E}) (Version: 1.0.456 - Citrix)
      Configurador_FNMT (HKLM-x32\...\{438D4C4C-B703-4971-9C3D-33FF8A010ADB}) (Version: 3.6 - FNMT-RCM)
      DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.3.0.0154 - Disc Soft Ltd)
      Defraggler (HKLM\...\Defraggler) (Version: 2.10.424 - © 2012 Piriform Ltd)
      ELAN Touchpad 11.15.0.18_X64 (HKLM\...\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
      Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
      Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
      GoToMeeting 8.6.0.7107 (HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\GoToMeeting) (Version: 8.6.0.7107 - CitrixOnline)
      KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
      Malwarebytes Anti-Malware versión 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
      Micromega Software System EasyScan (HKLM-x32\...\Micromega Software EasyScan) (Version: - )
      Microsoft Office Profesional Plus 2016 - es-es (HKLM\...\ProPlusRetail - es-es) (Version: 16.0.8067.2115 - Microsoft Corporation)
      Microsoft OneDrive (HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
      Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
      Mozilla Firefox 53.0.3 (x86 es-ES) (HKLM-x32\...\Mozilla Firefox 53.0.3 (x86 es-ES)) (Version: 53.0.3 - Mozilla)
      Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 53.0.3.6347 - Mozilla)
      Notepad2 (Notepad Replacement) (HKLM\...\Notepad2) (Version: 4.2.25.796 - © 2012 Florian Balmer)
      Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
      Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
      Office 16 Click-to-Run Licensing Component (Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
      Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7967.2073 - Microsoft Corporation) Hidden
      Panda Devices Agent (x32 Version: 1.03.08 - Panda Security) Hidden
      Panda Devices Agent (x32 Version: 1.08.00 - Panda Security) Hidden
      Panda Protection (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 18.01.00.0001 - Panda Security)
      Panda Protection (Version: 8.91.00 - Panda Security) Hidden
      PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
      Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.104 - Skype Technologies S.A.)
      Spotify (HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\Spotify) (Version: 1.0.54.1079.g3809528e - Spotify AB)
      TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.76421 - TeamViewer)
      VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
      WinRAR 4.20 (64-bit) (HKLM\...\WinRAR) (Version: 4.20 - © 2013 Alexander Roshal)

      ==================== Custom CLSID (Whitelisted): ==========================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      CustomCLSID: HKU\S-1-5-21-1477174034-2186171754-939287862-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Johanna\AppData\Local\Citrix\GoToMeeting\6956\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)

      ==================== Scheduled Tasks (Whitelisted) =============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

      Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-1477174034-2186171754-939287862-1001.job => C:\Users\Johanna\AppData\Local\Citrix\GoToMeeting\7107\g2mupdate.exe
      Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-1477174034-2186171754-939287862-1001.job => C:\Users\Johanna\AppData\Local\Citrix\GoToMeeting\7107\g2mupload.exe

      ==================== Shortcuts =============================

      (The entries could be listed to be restored or removed.)

      ==================== Loaded Modules (Whitelisted) ==============

      2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
      2017-05-10 19:59 - 2017-04-28 02:49 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
      2016-09-15 16:31 - 2016-09-07 06:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
      2017-03-15 10:29 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
      2017-03-15 10:30 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
      2017-03-15 10:30 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
      2017-03-15 10:30 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
      2017-05-10 19:59 - 2017-04-28 01:36 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
      2017-05-10 19:59 - 2017-04-28 01:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
      2017-05-10 19:59 - 2017-04-28 01:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
      2017-06-08 16:47 - 2017-06-08 16:47 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
      2017-06-08 16:47 - 2017-06-08 16:47 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
      2017-06-08 16:47 - 2017-06-08 16:47 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll
      2017-06-08 16:47 - 2017-06-08 16:47 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll
      2012-11-26 23:54 - 2012-11-26 23:54 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
      2017-05-19 20:17 - 2017-05-19 20:17 - 00073728 _____ () C:\Program Files\CCleaner\lang\lang-1034.dll
      2015-12-15 19:17 - 2015-12-15 19:17 - 00618544 _____ () C:\Program Files (x86)\Panda Security\Panda Security Protection\SQLite3.dll

      ==================== Alternate Data Streams (Whitelisted) =========

      (If an entry is included in the fixlist, only the ADS will be removed.)


      ==================== Safe Mode (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"

      ==================== Association (Whitelisted) ===============

      (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


      ==================== Internet Explorer trusted/restricted ===============

      (If an entry is included in the fixlist, it will be removed from the registry.)

      IE trusted site: HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\fnmt.es -> hxxp://fnmt.es
      IE trusted site: HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\fnmt.es -> hxxps://fnmt.es
      IE trusted site: HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\fnmt.gob.es -> hxxps://fnmt.gob.es
      IE trusted site: HKU\S-1-5-21-1477174034-2186171754-939287862-1001\...\fnmt.gob.es -> hxxp://fnmt.gob.es

      ==================== Hosts content: ===============================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2013-08-22 15:25 - 2017-05-26 23:18 - 00000873 _____ C:\WINDOWS\system32\Drivers\etc\hosts

      0.0.0.0 keystone.mwbsys.com

      ==================== Other Areas ============================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\Control Panel\Desktop\\Wallpaper ->
      DNS Servers: 80.58.61.250 - 80.58.61.254
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      Windows Firewall is enabled.

      ==================== MSCONFIG/TASK MANAGER disabled items ==


      ==================== FirewallRules (Whitelisted) ===============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      FirewallRules: [UDP Query User{5458EF3F-7BA3-43E3-89DD-CEA0E607A207}C:\users\johanna\appdata\roaming\utorrent\updates\3.4.8_42449.exe] => (Block) C:\users\johanna\appdata\roaming\utorrent\updates\3.4.8_42449.exe
      FirewallRules: [TCP Query User{86C2C31B-422A-466F-8695-59192D4A5D73}C:\users\johanna\appdata\roaming\utorrent\updates\3.4.8_42449.exe] => (Block) C:\users\johanna\appdata\roaming\utorrent\updates\3.4.8_42449.exe
      FirewallRules: [{094B32AB-0DAF-4412-A0C7-A452D9D8BD87}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\{FD126052-310E-4364-937B-6B5564F24578}\setup\hpznui40.exe
      FirewallRules: [UDP Query User{FCF8E38E-A274-43D2-AB14-C4C02B99D38F}C:\users\johanna\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\johanna\appdata\roaming\spotify\spotify.exe
      FirewallRules: [TCP Query User{E03A7897-918C-4381-A4C0-CED17343F30F}C:\users\johanna\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\johanna\appdata\roaming\spotify\spotify.exe
      FirewallRules: [UDP Query User{A946F3B4-3023-4A54-898A-B3810A42BDDC}C:\users\johanna\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\johanna\appdata\roaming\spotify\spotify.exe
      FirewallRules: [TCP Query User{995B4BF2-9775-47A1-A261-3E42007ECA5B}C:\users\johanna\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\johanna\appdata\roaming\spotify\spotify.exe
      FirewallRules: [{C6698F41-6D74-47A7-B06F-9E77BCA9B53F}] => (Allow) C:\Users\Johanna\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{F4C1E441-CF9F-4484-9580-3DFDB477CBC1}] => (Allow) C:\Users\Johanna\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{728634A7-6E04-4B17-A59B-286411307BD2}] => (Allow) C:\Users\Johanna\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{50427E56-B83F-4F17-A78B-D6628FDC98FA}] => (Allow) C:\Users\Johanna\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{54FE6B30-24DB-4201-AF75-8B8865BFB9AA}] => (Allow) C:\Users\Johanna\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{F8F682F3-F956-4CC4-85D9-61324B61EBA1}] => (Allow) C:\Users\Johanna\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [UDP Query User{829B770E-F7D8-4351-9BE1-9F93CCC2969F}C:\program files (x86)\ares\ares.exe] => (Allow) C:\program files (x86)\ares\ares.exe
      FirewallRules: [TCP Query User{3DB45DF6-FCA2-4DB9-ADA7-7B725D857260}C:\program files (x86)\ares\ares.exe] => (Allow) C:\program files (x86)\ares\ares.exe
      FirewallRules: [{8DD25D2B-0778-4ECD-B526-249CF87C60ED}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{6141516F-4BB7-43C4-BD2F-539C4022E81B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{30494B00-6196-4432-B00A-5E57357045EB}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
      FirewallRules: [{25250439-87FC-4B77-B743-F46FF725B789}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
      FirewallRules: [{D7CA55F1-4022-42FD-A0DF-B56D64BEDCF8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
      FirewallRules: [{AF1510D2-BA95-40C7-AD32-E803D601236F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
      FirewallRules: [{24C87774-AE0C-4E76-ACA9-5F3AAFF8249D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
      FirewallRules: [{34169BC1-ECAA-4777-A3C9-61582634DB5E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
      FirewallRules: [{D0CD5C4D-C63E-453C-B55F-B92DAA443F88}] => (Allow) LPort=1688
      FirewallRules: [{C372C985-42B1-40DE-B2E5-A0FC8C87D28D}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
      FirewallRules: [{5EB8AA24-B8BD-49DA-B03D-3EB12A00EA39}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
      FirewallRules: [{BCA78652-F502-41DB-94AE-78E1F98FF0FE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      FirewallRules: [{F7F72339-7177-40B9-97A9-4CD02F172259}] => (Allow) LPort=8317
      FirewallRules: [{E6AE05CC-896F-4197-8F38-D5B857CABCAB}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
      FirewallRules: [{5E36002C-C1BD-411C-9410-0D014B28F31D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
      FirewallRules: [{C291A725-4BCD-4BCD-8A0E-3736F82F9192}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
      FirewallRules: [{9C3070AC-2FE7-45C5-8024-CE7440238F2B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe

      ==================== Restore Points =========================

      31-05-2017 11:04:42 Windows Update
      07-06-2017 18:50:21 Installed Camtasia Studio 8
      11-06-2017 17:31:02 JRT Pre-Junkware Removal

      ==================== Faulty Device Manager Devices =============

      Name: Dispositivo base del sistema
      Description: Dispositivo base del sistema
      Class Guid:
      Manufacturer:
      Service:
      Problem: : The drivers for this device are not installed. (Code 28)
      Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

      Name: Dispositivo base del sistema
      Description: Dispositivo base del sistema
      Class Guid:
      Manufacturer:
      Service:
      Problem: : The drivers for this device are not installed. (Code 28)
      Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

      Name: 260ci WIA Driver (USB)
      Description: 260ci WIA Driver (USB)
      Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
      Manufacturer: Kyocera
      Service: usbscan
      Problem: : This device cannot start. (Code10)
      Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
      On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

      Name: 260ci WIA Driver (USB)
      Description: 260ci WIA Driver (USB)
      Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
      Manufacturer: Kyocera
      Service: usbscan
      Problem: : This device cannot start. (Code10)
      Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
      On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

      Name: Dispositivo base del sistema
      Description: Dispositivo base del sistema
      Class Guid:
      Manufacturer:
      Service:
      Problem: : The drivers for this device are not installed. (Code 28)
      Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


      ==================== Event log errors: =========================

      Application errors:
      ==================
      Error: (06/11/2017 05:31:05 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

      Details:
      AddLegacyDriverFiles: Unable to back up image of binary Protocolo de detección de nivel de vínculo de Microsoft.

      System Error:
      Acceso denegado.
      .

      Error: (06/11/2017 04:39:00 PM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Error al generar el contexto de activación para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Error en el archivo de manifiesto o directiva "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" en la línea 1.
      La identidad de componente encontrada en el manifiesto no coincide con la del componente solicitado.
      La referencia es UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      La definición es UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use sxstrace.exe para obtener un diagnóstico detallado.

      Error: (06/10/2017 08:09:36 PM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Error al generar el contexto de activación para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Error en el archivo de manifiesto o directiva "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" en la línea 1.
      La identidad de componente encontrada en el manifiesto no coincide con la del componente solicitado.
      La referencia es UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      La definición es UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use sxstrace.exe para obtener un diagnóstico detallado.

      Error: (06/10/2017 08:08:55 PM) (Source: SecurityCenter) (EventID: 16) (User: )
      Description: Error al actualizar el estado a SECURITY_PRODUCT_STATE_OFF (error %3).

      Error: (06/10/2017 08:08:54 PM) (Source: SecurityCenter) (EventID: 16) (User: )
      Description: Error al actualizar el estado a SECURITY_PRODUCT_STATE_ON (error %3).

      Error: (06/10/2017 08:08:52 PM) (Source: SecurityCenter) (EventID: 16) (User: )
      Description: Error al actualizar el estado a SECURITY_PRODUCT_STATE_OFF (error %3).

      Error: (06/10/2017 05:00:19 PM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Error al generar el contexto de activación para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Error en el archivo de manifiesto o directiva "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" en la línea 1.
      La identidad de componente encontrada en el manifiesto no coincide con la del componente solicitado.
      La referencia es UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      La definición es UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use sxstrace.exe para obtener un diagnóstico detallado.

      Error: (06/09/2017 10:25:14 AM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Error al generar el contexto de activación para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Error en el archivo de manifiesto o directiva "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" en la línea 1.
      La identidad de componente encontrada en el manifiesto no coincide con la del componente solicitado.
      La referencia es UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      La definición es UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use sxstrace.exe para obtener un diagnóstico detallado.

      Error: (06/08/2017 09:17:17 AM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Error al generar el contexto de activación para "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest". Error en el archivo de manifiesto o directiva "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" en la línea 1.
      La identidad de componente encontrada en el manifiesto no coincide con la del componente solicitado.
      La referencia es UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
      La definición es UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
      Use sxstrace.exe para obtener un diagnóstico detallado.

      Error: (06/07/2017 06:50:23 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
      Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

      Details:
      AddLegacyDriverFiles: Unable to back up image of binary Protocolo de detección de nivel de vínculo de Microsoft.

      System Error:
      Acceso denegado.
      .


      System errors:
      =============
      Error: (06/11/2017 05:46:36 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
      Description: El servidor {784E29F4-5EBE-4279-9948-1E8FE941646D} no se registró con DCOM dentro del tiempo de espera requerido.

      Error: (06/11/2017 05:43:36 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
      Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
      {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
      y APPID
      {F72671A9-012C-4725-9D2F-2A4D32D65169}
      al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

      Error: (06/11/2017 05:42:55 PM) (Source: Microsoft-Windows-EnhancedStorage-EhStorTcgDrv) (EventID: 10) (User: NT AUTHORITY)
      Description: A TCG Command has returned an error.
      Desc: AuthenticateSession
      Param1: 0x1
      Param2: 0x60000001c
      Param3: 0x900000006
      Param4: 0x0
      Status: 0x1

      Error: (06/11/2017 05:42:39 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
      Description: La configuración de permisos específico de la aplicación no concede el permiso Activación Local para la aplicación de servidor COM con CLSID
      {D63B10C5-BB46-4990-A94F-E40B9D520160}
      y APPID
      {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
      al usuario NT AUTHORITY\SYSTEM con SID (S-1-5-18) en la dirección LocalHost (con LRPC) que se ejecuta en el contenedor de aplicaciones con SID No disponible (No disponible). Este permiso de seguridad se puede modificar mediante la herramienta administrativa Servicios de componentes.

      Error: (06/11/2017 05:42:05 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
      Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Windows Search, pero ocurrió el siguiente error:
      Ya se está ejecutando una instancia de este servicio.

      Error: (06/11/2017 05:41:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: El servicio Panda Protection Service terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 0 milisegundos: Reiniciar el servicio.

      Error: (06/11/2017 05:41:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: El servicio panda_url_filtering Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

      Error: (06/11/2017 05:41:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
      Description: El servicio Panda Devices Agent terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 300000 milisegundos: Reiniciar el servicio.

      Error: (06/11/2017 05:41:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: El servicio Disc Soft Lite Bus Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

      Error: (06/11/2017 05:41:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: El servicio MBAMService se terminó de manera inesperada. Esto ha sucedido 2 veces.


      ==================== Memory info ===========================

      Processor: Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz
      Percentage of memory in use: 57%
      Total physical RAM: 3884.55 MB
      Available physical RAM: 1661 MB
      Total Virtual: 4588.55 MB
      Available Virtual: 1976.17 MB

      ==================== Drives ================================

      Drive c: () (Fixed) (Total:237.69 GB) (Free:40.49 GB) NTFS

      ==================== MBR & Partition Table ==================

      ========================================================
      Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: 48588123)
      Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=237.7 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

      ==================== End of Addition.txt ============================

    3. #3
      Moderadora Gral.
      Avatar de @Daniela
      Registrado
      abr 2011
      Ubicación
      España
      Mensajes
      23.819

      Re: Apertura de paginas de publicidad y problemas en chrome

      Hola jmirabel


      Pon el reporte de Malwarebytes mientras reviso FRST.

      Un saludo
      ✿◕‿◕✿ La impaciencia no es buena compañía ✿◕‿◕✿

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    4. #4
      Usuario Avatar de jmirabel
      Registrado
      jun 2017
      Ubicación
      España
      Mensajes
      3

      Re: Apertura de paginas de publicidad y problemas en chrome

      Malwarebytes Anti-Malware
      www.malwarebytes.org

      Fecha del análisis: 11/06/2017
      Hora del análisis: 23:04
      Archivo de registro: 1.txt
      Administrador: Sí

      Versión: 2.2.0.1024
      Base de datos de malwares: v2017.06.11.04
      Base de datos de rootkits: v2017.05.27.01
      Licencia: Premium
      Protección contra el malware: Activado
      Protección contra sitios web maliciosos: Activado
      Autoprotección: Desactivado

      SO: Windows 10
      CPU: x64
      Sistema de archivos: NTFS
      Usuario: Johanna

      Tipo de análisis: Análisis de amenazas
      Resultado: Completado
      Objetos analizados: 327986
      Tiempo transcurrido: 6 min, 35 seg

      Memoria: Activado
      Inicio: Activado
      Sistema de archivos: Activado
      Archivo: Activado
      Rootkits: Desactivado
      Heurística: Activado
      PUP: Activado
      PUM: Activado

      Procesos: 0
      (No hay elementos maliciosos detectados)

      Módulos: 0
      (No hay elementos maliciosos detectados)

      Claves del registro: 0
      (No hay elementos maliciosos detectados)

      Valores del registro: 0
      (No hay elementos maliciosos detectados)

      Datos del registro: 0
      (No hay elementos maliciosos detectados)

      Carpetas: 0
      (No hay elementos maliciosos detectados)

      Archivos: 0
      (No hay elementos maliciosos detectados)

      Sectores físicos: 0
      (No hay elementos maliciosos detectados)


      (end)

    5. #5
      Moderadora Gral.
      Avatar de @Daniela
      Registrado
      abr 2011
      Ubicación
      España
      Mensajes
      23.819

      Re: Apertura de paginas de publicidad y problemas en chrome

      Hola

      Sigue estos pasos, MUY Importante ~ Realiza una copia de seguridad del registro :

      • Para hacerlo descarga >> DelFix en tu escritorio.
        • Doble clic para ejecutarlo.(Si usas Windows Vista/7 u 8 presiona clic derecho y selecciona "Ejecutar como Administrador.")
        • Marca unicamente la casilla "Create registry backup".
      • Pulsar en Run.

        Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.


      A continuación inicia tu equipo desde el >> Modo Seguro de Windows con función de red.

      Si tu SO es Windows 8/8.1/10 usa el 2º MÉTODO: de esta Faq de Windows 8 (aplicable a Windows 10) >> ¿Cómo iniciar Windows 8/8.1 en Modo Seguro?, para trabajar desde ese modo de windows.


      Con los demás programas cerrados ve a >> Inicio >> Ejecutar >> y escribe notepad.exe.

      Ahora copia y pega estos archivos dentro del Notepad: (Se excluye la palabra código)

      Código:
      Start
      CreateRestorePoint:
      CloseProcesses:
      
      (© 2015 Microsoft Corporation) C:\Users\Johanna\AppData\Local\Microsoft\BingSvc\BingSvc.exe
      GroupPolicyScripts: Restriction <======= ATTENTION
      GroupPolicyScripts-x32: Restriction <======= ATTENTION
      HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pclatino.*************/
      HKU\S-1-5-21-1477174034-2186171754-939287862-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://pclatino.*************/
      Toolbar: HKLM - No Name - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - No File
      FF Extension: (Bing Search) - C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\Extensions\[email protected] [2017-03-05]
      FF Extension: (signTextJS) - C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\Extensions\[email protected] [2017-05-28]
      FF Extension: (Follow-on Search Telemetry) - C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\features\{544d9ab7-3e9b-49fd-9b3a-fef97fa3edc3}\[email protected] [2017-06-06]
      FF SearchPlugin: C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\ak96dsl9.default\searchplugins\bing-.xml [2017-03-05]
      CHR NewTab: Default -> Not-active:"chrome-extension://fcfenmboojpjinhpgggodefccipikbpd/newTab.html", Not-active:"chrome-extension://bnnelcjphpdfnliejknghmgjifnnkmoh/zlalwe.html", Not-active:"chrome-extension://mbjagikgfihlmlkbldaoklfikmcnjacb/newtab.html"
      CHR Extension: (Google Docs) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-24]
      CHR Extension: (Maniya sites) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnnelcjphpdfnliejknghmgjifnnkmoh [2017-02-27]
      CHR Extension: (Documentos de Google sin conexión) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-24]
      CHR Extension: (Kolyan site) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbjagikgfihlmlkbldaoklfikmcnjacb [2017-02-12]
      CHR Extension: (Compose Hot Mail) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\moacggjajgoklflpminchmojpagdfnmi [2017-05-22]
      CHR Extension: (Chrome Media Router) - C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-15]
      2017-06-10 20:09 - 2017-06-11 17:41 - 00000000 ____D C:\Program Files\Panda Security URL Filtering
      2017-06-10 20:09 - 2017-06-10 20:09 - 00000000 ____D C:\ProgramData\panda_url_filtering
      2017-06-10 19:59 - 2017-06-10 20:07 - 58012600 _____ (Panda Security, S.L.) C:\Users\Johanna\AppData\Local\Temp\{60C285D3-FC45-4D0E-9AD3-29BEC394D49D}.exe 
      
      CMD: ipconfig /flushdns
      CMD: ipconfig /renew
      CMD: bitsadmin /reset /allusers
      RemoveProxy:
      EmptyTemp:
      Hosts:
      end
      • Lo guardas bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

      Nota: Es necesario que el ejecutable Frst.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajara.

      ATENCION!!!! El siguiente Script de reparación fue hecho específicamente por un miembro del staff para este usuario, si tiene un problema similar por favor abra su propio tema para recibir ayuda personalizada. Usar Scripts de otros usuarios puede causar daños a su equipo

      • Ejecutas Frst.exe.
      • Presionas el botón Fix y aguardas a que termine.
      • La Herramienta guardara el reporte en tu escritorio (Fixlog.txt).
      • Lo pegas en tu próxima respuesta.


      Pon el reporte y comenta como sigue el problema.

      Un saludo
      ✿◕‿◕✿ La impaciencia no es buena compañía ✿◕‿◕✿

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.