• Registrarse
  • Iniciar sesión


  • Página 3 de 6 PrimeroPrimero 123456 ÚltimoÚltimo
    Resultados 21 al 30 de 56

    Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

    Reporte de JRT -+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.3 (04.10.2017) Operating System: Windows 8.1 Pro x64 Ran by CARLOS MONTALVAN (Administrator) on 29/06/2017 at 20:08:00.53 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 0 Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ...

    1. #21
      Usuario Avatar de Calin120
      Registrado
      oct 2007
      Ubicación
      Perú
      Mensajes
      29
      Reporte de JRT
      -+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Junkware Removal Tool (JRT) by Malwarebytes
      Version: 8.1.3 (04.10.2017)
      Operating System: Windows 8.1 Pro x64
      Ran by CARLOS MONTALVAN (Administrator) on 29/06/2017 at 20:08:00.53
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




      File System: 0




      Registry: 0





      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      Scan was completed on 29/06/2017 at 20:09:40.50
      End of JRT log
      ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

      Reporte de ADWCLEANER
      # AdwCleaner v6.047 - Archivo de registro creado 29/06/2017 en 20:20:42
      # Actualizado en 19/05/2017 por Malwarebytes
      # Base de datos : 2017-06-29.3 [Servidor]
      # Sistema Operativo : Windows 8.1 Pro (X64)
      # Nombre de usuario : CARLOS MONTALVAN - MONTALVAN
      # Ejecutado desde : C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\adwcleaner_6.047.exe
      # Modo: Limpiar
      # Soporte : https://www.malwarebytes.com/support



      ***** [ Servicios ] *****



      ***** [ Carpetas ] *****



      ***** [ Archivos ] *****



      ***** [ DLL ] *****



      ***** [ WMI ] *****



      ***** [ Accesos directos ] *****



      ***** [ Tareas programadas ] *****



      ***** [ Registro ] *****



      ***** [ Navegadores ] *****



      *************************

      :: Llaves "Tracing" eliminadas
      :: Se han borrado los ajustes de Winsock

      *************************

      C:\AdwCleaner\AdwCleaner[C0].txt - [1167 Bytes] - [18/06/2017 21:55:43]
      C:\AdwCleaner\AdwCleaner[C2].txt - [926 Bytes] - [29/06/2017 20:20:42]
      C:\AdwCleaner\AdwCleaner[S0].txt - [1404 Bytes] - [18/06/2017 21:55:24]
      C:\AdwCleaner\AdwCleaner[S1].txt - [1559 Bytes] - [29/06/2017 20:19:48]

      ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1144 Bytes] ##########

      Guardado de CCLEANER

      Tareas:
      Yes HKCU:Run CCleaner Monitoring Piriform Ltd CARLOS MONTALVAN "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
      Yes HKLM:Run Acrobat Assistant 8.0 Adobe Systems Inc. All users "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
      Yes HKLM:Run Adobe Acrobat Speed Launcher Adobe Systems Incorporated All users "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
      Yes HKLM:Run AdobeAAMUpdater-1.0 Adobe Systems Incorporated All users "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
      Yes HKLM:Run AdobeCS6ServiceManager Adobe Systems Incorporated All users "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
      Yes HKLM:Run APSDaemon Apple Inc. All users "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
      Yes HKLM:Run CanonQuickMenu CANON INC. All users C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
      Yes HKLM:Run Everything All users "C:\Program Files\Everything\Everything.exe" -startup
      Yes HKLM:Run RealDownloader RealNetworks, Inc. All users C:\program files (x86)\real\realplayer\RealDownloader\downloader2.exe
      Yes HKLM:Run RemoteControl11 CyberLink Corp. All users "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
      Yes HKLM:Run SwitchBoard Adobe Systems Incorporated All users C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
      Yes HKLM:Run TkBellExe RealNetworks, Inc. All users "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
      Yes HKLM:Run USB Security Zbshareware Lab All users C:\Program Files (x86)\USB Disk Security\USBGuard.exe
      Yes HKLM:Run VDeck VIA All users "C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" 1
      Yes Startup Common ImageBrowser EX Agent.lnk All users C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
      Yes Startup Common RealTimes.lnk RealNetworks, Inc. All users C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe

      Guardado de CCLEANER

      Programas:
      Adobe Acrobat Reader DC - Español Adobe Systems Incorporated 11/04/2017 250 MB 17.009.20044 All users
      Adobe Acrobat X Pro - Italiano, Español, Nederlands, Português Adobe Systems 13/09/2016 3.05 GB 10.1.16 All users
      Adobe AIR Adobe Systems Incorporated 05/07/2016 18.0.0.144 All users
      Adobe Creative Suite 6 Master Collection Adobe Systems Incorporated 05/07/2016 7.74 GB 6 All users
      Adobe Flash Player 26 NPAPI Adobe Systems Incorporated 16/06/2017 5.17 MB 26.0.0.131 All users
      Adobe Flash Player 26 PPAPI Adobe Systems Incorporated 16/06/2017 3.53 MB 26.0.0.131 All users
      Adobe Help Manager Adobe Systems Incorporated 05/07/2016 4.0.244 All users
      Adobe Lightroom Adobe Systems Incorporated 21/04/2017 1.42 GB 6.0 All users
      Adobe Shockwave Player 12.1 Adobe Systems, Inc 05/07/2016 53.3 MB 12.1.8.158 All users
      Adobe Widget Browser Adobe Systems Incorporated. 05/07/2016 2.0 Build 348 All users
      Apple Software Update Apple Inc. 10/09/2016 2.69 MB 2.2.0.150 All users
      Bitdefender Agent Bitdefender 19/06/2017 1.0.1 All users
      Canon Easy-WebPrint EX Canon Inc. 16/12/2016 1.7.0.0 All users
      Canon IJ Scan Utility Canon Inc. 16/12/2016 All users
      Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon Inc. 16/12/2016 4.1.0 All users
      Canon MG3500 series MP Drivers Canon Inc. 16/12/2016 1.01 All users
      Canon MG3500 series On-screen Manual Canon Inc. 16/12/2016 7.6.1 All users
      Canon My Image Garden Canon Inc. 16/12/2016 3.5.1 All users
      Canon My Image Garden Design Files Canon Inc. 16/12/2016 3.5.0 All users
      Canon My Printer Canon Inc. 16/12/2016 3.3.0 All users
      Canon Quick Menu Canon Inc. 16/12/2016 2.7.1 All users
      Canon Utilities Digital Photo Professional Canon Inc. 20/09/2016 3.14.40.0 All users
      Canon Utilities EOS Lens Registration Tool Canon Inc. 20/09/2016 1.1.0.6 All users
      Canon Utilities EOS Sample Music Canon Inc. 20/09/2016 1.0.1.1 All users
      Canon Utilities EOS Utility 2 Canon Inc. 20/09/2016 2.14.10.2 All users
      Canon Utilities EOS Web Service Registration Tool Canon Inc. 20/09/2016 1.0.1.3 All users
      Canon Utilities ImageBrowser EX Canon Inc. 20/09/2016 1.5.2.8 All users
      Canon Utilities Map Utility Canon Inc. 20/09/2016 1.7.2.6 All users
      Canon Utilities PhotoStitch Canon Inc. 20/09/2016 3.1.23.47 All users
      Canon Utilities Picture Style Editor Canon Inc. 20/09/2016 1.14.20.0 All users
      CCleaner Piriform 13/06/2017 5.26 All users
      Compatibilidad con Aplicaciones de Apple Apple Inc. 31/07/2016 64.0 MB 2.3.6 All users
      CorelDRAW Graphics Suite X8 (64-Bit) Corel Corporation 10/06/2017 1.45 GB 18.0.0.448 All users
      CyberLink PowerDVD 11 CyberLink Corp. 24/07/2016 224 MB 11.0.1620.51 All users
      ESET NOD32 Antivirus ESET, spol. s r.o. 24/07/2016 163 MB 9.0.318.20 All users
      Everything 1.3.4.686 (x64) 25/07/2016 All users
      FileZilla Client 3.25.2 Tim Kosse 02/05/2017 23.5 MB 3.25.2 All users
      Firebird 1.5.2.4731 Firebird Project 06/10/2016 All users
      Free Video to JPG Converter Digital Wave Ltd 24/05/2017 228 MB 5.0.101.201 All users
      Ghostscript GPL 8.64 (Msi Setup) Corel Corporation 10/06/2017 22.5 MB 8.64 All users
      Google Chrome Google, Inc. 24/07/2016 41.6 MB 59.0.3071.115 All users
      Google Earth Google 05/07/2016 116 MB 6.2.0.5905 All users
      HiSuite Huawei Technologies Co.,Ltd 13/01/2017 1.0 All users
      Intel(R) C++ Redistributables for Windows* on Intel(R) 64 Intel Corporation 10/06/2017 46.7 MB 11.1.048 All users
      Intel(R) Processor Graphics Intel Corporation 18/06/2017 10.18.10.4276 All users
      Java 8 Update 45 Oracle Corporation 24/07/2016 77.1 MB 8.0.450 All users
      Java 8 Update 45 (64-bit) Oracle Corporation 24/07/2016 89.0 MB 8.0.450 All users
      Light Image Resizer 5.0.2.0 ObviousIdea 22/01/2017 29.4 MB 5.0.2.0 All users
      Loquendo TTS: Jorge (Spanish) 29/09/2016 All users
      Loquendo TTS: Juan (Spanish) 29/09/2016 All users
      Microsoft .NET Framework 1.1 05/07/2016 All users
      Microsoft Office Professional Plus 2016 Microsoft Corporation 05/07/2016 16.0.4266.1001 All users
      Microsoft Silverlight Microsoft Corporation 14/06/2017 199 MB 5.1.50907.0 All users
      Microsoft Visual C++ 2005 Redistributable Microsoft Corporation 05/07/2016 4.84 MB 8.0.59193 All users
      Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Corporation 05/07/2016 6.83 MB 8.0.61000 All users
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Corporation 05/07/2016 13.1 MB 9.0.30729.4148 All users
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Corporation 02/11/2016 13.2 MB 9.0.30729.6161 All users
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 05/07/2016 10.1 MB 9.0.30729.4148 All users
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Corporation 02/11/2016 10.1 MB 9.0.30729.6161 All users
      Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Corporation 21/04/2017 13.8 MB 10.0.40219 All users
      Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Corporation 21/04/2017 15.0 MB 10.0.40219 All users
      Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Corporation 21/04/2017 20.5 MB 11.0.61030.0 All users
      Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Corporation 21/04/2017 17.3 MB 11.0.61030.0 All users
      Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 Microsoft Corporation 10/06/2017 24.4 MB 14.0.23506.0 All users
      Mozilla Firefox 54.0 (x86 es-ES) Mozilla 21/06/2017 88.8 MB 54.0 All users
      Mozilla Maintenance Service Mozilla 21/06/2017 295 KB 54.0.0.6368 All users
      MSI to redistribute MS VS2005 CRT libraries The Firebird Project 02/10/2016 1.58 MB 8.0.50727.42 All users
      Nero 05/07/2016 All users
      Nokia Connectivity Cable Driver 20/09/2016 7.1.32.69 All users
      Open Broadcaster Software 31/07/2016 All users
      Picasa 3 Google, Inc. 28/07/2016 82.2 MB 3.9.141.259 All users
      PIXELA AAC LC CODEC Canon Inc. 20/09/2016 1.1.0.1 All users
      QT Lite 2.9.0 24/07/2016 2.9.0 All users
      QuickTime 7 Apple Inc. 31/07/2016 67.9 MB 7.79.80.95 All users
      Real Alternative 1.9.0 24/07/2016 1.9.0 All users
      Recuva Piriform 24/05/2017 1.53 All users
      SAM Broadcaster (remove only) 06/10/2016 All users
      Skype™ 7.0 Skype Technologies S.A. 02/11/2016 47.9 MB 7.0.102 All users
      TeamViewer 7 TeamViewer 24/07/2016 7.0.12799 All users
      Telegram Desktop versión 0.9.56 Telegram Messenger LLP 25/06/2017 32.4 MB 0.9.56 CARLOS MONTALVAN
      TextAloud 3.0 NextUp.com 28/09/2016 22.9 MB 3.0 All users
      USB Disk Security Zbshareware Lab 05/07/2016 12.6 MB All users
      VJDirector2 Ultimate Edition Nanjing Naga Software Ltd. 31/07/2016 2.3.832.0 All users
      VLC media player VideoLAN 02/06/2017 2.2.6 All users
      VSO Image Resizer 2.0.1.3 VSO-Software 25/07/2016 2.0.1.3 All users
      Winamp Nullsoft, Inc 24/07/2016 5.63 All users
      WinRAR 4.10 (32-bit) win.rar GmbH 05/07/2016 4.10.0 All users
      WinZip 18.5 WinZip Computing, S.L. 24/07/2016 155 MB 18.5.11111 All users

    2. #22
      Colaborador Avatar de @OscarCanoL
      Registrado
      may 2008
      Ubicación
      España
      Mensajes
      5.522

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      Hola Calin120, veo que ya está ejecutándose los programas con el usuario principal

      Ran by CARLOS MONTALVAN (Administrator) on 29/06/2017 at 20:08:00.53
      # Nombre de usuario : CARLOS MONTALVAN - MONTALVAN
      # Ejecutado desde : C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\adwcleaner_6.047.exe

      ¿es correcto?
      Acrosknicht

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    3. #23
      Usuario Avatar de Calin120
      Registrado
      oct 2007
      Ubicación
      Perú
      Mensajes
      29

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      No, aun no.

      Estoy en alguno de los usuarios temporales:

      Aquí la captura de lo que es el usuario principal. que aun no se ejecuta.


    4. #24
      Colaborador Avatar de @OscarCanoL
      Registrado
      may 2008
      Ubicación
      España
      Mensajes
      5.522

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      Vale, repite los pasos de la respuesta #14. Déjalo que trabaje, no pares, canceles o apagues el ordenador mientras se hace la revisión con chkdsk.

      Si te fijas en tu captura de pantalla en la respuesta #19 el perfil del usuario termina en 1001 y es justamente esa id debe aparecerte en un reporte tras la ejecución de chkdsk.

      Un saludo.
      Acrosknicht

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    5. #25
      Usuario Avatar de Calin120
      Registrado
      oct 2007
      Ubicación
      Perú
      Mensajes
      29
      Se reinicio solo después de una hora exactamente.
      voy a intentar un nuevo proceso. Pero antes pegare el evento. Espero que ese sea.
      Gracias por tu apoyo.

      Esto fue lo que encontré.......?

      Nombre de registro:Application
      Origen: Microsoft-Windows-Wininit
      Fecha: 29/06/2017 10:08:02 p.m.
      Id. del evento:1001
      Categoría de la tarea:Ninguno
      Nivel: Información
      Palabras clave:Clásico
      Usuario: No disponible
      Equipo: MONTALVAN
      Descripción:


      Comprobando el sistema de archivos en C:
      El tipo del sistema de archivos es NTFS.
      La etiqueta de volumen es WIN 8,1.

      Uno de los discos necesita ser comprobado para ver coherencias.
      Se puede cancelar la comprobación de disco, pero se recomienda
      que continúe.
      Windows comprobará ahora el disco.

      Etapa 1: Examen de la estructura básica del sistema de archivos...
      422912 registros de archivos procesados.

      Comprobación de archivos completada.
      6740 registros de archivos grandes procesados.

      0 registros de archivos no válidos procesados.


      Etapa 2: Examen de la vinculación de nombres de archivos...
      544548 entradas de índice procesadas.

      Comprobación de índices completada.
      0 archivos no indizados examinados.

      0 archivos no indizados recuperados.


      Etapa 3: Examen de los descriptores de seguridad...
      Liberando 72 entradas de índice no usadas del índice $SII del archivo 0x9.
      Liberando 72 entradas de índice no usadas del índice $SDH del archivo 0x9.
      Liberando 72 descriptores de seguridad no usados.
      CHKDSK está compactando la secuencia de descriptores de seguridad
      Comprobación de descriptores de seguridad completada.
      60819 archivos de datos procesados.

      CHKDSK está comprobando el diario USN...
      39469984 bytes de USN procesados.

      Se ha completado la comprobación del diario USN.

      Etapa 4: Búsqueda de clústeres incorrectos en los datos del archivo de usuario...
      422896 archivos procesados.

      Comprobación de datos de archivo completada.

      Etapa 5: Búsqueda de clústeres incorrectos disponibles...
      26730085 clústeres disponibles procesados.

      La comprobación del espacio disponible se completó.
      CHKDSK detectó espacio disponible marcado como asignado en el mapa de bits
      del volumen.

      Windows ha hecho algunas correcciones en el sistema de archivos.
      No se requiere ninguna otra acción.

      255640575 KB de espacio total en disco.
      147987724 KB en 343559 archivos.
      196144 KB en 60822 índices.
      0 KB en sectores defectuosos.
      536367 KB en uso por el sistema.
      El archivo de registro ha ocupado 65536 kilobytes.
      106920340 KB disponibles en disco.

      4096 bytes en cada unidad de asignación.
      63910143 unidades de asignación en disco en total.
      26730085 unidades de asignación disponibles en disco.

      Información interna:
      00 74 06 00 a3 2b 06 00 10 8b 0b 00 00 00 00 00 .t...+..........
      de 03 00 00 65 00 00 00 00 00 00 00 00 00 00 00 ....e...........

      Windows ha finalizado la comprobación del disco.
      Espere mientras se reinicia el sistema.

    6. #26
      Colaborador Avatar de @OscarCanoL
      Registrado
      may 2008
      Ubicación
      España
      Mensajes
      5.522

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      Hola Calin120.

      Necesitamos que nos confirmes ciertos detalles:

      ¿Estás teniendo actualizaciones de Windows que te aparecen para instalar, las instalas y luego cuando inicias sesión, vuelven a salir las mismas actualizaciones cada vez que apagas y/o enciendes.?

      Hemos revisado tus últimos reportes y apreciamos este dato:

      "255640575 KB de espacio total en disco" y el tiempo de chequeo 1 hora
      ¿Tu disco duro actual es un disco SSD de 240gb?
      ¿Era el disco original con el que vino tu ordenador?
      ¿lo cambiaste recientemente por algún fallo?


      Te pedimos que en la medida de lo posible contestes a las interrogantes planteadas y cualquier otro dato que consideres relevante.

      Un saludo.
      Acrosknicht

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    7. #27
      Usuario Avatar de Calin120
      Registrado
      oct 2007
      Ubicación
      Perú
      Mensajes
      29

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      ¿Estás teniendo actualizaciones de Windows que te aparecen para instalar, las instalas y luego cuando inicias sesión, vuelven a salir las mismas actualizaciones cada vez que apagas y/o enciendes.?

      - No me aparece ninguna actualización



      ¿Tu disco duro actual es un disco SSD de 240gb?

      - No es un disco SSD.
      El sistema operativo funciona en un disco HDD particionado en 250 GB (c:).
      La otra unidad D: (250 GBB) es para guardar los archivos.
      Tengo otros discos sin particionar:
      (E:) con 500 GB
      (F:) con 2TB
      (H:) con 500 GB

      ¿Era el disco original con el que vino tu ordenador?
      - No es disco original. Mi computado fue ensamblada en mi ciudad por un técnico.

      ¿lo cambiaste recientemente por algún fallo?
      - La maquina fue armada más o menos hace un año y medio.

      Gracias por tu apoyo

    8. #28
      Colaborador Avatar de @OscarCanoL
      Registrado
      may 2008
      Ubicación
      España
      Mensajes
      5.522

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      Hola Calin120, nada que agradecer

      Sigue por favor estos pasos:

      • Desactivamos temporalmente el antivirus y/o cualquier programa de seguridad que tengamos.
      • Descarga >> Farbar Recovery Scan Tool seleccionando la versión adecuada para la arquitectura(32 o 64bits) de tu equipo. ¿Cómo saber si mi Windows es de 32 o 64 bits?
      • Guardamos la versión seleccionada de "FRST" en el escritorio >> Esto es muy importante..
      • Hacemos doble click para ejecutar FRST.(Si usas Windows Vista/7/8 o 10 presiona clic derecho y selecciona "Ejecutar como Administrador.")
      • En el mensaje de la ventana del Disclaimer, pulsamos Yes.
      • En la ventana principal pulsamos en el botón Scan y esperamos a que concluya el análisis.
      • Se abrirán dos(2) archivos(Logs), Frst.txt y Addition.txt, estos quedaran grabados en el escritorio.

      Para terminar abres los archivos Frst.txt y Addition.Txt para copiarlos y pegarlos con todo su contenido en tu próxima respuesta.

      Utilizaremos varios mensajes si recibimos un mensaje de error indicando que es muy largo. (igual como hiciste con el reporte extenso anterior)

      Saludos.
      Acrosknicht

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    9. #29
      Usuario Avatar de Calin120
      Registrado
      oct 2007
      Ubicación
      Perú
      Mensajes
      29

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      Mensaje de Frst.txt

      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-06-2017
      Ran by CARLOS MONTALVAN (administrator) on MONTALVAN (30-06-2017 16:50:36)
      Running from C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop
      Loaded Profiles: CARLOS MONTALVAN (Available Profiles: CARLOS MONTALVAN)
      Platform: Windows 8.1 Pro (Update) (X64) Language: Español (España, internacional)
      Internet Explorer Version 11 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: ***********************************************************************************************************

      ==================== Processes (Whitelisted) =================

      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

      (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
      () C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
      (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
      (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
      (Digital Wave Ltd.) C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
      (The Firebird Project) C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe
      () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
      (Bitdefender) C:\Program Files\Bitdefender Agent\ProductAgentService.exe
      (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
      (arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
      () C:\Program Files (x86)\Real\RealPlayer\UpdateService\RealPlayerUpdateSvc.exe
      (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
      (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
      (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
      (The Firebird Project) C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe
      (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
      (Intel Corporation) C:\Windows\System32\igfxEM.exe
      (Intel Corporation) C:\Windows\System32\igfxHK.exe
      (Intel Corporation) C:\Windows\System32\igfxTray.exe
      (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
      () C:\Program Files\Everything\Everything.exe
      () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
      (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
      (Zbshareware Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
      (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe
      () C:\Program Files\Everything\Everything.exe
      (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
      (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
      (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
      () C:\Program Files (x86)\Real\RealPlayer\RealDownloader\downloader2.exe
      (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
      (Microsoft Corporation) C:\Windows\splwow64.exe
      (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE

      ==================== Registry (Whitelisted) ====================

      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

      HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
      HKLM\...\Run: [VDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5301880 2012-11-30] (VIA)
      HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [1441792 2014-08-05] ()
      HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [695528 2015-01-31] (Zbshareware Lab)
      HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
      HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
      HKLM-x32\...\Run: [] => [X]
      HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
      HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
      HKLM-x32\...\Run: [RemoteControl11] => C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [234792 2011-04-19] (CyberLink Corp.)
      HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
      HKLM-x32\...\Run: [TkBellExe] => c:\program files (x86)\real\realplayer\Update\realsched.exe [352648 2016-09-25] (RealNetworks, Inc.)
      HKLM-x32\...\Run: [RealDownloader] => C:\program files (x86)\real\realplayer\RealDownloader\downloader2.exe [708336 2016-09-03] ()
      HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-06-09] (CANON INC.)
      Winlogon\Notify\igfxcui: igfxdev.dll [X]
      HKU\S-1-5-21-3922991227-27027531-2577069665-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
      Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk [2016-09-20]
      ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe ()
      Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2016-09-25]
      ShortcutTarget: RealTimes.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.)

      ==================== Internet (Whitelisted) ====================

      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

      Tcpip\Parameters: [DhcpNameServer] 190.113.220.18 190.113.220.51 190.113.220.54
      Tcpip\..\Interfaces\{04DFF949-B3EE-48BC-82D4-117633C5FCC0}: [DhcpNameServer] 190.113.220.18 190.113.220.51 190.113.220.54
      Tcpip\..\Interfaces\{D4D5E79A-CBA0-4363-A4E4-2307A8E7C5B2}: [DhcpNameServer] 200.48.225.146 200.48.225.130

      Internet Explorer:
      ==================
      HKU\S-1-5-21-3922991227-27027531-2577069665-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/es-pe/?ocid=iehp
      BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\program files (x86)\real\realplayer\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2016-09-03] (RealDownloader)
      BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office16\OCHelper.dll [2017-05-16] (Microsoft Corporation)
      BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
      BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2016-07-24] (Oracle Corporation)
      BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-22] (Microsoft Corporation)
      BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2016-07-24] (Oracle Corporation)
      BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\program files (x86)\real\realplayer\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2016-09-03] (RealDownloader)
      BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office16\OCHelper.dll [2015-07-31] (Microsoft Corporation)
      BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
      BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2016-07-24] (Oracle Corporation)
      BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
      BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-22] (Microsoft Corporation)
      BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2016-07-24] (Oracle Corporation)
      BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
      Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
      Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
      Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
      Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
      Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
      Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)
      Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2017-04-11] (Microsoft Corporation)

      FireFox:
      ========
      FF DefaultProfile: tpkxnz6v.default
      FF ProfilePath: C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Mozilla\Firefox\Profiles\tpkxnz6v.default [2017-06-30]
      FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
      FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2016-09-13] [not signed]
      FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-16] ()
      FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2016-07-24] (Oracle Corporation)
      FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2016-07-24] (Oracle Corporation)
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
      FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
      FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-09-19] (Adobe Systems)
      FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-16] ()
      FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2015-04-17] (Adobe Systems, Inc.)
      FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2015-10-29] (CANON INC.)
      FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2012-01-23] (Google)
      FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
      FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2016-07-24] (Oracle Corporation)
      FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2016-07-24] (Oracle Corporation)
      FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-09-13] (Microsoft Corporation)
      FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation)
      FF Plugin-x32: @real.com/nppl3260;version=18.1.5.699 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2016-09-25] (RealNetworks, Inc.)
      FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.69 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2008-09-10] (RealNetworks, Inc.)
      FF Plugin-x32: @real.com/nprpplugin;version=18.1.5.699 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2016-09-25] (RealPlayer)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
      FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
      FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-09-19] (Adobe Systems)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-09-13] (Microsoft Corporation)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2008-09-10] (RealNetworks, Inc.)
      FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll [2008-09-10] (RealNetworks, Inc.)

      Chrome:
      =======
      CHR Profile: C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default [2017-06-30]
      CHR Extension: (Presentaciones de Google) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-06-24]
      CHR Extension: (Google Docs) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-06-24]
      CHR Extension: (Google Drive) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-06-24]
      CHR Extension: (YouTube) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-06-24]
      CHR Extension: (Adobe Acrobat) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-06-24]
      CHR Extension: (Hojas de cálculo de Google) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-06-24]
      CHR Extension: (Documentos de Google sin conexión) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-24]
      CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-06-24]
      CHR Extension: (Gmail) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-06-24]
      CHR Extension: (Chrome Media Router) - C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-27]
      CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

      ==================== Services (Whitelisted) ====================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      S3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [32768 2004-07-15] (Microsoft Corporation) [File not signed]
      R2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-04-19] ()
      R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [70952 2011-03-31] (CyberLink)
      R2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [312616 2011-03-31] (CyberLink)
      R2 DigitalWave.Update.Service; C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe [440808 2017-03-22] (Digital Wave Ltd.)
      R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2770312 2017-06-19] (ESET)
      R2 FirebirdGuardianDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe [65536 2004-12-13] (The Firebird Project) [File not signed]
      R3 FirebirdServerDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe [1527893 2004-12-13] (The Firebird Project) [File not signed]
      R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-04-10] ()
      R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
      R2 ProductAgentService; C:\Program Files\Bitdefender Agent\ProductAgentService.exe [1254736 2017-04-11] (Bitdefender)
      R2 PSI_SVC_2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (arvato digital services llc)
      R2 RealPlayerUpdateSvc; C:\program files (x86)\real\realplayer\UpdateService\RealPlayerUpdateSvc.exe [35104 2016-09-03] ()
      R2 RealTimes Desktop Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [987408 2016-09-25] (RealNetworks, Inc.)
      S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
      R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2012-11-30] (VIA Technologies, Inc.)
      S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
      S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)

      ===================== Drivers (Whitelisted) ======================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [262792 2017-06-19] (ESET)
      S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2017-06-19] (ESET)
      R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [197248 2017-06-19] (ESET)
      R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [181384 2017-06-19] (ESET)
      U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2017-04-10] (Huawei Technologies Co., Ltd.)
      S3 usbser; C:\Windows\system32\drivers\usbser.sys [33280 2017-04-10] (Microsoft Corporation) [File not signed]
      S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
      S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
      S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
      R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-04-12] (CyberLink Corp.)

      ==================== NetSvcs (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


      ==================== One Month Created files and folders ========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2017-06-30 16:50 - 2017-06-30 16:51 - 00021314 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\FRST.txt
      2017-06-30 16:50 - 2017-06-30 16:50 - 00000000 ____D C:\FRST
      2017-06-30 16:49 - 2017-06-30 16:43 - 02440704 _____ (Farbar) C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\FRST64.exe
      2017-06-30 16:43 - 2017-06-30 16:43 - 02440704 _____ (Farbar) C:\Users\CARLOS MONTALVAN.MONTALVAN\Downloads\FRST64.exe
      2017-06-29 13:39 - 2017-06-29 14:24 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\vlc
      2017-06-29 00:08 - 2017-06-29 00:08 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\CEF
      2017-06-27 21:22 - 2017-06-27 21:22 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Apple
      2017-06-27 08:45 - 2017-06-27 08:45 - 00555469 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\Documents\IMG_20170627_0001.pdf
      2017-06-27 08:04 - 2017-06-30 10:24 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\ObviousIdea
      2017-06-26 18:39 - 2017-06-29 00:08 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\LocalLow\Adobe
      2017-06-25 21:59 - 2017-06-25 21:59 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\Documents\Plantillas personalizadas de Office
      2017-06-25 17:42 - 2017-06-30 11:28 - 00816128 ___SH C:\Users\CARLOS MONTALVAN.MONTALVAN\Downloads\Thumbs.db
      2017-06-25 15:09 - 2017-06-25 15:09 - 00001105 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\Telegram.lnk
      2017-06-25 15:09 - 2017-06-25 15:09 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Telegram Desktop
      2017-06-25 15:09 - 2017-06-25 15:09 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
      2017-06-25 03:22 - 2017-06-25 03:22 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\VirtualStore
      2017-06-25 03:21 - 2017-06-25 03:21 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\DVDVideoSoft
      2017-06-25 02:21 - 2017-06-30 16:43 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Everything
      2017-06-25 02:19 - 2017-06-22 22:41 - 00000299 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\Chequear_ Disco_Windows.bat
      2017-06-24 20:35 - 2017-06-24 20:35 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\WinRAR
      2017-06-24 07:52 - 2017-06-24 07:52 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Macromedia
      2017-06-24 07:33 - 2017-06-27 08:45 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Canon
      2017-06-24 07:33 - 2017-06-24 07:33 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Corel
      2017-06-24 07:32 - 2017-06-30 10:24 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Packages
      2017-06-24 07:32 - 2017-06-30 02:50 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\CrashDumps
      2017-06-24 07:32 - 2017-06-30 02:01 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Adobe
      2017-06-24 07:32 - 2017-06-29 19:10 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\LocalLow\Mozilla
      2017-06-24 07:32 - 2017-06-29 00:08 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Adobe
      2017-06-24 07:32 - 2017-06-24 20:41 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Google
      2017-06-24 07:32 - 2017-06-24 20:34 - 00002280 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop\Google Chrome.lnk
      2017-06-24 07:32 - 2017-06-24 07:56 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Mozilla
      2017-06-24 07:32 - 2017-06-24 07:32 - 00001433 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
      2017-06-24 07:32 - 2017-06-24 07:32 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Zbshareware Lab
      2017-06-24 07:32 - 2017-06-24 07:32 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Real
      2017-06-24 07:32 - 2017-06-24 07:32 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Mozilla
      2017-06-24 07:32 - 2017-06-24 07:32 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Apple Computer
      2017-06-24 07:32 - 2017-06-24 07:32 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Real
      2017-06-24 07:30 - 2017-06-28 01:58 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000020 ___SH C:\Users\CARLOS MONTALVAN.MONTALVAN\ntuser.ini
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Reciente
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Plantillas
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Mis documentos
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Menú Inicio
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Impresoras
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Entorno de red
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Documents\Mis vídeos
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Documents\Mis imágenes
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Documents\Mi música
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Datos de programa
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\Configuración local
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Historial
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Datos de programa
      2017-06-24 07:30 - 2017-06-24 07:30 - 00000000 _SHDL C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Archivos temporales de Internet
      2017-06-24 07:30 - 2016-11-02 19:05 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Local\Microsoft Help
      2017-06-24 07:30 - 2016-07-26 10:02 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\RealNetworks
      2017-06-24 07:30 - 2016-07-05 13:48 - 00000000 ____D C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Macromedia
      2017-06-24 07:30 - 2014-03-18 05:20 - 00000369 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
      2017-06-24 07:30 - 2014-03-18 05:20 - 00000369 _____ C:\Users\CARLOS MONTALVAN.MONTALVAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
      2017-06-23 10:58 - 2017-06-24 00:58 - 00004026 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9F362B13-ADFE-4F84-AB4E-AF07CAEBF707}
      2017-06-22 09:14 - 2017-06-22 09:14 - 00030991 _____ C:\ProgramData\agent.update.1498140876.bdinstall.bin
      2017-06-22 09:13 - 2017-06-23 01:23 - 00000000 ____D C:\Users\TEMP.MONTALVAN.017\AppData\Roaming\DVDVideoSoft
      2017-06-22 09:13 - 2017-06-23 01:23 - 00000000 ____D C:\Users\TEMP.MONTALVAN.017
      2017-06-21 10:00 - 2017-06-29 20:05 - 00000000 ____D C:\FSTool
      2017-06-21 03:46 - 2017-06-21 03:49 - 00000000 ____D C:\Users\TEMP.MONTALVAN.015\AppData\Roaming\DVDVideoSoft
      2017-06-21 03:46 - 2017-06-21 03:49 - 00000000 ____D C:\Users\TEMP.MONTALVAN.015
      2017-06-20 23:43 - 2017-06-20 23:43 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
      2017-06-19 23:12 - 2017-06-19 23:12 - 00181384 _____ (ESET) C:\Windows\system32\Drivers\epfwwfpr.sys
      2017-06-19 08:27 - 2017-06-19 21:22 - 00004026 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{7BCC78CD-B4BF-4925-AFB8-CB37DE447A21}
      2017-06-19 06:26 - 2017-06-20 03:06 - 00000000 ____D C:\Users\TEMP.MONTALVAN.014\AppData\Roaming\DVDVideoSoft
      2017-06-19 06:26 - 2017-06-20 03:06 - 00000000 ____D C:\Users\TEMP.MONTALVAN.014
      2017-06-19 00:46 - 2017-06-19 00:46 - 00000000 ____D C:\Program Files\Bitdefender Antivirus Free
      2017-06-19 00:43 - 2017-06-19 00:43 - 00003640 _____ C:\Windows\System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
      2017-06-19 00:41 - 2017-06-30 16:45 - 00000000 ____D C:\Program Files\Bitdefender Agent
      2017-06-19 00:41 - 2017-06-19 00:41 - 00047388 _____ C:\ProgramData\agent.1497850907.bdinstall.bin
      2017-06-19 00:41 - 2017-06-19 00:41 - 00000000 ____D C:\ProgramData\Bitdefender Agent
      2017-06-18 23:15 - 2017-06-19 00:50 - 00000000 ____D C:\Users\TEMP.MONTALVAN.013\AppData\Roaming\DVDVideoSoft
      2017-06-18 23:14 - 2017-06-19 00:50 - 00000000 ____D C:\Users\TEMP.MONTALVAN.013
      2017-06-18 22:00 - 2017-06-18 22:00 - 00000144 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
      2017-06-18 21:59 - 2017-06-18 22:29 - 00000000 ____D C:\Users\TEMP.MONTALVAN.012\AppData\Roaming\DVDVideoSoft
      2017-06-18 21:59 - 2017-06-18 22:29 - 00000000 ____D C:\Users\TEMP.MONTALVAN.012
      2017-06-18 21:52 - 2017-06-29 20:20 - 00000000 ____D C:\AdwCleaner
      2017-06-18 20:22 - 2017-06-18 20:22 - 00000451 _____ C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
      2017-06-18 20:20 - 2017-06-30 16:45 - 00000000 __SHD C:\Users\CARLOS MONTALVAN\IntelGraphicsProfiles
      2017-06-18 20:18 - 2017-06-18 20:18 - 00000000 ____D C:\Program Files\Intel
      2017-06-18 20:18 - 2017-06-18 20:18 - 00000000 ____D C:\Program Files (x86)\Intel
      2017-06-18 20:17 - 2017-06-18 20:18 - 00000000 ____D C:\Windows\LastGood.Tmp
      2017-06-18 10:55 - 2017-06-18 20:21 - 00000000 ____D C:\Users\TEMP.MONTALVAN.011\AppData\Roaming\DVDVideoSoft
      2017-06-18 10:54 - 2017-06-18 20:21 - 00000000 ____D C:\Users\TEMP.MONTALVAN.011
      2017-06-18 10:43 - 2017-06-18 10:49 - 00000000 ____D C:\ProgramData\HitmanPro
      2017-06-18 10:35 - 2017-06-18 10:54 - 00000000 ____D C:\Users\TEMP.MONTALVAN.010\AppData\Roaming\DVDVideoSoft
      2017-06-18 10:35 - 2017-06-18 10:54 - 00000000 ____D C:\Users\TEMP.MONTALVAN.010
      2017-06-18 10:11 - 2017-06-18 10:12 - 02744320 _____ C:\Users\TEMP.MONTALVAN.009\Downloads\ZHPCleaner.exe
      2017-06-18 09:45 - 2017-06-18 10:34 - 00000000 ____D C:\Users\TEMP.MONTALVAN.009
      2017-06-17 21:48 - 2017-06-17 22:06 - 00000000 ____D C:\Users\TEMP.MONTALVAN.008\AppData\Roaming\DVDVideoSoft
      2017-06-17 21:48 - 2017-06-17 22:06 - 00000000 ____D C:\Users\TEMP.MONTALVAN.008
      2017-06-17 21:33 - 2017-06-17 21:47 - 00000000 ____D C:\Users\TEMP.MONTALVAN.007\AppData\Roaming\DVDVideoSoft
      2017-06-17 21:32 - 2017-06-17 21:47 - 00000000 ____D C:\Users\TEMP.MONTALVAN.007
      2017-06-17 21:08 - 2017-06-17 21:22 - 00000000 ____D C:\Users\TEMP.MONTALVAN.006\AppData\Roaming\DVDVideoSoft
      2017-06-17 21:08 - 2017-06-17 21:22 - 00000000 ____D C:\Users\TEMP.MONTALVAN.006
      2017-06-16 15:19 - 2017-06-16 21:55 - 00004026 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E1917DEC-E3C1-4F88-A67C-F6330C34DBB9}
      2017-06-14 03:10 - 2017-06-02 07:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
      2017-06-14 03:10 - 2017-06-02 07:12 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
      2017-06-14 03:10 - 2017-06-02 07:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
      2017-06-14 03:10 - 2017-06-02 07:06 - 01001984 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
      2017-06-14 03:10 - 2017-06-02 07:01 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
      2017-06-14 03:10 - 2017-06-02 06:30 - 03635200 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
      2017-06-14 03:10 - 2017-06-02 06:03 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
      2017-06-14 03:10 - 2017-06-02 05:58 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
      2017-06-14 03:10 - 2017-06-02 05:25 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
      2017-06-14 03:10 - 2017-06-02 05:24 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
      2017-06-14 03:10 - 2017-06-02 05:17 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
      2017-06-14 03:10 - 2017-06-02 05:02 - 02751488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
      2017-06-14 03:10 - 2017-06-02 04:43 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
      2017-06-14 03:10 - 2017-06-02 04:43 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
      2017-06-14 03:10 - 2017-05-15 14:58 - 00121184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys
      2017-06-14 03:10 - 2017-05-14 15:44 - 04170240 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
      2017-06-14 03:10 - 2017-05-14 15:42 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
      2017-06-14 03:10 - 2017-05-14 15:26 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
      2017-06-14 03:10 - 2017-05-14 15:19 - 25738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
      2017-06-14 03:10 - 2017-05-14 15:19 - 01364040 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
      2017-06-14 03:10 - 2017-05-14 15:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
      2017-06-14 03:10 - 2017-05-14 14:55 - 05975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
      2017-06-14 03:10 - 2017-05-14 14:32 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
      2017-06-14 03:10 - 2017-05-14 14:31 - 01033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
      2017-06-14 03:10 - 2017-05-14 14:22 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
      2017-06-14 03:10 - 2017-05-14 14:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
      2017-06-14 03:10 - 2017-05-14 14:11 - 20274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
      2017-06-14 03:10 - 2017-05-14 14:10 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
      2017-06-14 03:10 - 2017-05-14 14:04 - 00315224 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
      2017-06-14 03:10 - 2017-05-14 14:03 - 00373080 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
      2017-06-14 03:10 - 2017-05-14 13:54 - 15252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
      2017-06-14 03:10 - 2017-05-14 13:52 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
      2017-06-14 03:10 - 2017-05-14 13:48 - 05274112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
      2017-06-14 03:10 - 2017-05-14 13:46 - 00880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
      2017-06-14 03:10 - 2017-05-14 13:44 - 04549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
      2017-06-14 03:10 - 2017-05-14 13:38 - 07796736 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
      2017-06-14 03:10 - 2017-05-14 13:37 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
      2017-06-14 03:10 - 2017-05-14 13:30 - 13664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
      2017-06-14 03:10 - 2017-05-14 13:16 - 05268992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
      2017-06-14 03:10 - 2017-05-14 13:15 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
      2017-06-14 03:10 - 2017-05-14 13:13 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
      2017-06-14 03:10 - 2017-05-14 13:11 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
      2017-06-14 03:10 - 2017-05-14 13:06 - 07441240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
      2017-06-14 03:10 - 2017-05-14 13:06 - 01737600 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
      2017-06-14 03:10 - 2017-05-14 13:06 - 01502000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
      2017-06-14 03:10 - 2017-05-12 11:16 - 01084928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
      2017-06-14 03:10 - 2017-05-12 11:13 - 01559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
      2017-06-14 03:10 - 2017-05-11 21:58 - 01985536 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
      2017-06-14 03:10 - 2017-05-11 21:48 - 01377792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
      2017-06-14 03:10 - 2017-05-11 21:18 - 03714560 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
      2017-06-14 03:10 - 2017-05-11 21:07 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
      2017-06-14 03:10 - 2017-05-11 21:04 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
      2017-06-14 03:10 - 2017-05-11 21:00 - 02240512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
      2017-06-14 03:10 - 2017-05-11 18:36 - 22361848 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
      2017-06-14 03:10 - 2017-05-11 18:32 - 19788672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
      2017-06-14 03:10 - 2017-05-10 13:19 - 00101720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
      2017-06-14 03:10 - 2017-05-06 11:05 - 01094656 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
      2017-06-14 03:10 - 2017-05-06 11:04 - 00865792 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
      2017-06-14 03:09 - 2017-05-14 13:40 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
      2017-06-14 03:09 - 2017-05-14 13:27 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
      2017-06-14 03:09 - 2017-05-14 13:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
      2017-06-14 03:09 - 2017-05-12 12:05 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
      2017-06-14 03:09 - 2017-05-12 10:51 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
      2017-06-14 03:09 - 2017-05-12 10:50 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
      2017-06-14 03:09 - 2017-05-12 10:48 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
      2017-06-14 03:09 - 2017-05-12 10:47 - 00726528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
      2017-06-14 03:09 - 2017-05-11 23:10 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
      2017-06-14 03:09 - 2017-05-11 21:11 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
      2017-06-14 03:09 - 2017-05-11 21:10 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
      2017-06-14 03:09 - 2017-05-11 21:06 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
      2017-06-14 00:04 - 2017-06-14 08:25 - 00000000 ____D C:\Users\TEMP.MONTALVAN.005\AppData\Roaming\DVDVideoSoft
      2017-06-14 00:04 - 2017-06-14 08:25 - 00000000 ____D C:\Users\TEMP.MONTALVAN.005
      2017-06-13 23:35 - 2017-06-21 10:06 - 00000000 ____D C:\ProgramData\Malwarebytes
      2017-06-13 23:35 - 2017-06-14 08:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
      2017-06-13 23:08 - 2017-06-14 00:04 - 00000000 ____D C:\Users\TEMP.MONTALVAN.004\AppData\Roaming\DVDVideoSoft
      2017-06-13 23:08 - 2017-06-14 00:04 - 00000000 ____D C:\Users\TEMP.MONTALVAN.004
      2017-06-13 22:15 - 2017-06-13 23:07 - 00000000 ____D C:\Users\TEMP.MONTALVAN.003\AppData\Roaming\DVDVideoSoft
      2017-06-13 22:15 - 2017-06-13 23:07 - 00000000 ____D C:\Users\TEMP.MONTALVAN.003
      2017-06-13 12:06 - 2017-06-21 10:20 - 00000000 ____D C:\Program Files (x86)\ClamWin
      2017-06-13 10:16 - 2017-06-13 22:14 - 00000000 ____D C:\Users\TEMP.MONTALVAN.002\AppData\Roaming\DVDVideoSoft
      2017-06-13 10:16 - 2017-06-13 22:14 - 00000000 ____D C:\Users\TEMP.MONTALVAN.002
      2017-06-13 08:25 - 2017-06-13 08:25 - 00000000 _____ C:\autoexec.bat
      2017-06-13 08:07 - 2017-06-13 10:15 - 00000000 ____D C:\Users\TEMP.MONTALVAN.001\AppData\Roaming\DVDVideoSoft
      2017-06-13 08:07 - 2017-06-13 10:15 - 00000000 ____D C:\Users\TEMP.MONTALVAN.001
      2017-06-13 07:38 - 2017-06-13 08:00 - 00000000 ____D C:\Users\TEMP.MONTALVAN.000\AppData\Roaming\DVDVideoSoft
      2017-06-13 07:38 - 2017-06-13 08:00 - 00000000 ____D C:\Users\TEMP.MONTALVAN.000
      2017-06-13 07:26 - 2017-06-13 07:26 - 00000000 ____D C:\Users\TEMP.MONTALVAN\Downloads\1 Ricardo Gareca
      2017-06-12 23:44 - 2017-06-12 23:44 - 00181700 _____ C:\Users\TEMP.MONTALVAN\Downloads\docentedecolumbiauniversityenucv.zip
      2017-06-12 23:41 - 2017-06-12 23:41 - 01486160 _____ C:\Users\TEMP.MONTALVAN\Downloads\grllcomprometetotalapoyoaorganizacindeloscensosde.zip
      2017-06-12 23:41 - 2017-06-12 23:41 - 01041829 _____ C:\Users\TEMP.MONTALVAN\Downloads\escuelasprofesionalesdelaucvpasanauditoriainterna.zip
      2017-06-12 23:39 - 2017-06-12 23:39 - 07433548 _____ C:\Users\TEMP.MONTALVAN\Downloads\apoyoendifusinradialytvspotcorpuschristiarquidio.zip
      2017-06-12 12:35 - 2017-06-13 07:23 - 00000000 ____D C:\Users\TEMP.MONTALVAN
      2017-06-12 12:35 - 2017-06-13 03:21 - 00000000 ____D C:\Users\TEMP.MONTALVAN\AppData\Roaming\DVDVideoSoft
      2017-06-12 07:56 - 2017-06-12 12:34 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\DVDVideoSoft
      2017-06-12 07:56 - 2017-06-12 12:34 - 00000000 ____D C:\Users\TEMP
      2017-06-12 00:41 - 2017-06-12 00:41 - 04807281 _____ C:\Users\CARLOS MONTALVAN\Downloads\2_centrorecreacionallarinconadalunes14dejunio2010.zip
      2017-06-12 00:41 - 2017-06-12 00:41 - 04524433 _____ C:\Users\CARLOS MONTALVAN\Downloads\3_centrorecreacionallarinconadalunes14dejunio2010.zip
      2017-06-12 00:40 - 2017-06-12 00:40 - 06111251 _____ C:\Users\CARLOS MONTALVAN\Downloads\centrorecreacionallarinconadalunes14dejunio20101ra.zip
      2017-06-12 00:40 - 2017-06-12 00:40 - 04422582 _____ C:\Users\CARLOS MONTALVAN\Downloads\4_centrorecreacionallarinconadalunes14dejunio2010.zip
      2017-06-12 00:40 - 2017-06-12 00:40 - 02783691 _____ C:\Users\CARLOS MONTALVAN\Downloads\5_centrorecreacionallarinconadalunes14dejunio2010.zip
      2017-06-11 18:01 - 2017-06-11 18:01 - 00003160 _____ C:\Windows\System32\Tasks\CorelUpdateHelperTask
      2017-06-10 18:14 - 2017-03-20 00:16 - 00993632 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
      2017-06-10 18:14 - 2017-03-20 00:16 - 00987848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
      2017-06-10 18:14 - 2017-03-20 00:16 - 00690016 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
      2017-06-10 18:14 - 2017-03-20 00:16 - 00484552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
      2017-06-10 18:14 - 2016-11-30 01:34 - 00028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
      2017-06-10 18:14 - 2016-11-30 01:27 - 00030400 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
      2017-06-10 04:39 - 2017-06-10 04:37 - 00003072 _____ C:\Users\Public\Desktop\Corel CAPTURE X8 (64-Bit).lnk
      2017-06-10 04:39 - 2017-06-10 04:36 - 00003079 _____ C:\Users\Public\Desktop\Corel PHOTO-PAINT X8 (64-Bit).lnk
      2017-06-10 04:39 - 2017-06-10 04:36 - 00003031 _____ C:\Users\Public\Desktop\CorelDRAW X8 (64-Bit).lnk
      2017-06-10 04:39 - 2017-06-10 04:36 - 00002283 _____ C:\Users\Public\Desktop\Corel Font Manager X8 (64-Bit).lnk
      2017-06-10 04:38 - 2017-06-10 04:39 - 00003340 _____ C:\Windows\System32\Tasks\CorelUpdateHelperTaskCore
      2017-06-10 04:38 - 2017-06-10 04:38 - 00000000 ____D C:\Program Files (x86)\gs
      2017-06-10 04:38 - 2017-06-10 04:38 - 00000000 ____D C:\Program Files (x86)\Corel
      2017-06-10 04:37 - 2017-06-10 04:37 - 00000000 ____D C:\Users\Public\Documents\Corel
      2017-06-10 04:36 - 2017-06-10 04:39 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Roaming\Corel
      2017-06-10 04:36 - 2017-06-10 04:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X8 (64-bit)
      2017-06-10 04:36 - 2017-06-10 04:36 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Documents\Corel
      2017-06-10 04:35 - 2017-06-10 04:39 - 00000000 ____D C:\ProgramData\Corel
      2017-06-10 04:33 - 2017-06-10 04:38 - 00000000 ____D C:\Program Files\Corel
      2017-06-09 02:30 - 2017-06-11 03:14 - 00003540 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_CARLOS MONTALVAN
      2017-06-09 02:30 - 2017-06-11 03:14 - 00003534 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_CARLOS MONTALVAN
      2017-06-09 02:30 - 2017-06-09 02:30 - 00003658 _____ C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_CARLOS MONTALVAN
      2017-06-09 02:30 - 2017-06-09 02:30 - 00003268 _____ C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_CARLOS MONTALVAN
      2017-06-06 23:06 - 2017-06-06 23:06 - 00145838 _____ C:\Users\CARLOS MONTALVAN\Downloads\lista_medios_acreditados_trujillo.pdf
      2017-06-06 09:22 - 2017-06-06 09:22 - 00234434 _____ C:\Users\CARLOS MONTALVAN\Downloads\WhatsApp Image 2017-06-06 at 9.09.05 AM.jpeg
      2017-06-05 09:36 - 2017-06-05 09:36 - 00349231 _____ C:\Users\CARLOS MONTALVAN\Downloads\Top-10-de-los-mejores-hosting (2).pdf
      2017-06-01 08:20 - 2017-06-01 08:21 - 00000097 _____ C:\Users\CARLOS MONTALVAN\Downloads\series-numericas-razonamiento.html.txt
      2017-05-31 23:14 - 2017-05-31 23:14 - 00001010 _____ C:\Users\Public\Desktop\HiSuite.lnk
      2017-05-31 23:14 - 2017-05-31 23:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite
      2017-05-31 23:13 - 2017-05-31 23:14 - 00000000 ____D C:\Program Files (x86)\HiSuite

      ==================== One Month Modified files and folders ========

      (If an entry is included in the fixlist, the file/folder will be moved.)

      2017-06-30 16:45 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Inf
      2017-06-30 16:44 - 2013-08-22 09:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
      2017-06-30 13:04 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\AppReadiness
      2017-06-29 23:55 - 2016-07-24 16:20 - 15610880 ___SH C:\Users\CARLOS MONTALVAN\Downloads\Thumbs.db
      2017-06-27 08:47 - 2016-12-16 22:16 - 00000000 ____D C:\ProgramData\CanonIJPLM
      2017-06-27 07:35 - 2014-03-18 05:11 - 01987694 _____ C:\Windows\system32\PerfStringBackup.INI
      2017-06-27 07:35 - 2014-03-18 04:31 - 00866504 _____ C:\Windows\system32\perfh00A.dat
      2017-06-27 07:35 - 2014-03-18 04:31 - 00194712 _____ C:\Windows\system32\perfc00A.dat
      2017-06-26 22:53 - 2016-07-05 12:54 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3922991227-27027531-2577069665-1001
      2017-06-26 14:11 - 2016-07-24 12:22 - 00002220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
      2017-06-25 07:05 - 2013-08-22 08:25 - 00262144 ___SH C:\Windows\system32\config\BBI
      2017-06-22 09:13 - 2016-11-23 20:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
      2017-06-22 09:13 - 2016-07-24 12:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
      2017-06-21 00:08 - 2016-11-14 17:36 - 00003412 _____ C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3922991227-27027531-2577069665-1001
      2017-06-19 23:12 - 2015-09-23 09:30 - 00262792 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
      2017-06-19 23:12 - 2015-09-23 09:30 - 00197248 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
      2017-06-19 23:12 - 2015-09-23 09:30 - 00015488 _____ (ESET) C:\Windows\system32\Drivers\eelam.sys
      2017-06-18 20:20 - 2016-07-05 12:48 - 00000000 ____D C:\Users\CARLOS MONTALVAN
      2017-06-17 21:30 - 2016-11-02 19:03 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
      2017-06-17 21:29 - 2016-11-02 19:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
      2017-06-17 21:29 - 2016-11-02 19:03 - 00000000 ____D C:\Program Files\Microsoft Silverlight
      2017-06-17 21:29 - 2013-08-22 10:36 - 00000000 ___RD C:\Windows\ToastData
      2017-06-17 21:29 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\rescache
      2017-06-17 21:29 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\Sysprep
      2017-06-17 21:27 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\registration
      2017-06-16 17:19 - 2016-10-23 08:29 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
      2017-06-16 17:19 - 2016-10-23 08:06 - 00004296 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
      2017-06-16 17:19 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
      2017-06-16 17:19 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\Macromed
      2017-06-15 20:53 - 2013-08-22 10:36 - 00000000 ___HD C:\Program Files\WindowsApps
      2017-06-14 18:53 - 2013-08-22 10:20 - 00000000 ____D C:\Windows\CbsTemp
      2017-06-14 08:44 - 2013-08-22 09:44 - 05174696 _____ C:\Windows\system32\FNTCACHE.DAT
      2017-06-14 08:40 - 2013-08-22 08:25 - 00000167 _____ C:\Windows\win.ini
      2017-06-14 08:38 - 2016-07-24 17:21 - 00000000 ____D C:\Windows\system32\MRT
      2017-06-14 08:35 - 2016-07-24 17:21 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
      2017-06-13 23:02 - 2016-10-02 20:18 - 00000000 ____D C:\Program Files\CCleaner
      2017-06-13 22:57 - 2016-10-02 20:18 - 00000841 _____ C:\Users\Public\Desktop\CCleaner.lnk
      2017-06-13 14:39 - 2016-10-02 15:25 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Downloads\sambcv.4.9.1_vocs
      2017-06-13 13:56 - 2017-01-16 13:37 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Downloads\archivar 2017
      2017-06-12 01:16 - 2016-07-25 20:26 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Roaming\Everything
      2017-06-12 01:08 - 2016-11-24 08:35 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\LocalLow\Mozilla
      2017-06-12 00:05 - 2016-07-05 14:46 - 00004026 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{33292B2C-F2DC-4CD0-9434-2798D2FA1962}
      2017-06-11 20:44 - 2016-07-25 21:19 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Roaming\VSO
      2017-06-11 20:38 - 2017-05-15 00:35 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Downloads\1 Notas
      2017-06-11 03:14 - 2016-07-05 13:48 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Local\Adobe
      2017-06-10 06:51 - 2017-01-22 23:33 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Roaming\ObviousIdea
      2017-06-10 04:35 - 2016-07-25 22:39 - 00000000 ____D C:\ProgramData\Package Cache
      2017-06-09 22:31 - 2016-07-05 12:48 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Local\Packages
      2017-06-09 10:35 - 2017-05-26 09:06 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Desktop\Programas auxiliares
      2017-06-09 03:07 - 2016-08-21 22:34 - 00047104 ___SH C:\Users\CARLOS MONTALVAN\Documents\Thumbs.db
      2017-06-06 12:19 - 2017-04-08 22:58 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Desktop\Santos de Calipuy
      2017-06-04 01:49 - 2016-07-25 22:30 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Roaming\vlc
      2017-06-03 23:00 - 2017-04-02 22:23 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Downloads\2
      2017-06-02 21:31 - 2016-11-10 16:50 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
      2017-06-02 21:31 - 2016-11-10 16:50 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
      2017-06-01 00:32 - 2017-01-13 21:17 - 00000000 ____D C:\Users\CARLOS MONTALVAN\AppData\Local\Hisuite
      2017-06-01 00:31 - 2017-01-14 23:26 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Downloads\Calipuy 2017
      2017-05-31 22:57 - 2017-05-10 21:21 - 00000000 ____D C:\Users\CARLOS MONTALVAN\Downloads\Casas modelo

      ==================== Files in the root of some directories =======

      2017-06-19 00:41 - 2017-06-19 00:41 - 0047388 _____ () C:\ProgramData\agent.1497850907.bdinstall.bin
      2017-06-22 09:14 - 2017-06-22 09:14 - 0030991 _____ () C:\ProgramData\agent.update.1498140876.bdinstall.bin
      2016-10-06 17:34 - 2016-10-06 17:34 - 0004892 _____ () C:\ProgramData\auqrgqib.ttw

      Some files in TEMP:
      ====================
      2016-12-06 08:48 - 2016-11-13 08:57 - 0186280 _____ (RealNetworks, Inc.) C:\Users\CARLOS MONTALVAN\AppData\Local\Temp\lowproc.exe
      2016-12-16 22:15 - 2015-06-16 14:47 - 1052704 ____N (CANON INC.) C:\Users\CARLOS MONTALVAN\AppData\Local\Temp\MSETUP4.EXE
      2016-12-06 08:48 - 2016-11-13 08:58 - 0096496 _____ (RealNetworks, Inc.) C:\Users\CARLOS MONTALVAN\AppData\Local\Temp\stubhelper.dll
      2016-12-16 22:16 - 2013-01-31 09:24 - 0354392 _____ (CANON INC.) C:\Users\CARLOS MONTALVAN\AppData\Local\Temp\uninstall.exe
      2017-06-02 11:44 - 2017-06-02 11:45 - 30950664 _____ () C:\Users\CARLOS MONTALVAN\AppData\Local\Temp\vlc-2.2.6-win32.exe

      ==================== Bamital & volsnap ======================

      (There is no automatic fix for files that do not pass verification.)

      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

      LastRegBack: 2017-06-27 09:51

      ==================== End of FRST.txt ============================

    10. #30
      Usuario Avatar de Calin120
      Registrado
      oct 2007
      Ubicación
      Perú
      Mensajes
      29

      Re: Se modifica la página de inicio de Windows "com Surrogate dejo de funcionar"

      Mensaje de Addition.txt

      Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-06-2017
      Ran by CARLOS MONTALVAN (30-06-2017 16:51:33)
      Running from C:\Users\CARLOS MONTALVAN.MONTALVAN\Desktop
      Windows 8.1 Pro (Update) (X64) (2016-07-05 17:48:30)
      Boot Mode: Normal
      ==========================================================


      ==================== Accounts: =============================

      Administrador (S-1-5-21-3922991227-27027531-2577069665-500 - Administrator - Disabled)
      ASPNET (S-1-5-21-3922991227-27027531-2577069665-1004 - Limited - Enabled)
      CARLOS MONTALVAN (S-1-5-21-3922991227-27027531-2577069665-1001 - Administrator - Enabled) => C:\Users\CARLOS MONTALVAN.MONTALVAN
      HomeGroupUser$ (S-1-5-21-3922991227-27027531-2577069665-1003 - Limited - Enabled)
      Invitado (S-1-5-21-3922991227-27027531-2577069665-501 - Limited - Enabled)

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AV: ESET NOD32 Antivirus 9.0.408.1 (Disabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
      AS: ESET NOD32 Antivirus 9.0.408.1 (Disabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
      AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

      ==================== Installed Programs ======================

      (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
      Adobe Acrobat X Pro - Italiano, Español, Nederlands, Português (HKLM-x32\...\{AC76BA86-1040-7D70-7760-000000000005}) (Version: 10.1.16 - Adobe Systems)
      Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
      Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
      Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
      Adobe Flash Player 26 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
      Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
      Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.0 - Adobe Systems Incorporated)
      Adobe Shockwave Player 12.1 (HKLM-x32\...\{0E3C52E0-B4F1-4D1E-B172-E390813BD9FE}) (Version: 12.1.8.158 - Adobe Systems, Inc)
      Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
      Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
      Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender)
      bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
      Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
      Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
      Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.1.0 - Canon Inc.)
      Canon MG3500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3500_series) (Version: 1.01 - Canon Inc.)
      Canon MG3500 series On-screen Manual (HKLM-x32\...\Canon MG3500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
      Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.5.1 - Canon Inc.)
      Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.5.0 - Canon Inc.)
      Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
      Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.7.1 - Canon Inc.)
      Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.14.40.0 - Canon Inc.)
      Canon Utilities EOS Lens Registration Tool (HKLM-x32\...\EOS Lens Registration Tool) (Version: 1.1.0.6 - Canon Inc.)
      Canon Utilities EOS Sample Music (HKLM-x32\...\EOS Sample Music) (Version: 1.0.1.1 - Canon Inc.)
      Canon Utilities EOS Utility 2 (HKLM-x32\...\EOS Utility 2) (Version: 2.14.10.2 - Canon Inc.)
      Canon Utilities EOS Web Service Registration Tool (HKLM-x32\...\EOS Web Service Registration Tool) (Version: 1.0.1.3 - Canon Inc.)
      Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.5.2.8 - Canon Inc.)
      Canon Utilities Map Utility (HKLM-x32\...\Map Utility Parent) (Version: 1.7.2.6 - Canon Inc.)
      Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.)
      Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.14.20.0 - Canon Inc.)
      CCleaner (HKLM\...\CCleaner) (Version: 5.26 - Piriform)
      Compatibilidad con Aplicaciones de Apple (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
      Corel Update Manager (HKLM\...\{B8C05FFE-C36F-4F17-AD20-739E4BC65AC9}) (Version: 2.3.170 - Corel corporation) Hidden
      CorelDRAW Graphics Suite X8 - BR (x64) (HKLM\...\{67D57366-EFCC-46DA-BB1F-BBE89B377177}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Capture (x64) (HKLM\...\{1253ED86-69FD-4A7B-BDF2-96A522583A88}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Common (x64) (HKLM\...\{72922AB6-F920-4C98-985D-EC90CE0918D4}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Connect (x64) (HKLM\...\{9782A612-03A7-488F-A598-33558163D8F8}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - CS (x64) (HKLM\...\{300DB480-7301-436A-A312-B695B2BC6D71}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - CT (x64) (HKLM\...\{43C4A17D-93D9-41C6-8ACA-370EA390ED2A}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Custom Data (x64) (HKLM\...\{02C85FBD-87D3-4352-BF2E-AFE897CD5559}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - CZ (x64) (HKLM\...\{A67AEE14-0435-4B8C-A367-F5EDE6CAF9F6}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - DE (x64) (HKLM\...\{4AA43BE3-D21B-44D7-B9CD-86692DEF3706}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Draw (x64) (HKLM\...\{A66E09BB-9892-421D-9EB9-311D12AA5244}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - EN (x64) (HKLM\...\{A0845CAD-ED13-46A4-A050-5ACE4631FDEC}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - ES (x64) (HKLM\...\{B1452C41-DC90-4B58-8320-ABB515E87FFB}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Filters (x64) (HKLM\...\{6E6D1438-33CC-413B-BC96-3497B1271CDD}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Font Manager (x64) (HKLM\...\{5FB5FF89-0938-49D9-850B-53B78B84A7E4}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - FR (x64) (HKLM\...\{0A182180-3BAF-4B94-BFD0-CF082CC5FF0D}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - IPM (x64) (HKLM\...\{A040C72A-0ADC-4FB9-9DB4-19B18F6053F1}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - IPM Content (x64) (HKLM\...\{FB081BA0-08D2-4C8C-9E55-788A90430BE3}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - IT (x64) (HKLM\...\{8285FEBA-D373-493F-BC78-934F84A0A298}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - JP (x64) (HKLM\...\{F5A1D3E4-416E-4723-AD35-86A372B99174}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - NL (x64) (HKLM\...\{A7922CC8-0EBD-497B-B381-5B3992905327}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - PHOTO-PAINT (x64) (HKLM\...\{04D8C47E-C0FE-4CA5-8878-91ECD9552109}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - PL (x64) (HKLM\...\{6F03D92C-48DB-4182-8A51-BEF8FE64B72C}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Redist (x64) (HKLM\...\{50D1BD2D-6D8C-45A8-9DB5-CDAB7227DB36}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - RU (x64) (HKLM\...\{B83D220A-33AB-4AF5-963A-887BD971270E}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Setup Files (x64) (HKLM\...\{4B3FC55D-E999-4BEC-AF29-1091E574961F}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - VBA (x64) (HKLM\...\{48DD8181-A983-447B-9660-A55A935CA751}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - VideoBrowser (x64) (HKLM\...\{81EBD8D4-9142-4D33-BF34-D99EFC1180F5}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Workspaces (x64) (HKLM\...\{1D4B870D-A5A8-4B88-9520-ED8EFD545AA1}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 - Writing Tools (x64) (HKLM\...\{23A2ABD8-8231-48AD-AD71-FF0566A7DD8F}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 (64-Bit) (HKLM\...\_{4B3FC55D-E999-4BEC-AF29-1091E574961F}) (Version: 18.0.0.448 - Corel Corporation)
      CorelDRAW Graphics Suite X8 (HKLM\...\{ECFAF1D6-342D-4AE2-B6BF-82B22F9FE8DE}) (Version: 18.0 - Corel Corporation) Hidden
      CorelDRAW Graphics Suite X8 -TR (x64) (HKLM\...\{ACC8C1B0-E560-4B42-AA52-9CAD14883B29}) (Version: 18.0 - Corel Corporation) Hidden
      CyberLink PowerDVD 11 (HKLM-x32\...\InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}) (Version: 11.0.1620.51 - CyberLink Corp.)
      Eines de correcció del Microsoft Office 2016: català (HKLM\...\{90160000-001F-0403-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
      ESET NOD32 Antivirus (HKLM\...\{3FA0C8FD-AC18-4031-907A-79FBA69F1899}) (Version: 9.0.318.20 - ESET, spol. s r.o.)
      Everything 1.3.4.686 (x64) (HKLM\...\Everything) (Version: - )
      Ferramentas de verificación de Microsoft Office 2016 - Galego (HKLM\...\{90160000-001F-0456-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
      FileZilla Client 3.25.2 (HKLM-x32\...\FileZilla Client) (Version: 3.25.2 - Tim Kosse)
      Firebird 1.5.2.4731 (HKLM-x32\...\FBDBServer_1_5_is1) (Version: - Firebird Project)
      Free Video to JPG Converter (HKLM-x32\...\Free Video to JPG Converter_is1) (Version: 5.0.101.201 - Digital Wave Ltd)
      Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\_{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation)
      Ghostscript GPL 8.64 (Msi Setup) (HKLM-x32\...\{06CD45E6-FF5E-4D8E-BC01-B276A90DADF2}) (Version: 8.64 - Corel Corporation) Hidden
      Google Chrome (HKLM-x32\...\{6A21C1E8-DAC1-3C18-BCDC-2DBB4B352AD8}) (Version: 59.0.3071.115 - Google, Inc.)
      Google Earth (HKLM-x32\...\{528145C0-462A-11E1-B8B4-B8AC6F97B88E}) (Version: 6.2.0.5905 - Google)
      Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
      Herramientas de corrección de Microsoft Office 2016: español (HKLM\...\{90160000-001F-0C0A-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
      HiSuite (HKLM-x32\...\Hi Suite) (Version: 1.0 - Huawei Technologies Co.,Ltd)
      Intel(R) C++ Redistributables for Windows* on Intel(R) 64 (HKLM-x32\...\{D2437C5C-2D8C-40D2-8059-689AD7239FA3}) (Version: 11.1.048 - Intel Corporation)
      Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
      Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
      Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
      Light Image Resizer 5.0.2.0 (HKLM-x32\...\{D5C093E0-D3DF-42D3-AFD6-CAAFB6985CBC}_is1) (Version: 5.0.2.0 - ObviousIdea)
      Loquendo TTS: Jorge (Spanish) (HKLM-x32\...\LoqTTS-Jorge_is1) (Version: - )
      Loquendo TTS: Juan (Spanish) (HKLM-x32\...\LoqTTS-Juan_is1) (Version: - )
      Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
      Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
      Mozilla Firefox 54.0 (x86 es-ES) (HKLM-x32\...\Mozilla Firefox 54.0 (x86 es-ES)) (Version: 54.0 - Mozilla)
      Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 54.0.0.6368 - Mozilla)
      MSI to redistribute MS VS2005 CRT libraries (HKLM-x32\...\{A8D93648-9F7F-407D-915C-62044644C3DA}) (Version: 8.0.50727.42 - The Firebird Project)
      Nero (HKLM-x32\...\Nero) (Version: - )
      Nokia Connectivity Cable Driver (HKLM\...\{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}) (Version: 7.1.32.69 - )
      Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
      PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
      ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
      Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
      PIXELA AAC LC CODEC (HKLM-x32\...\PIXELA AAC LC CODEC) (Version: 1.1.0.1 - Canon Inc.)
      QT Lite 2.9.0 (HKLM-x32\...\qt7lite_is1) (Version: 2.9.0 - )
      QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
      Real Alternative 1.9.0 (HKLM-x32\...\RealAlt_is1) (Version: 1.9.0 - )
      RealDownloader (HKLM-x32\...\{13743594-F75E-491E-9EFF-203C8F8DF705}) (Version: 18.1.5.699 - RealNetworks) Hidden
      RealDownloader (HKLM-x32\...\{410F406E-7AFC-4E9F-BF7E-0CB3C72BDAB9}) (Version: 18.1.5.699 - RealNetworks, Inc.) Hidden
      RealDownloader (HKLM-x32\...\{4e8ca438-78fb-4658-ac5b-2d128f60c54e}) (Version: 18.1.5.699 - RealNetworks) Hidden
      RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden
      RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden
      RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden
      Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
      Revisores de Texto do Microsoft Office 2016 – Português (Brasil) (HKLM\...\{90160000-001F-0416-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
      SAM Broadcaster (remove only) (HKLM-x32\...\SAM3) (Version: - )
      Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
      TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.12799 - TeamViewer)
      Telegram Desktop versión 0.9.56 (HKU\S-1-5-21-3922991227-27027531-2577069665-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 0.9.56 - Telegram Messenger LLP)
      TextAloud 3.0 (HKLM-x32\...\TextAloud3_is1) (Version: 3.0 - NextUp.com)
      UpdateService (HKLM-x32\...\{E3AE96D6-E196-45B4-AF62-2B41998B9E37}) (Version: 1.0.0 - RealNetworks, Inc.) Hidden
      USB Disk Security (HKLM-x32\...\USB Disk Security_is1) (Version: - Zbshareware Lab)
      vc2012_redist (HKLM-x32\...\{9402AEF2-5981-4097-8BE2-6501DAC4DBFD}) (Version: 1.0.0.0 - Realnetworks) Hidden
      Video Downloader (HKLM-x32\...\{80CE5A20-ACAD-46A7-94A0-5FD34A7744F3}) (Version: 1.2.0 - RealNetworks) Hidden
      VJDirector2 Ultimate Edition (HKLM-x32\...\VJDirector2 Ultimate Edition) (Version: 2.3.832.0 - Nanjing Naga Software Ltd.)
      VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
      vs2015_redist x64 (HKLM\...\{EAED8692-5B63-4665-B857-D626633691DA}) (Version: 1.0.0.0 - Realnetworks) Hidden
      vs2015_redist x86 (HKLM-x32\...\{BD46163A-0331-4A61-B65A-7B66D7C93F8E}) (Version: 1.0.0.0 - Realnetworks) Hidden
      VSO Image Resizer 2.0.1.3 (HKLM-x32\...\{3EE51BAD-9916-49C7-90BA-3D500B031E0C}_is1) (Version: 2.0.1.3 - VSO-Software)
      Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
      WinRAR 4.10 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.10.0 - win.rar GmbH)
      WinZip 18.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )

      ==================== Custom CLSID (Whitelisted): ==========================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


      ==================== Scheduled Tasks (Whitelisted) =============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      Task: {00721BDD-AB63-4D9D-8224-3AF1A2FCF802} - System32\Tasks\RealDownloader Update Check => C:\program files (x86)\real\realplayer\RealDownloader\downloader2.exe [2016-09-03] ()
      Task: {091998EF-A7C0-4C9B-AEC7-6A8F9E3DE899} - System32\Tasks\{9072A6EE-492E-449C-94CC-FCBE99865E1D} => pcalua.exe -a "E:\Sofware 2016\Sambroadcaster2016.3\Sambroadcaster2016.3\reseter.exe" -d "E:\Sofware 2016\Sambroadcaster2016.3\Sambroadcaster2016.3"
      Task: {0BCBB3BB-C3B4-43E2-9BB7-AFA43185B725} - System32\Tasks\ReclaimerUpdateFiles_CARLOS MONTALVAN => C:\Users\CARLOS MONTALVAN\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.07\agent\rnupgagent.exe [2017-06-08] (RealNetworks, Inc.)
      Task: {2B4D6107-4934-49AA-A163-90E750EC8A39} - System32\Tasks\CorelUpdateHelperTaskCore => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2017-05-29] (Corel Corporation)
      Task: {3675BA70-9BE6-45CB-9B9F-EDE130D8138A} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3922991227-27027531-2577069665-1001 => C:\program files (x86)\real\realplayer\RealDownloader\recordingmanager.exe [2016-09-03] (RealNetworks, Inc.)
      Task: {390BA95C-BD95-4019-A048-05B36A76E190} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3922991227-27027531-2577069665-1001 => C:\program files (x86)\real\realplayer\RealDownloader\RealUpgrade.exe [2016-09-03] (RealNetworks, Inc.)
      Task: {532A7263-CA76-4519-9BDE-56C8D361FB72} - System32\Tasks\CorelUpdateHelperTask => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe [2017-05-29] (Corel Corporation)
      Task: {5AFAEC59-F986-4B4F-A25E-BF8F39E3608E} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
      Task: {6BDDF12D-B6BE-4C08-9246-3D54D27FAEC0} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3922991227-27027531-2577069665-1001 => C:\program files (x86)\real\realplayer\RealDownloader\RealUpgrade.exe [2016-09-03] (RealNetworks, Inc.)
      Task: {6E888C7A-1148-4834-B8A8-CE446AB78317} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2015-07-31] (Microsoft Corporation)
      Task: {76E0176C-98CA-44FB-8134-DF09CDC0B544} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-21] (Piriform Ltd)
      Task: {774EA482-5C27-43EE-BBA8-0A3712EDC7B7} - System32\Tasks\AdobeAAMUpdater-1.0-MONTALVAN-CARLOS MONTALVAN => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19] (Adobe Systems Incorporated)
      Task: {7A93ABD8-AA45-4EB0-B1AC-A93167C1046F} - System32\Tasks\{84AE3A7F-7727-4885-BD62-951F466AA00F} => pcalua.exe -a "C:\Program Files (x86)\SpacialAudio\SAMBC\reseter_parche.exe" -d "C:\Program Files (x86)\SpacialAudio\SAMBC"
      Task: {7FB992FB-D9E8-4A95-A795-EB7F6E51CB8C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-24] (Google Inc.)
      Task: {86DA8B22-4283-4341-B3EC-159075BDC902} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
      Task: {9A618019-761E-4B62-BCC2-D4DA26827412} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-13] (Adobe Systems Incorporated)
      Task: {A17778E3-6B54-4F65-95DE-D9D0E1CAA570} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
      Task: {AB5775E4-53CD-4544-8C64-A9015A586AB5} - System32\Tasks\RNUpgradeHelperLogonPrompt_CARLOS MONTALVAN => C:\Users\CARLOS MONTALVAN\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.07\agent\rnupgagent.exe [2017-06-08] (RealNetworks, Inc.)
      Task: {B6115D6B-02DE-4038-A660-3696F957D99E} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe [2017-04-11] (Bitdefender)
      Task: {B7217604-683E-4E1B-89BE-D0BCD9157424} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_131_pepper.exe [2017-06-16] (Adobe Systems Incorporated)
      Task: {C8330BCF-B141-453C-9D06-2A610458383A} - System32\Tasks\{EAE30693-DAEF-40C3-8EBD-F1B76185A001} => pcalua.exe -a "E:\Sofware 2016\Sambroadcaster2016.3\reseter_parche.exe" -d "E:\Sofware 2016\Sambroadcaster2016.3"
      Task: {E6095178-F39E-426D-94C9-E37819E4EE91} - System32\Tasks\RNUpgradeHelperResumePrompt_CARLOS MONTALVAN => C:\Users\CARLOS MONTALVAN\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.07\agent\rnupgagent.exe [2017-06-08] (RealNetworks, Inc.)
      Task: {E9D1E7F5-59E0-4B27-BBE5-CA5A82663B23} - System32\Tasks\ReclaimerUpdateXML_CARLOS MONTALVAN => C:\Users\CARLOS MONTALVAN\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.07\agent\rnupgagent.exe [2017-06-08] (RealNetworks, Inc.)
      Task: {EB287430-ED3A-4F41-8E4E-33AC263D4767} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
      Task: {F4D2A9F7-B449-409C-8F34-45888E6B6438} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\Office16\msoia.exe [2015-07-31] (Microsoft Corporation)
      Task: {F9BCD1B0-ECC6-4FB5-A8D2-48D1F9630833} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-24] (Google Inc.)

      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


      ==================== Shortcuts & WMI ========================

      (The entries could be listed to be restored or removed.)


      ==================== Loaded Modules (Whitelisted) ==============

      2016-07-05 13:22 - 2012-01-09 19:44 - 00193536 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
      2016-07-24 12:02 - 2011-04-19 22:56 - 00083240 _____ () C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
      2017-04-10 21:17 - 2017-04-10 21:17 - 00192200 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
      2016-09-03 12:18 - 2016-09-03 12:18 - 00035104 _____ () C:\program files (x86)\real\realplayer\UpdateService\RealPlayerUpdateSvc.exe
      2016-07-24 11:25 - 2012-11-14 02:22 - 00078456 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
      2016-07-24 11:25 - 2012-11-14 02:22 - 00386168 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
      2016-07-25 20:26 - 2014-08-05 20:04 - 01441792 _____ () C:\Program Files\Everything\Everything.exe
      2016-09-20 00:40 - 2015-02-10 15:08 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
      2016-12-16 15:03 - 2016-12-16 15:03 - 00054488 _____ () C:\Program Files\CCleaner\branding.dll
      2016-09-03 11:11 - 2016-09-03 11:11 - 00708336 _____ () C:\Program Files (x86)\Real\RealPlayer\RealDownloader\downloader2.exe
      2017-05-24 09:06 - 2017-03-20 17:06 - 00114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll
      2017-05-24 09:06 - 2017-03-20 17:06 - 00108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll
      2017-05-24 09:06 - 2017-03-20 17:06 - 00024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll
      2017-05-24 09:06 - 2017-03-20 17:06 - 00048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll
      2016-09-03 12:18 - 2016-09-03 12:18 - 00040248 _____ () C:\program files (x86)\real\realplayer\UpdateService\DL2UpdatePlugin.dll
      2016-09-03 12:18 - 2016-09-03 12:18 - 00042296 _____ () C:\program files (x86)\real\realplayer\UpdateService\RealDownloaderUpdatePlugin.dll
      2016-09-03 12:18 - 2016-09-03 12:18 - 00039752 _____ () C:\program files (x86)\real\realplayer\UpdateService\VideoDLUpdatePlugin.dll
      2016-09-20 00:40 - 2015-02-18 14:11 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll
      2016-07-05 13:26 - 2013-06-25 11:03 - 00036864 _____ () C:\Program Files (x86)\USB Disk Security\locales\spanish.dll
      2016-09-25 12:57 - 2016-09-25 12:57 - 00034064 _____ () c:\program files (x86)\real\realplayer\RPDS\Tools\ffmpeg\mediautil.dll
      2015-09-24 10:42 - 2015-09-24 10:42 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\es_ES\acrotray.esp
      2016-09-25 12:57 - 2016-09-25 12:57 - 00653072 _____ () c:\program files (x86)\real\realplayer\RPDS\Lib\r1api.dll
      2016-09-03 11:11 - 2016-09-03 11:11 - 00082672 _____ () C:\Program Files (x86)\Real\RealPlayer\RealDownloader\dtvhooks.dll

      ==================== Alternate Data Streams (Whitelisted) =========

      (If an entry is included in the fixlist, only the ADS will be removed.)

      AlternateDataStreams: C:\ProgramData\Temp:86096EA4 [127]
      AlternateDataStreams: C:\Users\CARLOS MONTALVAN\Cookies:0jToHq308XYGfxODnyMEzZxS [1964]

      ==================== Safe Mode (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

      ==================== Association (Whitelisted) ===============

      (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


      ==================== Internet Explorer trusted/restricted ===============

      (If an entry is included in the fixlist, it will be removed from the registry.)


      ==================== Hosts content: ===============================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2013-08-22 08:25 - 2017-06-18 10:24 - 00000873 _____ C:\Windows\system32\Drivers\etc\hosts


      ==================== Other Areas ============================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-3922991227-27027531-2577069665-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
      DNS Servers: 190.113.220.18 - 190.113.220.51
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
      Windows Firewall is enabled.

      ==================== MSCONFIG/TASK MANAGER disabled items ==


      ==================== FirewallRules (Whitelisted) ===============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      FirewallRules: [{F88AFEF8-8334-46C1-8574-8DB10995D40D}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
      FirewallRules: [{E32723C4-E57F-42FE-BD9A-A40C8C6491DA}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
      FirewallRules: [{A9F164F9-BAE3-4B1D-ABFA-D8F8EBC06C1C}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
      FirewallRules: [{C9334163-97BF-432D-AE13-4F4190BA00A0}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
      FirewallRules: [{7AC1DC56-4FD5-494D-BA42-F78EEFDF3462}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
      FirewallRules: [{3D0A9FBC-0E3B-4C17-9431-66901D3992BD}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
      FirewallRules: [{7C11ED73-D082-4214-BBCB-3063E38F7042}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
      FirewallRules: [{D4665522-C50B-4C1A-B796-14B2DDD2B313}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
      FirewallRules: [{771947F2-BBC5-4BE6-8C8D-601B0FEC39E8}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\PowerDVD11.exe
      FirewallRules: [{7AF69BF0-6B2B-414C-9A5E-6F99404EB19B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
      FirewallRules: [{CC7BC506-C8C5-4B76-AD31-50F212D16ED2}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
      FirewallRules: [{A2DCAAE0-17E4-4332-891D-BDF948367B58}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD11\Movie\PowerDVD Cinema\PowerDVDCinema11.exe
      FirewallRules: [{9C780B8E-2245-4E5D-9AC8-FB9E4BA3C939}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
      FirewallRules: [{99340087-41FD-4CD2-8F03-599094EE3731}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
      FirewallRules: [TCP Query User{5FFCFCDF-ACDC-4DFA-B49B-0079F81E3821}C:\program files (x86)\nagasoft\vjdirector2 ultimate edition\vjd2.exe] => (Allow) C:\program files (x86)\nagasoft\vjdirector2 ultimate edition\vjd2.exe
      FirewallRules: [UDP Query User{89691247-70F4-453D-B381-D71D441BC0D3}C:\program files (x86)\nagasoft\vjdirector2 ultimate edition\vjd2.exe] => (Allow) C:\program files (x86)\nagasoft\vjdirector2 ultimate edition\vjd2.exe
      FirewallRules: [{3B8B6C96-37D6-4A4D-B12A-3F32F022A672}] => (Block) %ProgramFiles% (x86)\Nagasoft\VJDirector2 Ultimate Edition\VJD2.exe
      FirewallRules: [{707A6F96-5CB7-45F1-853D-D7ED064E20C5}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe
      FirewallRules: [{BC1E2399-F677-4534-9EDE-5F1B3EE5DE27}] => (Allow) C:\Program Files (x86)\Canon\EOS Utility\EOSUPNPSV.exe
      FirewallRules: [{DF9817AA-4DEF-4284-8911-20A4E44E10F5}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
      FirewallRules: [TCP Query User{93BFED9D-88BE-468F-B56A-0A2F623D5E5E}F:\a disco\datadatadatadatadata\scouts\scoutlink\mirc de danniels\opslmirc\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\mirc de danniels\opslmirc\opslmirc\mirc.exe
      FirewallRules: [UDP Query User{B6FB51DD-AA07-4360-9642-5321DBF00356}F:\a disco\datadatadatadatadata\scouts\scoutlink\mirc de danniels\opslmirc\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\mirc de danniels\opslmirc\opslmirc\mirc.exe
      FirewallRules: [TCP Query User{8F2419E2-3148-462E-9976-BA63084D99BC}F:\a disco\datadatadatadatadata\scouts\scoutlink\mircopcorregido\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\mircopcorregido\opslmirc\mirc.exe
      FirewallRules: [UDP Query User{F7830E0B-450F-4E4D-9CD1-AC3EF9B1A0CF}F:\a disco\datadatadatadatadata\scouts\scoutlink\mircopcorregido\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\mircopcorregido\opslmirc\mirc.exe
      FirewallRules: [TCP Query User{C570075A-CAA3-45A1-83CA-D5434A51181E}F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2012\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2012\opslmirc\mirc.exe
      FirewallRules: [UDP Query User{97ACBB17-ED0C-4E0F-B65C-4B6A73BE13F7}F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2012\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2012\opslmirc\mirc.exe
      FirewallRules: [TCP Query User{201435A1-ABCE-4CCC-8E0C-0FC70F8BE9D1}F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2013\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2013\mirc.exe
      FirewallRules: [UDP Query User{D6C795C4-145A-4ACB-85D4-D5E3816313B4}F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2013\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\opslmirc 2013\mirc.exe
      FirewallRules: [TCP Query User{0FE5EF36-6F99-4D6E-A3BC-332AE585A554}F:\a disco\datadatadatadatadata\scouts\scoutlink\scoutlink 2012\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\scoutlink 2012\opslmirc\mirc.exe
      FirewallRules: [UDP Query User{FDA9F77E-925E-4569-B505-14593C534480}F:\a disco\datadatadatadatadata\scouts\scoutlink\scoutlink 2012\opslmirc\mirc.exe] => (Allow) F:\a disco\datadatadatadatadata\scouts\scoutlink\scoutlink 2012\opslmirc\mirc.exe
      FirewallRules: [TCP Query User{5CB8504C-50A7-4B2E-AE5A-93CA62BE8AD4}C:\program files (x86)\spacialaudio\sambc\sambc.exe] => (Allow) C:\program files (x86)\spacialaudio\sambc\sambc.exe
      FirewallRules: [UDP Query User{51D1CA75-9BC6-4B81-B2FA-4402CEA795A0}C:\program files (x86)\spacialaudio\sambc\sambc.exe] => (Allow) C:\program files (x86)\spacialaudio\sambc\sambc.exe
      FirewallRules: [{8D671818-386A-45BB-9041-F5AD4EC71B87}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
      FirewallRules: [{A052C2CF-BB9A-45D8-945B-5F91A3251AE5}] => (Allow) C:\Program Files\Microsoft Office\Office16\lync.exe
      FirewallRules: [{D182CC3E-0C63-426E-ACFE-C08042F6763D}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
      FirewallRules: [{28A86B5E-1C5D-44D1-BAD8-2FA4F11793A4}] => (Allow) C:\Program Files\Microsoft Office\Office16\UcMapi.exe
      FirewallRules: [{EDC435FC-580E-4A74-ADEB-489CD7C52836}] => (Block) c:\Program Files\Corel\CorelDRAW Graphics Suite X8\Programs64\CorelDrw.exe
      FirewallRules: [{3B15FC37-5269-4A46-99EA-7C7A5CB20E1E}] => (Block) c:\Program Files\Corel\CorelDRAW Graphics Suite X8\Programs64\CorelPP.exe
      FirewallRules: [{57C25564-1EBF-4674-8EB1-B724233E35CA}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      FirewallRules: [TCP Query User{CAC88BB9-EB00-405D-AFE3-49CACFDAC77E}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
      FirewallRules: [UDP Query User{8F8F0FE5-C3B4-4EB4-8CF8-A5B87417ABFA}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe

      ==================== Restore Points =========================

      17-06-2017 21:22:03 Operación de restauración
      17-06-2017 21:44:04 JRT Pre-Junkware Removal
      27-06-2017 10:08:30 Punto de control programado
      29-06-2017 20:08:02 JRT Pre-Junkware Removal

      ==================== Faulty Device Manager Devices =============

      Name: Controladora multimedia
      Description: Controladora multimedia
      Class Guid:
      Manufacturer:
      Service:
      Problem: : The drivers for this device are not installed. (Code 28)
      Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


      ==================== Event log errors: =========================

      Application errors:
      ==================
      Error: (06/30/2017 02:50:31 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nombre de la aplicación con errores: PhotosApp.exe, versión: 6.3.9600.17418, marca de tiempo: 0x5458237f
      Nombre del módulo con errores: FileManagerApp.dll, versión: 6.3.9600.17418, marca de tiempo: 0x54582358
      Código de excepción: 0x80000003
      Desplazamiento de errores: 0x00000000000214ec
      Identificador del proceso con errores: 0xf00
      Hora de inicio de la aplicación con errores: 0x01d2f175860aa96c
      Ruta de acceso de la aplicación con errores: C:\Windows\FileManager\PhotosApp.exe
      Ruta de acceso del módulo con errores: C:\Windows\FileManager\FileManagerApp.dll
      Identificador del informe: c9ba8279-5d68-11e7-82c4-94de8075a816
      Nombre completo del paquete con errores: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy
      Identificador de aplicación relativa del paquete con errores: Microsoft.Windows.PhotoManager

      Error: (06/30/2017 02:37:14 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nombre de la aplicación con errores: PhotosApp.exe, versión: 6.3.9600.17418, marca de tiempo: 0x5458237f
      Nombre del módulo con errores: FileManagerApp.dll, versión: 6.3.9600.17418, marca de tiempo: 0x54582358
      Código de excepción: 0x80000003
      Desplazamiento de errores: 0x00000000000214ec
      Identificador del proceso con errores: 0x688
      Hora de inicio de la aplicación con errores: 0x01d2f173ab3e0f27
      Ruta de acceso de la aplicación con errores: C:\Windows\FileManager\PhotosApp.exe
      Ruta de acceso del módulo con errores: C:\Windows\FileManager\FileManagerApp.dll
      Identificador del informe: eefce57a-5d66-11e7-82c4-94de8075a816
      Nombre completo del paquete con errores: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy
      Identificador de aplicación relativa del paquete con errores: Microsoft.Windows.PhotoManager

      Error: (06/30/2017 02:20:09 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MONTALVAN)
      Description: No se pudo activar la aplicación FileManager_cw5n1h2txyewy!Microsoft.Windows.PhotoManager debido al error: -2144927148. Consulte el registro Microsoft-Windows-TWinUI/Operational para obtener más información.

      Error: (06/30/2017 02:14:32 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nombre de la aplicación con errores: PhotosApp.exe, versión: 6.3.9600.17418, marca de tiempo: 0x5458237f
      Nombre del módulo con errores: twinapi.appcore.dll, versión: 6.3.9600.17415, marca de tiempo: 0x54503c4d
      Código de excepción: 0xc000027b
      Desplazamiento de errores: 0x0000000000063c1f
      Identificador del proceso con errores: 0x4f8
      Hora de inicio de la aplicación con errores: 0x01d2f1707239023b
      Ruta de acceso de la aplicación con errores: C:\Windows\FileManager\PhotosApp.exe
      Ruta de acceso del módulo con errores: C:\Windows\System32\twinapi.appcore.dll
      Identificador del informe: c3053449-5d63-11e7-82c4-94de8075a816
      Nombre completo del paquete con errores: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy
      Identificador de aplicación relativa del paquete con errores: Microsoft.Windows.PhotoManager

      Error: (06/30/2017 01:47:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MONTALVAN)
      Description: No se pudo activar la aplicación FileManager_cw5n1h2txyewy!Microsoft.Windows.PhotoManager debido al error: -2144927148. Consulte el registro Microsoft-Windows-TWinUI/Operational para obtener más información.

      Error: (06/30/2017 01:38:49 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MONTALVAN)
      Description: No se pudo activar la aplicación FileManager_cw5n1h2txyewy!Microsoft.Windows.PhotoManager debido al error: -2144927148. Consulte el registro Microsoft-Windows-TWinUI/Operational para obtener más información.

      Error: (06/30/2017 01:38:01 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nombre de la aplicación con errores: PhotosApp.exe, versión: 6.3.9600.17418, marca de tiempo: 0x5458237f
      Nombre del módulo con errores: twinapi.appcore.dll, versión: 6.3.9600.17415, marca de tiempo: 0x54503c4d
      Código de excepción: 0xc000027b
      Desplazamiento de errores: 0x0000000000063c1f
      Identificador del proceso con errores: 0x1670
      Hora de inicio de la aplicación con errores: 0x01d2f16b4a356152
      Ruta de acceso de la aplicación con errores: C:\Windows\FileManager\PhotosApp.exe
      Ruta de acceso del módulo con errores: C:\Windows\System32\twinapi.appcore.dll
      Identificador del informe: a933837d-5d5e-11e7-82c4-94de8075a816
      Nombre completo del paquete con errores: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy
      Identificador de aplicación relativa del paquete con errores: Microsoft.Windows.PhotoManager

      Error: (06/30/2017 12:47:07 AM) (Source: SideBySide) (EventID: 35) (User: )
      Description: Error al generar el contexto de activación para "c:\program files (x86)\nero\nero 12\nero burning rom\NeroCmd.exe.Manifest". Error en el archivo de manifiesto o directiva "c:\program files (x86)\nero\nero 12\nero burning rom\SMC\SMC.MANIFEST" en la línea 3.
      La identidad de componente encontrada en el manifiesto no coincide con la del componente solicitado.
      La referencia es SMC,processorArchitecture="x86",type="win32",version="8.2.0.0".
      La definición es SMC,processorArchitecture="x86",type="win32",version="12.0.0.0".
      Use sxstrace.exe para obtener un diagnóstico detallado.

      Error: (06/30/2017 12:28:55 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nombre de la aplicación con errores: PhotosApp.exe, versión: 6.3.9600.17418, marca de tiempo: 0x5458237f
      Nombre del módulo con errores: FileManagerApp.dll, versión: 6.3.9600.17418, marca de tiempo: 0x54582358
      Código de excepción: 0x80000003
      Desplazamiento de errores: 0x00000000000214ec
      Identificador del proceso con errores: 0x5a8
      Hora de inicio de la aplicación con errores: 0x01d2f161be239211
      Ruta de acceso de la aplicación con errores: C:\Windows\FileManager\PhotosApp.exe
      Ruta de acceso del módulo con errores: C:\Windows\FileManager\FileManagerApp.dll
      Identificador del informe: 01d4bc4e-5d55-11e7-82c4-94de8075a816
      Nombre completo del paquete con errores: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy
      Identificador de aplicación relativa del paquete con errores: Microsoft.Windows.PhotoManager

      Error: (06/30/2017 12:24:52 AM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Nombre de la aplicación con errores: PhotosApp.exe, versión: 6.3.9600.17418, marca de tiempo: 0x5458237f
      Nombre del módulo con errores: FileManagerApp.dll, versión: 6.3.9600.17418, marca de tiempo: 0x54582358
      Código de excepción: 0x80000003
      Desplazamiento de errores: 0x00000000000214ec
      Identificador del proceso con errores: 0xcb8
      Hora de inicio de la aplicación con errores: 0x01d2f1612d6a6ffb
      Ruta de acceso de la aplicación con errores: C:\Windows\FileManager\PhotosApp.exe
      Ruta de acceso del módulo con errores: C:\Windows\FileManager\FileManagerApp.dll
      Identificador del informe: 713feb0a-5d54-11e7-82c4-94de8075a816
      Nombre completo del paquete con errores: FileManager_6.3.9600.16384_neutral_neutral_cw5n1h2txyewy
      Identificador de aplicación relativa del paquete con errores: Microsoft.Windows.PhotoManager


      System errors:
      =============
      Error: (06/30/2017 01:23:07 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
      Description: 4

      Error: (06/30/2017 01:03:26 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
      Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80070002: Microsoft.Reader.

      Error: (06/30/2017 09:53:36 AM) (Source: DCOM) (EventID: 10010) (User: MONTALVAN)
      Description: El servidor {1B1F472E-3221-4826-97DB-2C2324D389AE} no se registró con DCOM dentro del tiempo de espera requerido.

      Error: (06/30/2017 09:53:06 AM) (Source: DCOM) (EventID: 10010) (User: MONTALVAN)
      Description: El servidor {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} no se registró con DCOM dentro del tiempo de espera requerido.

      Error: (06/30/2017 09:52:57 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
      Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80070002: Microsoft.Reader.

      Error: (06/30/2017 08:54:37 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
      Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80070002: Microsoft.Reader.

      Error: (06/29/2017 10:18:49 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
      Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80070002: Microsoft.Reader.

      Error: (06/29/2017 09:05:13 PM) (Source: Microsoft-Windows-Ntfs) (EventID: 98) (User: MONTALVAN)
      Description: C:\Device\HarddiskVolume23

      Error: (06/29/2017 08:33:02 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
      Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80070002: Microsoft.Reader.

      Error: (06/29/2017 08:21:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
      Description: El servicio Servicio de uso compartido de red del Reproductor de Windows Media depende del servicio Windows Search, el cual no pudo iniciarse debido al siguiente error:
      No se puede iniciar el servicio debido a un error en el inicio de sesión.


      CodeIntegrity:
      ===================================
      Date: 2017-01-28 14:32:57.167
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2017-01-28 14:32:57.083
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2017-01-28 14:24:37.796
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2017-01-28 14:24:37.712
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2017-01-28 14:23:48.619
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2017-01-28 14:23:48.523
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\usbser.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

      Date: 2016-10-28 07:17:33.887
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


      ==================== Memory info ===========================

      Processor: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
      Percentage of memory in use: 10%
      Total physical RAM: 16271.67 MB
      Available physical RAM: 14625.76 MB
      Total Virtual: 18703.67 MB
      Available Virtual: 17073.86 MB

      ==================== Drives ================================

      Drive c: (WIN 8,1) (Fixed) (Total:243.8 GB) (Free:101.14 GB) NTFS
      Drive d: (software) (Fixed) (Total:244.14 GB) (Free:89.34 GB) NTFS
      Drive e: () (Fixed) (Total:443.23 GB) (Free:81.72 GB) NTFS
      Drive f: () (Fixed) (Total:1862.5 GB) (Free:135.34 GB) NTFS
      Drive h: () (Fixed) (Total:465.24 GB) (Free:331.58 GB) NTFS

      ==================== MBR & Partition Table ==================

      ========================================================
      Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 6E6A2DFB)
      Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=243.8 GB) - (Type=07 NTFS)
      Partition 3: (Not Active) - (Size=244.1 GB) - (Type=OF Extended)
      Partition 4: (Not Active) - (Size=443.2 GB) - (Type=07 NTFS)

      ========================================================
      Disk: 1 (Size: 465.8 GB) (Disk ID: F9B4F9B4)

      Partition: GPT.

      ========================================================
      Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)

      Partition: GPT.

      ==================== End of Addition.txt ============================