• Registrarse
  • Iniciar sesión


  • Página 2 de 3 PrimeroPrimero 123 ÚltimoÚltimo
    Resultados 11 al 20 de 23

    Ordenador se queda bloqueado y lento

    ...

    1. #11
      Usuario Avatar de bulldog48
      Registrado
      ene 2018
      Ubicación
      España
      Mensajes
      13

      Re: Ordenador se queda bloqueado y lento

      Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24.02.2018
      Ran by admin (25-02-2018 15:04:43)
      Running from C:\Users\admin\Desktop
      Windows 7 Home Premium Service Pack 1 (X64) (2014-04-10 11:17:18)
      Boot Mode: Normal
      ==========================================================


      ==================== Accounts: =============================

      admin (S-1-5-21-580467305-273187244-10777062-1000 - Administrator - Enabled) => C:\Users\admin
      Administrador (S-1-5-21-580467305-273187244-10777062-500 - Administrator - Disabled)
      HomeGroupUser$ (S-1-5-21-580467305-273187244-10777062-1002 - Limited - Enabled)
      Invitado (S-1-5-21-580467305-273187244-10777062-501 - Limited - Disabled)

      ==================== Security Center ========================

      (If an entry is included in the fixlist, it will be removed.)

      AV: 360 Total Security (Enabled - Up to date) {0371CA44-3F80-A1D3-BECE-910620B58D50}
      AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      AS: 360 Total Security (Enabled - Up to date) {B8102BA0-19BA-AE5D-847E-AA745B32C7ED}

      ==================== Installed Programs ======================

      (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

      µTorrent (HKU\S-1-5-21-580467305-273187244-10777062-1000\...\uTorrent) (Version: 3.5.1.44332 - BitTorrent Inc.)
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0015-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0016-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0018-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0019-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001A-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001B-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0403-0000-0000000FF1CE}_PROPLUS_{BEADB115-DB47-4BD0-A9EC-AE585AFAB2D8}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0416-0000-0000000FF1CE}_PROPLUS_{8A524694-0CA4-476A-9301-B1E9D70FC952}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-042D-0000-0000000FF1CE}_PROPLUS_{017A6981-5E03-4A97-830A-35FE0927BB7F}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0456-0000-0000000FF1CE}_PROPLUS_{A3A03B41-14EA-4E50-97D8-FCF429AE0CCB}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-002A-0C0A-1000-0000000FF1CE}_PROPLUS_{430AE3E6-E982-4958-90FC-1C062BC74E22}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0044-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}) (Version: - Microsoft) Hidden
      2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-006E-0C0A-0000-0000000FF1CE}_PROPLUS_{430AE3E6-E982-4958-90FC-1C062BC74E22}) (Version: - Microsoft) Hidden
      360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 9.6.0.1245 - 360 Security Center)
      64 Bit HP CIO Components Installer (HKLM\...\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden
      Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 18.011.20036 - Adobe Systems Incorporated)
      Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.161 - Adobe Systems Incorporated)
      Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.161 - Adobe Systems Incorporated)
      Apowersoft Online Launcher versión 1.4.4 (HKU\S-1-5-21-580467305-273187244-10777062-1000\...\{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1) (Version: 1.4.4 - APOWERSOFT LIMITED)
      BufferChm (HKLM-x32\...\{FA0FF682-CC70-4C57-93CD-E276F3E7537E}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      CCleaner (HKLM\...\CCleaner) (Version: 5.39 - Piriform)
      Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
      Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
      Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
      Copy (HKLM-x32\...\{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      D110 (HKLM-x32\...\{55C4B9E9-39C8-4BD6-9BCF-41BE40393A5F}) (Version: 140.0.142.000 - Hewlett-Packard) Hidden
      Destinations (HKLM-x32\...\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 140.0.77.000 - Hewlett-Packard) Hidden
      DeviceDiscovery (HKLM-x32\...\{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
      DJ_AIO_06_F2400_SW_Min (HKLM-x32\...\{5546F4E9-B0F4-4F54-B949-2AB006C9284F}) (Version: 140.0.690.000 - Hewlett-Packard) Hidden
      ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
      F2400 (HKLM-x32\...\{6DBB66CD-38C7-472C-BBB9-06BFDA182A29}) (Version: 140.0.690.000 - Hewlett-Packard) Hidden
      GPBaseService2 (HKLM-x32\...\{BB3447F6-9553-4AA9-960E-0DB5310C5779}) (Version: 140.0.211.000 - Hewlett-Packard) Hidden
      HP ENVY 4500 series Ayuda (HKLM-x32\...\{083DCC02-5EB2-48B0-8BFF-F2D367F5AFB7}) (Version: 30.0.0 - Hewlett Packard)
      HP ENVY 4500 series Software básico del dispositivo (HKLM\...\{F1F56388-1766-41E4-BFBE-F23671D56574}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
      HP Support Solutions Framework (HKLM-x32\...\{21925AE1-929D-4222-B38B-80BC30BBE09C}) (Version: 12.8.47.1 - HP)
      HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
      HPAppStudio (HKLM-x32\...\{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}) (Version: 140.0.95.000 - Hewlett-Packard) Hidden
      HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
      HPPhotoGadget (HKLM-x32\...\{CAE4213F-F797-439D-BD9E-79B71D115BE3}) (Version: 140.0.524.000 - Hewlett-Packard) Hidden
      hpPrintProjects (HKLM-x32\...\{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}) (Version: 130.0.303.000 - Hewlett-Packard) Hidden
      HPProductAssistant (HKLM-x32\...\{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      HPSSupply (HKLM-x32\...\{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}) (Version: 140.0.211.000 - Hewlett-Packard) Hidden
      hpWLPGInstaller (HKLM-x32\...\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}) (Version: 130.0.303.000 - Hewlett-Packard) Hidden
      Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
      Intel(R) Management Engine Interface (HKLM\...\HECI) (Version: - Intel Corporation)
      Intel(R) Network Connections 19.5.300.2 (HKLM\...\PROSetDX) (Version: 19.5.300.2 - Intel)
      Java 8 Update 144 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
      Java SE Development Kit 8 Update 131 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180131}) (Version: 8.0.1310.11 - Oracle Corporation)
      Malwarebytes versión 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
      MarketResearch (HKLM-x32\...\{D360FA88-17C8-4F14-B67F-13AAF9607B12}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      Mediatek RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.5.39.165 - MediatekWiFi)
      Microsoft .NET Framework 4.7.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.7.02558 - Microsoft Corporation)
      Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
      Microsoft Office Excel 2007 Help Actualización (KB963678) (HKLM-x32\...\{90120000-0016-0C0A-0000-0000000FF1CE}_PROPLUS_{59E09C3D-4878-47D9-87DB-6D0018026889}) (Version: - Microsoft)
      Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
      Microsoft Office Outlook 2007 Help Actualización (KB963677) (HKLM-x32\...\{90120000-001A-0C0A-0000-0000000FF1CE}_PROPLUS_{59C244C2-0C37-4E85-8F7E-DBDD3958B694}) (Version: - Microsoft)
      Microsoft Office Powerpoint 2007 Help Actualización (KB963669) (HKLM-x32\...\{90120000-0018-0C0A-0000-0000000FF1CE}_PROPLUS_{F318245D-05AE-4681-A749-A036CE44AF29}) (Version: - Microsoft)
      Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
      Microsoft Office Word 2007 Help Actualización (KB963665) (HKLM-x32\...\{90120000-001B-0C0A-0000-0000000FF1CE}_PROPLUS_{377BA42A-1C84-45D6-94B8-6D00887D172D}) (Version: - Microsoft)
      Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{650c9b4a-60ec-4e4e-8d8e-32d85ce3b7c5}) (Version: 11.0.61030.0 - Microsoft Corporation)
      Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
      Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
      Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
      MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
      Network64 (HKLM\...\{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}) (Version: 140.0.221.000 - Hewlett-Packard) Hidden
      Network64 (HKLM\...\{CE47BA54-78AC-409F-9151-BDF5BE15A804}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      Plex Media Server (HKLM-x32\...\{1b8e71fc-44b8-4550-9376-72db5f2746ce}) (Version: 1.11.3.4803 - Plex, Inc.)
      Plex Media Server (HKLM-x32\...\{617D6B5B-FCAE-43F5-9B09-73798070833E}) (Version: 1.11.3803 - Plex, Inc.) Hidden
      PS_AIO_07_D110_SW_Min (HKLM-x32\...\{42BBA4CC-EFB6-4653-A2CC-F305D4B399C3}) (Version: 140.0.142.000 - Hewlett-Packard) Hidden
      QuickTransfer (HKLM-x32\...\{E517094C-06B6-419F-8FFD-EF4F57972130}) (Version: 140.0.98.000 - Hewlett-Packard) Hidden
      Revo Uninstaller 2.0.3 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.3 - VS Revo Group, Ltd.)
      RXO 2019 (HKLM-x32\...\RXO 2019_is1) (Version: - Digital Memory)
      Scan (HKLM-x32\...\{06A1D88C-E102-4527-AF70-29FFD7AF215A}) (Version: 140.0.80.000 - Hewlett-Packard) Hidden
      Secure [email protected] (HKLM-x32\...\{DA7B3D24-A6C2-4D3D-86B1-040C9AF5F7A3}) (Version: 3.20.2460.0 - Valassis)
      SmartWebPrinting (HKLM-x32\...\{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}) (Version: 140.0.186.000 - Hewlett-Packard) Hidden
      SolutionCenter (HKLM-x32\...\{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}) (Version: 140.0.213.000 - Hewlett-Packard) Hidden
      SoundMAX (HKLM-x32\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.2.6595 - Analog Devices)
      Status (HKLM-x32\...\{2FB9EA69-51D4-4913-9AD5-762C034DE811}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      Stopping Plex (HKLM-x32\...\{E70B9551-B5D4-41BC-AB7C-EE44025F77DC}) (Version: 1.11.3803 - Plex, Inc.) Hidden
      TecnologÃ*a de gestión activa Intel® (HKLM\...\MESOL) (Version: - Intel Corporation)
      Toolbox (HKLM-x32\...\{292F0F52-B62D-4E71-921B-89A682402201}) (Version: 140.0.428.000 - Hewlett-Packard) Hidden
      TP-LINK TL-WN821N(C)_TL-WN822N_TL-WN823N Controlador (HKLM-x32\...\{852E893E-E4FD-45BB-8B17-72ADDF686974}) (Version: 1.3.1 - TP-LINK)
      TrayApp (HKLM-x32\...\{CD31E63D-47FD-491C-8117-CF201D0AFAB5}) (Version: 140.0.212.000 - Hewlett-Packard) Hidden
      TunnelBear (HKLM-x32\...\{35184AD1-A3C9-4B38-A1F3-3D9C48EFAAEC}) (Version: 2.3.25.0 - TunnelBear) Hidden
      Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
      Utilidad de configuración inalámbrica de TP-LINK (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
      VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
      WebReg (HKLM-x32\...\{8EE94FD8-5F52-4463-A340-185D16328158}) (Version: 140.0.212.017 - Hewlett-Packard) Hidden
      WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)

      ==================== Custom CLSID (Whitelisted): ==========================

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
      ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers1: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2018-02-09] ()
      ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-09-11] (Alexander Roshal)
      ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-09-11] (Alexander Roshal)
      ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
      ContextMenuHandlers4: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2018-02-09] ()
      ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2009-09-23] (Intel Corporation)
      ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
      ContextMenuHandlers6: [SD360] -> {086F171D-5ED1-4ED2-B736-CFF3AD6A128E} => C:\Program Files (x86)\360\Total Security\MenuEx64.dll [2018-02-09] ()
      ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2014-09-11] (Alexander Roshal)
      ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2014-09-11] (Alexander Roshal)

      ==================== Scheduled Tasks (Whitelisted) =============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      Task: {1CE0434A-5D74-4F3A-8DD5-54DDA59BBE03} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
      Task: {1DDD8D51-08BD-42CC-8367-87B114773F33} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-01-09] (Piriform Ltd)
      Task: {4177B0D1-82F9-4C02-82F1-614E019A0EA6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-01-17] (Adobe Systems Incorporated)
      Task: {46DF8F46-4B13-4F17-97E2-7A62AD0DE855} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_161_pepper.exe [2018-02-09] (Adobe Systems Incorporated)
      Task: {63FE18CB-D7C0-4ABB-9940-284FB6B7DF3D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-01-09] (Piriform Ltd)
      Task: {8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302} - System32\Tasks\{3F285699-0F26-43AC-A15F-ACC1A01A7CAA} => "c:\program files (x86)\google\chrome\application\chrome.exe" hxxps://www.skype.com/go/downloading?source=lightinstaller&ver=7.39.0.102&LastError=12040
      Task: {A3671A32-85E1-421E-8906-2AD6BFCEAE2E} - System32\Tasks\SmartShare => C:\Program Files (x86)\LG Software\LG Smart Share\SmartShareStart.exe
      Task: {A5435483-3AC3-40F4-BC74-E5E8DE7BCD5C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-02-09] (Adobe Systems Incorporated)
      Task: {C2C8B80C-68B9-4D5A-B824-7E9F8CBF9A37} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)

      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


      ==================== Shortcuts & WMI ========================

      (The entries could be listed to be restored or removed.)


      Shortcut: C:\Users\admin\Favorites\Sitio para descargas de NCH Software.lnk -> hxxp://www.nchsoftware.com/es/index.htm

      ==================== Loaded Modules (Whitelisted) ==============

      2018-02-23 14:18 - 2018-02-09 12:48 - 000818784 _____ () C:\Program Files (x86)\360\Total Security\MenuEx64.dll
      2017-07-28 15:05 - 2014-04-08 08:43 - 000847360 _____ () C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\TWCU.exe
      2018-02-23 14:18 - 2018-02-09 12:48 - 000099240 _____ () C:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
      2017-07-28 15:05 - 2014-04-08 08:42 - 001401344 _____ () C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\nicLan.dll
      2017-07-28 15:05 - 2014-04-08 08:42 - 000193024 _____ () C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\DC_WFF.dll
      2018-02-23 14:18 - 2018-02-09 12:48 - 000567392 _____ () C:\Program Files (x86)\360\Total Security\safemon\wdui2.dll

      ==================== Alternate Data Streams (Whitelisted) =========

      (If an entry is included in the fixlist, only the ADS will be removed.)

      AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

      ==================== Safe Mode (Whitelisted) ===================

      (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"

      ==================== Association (Whitelisted) ===============

      (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


      ==================== Internet Explorer trusted/restricted ===============

      (If an entry is included in the fixlist, it will be removed from the registry.)

      IE trusted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\gob.es -> hxxps://agenciatributaria.gob.es
      IE trusted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\localhost -> localhost
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\008i.com -> 008i.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\008k.com -> 008k.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\00hq.com -> 00hq.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0190-dialers.com -> 0190-dialers.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\01i.info -> 01i.info
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0411dd.com -> 0411dd.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0511zfhl.com -> 0511zfhl.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\05p.com -> 05p.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0632qyw.com -> 0632qyw.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0calories.net -> 0calories.net
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0cj.net -> 0cj.net
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\0scan.com -> 0scan.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\1-se.com -> 1-se.com
      IE restricted site: HKU\S-1-5-21-580467305-273187244-10777062-1000\...\1001movie.com -> 1001movie.com

      There are 6091 more sites.


      ==================== Hosts content: ===============================

      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

      2015-03-19 23:32 - 2017-08-06 13:08 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts

      127.0.0.1 localhost

      ==================== Other Areas ============================

      (Currently there is no automatic fix for this section.)

      HKU\S-1-5-21-580467305-273187244-10777062-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
      DNS Servers: 212.166.211.4 - 62.81.16.164
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
      Windows Firewall is enabled.

      ==================== MSCONFIG/TASK MANAGER disabled items ==

      MSCONFIG\Services: AdobeARMservice => 2
      MSCONFIG\Services: gupdate => 2
      MSCONFIG\Services: gupdatem => 3
      MSCONFIG\Services: SkypeUpdate => 2
      MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
      MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Utilitaire Réseau sans-fil Bewan.lnk => C:\Windows\pss\Utilitaire Réseau sans-fil Bewan.lnk.CommonStartup
      MSCONFIG\startupfolder: C:^Users^admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hpqtra08.exe => C:\Windows\pss\hpqtra08.exe.Startup
      MSCONFIG\startupfolder: C:^Users^admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Supervisar alertas de tinta - HP ENVY 4500 series.lnk => C:\Windows\pss\Supervisar alertas de tinta - HP ENVY 4500 series.lnk.Startup
      MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
      MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
      MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
      MSCONFIG\startupreg: Plex Media Server => "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
      MSCONFIG\startupreg: Report => C:\AdwCleaner\AdwCleaner[C1].txt
      MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
      MSCONFIG\startupreg: uTorrent => "C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
      MSCONFIG\startupreg: Web Companion => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize

      ==================== FirewallRules (Whitelisted) ===============

      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      FirewallRules: [TCP Query User{6302353A-1AE5-4837-BBFF-62F489AF6E5F}C:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe
      FirewallRules: [UDP Query User{783E3630-5CCC-44AD-B02F-EEF7F42E7932}C:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe] => (Allow) C:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe
      FirewallRules: [{5AFE954C-07A6-4140-9598-E91B2891C7BB}] => (Allow) C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{AEDB6117-5FC1-43C4-8DE9-F98CFA860C95}] => (Allow) C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{7B0A27DF-E0F5-40FB-9BBE-C7456842FE0E}] => (Allow) C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{5F25039F-178D-4578-B103-FE311FC15104}] => (Allow) C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{C586FC6B-3207-4718-92C7-2644016EE874}] => (Allow) C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{68803245-847F-4EB2-A6D2-F28351006BF6}] => (Allow) C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe
      FirewallRules: [{0AF39564-5633-471F-A0C5-6E5FC4932A54}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
      FirewallRules: [{39D9E734-2F7D-4AE0-8737-FCA9C0A32317}] => (Allow) C:\Program Files (x86)\360\Total Security\softmgr\360InstantSetup.exe
      FirewallRules: [{ED99BD24-C467-4D48-8D40-389CB8DFBF51}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
      FirewallRules: [{A2F9DB05-5111-42F6-8692-F5E23DD1C42A}] => (Allow) C:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
      FirewallRules: [TCP Query User{C710EC0B-B1EB-4313-A307-561EE3652845}F:\emule2\emule\emule.exe] => (Allow) F:\emule2\emule\emule.exe
      FirewallRules: [UDP Query User{54DA1D51-4668-4BC7-AB3B-9F39F2B9563C}F:\emule2\emule\emule.exe] => (Allow) F:\emule2\emule\emule.exe
      FirewallRules: [TCP Query User{24B8F90B-F500-4C3B-935C-B9BAF36B300D}F:\plex\plex media server\plex media server.exe] => (Allow) F:\plex\plex media server\plex media server.exe
      FirewallRules: [UDP Query User{EA5C0B21-614F-4BFE-9E07-B05421EEFB4D}F:\plex\plex media server\plex media server.exe] => (Allow) F:\plex\plex media server\plex media server.exe
      FirewallRules: [TCP Query User{410375E7-284E-4B98-A21F-31F8D7F590C1}F:\plex\plex media server\plex dlna server.exe] => (Allow) F:\plex\plex media server\plex dlna server.exe
      FirewallRules: [UDP Query User{3738E4CA-5E96-4C1C-B0D9-38865DC4985D}F:\plex\plex media server\plex dlna server.exe] => (Allow) F:\plex\plex media server\plex dlna server.exe
      FirewallRules: [{5CE257FE-A557-4259-B54C-F61C7114D7F4}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
      FirewallRules: [{4B136F3D-39F6-415B-BC8A-0C5AA0E2430E}] => (Allow) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe

      ==================== Restore Points =========================

      19-02-2018 09:41:38 Windows Update
      19-02-2018 22:38:45 Plex Media Server
      19-02-2018 22:40:19 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
      24-02-2018 00:32:02 Windows Update

      ==================== Faulty Device Manager Devices =============


      ==================== Event log errors: =========================

      Application errors:
      ==================
      Error: (02/25/2018 02:47:29 PM) (Source: RalinkRegistryWriter) (EventID: 0) (User: )
      Description: Event-ID 0

      Error: (02/25/2018 02:47:11 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
      Description: Omitiendo: error de validación de Eap method DLL path name. Error: typeId=43, authorId=9, vendorId=0, vendorType=0

      Error: (02/25/2018 02:47:11 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
      Description: Omitiendo: error de validación de Eap method DLL path name. Error: typeId=25, authorId=9, vendorId=0, vendorType=0

      Error: (02/25/2018 12:06:55 AM) (Source: SideBySide) (EventID: 80) (User: )
      Description: Error al generar el contexto de activación para "C:\Users\admin\Desktop\esetsmartinstaller_esn.exe". Error en el archivo de manifiesto o directiva "" en la lÃ*nea .
      Una versión de componente requerida por la aplicación está en conflicto con la versión de otro componente activo.
      Los componentes en conflicto son:.
      Componente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
      Componente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

      Error: (02/25/2018 12:06:48 AM) (Source: SideBySide) (EventID: 80) (User: )
      Description: Error al generar el contexto de activación para "C:\Users\admin\Desktop\esetsmartinstaller_esn.exe". Error en el archivo de manifiesto o directiva "" en la lÃ*nea .
      Una versión de componente requerida por la aplicación está en conflicto con la versión de otro componente activo.
      Los componentes en conflicto son:.
      Componente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
      Componente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

      Error: (02/25/2018 12:06:47 AM) (Source: SideBySide) (EventID: 80) (User: )
      Description: Error al generar el contexto de activación para "C:\Users\admin\Desktop\esetsmartinstaller_esn.exe". Error en el archivo de manifiesto o directiva "" en la lÃ*nea .
      Una versión de componente requerida por la aplicación está en conflicto con la versión de otro componente activo.
      Los componentes en conflicto son:.
      Componente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
      Componente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

      Error: (02/25/2018 12:06:23 AM) (Source: SideBySide) (EventID: 80) (User: )
      Description: Error al generar el contexto de activación para "C:\Users\admin\Desktop\esetsmartinstaller_esn.exe". Error en el archivo de manifiesto o directiva "" en la lÃ*nea .
      Una versión de componente requerida por la aplicación está en conflicto con la versión de otro componente activo.
      Los componentes en conflicto son:.
      Componente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
      Componente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

      Error: (02/25/2018 12:06:02 AM) (Source: SideBySide) (EventID: 80) (User: )
      Description: Error al generar el contexto de activación para "C:\Users\admin\Desktop\esetsmartinstaller_esn.exe". Error en el archivo de manifiesto o directiva "" en la lÃ*nea .
      Una versión de componente requerida por la aplicación está en conflicto con la versión de otro componente activo.
      Los componentes en conflicto son:.
      Componente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
      Componente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.


      System errors:
      =============
      Error: (02/25/2018 02:51:09 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
      Description: El servicio HP Network Devices Support se cerró con el siguiente error:
      El sistema no puede encontrar el archivo especificado.

      Error: (02/25/2018 02:49:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
      Description: El servicio Ralink Registry Writer 64 se terminó de manera inesperada. Esto ha sucedido 1 veces.

      Error: (02/25/2018 02:48:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
      Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Wondershare Application Framework Service.

      Error: (02/25/2018 02:47:29 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
      Description: El servicio Ralink Registry Writer se cerró con el siguiente error:
      Todas las instancias de canalización están en uso.

      Error: (02/25/2018 02:47:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
      Description: El servicio Servicio HP CUE DeviceDiscovery se cerró con el siguiente error:
      El sistema no puede encontrar el archivo especificado.

      Error: (02/25/2018 02:42:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: El servicio eapihdrv no pudo iniciarse debido al siguiente error:
      Se ha bloqueado la descarga de este controlador

      Error: (02/25/2018 02:42:37 AM) (Source: Application Popup) (EventID: 1060) (User: )
      Description: Se bloqueó la carga de \??\C:\Users\admin\AppData\Local\Temp\ehdrv.sys por una incompatibilidad con este sistema. Póngase en contacto con el fabricante del software para obtener una versión compatible del controlador.

      Error: (02/25/2018 02:42:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: El servicio eapihdrv no pudo iniciarse debido al siguiente error:
      Se ha bloqueado la descarga de este controlador


      Windows Defender:
      ===================================
      Date: 2017-08-05 20:45:14.540
      Description:
      El examen de Windows Defender se detuvo antes de completarse.
      Id. de examen:{70E4FE7C-0142-4E05-9966-77312315A602}
      Tipo de examen:AntiSpyware
      Parámetros de examen:Examen rápido
      Usuario:admin-PC\admin

      Date: 2017-10-24 12:11:30.343
      Description:
      Windows Defender encontró un error al intentar cargar firmas e intentará restablecer un conjunto de firmas conocidas.
      Firmas intentadas:Actual
      Código de error:0x80070002
      Descripción de error:El sistema no puede encontrar el archivo especificado.
      Versión de firma:0.0.0.0
      Versión de motor:0.0.0.0

      CodeIntegrity:
      ===================================

      Date: 2018-02-13 22:36:57.827
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Users\admin\AppData\Local\Temp\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2018-02-13 22:36:57.717
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Users\admin\AppData\Local\Temp\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2017-10-24 11:03:42.468
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Windows\System32\drivers\nwifi.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2017-10-24 11:03:42.250
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\Windows\System32\drivers\nwifi.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2017-08-06 14:07:47.872
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\ComboFix\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2017-08-06 14:07:47.763
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\ComboFix\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2015-03-19 21:46:38.171
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\ComboFix\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      Date: 2015-03-19 21:46:37.984
      Description:
      Windows no puede comprobar la integridad de imagen del archivo \Device\HarddiskVolume2\ComboFix\catchme.sys porque el hash del archivo no se encuentra en el sistema. Puede que un cambio reciente de hardware o software haya instalado un archivo dañado o con una firma incorrecta, o que exista un software malintencionado de origen desconocido.

      ==================== Memory info ===========================

      Processor: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
      Percentage of memory in use: 54%
      Total physical RAM: 2022.3 MB
      Available physical RAM: 927.82 MB
      Total Virtual: 4044.59 MB
      Available Virtual: 2938.07 MB

      ==================== Drives ================================

      Drive c: () (Fixed) (Total:74.44 GB) (Free:23.14 GB) NTFS

      \\?\Volume{b9c25659-c0a0-11e3-b022-806e6f6e6963}\ (Reservado para el sistema) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

      ==================== MBR & Partition Table ==================

      ========================================================
      Disk: 0 (MBR Code: Windows 7/8/10) (Size: 74.5 GB) (Disk ID: E7A6E659)
      Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
      Partition 2: (Not Active) - (Size=74.4 GB) - (Type=07 NTFS)

      ==================== End of Addition.txt ============================

    2. #12
      Moderador
      Avatar de @MiguelRiaguel
      Registrado
      dic 2008
      Ubicación
      España
      Mensajes
      12.256

      Re: Ordenador se queda bloqueado y lento

      Sí... he visto que has cambiado el Panda Antivirus y en su lugar has instalado 360 Total Security. Si es una solución que te convence, no es mala opción. No obstante, actualmente dentro de las opciones gratuitas prefiero Kaspersky Free.

      Voy a enviarte un script de reparación con FRST; entre otras cosas, voy a intentar poner tus navegadores a cero (eliminando plugins, extensiones, etc). Por eso, realiza una copia de seguridad de tus marcadores (por si acaban eliminándose):



      Ahora sigue estos pasos, MUY Importante ~ Realiza una copia de seguridad del registro:

      • Para hacerlo descarga >> DelFix.exe en tu escritorio.

        • Doble clic para ejecutarlo.(Si usas Windows Vista/7 u 8 presiona clic derecho y selecciona "Ejecutar como Administrador.")

        • Atención, ahora marca/selecciona únicamente la casilla "Create registry backup", las demás NO.

      • Pulsar en Run.

        Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.


      A continuación, ve a:

      Inicio >>> Ejecutar >>>Escribes notepad.exe.

      Ahora copia y pega estos archivos dentro del Notepad: (Se excluye la palabra código)

      Código:
      Start
      CreateRestorePoint:
      CloseProcesses:
      
      GroupPolicyScripts: Restriction <==== ATTENTION
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
      HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.es/
      SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
      SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
      SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
      SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
      SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
      SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
      SearchScopes: HKU\S-1-5-21-580467305-273187244-10777062-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D110817-A2D586A4510&form=CONBDF&conlogo=CT3335800&q={searchTerms}
      SearchScopes: HKU\S-1-5-21-580467305-273187244-10777062-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D110817-A2D586A4510&form=CONBDF&conlogo=CT3335800&q={searchTerms}
      BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-30] (Oracle Corporation)
      BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2018-02-09] (Qihu 360 Software Co., Ltd.)
      BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-30] (Oracle Corporation)
      BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2018-02-09] (Qihu 360 Software Co., Ltd.)
      Toolbar: HKLM-x32 - No Name - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - No File
      DPF: HKLM-x32 {2DAB6EF1-66C3-427C-87CD-8DC448C47EAE} hxxps://www5.aeat.es/es13/h/tgvicab.cab
      DPF: HKLM-x32 {947B00D2-962D-4A35-9E48-98EE6A442B41} hxxps://www1.agenciatributaria.gob.es/ADUA/internet/aded1503.cab
      DPF: HKLM-x32 {B785FA3C-1DE9-4D20-8396-613C486FE95E} hxxps://www1.agenciatributaria.gob.es/es13/h/cactivex.cab
      FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default [2018-02-23]
      FF Homepage: Mozilla\Firefox\Profiles\QyAtE5pv.default -> hxxps://www.malwarebytes.org/restorebrowser/
      FF Extension: (Avira Browser Safety) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default\Extensions\[email protected] [2016-01-19] [Legacy]
      FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-30] (Oracle Corporation)
      FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-30] (Oracle Corporation)
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
      FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-580467305-273187244-10777062-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\admin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-01-20] (RocketLife, LLP)
      CHR HKLM\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
      CHR HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
      OPR Extension: (Ghostery) - C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg [2017-06-03]
      S2 hpqddsvc; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      S2 hpqddsvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      S2 HPSLPSVC; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      S2 HPSLPSVC; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
      ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      Task: {8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302} - System32\Tasks\{3F285699-0F26-43AC-A15F-ACC1A01A7CAA} => "c:\program files (x86)\google\chrome\application\chrome.exe" hxxps://www.skype.com/go/downloading?source=lightinstaller&ver=7.39.0.102&LastError=12040
      AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
      
      CMD:  ipconfig /release 
      CMD:  ipconfig /renew 
      CMD:  ipconfig /flushdns 
      CMD:  ipconfig /registerdns
      RemoveProxy:
      EmptyTemp:
      Hosts:
      end
      • Lo guardas bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.
      Nota: Es necesario que el ejecutable Frst.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajara.


      • Ejecutas Frst.exe.
      • Presionas el botón Fix y aguardas a que termine.
      • La Herramienta guardara el reporte en tu escritorio (Fixlog.txt).
      • Lo pegas en tu próxima respuesta.


      Reinicias el equipo y comentas cómo sigue funcionando todo.
      Saludos.
      El problema de los virus es pasajero y durará un par de años / John McAfee - fundador de McAfee

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    3. #13
      Usuario Avatar de bulldog48
      Registrado
      ene 2018
      Ubicación
      España
      Mensajes
      13

      Re: Ordenador se queda bloqueado y lento

      Hola te dejo los log,en cuanto al equipo voy a probarlo a ver que tal,he cambiado el antivirus por el que me dijiste y he instalado Opera,aún se sigue bloqueando algo pero menos...ya te diré.



      # DelFix v1.013 - Logfile created 27/02/2018 at 13:05:21
      # Updated 17/04/2016 by Xplode
      # Username : admin - ADMIN-PC
      # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

      ~ Creating registry backup ... OK

      ########## - EOF - ##########


      Fix result of Farbar Recovery Scan Tool (x64) Version: 24.02.2018
      Ran by admin (27-02-2018 13:12:52) Run:1
      Running from C:\Users\admin\Desktop
      Loaded Profiles: admin (Available Profiles: admin)
      Boot Mode: Normal
      ==============================================

      fixlist content:
      *****************
      Start
      CreateRestorePoint:
      CloseProcesses:

      GroupPolicyScripts: Restriction <==== ATTENTION
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
      HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.es/
      SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
      SearchScopes: HKU\S-1-5-21-580467305-273187244-10777062-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D110817-A2D586A4510&form=CONBDF&conlogo=CT3335800&q={searchTerms}
      SearchScopes: HKU\S-1-5-21-580467305-273187244-10777062-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D110817-A2D586A4510&form=CONBDF&conlogo=CT3335800&q={searchTerms}
      BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-30] (Oracle Corporation)
      BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2018-02-09] (Qihu 360 Software Co., Ltd.)
      BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-30] (Oracle Corporation)
      BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2018-02-09] (Qihu 360 Software Co., Ltd.)
      Toolbar: HKLM-x32 - No Name - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - No File
      DPF: HKLM-x32 {2DAB6EF1-66C3-427C-87CD-8DC448C47EAE} hxxps://www5.aeat.es/es13/h/tgvicab.cab
      DPF: HKLM-x32 {947B00D2-962D-4A35-9E48-98EE6A442B41} hxxps://www1.agenciatributaria.gob.es/ADUA/internet/aded1503.cab
      DPF: HKLM-x32 {B785FA3C-1DE9-4D20-8396-613C486FE95E} hxxps://www1.agenciatributaria.gob.es/es13/h/cactivex.cab
      FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default [2018-02-23]
      FF Homepage: Mozilla\Firefox\Profiles\QyAtE5pv.default -> hxxps://www.malwarebytes.org/restorebrowser/
      FF Extension: (Avira Browser Safety) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default\Extensions\[email protected] [2016-01-19] [Legacy]
      FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-30] (Oracle Corporation)
      FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-30] (Oracle Corporation)
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
      FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-580467305-273187244-10777062-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\admin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-01-20] (RocketLife, LLP)
      CHR HKLM\...\Chrome\Extension: [fagakgcelolinfnkfgekcnedpaklfcok] - hxxps://clients2.google.com/service/update2/crx
      CHR HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
      OPR Extension: (Ghostery) - C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg [2017-06-03]
      S2 hpqddsvc; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      S2 hpqddsvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      S2 HPSLPSVC; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      S2 HPSLPSVC; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
      ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
      ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
      Task: {8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302} - System32\Tasks\{3F285699-0F26-43AC-A15F-ACC1A01A7CAA} => "c:\program files (x86)\google\chrome\application\chrome.exe" hxxps://www.skype.com/go/downloading?source=lightinstaller&ver=7.39.0.102&LastError=12040
      AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]

      CMD: ipconfig /release
      CMD: ipconfig /renew
      CMD: ipconfig /flushdns
      CMD: ipconfig /registerdns
      RemoveProxy:
      EmptyTemp:
      Hosts:
      end
      *****************

      Restore point was successfully created.
      Processes closed successfully.
      C:\Windows\system32\GroupPolicy\Machine => moved successfully
      C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
      C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
      HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
      "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Search Page" => removed successfully
      "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page" => removed successfully
      HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
      HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
      HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
      "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
      HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found
      HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
      "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
      HKLM\Software\Wow6432Node\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found
      "HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
      "HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => removed successfully
      HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found
      "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => removed successfully
      "HKLM\Software\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => removed successfully
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B69F34DD-F0F9-42DC-9EDD-957187DA688D} => key not found
      "HKLM\Software\Classes\CLSID\{B69F34DD-F0F9-42DC-9EDD-957187DA688D}" => removed successfully
      "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => removed successfully
      "HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => removed successfully
      HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B69F34DD-F0F9-42DC-9EDD-957187DA688D} => key not found
      HKLM\Software\Wow6432Node\Classes\CLSID\{B69F34DD-F0F9-42DC-9EDD-957187DA688D} => key not found
      "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}" => removed successfully
      HKLM\Software\Wow6432Node\Classes\CLSID\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} => key not found
      "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{2DAB6EF1-66C3-427C-87CD-8DC448C47EAE}" => removed successfully
      HKLM\Software\Wow6432Node\Classes\CLSID\{2DAB6EF1-66C3-427C-87CD-8DC448C47EAE} => key not found
      "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{947B00D2-962D-4A35-9E48-98EE6A442B41}" => removed successfully
      HKLM\Software\Wow6432Node\Classes\CLSID\{947B00D2-962D-4A35-9E48-98EE6A442B41} => key not found
      "HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{B785FA3C-1DE9-4D20-8396-613C486FE95E}" => removed successfully
      HKLM\Software\Wow6432Node\Classes\CLSID\{B785FA3C-1DE9-4D20-8396-613C486FE95E} => key not found
      C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default => moved successfully
      C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default => path removed successfully
      FF Homepage: Mozilla\Firefox\Profiles\QyAtE5pv.default -> hxxps://www.malwarebytes.org/restorebrowser/ => "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default\prefs.js" not found
      "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\QyAtE5pv.default\Extensions\[email protected]" => not found
      "HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.144.2" => removed successfully
      C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll => moved successfully
      "HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.144.2" => removed successfully
      C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll => moved successfully
      "HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0" => removed successfully
      c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll => moved successfully
      "HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0" => removed successfully
      c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll => moved successfully
      "HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4" => removed successfully
      C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll => moved successfully
      "HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader" => removed successfully
      C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll => moved successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5" => removed successfully
      C:\Users\admin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll => moved successfully
      "HKLM\SOFTWARE\Google\Chrome\Extensions\fagakgcelolinfnkfgekcnedpaklfcok" => removed successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj" => removed successfully
      C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Extensions\bbkekonodcdmedgffkkbgmnnekbainbg => moved successfully
      "HKLM\System\CurrentControlSet\Services\hpqddsvc" => removed successfully
      hpqddsvc => service removed successfully
      hpqddsvc => service not found.
      "HKLM\System\CurrentControlSet\Services\HPSLPSVC" => removed successfully
      HPSLPSVC => service removed successfully
      HPSLPSVC => service not found.
      "HKLM\System\CurrentControlSet\Services\AppMgmt" => removed successfully
      AppMgmt => service removed successfully
      "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw" => removed successfully
      HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
      "HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Glary Utilities" => removed successfully
      HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} => key not found
      "HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\Glary Utilities" => removed successfully
      HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} => key not found
      "HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Glary Utilities" => removed successfully
      HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} => key not found
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302} => could not remove key. ErrorCode1: 0x00000002
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302} => could not remove key. ErrorCode1: 0x00000002
      C:\Windows\System32\Tasks\{3F285699-0F26-43AC-A15F-ACC1A01A7CAA} => moved successfully
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3F285699-0F26-43AC-A15F-ACC1A01A7CAA} => could not remove key. ErrorCode1: 0x00000002
      C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully

      ========= ipconfig /release =========


      Configuraci¢n IP de Windows

      No se puede realizar ninguna operaci¢n en Conexi¢n de *rea local 5 mientras los medios
      est‚n desconectados.
      No se puede realizar ninguna operaci¢n en Conexi¢n de *rea local 4 mientras los medios
      est‚n desconectados.

      Adaptador de Ethernet Conexi¢n de *rea local 5:

      Estado de los medios. . . . . . . . . . . : medios desconectados
      Sufijo DNS espec¡fico para la conexi¢n. . :

      Adaptador de Ethernet Conexi¢n de *rea local 4:

      Estado de los medios. . . . . . . . . . . : medios desconectados
      Sufijo DNS espec¡fico para la conexi¢n. . :

      Adaptador de Ethernet Conexi¢n de *rea local 3:

      Sufijo DNS espec¡fico para la conexi¢n. . :
      V¡nculo: direcci¢n IPv6 local. . . : fe80::1158:80a5:58c1:ef79%14
      Puerta de enlace predeterminada . . . . . :

      ========= End of CMD: =========


      ========= ipconfig /renew =========


      Configuraci¢n IP de Windows

      No se puede realizar ninguna operaci¢n en Conexi¢n de *rea local 5 mientras los medios
      est‚n desconectados.
      No se puede realizar ninguna operaci¢n en Conexi¢n de *rea local 4 mientras los medios
      est‚n desconectados.

      Adaptador de Ethernet Conexi¢n de *rea local 5:

      Estado de los medios. . . . . . . . . . . : medios desconectados
      Sufijo DNS espec¡fico para la conexi¢n. . :

      Adaptador de Ethernet Conexi¢n de *rea local 4:

      Estado de los medios. . . . . . . . . . . : medios desconectados
      Sufijo DNS espec¡fico para la conexi¢n. . :

      Adaptador de Ethernet Conexi¢n de *rea local 3:

      Sufijo DNS espec¡fico para la conexi¢n. . : home
      V¡nculo: direcci¢n IPv6 local. . . : fe80::1158:80a5:58c1:ef79%14
      Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.1.65
      M*scara de subred . . . . . . . . . . . . : 255.255.255.0
      Puerta de enlace predeterminada . . . . . : 192.168.1.1

      ========= End of CMD: =========


      ========= ipconfig /flushdns =========


      Configuraci¢n IP de Windows

      Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.

      ========= End of CMD: =========


      ========= ipconfig /registerdns =========


      Configuraci¢n IP de Windows

      Se inici¢ el registro de los registros de recursos DNS para todos
      los adaptadores de este equipo. Cualquier error se notificar* en
      el Visor de eventos en 15 minutos.

      ========= End of CMD: =========


      ========= RemoveProxy: =========

      "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => removed successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => removed successfully
      "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
      "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
      "HKU\S-1-5-21-580467305-273187244-10777062-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


      ========= End of RemoveProxy: =========

      C:\Windows\System32\Drivers\etc\hosts => moved successfully
      Hosts restored successfully.

      =========== EmptyTemp: ==========

      BITS transfer queue => 16777216 B
      DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10722080 B
      Java, Flash, Steam htmlcache => 1080 B
      Windows/system/drivers => 8884220 B
      Edge => 0 B
      Chrome => 0 B
      Firefox => 420037 B
      Opera => 16833701 B

      Temp, IE cache, history, cookies, recent:
      Users => 0 B
      Default => 33125 B
      Public => 0 B
      ProgramData => 0 B
      systemprofile => 115741036 B
      systemprofile32 => 114571 B
      LocalService => 132244 B
      NetworkService => 66228 B
      admin => 86493681 B

      RecycleBin => 0 B
      EmptyTemp: => 244.3 MB temporary data Removed.

      ================================

      Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 27-02-2018 13:30:29)


      Result of scheduled keys to remove after reboot:

      "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302}" => removed successfully
      "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A09AC3E-ABE9-4928-A4BD-F1EBB0F3F302}" => removed successfully
      "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3F285699-0F26-43AC-A15F-ACC1A01A7CAA}" => removed successfully

      ==== End of Fixlog 13:30:29 ====

    4. #14
      Moderador
      Avatar de @MiguelRiaguel
      Registrado
      dic 2008
      Ubicación
      España
      Mensajes
      12.256

      Re: Ordenador se queda bloqueado y lento

      Vuelve a ejecutar >> DelFix.exe de la siguiente manera:

      • Doble clic para ejecutarlo. (Si usas Windows Vista/7 u 8 presiona clic derecho y selecciona "Ejecutar como Administrador.")
        • Marca todas las casillas, y pulsas en Run


      Se abrirá el informe (DelFix.txt), puedes cerrarlo. Estamos en contacto.
      Saludos
      El problema de los virus es pasajero y durará un par de años / John McAfee - fundador de McAfee

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    5. #15
      Usuario Avatar de bulldog48
      Registrado
      ene 2018
      Ubicación
      España
      Mensajes
      13
      Hola el pc sigue funcionando algo lento y se sigue bloqueando a veces,he desinstalado el antivirus que me recomendaste ya que me daba la impresión lo ralentizaba y probare con otro descargado de aquí.
      Ya me dices los pasos a seguir.
      Gracias




      he instalado el avast y me sigue llendo el ordenador lento,sin necesidad de estar en internet se me bloquea,instale el opera y tarda mucho en abrirse y luego a veces se bloquea tambien.

      ya me diras.un saludo

    6. #16
      Moderador
      Avatar de @MiguelRiaguel
      Registrado
      dic 2008
      Ubicación
      España
      Mensajes
      12.256

      Re: Ordenador se queda bloqueado y lento

      Vamos a utilizar una herramienta de reparación como es Windows Repair (All In One).

      Esta herramienta tiene varios pasos (steps) para reparar windows. Yo te voy a recomendar que realices el Step4: System File Check para que compruebe los archivos de sistema y los repare en caso que sea necesario. Posteriormente, pulsas sobre la pestaña Repairs >> y pulsas sobre Open repairs. El programa realizará un backup automático del registro de tu sistema, y posteriormente accederas a la ventana de reparación:



      Importante que tengas seleccionadas todas las opciones (no recuerdo muy bien pero creo que tiene sobre 33 opciones; las que son específicamente de Windows 8 no son necesarias que las selecciones). Para iniciar la reparación pulsa en Star Repairs. Deja al programa que realice todas las acciones necesarias para la reparación y cuando finalice, reinicias el equipo. Compruebas resultados.

      Saludos.
      El problema de los virus es pasajero y durará un par de años / John McAfee - fundador de McAfee

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    7. #17
      Usuario Avatar de bulldog48
      Registrado
      ene 2018
      Ubicación
      España
      Mensajes
      13

      Re: Ordenador se queda bloqueado y lento

      Hola funciona algo mejor pero el Opera tarda mucho en iniciarse y luego a veces aún se queda colgado,con el explorer pasa lo mismo,el antivirus lo cambié por el avast.

      Un Saludo

    8. #18
      Moderador
      Avatar de @MiguelRiaguel
      Registrado
      dic 2008
      Ubicación
      España
      Mensajes
      12.256

      Re: Ordenador se queda bloqueado y lento

      Descargar OTL.exe By OldTimer en tu Escritorio .

      Ahora realiza los siguientes pasos



      • Cierra todos programas que tengas abiertos ( msn, internet explorer,mozilla,Emule,Ares..) y hacer doble click en el ícono de OTL para ejecutarlo.
      • Ahora en el menú solo debes cambiar debajo de donde pone: "Tipo de Análisis" poner Resultado Mínimo.
      • Marcar las opciones: Buscar LOP y Buscar Purity.
      • Marcar las Opciones >> Omitir Archivos De Microsoft y Usar Listado de Compañías Reconocidas.
      • Copiar y Pegar el siguiente script bajo la casilla Análisis Personalizados/Código de Reparación:

        netsvcs
        msconfig
        %SYSTEMDRIVE%\*.*
        CREATERESTOREPOINT
      • Por favor No cambies el resto de la configuración a menos que te lo solicitemos.




      • Presionar el botón >> Analizar.
      • Una vez que termine, se abrirán dos (2) archivos, OTL.Txt y Extras.Txt. Éstos archivos estarán grabados en el mismo lugar donde OTL.exe fue descargado.
      • Copiar y pegar el contenido del archivo OTL.txt en tu próxima respuesta.


      El problema de los virus es pasajero y durará un par de años / John McAfee - fundador de McAfee

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    9. #19
      Usuario Avatar de bulldog48
      Registrado
      ene 2018
      Ubicación
      España
      Mensajes
      13

      Re: Ordenador se queda bloqueado y lento

      OTL logfile created on: 23/03/2018 15:44:39 - Run 1
      OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\admin\Desktop
      64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
      Internet Explorer (Version = 9.11.9600.18952)
      Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

      1,97 Gb Total Physical Memory | 1,13 Gb Available Physical Memory | 57,21% Memory free
      3,95 Gb Paging File | 2,58 Gb Available in Paging File | 65,43% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 74,44 Gb Total Space | 22,47 Gb Free Space | 30,19% Space Free | Partition Type: NTFS
      Drive F: | 931,50 Gb Total Space | 136,82 Gb Free Space | 14,69% Space Free | Partition Type: NTFS

      Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
      Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

      ========== Processes (SafeList) ==========

      PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
      PRC - C:\Archivos de programa\AVAST Software\Avast\AvastUI.exe (AVAST Software)
      PRC - C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe (Plex, Inc.)
      PRC - C:\Archivos de programa\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
      PRC - C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe (Mediatek Inc.)
      PRC - C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\TWCU.exe ()
      PRC - C:\Program Files (x86)\Intel\AMT\UNS.exe (Intel)


      ========== Modules (No Company Name) ==========

      MOD - C:\Archivos de programa\AVAST Software\Avast\libcef.dll ()
      MOD - C:\Archivos de programa\AVAST Software\Avast\streamback.dll ()
      MOD - C:\Archivos de programa\AVAST Software\Avast\tasks_core.dll ()
      MOD - C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\TWCU.exe ()
      MOD - C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\nicLan.dll ()
      MOD - C:\Program Files (x86)\TP-LINK\Utilidad de configuración inalámbrica de TP-LINK\DC_WFF.dll ()


      ========== Services (SafeList) ==========

      SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
      SRV:64bit: - (DiagTrack) -- C:\Windows\SysNative\diagtrack.dll (Microsoft Corporation)
      SRV:64bit: - (Intel(R) -- C:\Windows\SysNative\IPROSetMonitor.exe (Intel Corporation)
      SRV - (PlexUpdateService) -- C:\Program Files (x86)\Plex\Plex Media Server\Plex Update Service.exe (Plex, Inc.)
      SRV - (avast! Antivirus) -- C:\Archivos de programa\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
      SRV - (aswbIDSAgent) -- C:\Archivos de programa\AVAST Software\Avast\x64\aswidsagenta.exe (AVAST Software)
      SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
      SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
      SRV - (HPSupportSolutionsFrameworkService) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (HP Inc.)
      SRV - (MBAMService) -- C:\Archivos de programa\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes)
      SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
      SRV - (WsAppService) -- C:\Program Files (x86)\Wondershare\WAF\2.4.3.229\WsAppService.exe (Wondershare)
      SRV - (MediatekRegistryWriter64) -- C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe (Mediatek Inc.)
      SRV - (MediatekRegistryWriter) -- C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe (Mediatek Inc.)
      SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
      SRV - (UNS) -- C:\Program Files (x86)\Intel\AMT\UNS.exe (Intel)
      SRV - (LMS) -- C:\Program Files (x86)\Intel\AMT\LMS.exe (Intel)
      SRV - (RalinkRegistryWriter64) -- C:\Program Files (x86)\Bewan\Common\RaRegistry64.exe (Ralink Technology, Corp.)
      SRV - (RalinkRegistryWriter) -- C:\Program Files (x86)\Bewan\Common\RaRegistry.exe (Ralink Technology, Corp.)


      ========== Driver Services (SafeList) ==========

      DRV:64bit: - (aswStm) -- C:\Windows\SysNative\drivers\aswStm.sys (AVAST Software)
      DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
      DRV:64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys (AVAST Software)
      DRV:64bit: - (aswArPot) -- C:\Windows\SysNative\drivers\aswArPot.sys (AVAST Software)
      DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
      DRV:64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys (AVAST Software)
      DRV:64bit: - (aswHwid) -- C:\Windows\SysNative\drivers\aswHwid.sys (AVAST Software)
      DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
      DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
      DRV:64bit: - (aswHdsKe) -- C:\Windows\SysNative\drivers\aswHdsKe.sys (AVAST Software)
      DRV:64bit: - (aswbuniv) -- C:\Windows\SysNative\drivers\aswbuniva.sys (AVAST Software)
      DRV:64bit: - (aswblog) -- C:\Windows\SysNative\drivers\aswbloga.sys (AVAST Software)
      DRV:64bit: - (aswbidsdriver) -- C:\Windows\SysNative\drivers\aswbidsdrivera.sys (AVAST Software)
      DRV:64bit: - (aswbidsh) -- C:\Windows\SysNative\drivers\aswbidsha.sys (AVAST Software)
      DRV:64bit: - (MBAMFarflt) -- C:\Windows\SysNative\drivers\farflt.sys (Malwarebytes)
      DRV:64bit: - (MBAMWebProtection) -- C:\Windows\SysNative\drivers\mwac.sys (Malwarebytes)
      DRV:64bit: - (ESProtectionDriver) -- C:\Windows\SysNative\drivers\mbae64.sys ()
      DRV:64bit: - (wdm_usb) -- C:\Windows\SysNative\drivers\usb2ser.sys (MBB)
      DRV:64bit: - (taphss6) -- C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
      DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
      DRV:64bit: - (netr28ux) -- C:\Windows\SysNative\drivers\netr28ux.sys (MediaTek Inc.)
      DRV:64bit: - (tap-tb-0901) -- C:\Windows\SysNative\drivers\tap-tb-0901.sys (The OpenVPN Project)
      DRV:64bit: - (psadd) -- C:\Windows\SysNative\drivers\psadd.sys (Lenovo (United States) Inc.)
      DRV:64bit: - (RTL8192cu) -- C:\Windows\SysNative\drivers\RTL8192cu.sys (Realtek Semiconductor Corporation )
      DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
      DRV:64bit: - (tap0901) -- C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
      DRV:64bit: - (e1express) -- C:\Windows\SysNative\drivers\e1e6232e.sys (Intel Corporation)
      DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
      DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
      DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
      DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
      DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
      DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
      DRV:64bit: - (ADIHdAudAddService) -- C:\Windows\SysNative\drivers\ADIHdAud.sys (Analog Devices, Inc.)
      DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
      DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
      DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
      DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
      DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
      DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
      DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
      DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
      DRV - (HWiNFO32) -- C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS (REALiX(tm))
      DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


      ========== Standard Registry (SafeList) ==========


      ========== Internet Explorer ==========

      IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
      IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
      IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,IE11UpgradePageShownTime = A0 51 D5 F7 AF 07 D3 01 [binary data]
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.es/
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = es
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = DE 4A 50 24 C5 B0 D3 01 [binary data]
      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Variant error.
      IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
      IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?pc=COSP&ptag=D110817-A2D586A4510&form=CONBDF&conlogo=CT3335800&q={searchTerms}
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



      [2017/02/12 14:04:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\admin\AppData\Roaming\mozilla\Extensions

      O1 HOSTS File: ([2018/03/07 00:25:34 | 000,000,855 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
      O1 - Hosts: 127.0.0.1 localhost
      O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Archivos de programa\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
      O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Archivos de programa\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
      O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - No CLSID value found.
      O4:64bit: - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvLaunch.exe (AVAST Software)
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: MaxGPOScriptWait = 600
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPath = 1
      O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
      O9:64bit: - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
      O9:64bit: - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
      O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
      O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
      O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
      O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
      O13 - gopher Prefix: missing
      O15 - HKCU\..Trusted Domains: gob.es ([agenciatributaria] https in Trusted sites)
      O15 - HKCU\..Trusted Domains: localhost ([]* in Trusted sites)
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.166.211.4 62.81.16.164
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{984CB68C-9116-4F84-967F-4EADB2509249}: DhcpNameServer = 212.166.211.4 62.81.16.164
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C049E9E2-34E2-4A3C-A0A2-CBFE4B2EA49F}: DhcpNameServer = 62.81.16.164 62.81.16.213
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C3130F86-9CC7-46F9-9375-988DBA654B6A}: DhcpNameServer = 87.216.1.65 87.216.1.66
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D3C8BC0C-C904-4C50-BC91-E009B88DA095}: DhcpNameServer = 80.58.61.250 80.58.61.254
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E11D3B52-1ECE-440F-9964-17AF6528C956}: DhcpNameServer = 212.166.211.4 62.81.16.164
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8EE3C42-7208-4215-A0B3-1038F12E8D63}: DhcpNameServer = 172.18.11.1
      O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
      O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
      O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
      O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
      O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
      O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
      O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
      O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
      O32 - HKLM CDRom: AutoRun - 1
      O34 - HKLM BootExecute: (autocheck autochk *)
      O35:64bit: - HKLM\..comfile [open] -- "%1" %*
      O35:64bit: - HKLM\..exefile [open] -- "%1" %*
      O35 - HKLM\..comfile [open] -- "%1" %*
      O35 - HKLM\..exefile [open] -- "%1" %*
      O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
      O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
      O37 - HKLM\...com [@ = comfile] -- "%1" %*
      O37 - HKLM\...exe [@ = exefile] -- "%1" %*
      O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
      O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
      O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


      MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - - File not found
      MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Utilitaire Réseau sans-fil Bewan.lnk - - File not found
      MsConfig:64bit - StartUpFolder: C:^Users^admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hpqtra08.exe - - File not found
      MsConfig:64bit - StartUpFolder: C:^Users^admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Supervisar alertas de tinta - HP ENVY 4500 series.lnk - C:\Windows\SysNative\rundll32.exe - (Microsoft Corporation)
      MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
      MsConfig:64bit - StartUpReg: CCleaner Monitoring - hkey= - key= - C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
      MsConfig:64bit - StartUpReg: GoogleDriveSync - hkey= - key= - File not found
      MsConfig:64bit - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
      MsConfig:64bit - StartUpReg: Plex Media Server - hkey= - key= - C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
      MsConfig:64bit - StartUpReg: Report - hkey= - key= - File not found
      MsConfig:64bit - StartUpReg: Skype - hkey= - key= - File not found
      MsConfig:64bit - StartUpReg: uTorrent - hkey= - key= - C:\Users\admin\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
      MsConfig:64bit - StartUpReg: Web Companion - hkey= - key= - File not found
      MsConfig:64bit - State: "startup" - Reg Error: Unable to open variant key
      MsConfig:64bit - State: "bootini" - Reg Error: Unable to open variant key
      MsConfig:64bit - State: "services" - Reg Error: Unable to open variant key

      CREATERESTOREPOINT
      Restore point Set: OTL Restore Point

      ========== Files/Folders - Created Within 30 Days ==========

      [2018/03/23 15:39:53 | 000,601,088 | ---- | C] (OldTimer Tools) -- C:\Users\admin\Desktop\OTL.exe
      [2018/03/22 20:12:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
      [2018/03/14 15:37:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Plex
      [2018/03/14 15:28:47 | 076,806,240 | ---- | C] (Plex, Inc.) -- C:\Users\admin\Documents\Plex-Media-Server-1.12.0.4829-6de959918.exe
      [2018/03/07 08:52:24 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
      [2018/03/07 08:45:12 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
      [2018/03/07 00:29:36 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\catroot2
      [2018/03/06 23:33:20 | 000,000,000 | ---D | C] -- C:\RegBackup
      [2018/03/06 23:15:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tweaking.com
      [2018/03/06 23:06:30 | 000,000,000 | ---D | C] -- C:\Users\admin\Desktop\examen valenciano
      [2018/03/04 20:53:16 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\AVAST Software
      [2018/03/04 20:50:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
      [2018/03/04 20:49:59 | 000,380,528 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys
      [2018/03/04 20:49:59 | 000,205,976 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
      [2018/03/04 20:49:58 | 000,460,520 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
      [2018/03/04 20:49:58 | 000,146,656 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
      [2018/03/04 20:49:58 | 000,084,368 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys
      [2018/03/04 20:49:57 | 000,196,648 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswArPot.sys
      [2018/03/04 20:49:57 | 000,046,968 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys
      [2018/03/04 20:49:56 | 001,026,696 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
      [2018/03/04 20:49:56 | 000,110,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
      [2018/03/04 20:49:55 | 000,343,752 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbloga.sys
      [2018/03/04 20:49:55 | 000,199,440 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbidsha.sys
      [2018/03/04 20:49:55 | 000,057,680 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbuniva.sys
      [2018/03/04 20:49:54 | 000,227,504 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbidsdrivera.sys
      [2018/03/04 20:49:54 | 000,215,320 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHdsKe.sys
      [2018/03/04 20:49:42 | 000,380,768 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
      [2018/03/04 20:49:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVAST Software
      [2018/03/04 20:47:43 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
      [2018/02/27 19:54:05 | 000,000,000 | ---D | C] -- C:\Users\admin\Desktop\COMENTARIO CRÍTICO
      [2018/02/27 12:27:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AV
      [2018/02/27 12:20:37 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
      [2018/02/27 12:14:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
      [2018/02/24 16:30:48 | 000,000,000 | ---D | C] -- C:\Users\admin\AppData\Roaming\360DrvMgr
      [2018/02/23 14:32:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Midori
      [2016/05/17 16:48:35 | 035,296,808 | ---- | C] (AEAT) -- C:\Users\admin\Renta2015_windows_1_20.exe

      ========== Files - Modified Within 30 Days ==========

      [2018/03/23 15:40:35 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\admin\Desktop\OTL.exe
      [2018/03/23 14:23:00 | 000,023,392 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      [2018/03/23 14:23:00 | 000,023,392 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      [2018/03/23 14:12:59 | 000,439,544 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
      [2018/03/23 14:12:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
      [2018/03/23 14:12:40 | 1590,398,976 | -HS- | M] () -- C:\hiberfil.sys
      [2018/03/14 15:28:51 | 076,806,240 | ---- | M] (Plex, Inc.) -- C:\Users\admin\Documents\Plex-Media-Server-1.12.0.4829-6de959918.exe
      [2018/03/14 14:59:01 | 001,596,488 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
      [2018/03/14 14:59:01 | 000,703,712 | ---- | M] () -- C:\Windows\SysNative\perfh00A.dat
      [2018/03/14 14:59:01 | 000,623,718 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
      [2018/03/14 14:59:01 | 000,142,070 | ---- | M] () -- C:\Windows\SysNative\perfc00A.dat
      [2018/03/14 14:59:01 | 000,108,546 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
      [2018/03/14 13:50:28 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
      [2018/03/07 00:25:34 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
      [2018/03/06 23:33:46 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-ADMIN-PC-Windows-7-Home-Premium-(64-bit).dat
      [2018/03/04 20:50:41 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
      [2018/03/04 20:49:34 | 000,205,976 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
      [2018/03/04 20:49:33 | 000,460,520 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
      [2018/03/04 20:49:33 | 000,380,768 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
      [2018/03/04 20:49:33 | 000,380,528 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys
      [2018/03/04 20:49:33 | 000,196,648 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswArPot.sys
      [2018/03/04 20:49:33 | 000,146,656 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
      [2018/03/04 20:49:33 | 000,084,368 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys
      [2018/03/04 20:49:33 | 000,046,968 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys
      [2018/03/04 20:49:32 | 000,110,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
      [2018/03/04 20:48:54 | 001,026,696 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
      [2018/03/04 20:48:42 | 000,215,320 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHdsKe.sys
      [2018/03/04 20:48:40 | 000,057,680 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbuniva.sys
      [2018/03/04 20:48:37 | 000,343,752 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbloga.sys
      [2018/03/04 20:48:35 | 000,227,504 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbidsdrivera.sys
      [2018/03/04 20:48:35 | 000,199,440 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswbidsha.sys
      [2018/02/27 13:26:40 | 000,000,035 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts_bak_63
      [2018/02/27 12:21:59 | 000,001,089 | ---- | M] () -- C:\Users\Public\Desktop\Navegador Opera.lnk
      [2018/02/26 18:35:14 | 000,018,134 | ---- | M] () -- C:\Users\admin\Desktop\enero.pdf
      [2018/02/26 18:34:55 | 000,017,832 | ---- | M] () -- C:\Users\admin\Desktop\feb.pdf
      [2018/02/26 18:27:53 | 000,014,511 | ---- | M] () -- C:\Users\admin\Desktop\OperacionCBTFServlet.pdf

      ========== Files Created - No Company Name ==========

      [2018/03/23 14:12:42 | 000,439,544 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
      [2018/03/06 23:33:46 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-ADMIN-PC-Windows-7-Home-Premium-(64-bit).dat
      [2018/03/04 20:50:41 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
      [2018/02/27 12:22:05 | 000,001,089 | ---- | C] () -- C:\Users\Public\Desktop\Navegador Opera.lnk
      [2018/02/27 12:22:05 | 000,001,089 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
      [2018/02/26 18:35:14 | 000,018,134 | ---- | C] () -- C:\Users\admin\Desktop\enero.pdf
      [2018/02/26 18:34:55 | 000,017,832 | ---- | C] () -- C:\Users\admin\Desktop\feb.pdf
      [2017/08/29 18:55:32 | 000,000,232 | ---- | C] () -- C:\Windows\SysWow64\dllhost.exe.config
      [2017/08/08 18:44:10 | 000,518,144 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
      [2017/04/30 22:34:47 | 000,000,132 | ---- | C] () -- C:\Windows\setihome.ini
      [2016/06/29 13:55:33 | 000,007,633 | ---- | C] () -- C:\Users\admin\AppData\Local\Resmon.ResmonCfg
      [2016/06/27 02:11:54 | 000,000,408 | ---- | C] () -- C:\Users\admin\AppData\Roaming\CamShapes.ini
      [2016/06/27 02:11:54 | 000,000,408 | ---- | C] () -- C:\Users\admin\AppData\Roaming\CamLayout.ini
      [2016/06/27 02:11:54 | 000,000,046 | ---- | C] () -- C:\Users\admin\AppData\Roaming\Camdata.ini
      [2016/06/27 02:03:57 | 000,004,536 | ---- | C] () -- C:\Users\admin\AppData\Roaming\CamStudio.cfg
      [2016/06/27 01:41:15 | 000,000,096 | ---- | C] () -- C:\Users\admin\AppData\Roaming\version2.xml
      [2016/06/13 01:15:25 | 000,144,840 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
      [2016/03/03 14:23:22 | 000,000,600 | ---- | C] () -- C:\Users\admin\PUTTY.RND
      [2015/10/30 20:42:04 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
      [2015/08/01 03:14:31 | 000,000,008 | RHS- | C] () -- C:\ProgramData\ntuser.pol
      [2015/04/12 17:53:44 | 000,003,584 | ---- | C] () -- C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

      ========== ZeroAccess Check ==========

      [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

      [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

      [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

      [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
      "" = C:\Windows\SysNative\shell32.dll -- [2018/01/01 03:18:30 | 014,183,936 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment

      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
      "" = %SystemRoot%\system32\shell32.dll -- [2018/01/01 03:00:12 | 012,880,384 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Apartment

      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free

      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
      "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 03:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Free

      [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
      "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
      "ThreadingModel" = Both

      [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

      ========== LOP Check ==========

      [2016/07/11 14:05:27 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\.Tribler
      [2018/02/27 10:53:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\360DrvMgr
      [2016/09/14 00:52:47 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Apowersoft
      [2018/03/04 20:53:16 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVAST Software
      [2016/05/21 19:46:38 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Binary data
      [2016/02/14 1731 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\calibre
      [2016/04/08 01:23:57 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Camfrog
      [2018/02/14 21:16:23 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\DiskDefrag
      [2016/03/03 14:18:58 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\FreeHideIP
      [2018/02/14 22:06:51 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\GlarySoft
      [2015/10/19 19:12:53 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Hard Disk Sentinel
      [2016/07/04 13:43:37 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\IObit
      [2016/01/10 1459 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\LibreOffice
      [2018/03/04 20:42:52 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\MPC-HC
      [2016/07/05 01:04:23 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Opera Software
      [2018/02/23 1416 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Panda Security
      [2017/07/07 12:14:31 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SecureData
      [2016/08/18 18:28:00 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\SMRecorder
      [2018/02/15 19:36:56 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TP-LINK
      [2014/04/10 18:47:46 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TuneUp Software
      [2016/06/27 02:07:59 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\TunnelBear
      [2018/03/23 15:33:20 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\uTorrent
      [2016/02/14 1727 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Valassis
      [2016/02/14 1727 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Visan
      [2016/02/17 18:47:08 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\webex
      [2017/08/29 19:02:25 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Wondershare
      [2017/07/30 22:51:21 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Yandex
      [2018/02/13 13:59:40 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\ZHP

      ========== Purity Check ==========



      ========== Custom Scans ==========

      < %SYSTEMDRIVE%\*.* >
      [2016/02/14 18:16:39 | 000,020,224 | ---- | M] () -- C:\bootsqm.dat
      [2018/02/27 17:31:37 | 000,000,729 | ---- | M] () -- C:\DelFix.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
      [2007/11/07 07:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
      [2007/11/07 07:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
      [2007/11/07 07:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
      [2007/11/07 07:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
      [2018/03/23 14:12:40 | 1590,398,976 | -HS- | M] () -- C:\hiberfil.sys
      [2007/11/07 07:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
      [2007/11/07 07:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
      [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
      [2007/11/07 07:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
      [2007/11/07 07:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
      [2007/11/07 07:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
      [2007/11/07 07:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
      [2007/11/07 07:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
      [2007/11/07 07:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
      [2007/11/07 07:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
      [2018/03/23 14:12:41 | 2120,531,968 | -HS- | M] () -- C:\pagefile.sys
      [2009/10/06 11:57:48 | 000,000,096 | ---- | M] () -- C:\Program1
      [2007/11/07 07:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
      [2007/11/07 07:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
      [2007/11/07 07:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI

      < End of report >

    10. #20
      Usuario Avatar de bulldog48
      Registrado
      ene 2018
      Ubicación
      España
      Mensajes
      13

      Re: Ordenador se queda bloqueado y lento

      OTL Extras logfile created on: 23/03/2018 15:44:39 - Run 1
      OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\admin\Desktop
      64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
      Internet Explorer (Version = 9.11.9600.18952)
      Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

      1,97 Gb Total Physical Memory | 1,13 Gb Available Physical Memory | 57,21% Memory free
      3,95 Gb Paging File | 2,58 Gb Available in Paging File | 65,43% Paging File free
      Paging file location(s): ?:\pagefile.sys [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
      Drive C: | 74,44 Gb Total Space | 22,47 Gb Free Space | 30,19% Space Free | Partition Type: NTFS
      Drive F: | 931,50 Gb Total Space | 136,82 Gb Free Space | 14,69% Space Free | Partition Type: NTFS

      Computer Name: ADMIN-PC | User Name: admin | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
      Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

      ========== Extra Registry (SafeList) ==========


      ========== File Associations ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
      .html[@ = ProgID] -- Reg Error: Unable to open value key File not found
      .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
      .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
      .html [@ = ProgID] -- Reg Error: Unable to open value key File not found

      [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
      .html [@ = ProgID] -- Reg Error: Unable to open value key File not found

      ========== Shell Spawning ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
      batfile [open] -- "%1" %*
      cmdfile [open] -- "%1" %*
      comfile [open] -- "%1" %*
      exefile [open] -- "%1" %*
      helpfile [open] -- Reg Error: Unable to open value key
      htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
      htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
      htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
      http [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software)
      https [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software)
      inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
      InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
      InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
      piffile [open] -- "%1" %*
      regfile [merge] -- Reg Error: Unable to open value key
      scrfile [config] -- "%1"
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- "%1" /S
      txtfile [edit] -- Reg Error: Unable to open value key
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
      Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
      Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
      Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [explore] -- Reg Error: Value error.
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
      CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
      batfile [open] -- "%1" %*
      cmdfile [open] -- "%1" %*
      comfile [open] -- "%1" %*
      cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
      exefile [open] -- "%1" %*
      helpfile [open] -- Reg Error: Unable to open value key
      htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
      htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
      http [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software)
      https [open] -- "C:\Program Files\Opera\launcher.exe" -noautoupdate -- "%1" (Opera Software)
      inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
      piffile [open] -- "%1" %*
      regfile [merge] -- Reg Error: Unable to open value key
      scrfile [config] -- "%1"
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- "%1" /S
      txtfile [edit] -- Reg Error: Unable to open value key
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
      Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
      Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
      Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Folder [explore] -- Reg Error: Value error.
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
      CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

      ========== Security Center Settings ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      "cval" = 1
      "UpdatesDisableNotify" = 0

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
      "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
      "AntiVirusOverride" = 0
      "AntiSpywareOverride" = 0
      "FirewallOverride" = 0

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

      ========== System Restore Settings ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
      "DisableSR" = 0

      ========== Firewall Settings ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 0

      ========== Authorized Applications List ==========

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


      ========== Vista Active Open Ports Exception List ==========

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      "{12B47533-567D-4349-90AD-B69DFCBBA832}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
      "{2E586839-BB60-4E67-9A10-44D655899C55}" = rport=55185 | protocol=17 | dir=out | name=emule |
      "{369F5E8A-B5BD-40FB-BCAC-5F7893602A80}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\opera\51.0.2830.40\opera.exe |
      "{54CC2B9C-0499-44F2-BE62-3BA8B78DDBCE}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\opera\51.0.2830.55\opera.exe |
      "{55B2AF6D-72AF-43AB-B0BE-880909338B6B}" = rport=137 | protocol=17 | dir=out | app=system |
      "{643176DC-603F-4B7E-A630-A18A48540DB4}" = rport=138 | protocol=17 | dir=out | app=system |
      "{69F08780-F623-45B6-85DD-7A989E659350}" = lport=139 | protocol=6 | dir=in | app=system |
      "{86FDFA38-9C04-4EBF-9952-C99346669F86}" = lport=137 | protocol=17 | dir=in | app=system |
      "{9B42B8B3-3451-4172-B5E7-75F663E0CE2C}" = rport=445 | protocol=6 | dir=out | app=system |
      "{B99ADA06-7F1B-45E0-97CF-111F9757A78F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
      "{C14BEE3B-C8E9-45EC-9F08-68E5F8F89030}" = lport=138 | protocol=17 | dir=in | app=system |
      "{CC546E63-6677-4B07-8BCE-F282EF0EBB27}" = rport=139 | protocol=6 | dir=out | app=system |
      "{D35FCAD1-99C5-4214-8E47-A2D7ACB638EB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
      "{D7086E5D-A4F9-471F-8F69-C34028F167A4}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
      "{EA566BAC-0E57-49F8-93B8-A7BD17795957}" = lport=445 | protocol=6 | dir=in | app=system |
      "{F038A668-D24A-4B06-A6F6-F51EAB79645F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
      "{F59FC3F5-4A91-4C1E-943B-AAC4B58496DE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

      ========== Vista Active Application Exception List ==========

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      "{01B506DD-40C1-4104-A280-1287672C3C43}" = protocol=58 | dir=out | [email protected],-28546 |
      "{5AFE954C-07A6-4140-9598-E91B2891C7BB}" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
      "{5F25039F-178D-4578-B103-FE311FC15104}" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
      "{68803245-847F-4EB2-A6D2-F28351006BF6}" = protocol=17 | dir=out | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
      "{7143A53E-412D-4065-8CBE-7A34B4BD6629}" = dir=in | app=c:\program files (x86)\plex\plex media server\plexscripthost.exe |
      "{7B0A27DF-E0F5-40FB-9BBE-C7456842FE0E}" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
      "{7B41ECE6-AC1D-484D-8FE1-A8A95A190BF0}" = protocol=1 | dir=out | [email protected],-28544 |
      "{96F5F7A3-C900-4D23-8319-9D597B0BC8CE}" = protocol=58 | dir=in | [email protected],-28545 |
      "{9E836BA0-1786-4F0A-92D8-AD5A37828A22}" = dir=in | app=c:\program files (x86)\plex\plex media server\plex tuner service.exe |
      "{AEDB6117-5FC1-43C4-8DE9-F98CFA860C95}" = protocol=6 | dir=out | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
      "{C586FC6B-3207-4718-92C7-2644016EE874}" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\utorrent\utorrent.exe |
      "{D5241196-316C-4EB7-9B3B-2F502AC5715C}" = protocol=1 | dir=in | [email protected],-28543 |
      "{F2919328-27DC-45D4-9AC7-CC3C3AAACF17}" = dir=in | app=c:\program files (x86)\plex\plex media server\plex dlna server.exe |
      "TCP Query User{24B8F90B-F500-4C3B-935C-B9BAF36B300D}F:\plex\plex media server\plex media server.exe" = protocol=6 | dir=in | app=f:\plex\plex media server\plex media server.exe |
      "TCP Query User{3F87C3EA-2CF7-4B62-8876-7A4257050D49}F:\emule2\emule\emule.exe" = protocol=6 | dir=in | app=f:\emule2\emule\emule.exe |
      "TCP Query User{410375E7-284E-4B98-A21F-31F8D7F590C1}F:\plex\plex media server\plex dlna server.exe" = protocol=6 | dir=in | app=f:\plex\plex media server\plex dlna server.exe |
      "TCP Query User{427F2D8E-CA48-4274-BD04-77781CB1E29F}C:\program files (x86)\plex\plex media server\plex media server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\plex\plex media server\plex media server.exe |
      "TCP Query User{6302353A-1AE5-4837-BBFF-62F489AF6E5F}C:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe |
      "TCP Query User{BA45E012-82E3-431E-9D97-44A10AEABB8F}C:\program files (x86)\plex\plex media server\plex media server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\plex\plex media server\plex media server.exe |
      "UDP Query User{3738E4CA-5E96-4C1C-B0D9-38865DC4985D}F:\plex\plex media server\plex dlna server.exe" = protocol=17 | dir=in | app=f:\plex\plex media server\plex dlna server.exe |
      "UDP Query User{6CE746BD-8859-430B-AAC4-1DFA144437ED}C:\program files (x86)\plex\plex media server\plex media server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\plex\plex media server\plex media server.exe |
      "UDP Query User{783E3630-5CCC-44AD-B02F-EEF7F42E7932}C:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp envy 4500 series\bin\hpnetworkcommunicatorcom.exe |
      "UDP Query User{9BBB58C3-70DF-410E-8DF6-06288AB5C2D5}F:\emule2\emule\emule.exe" = protocol=17 | dir=in | app=f:\emule2\emule\emule.exe |

      ========== HKEY_LOCAL_MACHINE Uninstall List ==========

      64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
      "{26A24AE4-039D-4CA4-87B4-2F64180144F0}" = Java 8 Update 144 (64-bit)
      "{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes versión 3.3.1.2183
      "{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
      "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
      "{50A2BC33-C9CD-3BF1-A8FF-53C10A0B183C}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24215
      "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
      "{64A3A4F4-B792-11D6-A78A-00B0D0180131}" = Java SE Development Kit 8 Update 131 (64-bit)
      "{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
      "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
      "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
      "{90120000-002A-0C0A-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Spanish) 2007
      "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.7.1
      "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082" = Microsoft .NET Framework 4.7.1 (español)
      "{AC5CA97A-BFC2-3787-A9FA-300C3ABA608B}" = Microsoft .NET Framework 4.7.1 (ESN)
      "{CE47BA54-78AC-409F-9151-BDF5BE15A804}" = Network64
      "{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
      "{D8A3D01E-BCBB-491B-856F-61E3B8563E32}" = Intel(R) Network Connections 19.5.300.2
      "{E0C7523C-686B-3EE6-8FB1-CB4339E30EDD}" = Microsoft .NET Framework 4.7.1
      "{EF1EC6A9-17DE-3DA9-B040-686A1E8A8B04}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24215
      "{F1F56388-1766-41E4-BFBE-F23671D56574}" = HP ENVY 4500 series Software básico del dispositivo
      "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
      "CCleaner" = CCleaner
      "HDMI" = Intel(R) Graphics Media Accelerator Driver
      "HECI" = Intel(R) Management Engine Interface
      "MESOL" = Tecnología de gestión activa Intel®
      "PROSetDX" = Intel(R) Network Connections 19.5.300.2
      "WinRAR archiver" = WinRAR 5.11 (64-bit)

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
      "{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
      "{083DCC02-5EB2-48B0-8BFF-F2D367F5AFB7}" = HP ENVY 4500 series Ayuda
      "{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
      "{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
      "{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
      "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
      "{21925AE1-929D-4222-B38B-80BC30BBE09C}" = HP Support Solutions Framework
      "{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}" = Mediatek RT2870 Wireless LAN Card
      "{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
      "{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
      "{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
      "{319D91C6-3D44-436C-9F79-36C0D22372DC}" = Utilidad de configuración inalámbrica de TP-LINK
      "{35184AD1-A3C9-4B38-A1F3-3D9C48EFAAEC}" = TunnelBear
      "{366AF62D-D58F-4F59-B409-5DB072FE3028}" = Stopping Plex
      "{42BBA4CC-EFB6-4653-A2CC-F305D4B399C3}" = PS_AIO_07_D110_SW_Min
      "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
      "{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
      "{5546F4E9-B0F4-4F54-B949-2AB006C9284F}" = DJ_AIO_06_F2400_SW_Min
      "{55C4B9E9-39C8-4BD6-9BCF-41BE40393A5F}" = D110
      "{565E7B0E-B76B-4EAD-9753-F1E72A5CF12E}" = HPAppStudio
      "{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
      "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
      "{650c9b4a-60ec-4e4e-8d8e-32d85ce3b7c5}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
      "{69BCE4AC-9572-3271-A2FB-9423BDA36A43}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215
      "{6DBB66CD-38C7-472C-BBB9-06BFDA182A29}" = F2400
      "{852E893E-E4FD-45BB-8B17-72ADDF686974}" = TP-LINK TL-WN821N(C)_TL-WN822N_TL-WN823N Controlador
      "{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
      "{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
      "{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
      "{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-0015-0C0A-0000-0000000FF1CE}" = Microsoft Office Access MUI (Spanish) 2007
      "{90120000-0015-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007
      "{90120000-0016-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007
      "{90120000-0018-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-0019-0C0A-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Spanish) 2007
      "{90120000-0019-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Spanish) 2007
      "{90120000-001A-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007
      "{90120000-001B-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
      "{90120000-001F-0403-0000-0000000FF1CE}_PROPLUS_{BEADB115-DB47-4BD0-A9EC-AE585AFAB2D8}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
      "{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
      "{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
      "{90120000-001F-0416-0000-0000000FF1CE}_PROPLUS_{8A524694-0CA4-476A-9301-B1E9D70FC952}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
      "{90120000-001F-042D-0000-0000000FF1CE}_PROPLUS_{017A6981-5E03-4A97-830A-35FE0927BB7F}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
      "{90120000-001F-0456-0000-0000000FF1CE}_PROPLUS_{A3A03B41-14EA-4E50-97D8-FCF429AE0CCB}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
      "{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-002A-0C0A-1000-0000000FF1CE}_PROPLUS_{430AE3E6-E982-4958-90FC-1C062BC74E22}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007
      "{90120000-0044-0C0A-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Spanish) 2007
      "{90120000-0044-0C0A-0000-0000000FF1CE}_PROPLUS_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007
      "{90120000-006E-0C0A-0000-0000000FF1CE}_PROPLUS_{430AE3E6-E982-4958-90FC-1C062BC74E22}" = 2007 Microsoft Office Suite Service Pack 3 (SP3)
      "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
      "{912D30CF-F39E-4B31-AD9A-123C6B794EE2}" = HP Update
      "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
      "{9BE466FF-70B7-4DA8-807C-DB4C3610FDAA}" = Copy
      "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
      "{AC35A885-0F8F-4857-B7DA-6E8DFB43E6B3}" = HPSSupply
      "{AC76BA86-0804-1033-1959-001824265200}" = Adobe Refresh Manager
      "{AC76BA86-7AD7-1034-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Español
      "{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
      "{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}" = HPDiagnosticAlert
      "{b75df829-7b5f-4ff5-8fa7-97f261f23960}" = Plex Media Server
      "{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
      "{BBC1706D-098F-4839-ABC1-30D8CBE344DC}" = Plex Media Server
      "{BBF2AC74-720C-3CB3-8291-5E34039232FA}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215
      "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
      "{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
      "{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
      "{C9EF1AAF-B542-41C8-A537-1142DA5D4AEC}" = HP Customer Experience Enhancements
      "{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
      "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
      "{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
      "{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
      "{d992c12e-cab2-426f-bde3-fb8c53950b0d}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
      "{DA7B3D24-A6C2-4D3D-86B1-040C9AF5F7A3}" = Secure [email protected]
      "{e2803110-78b3-4664-a479-3611a381656a}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
      "{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
      "{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
      "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
      "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
      "{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
      "{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
      "{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
      "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
      "Adobe Flash Player ActiveX" = Adobe Flash Player 28 ActiveX
      "Adobe Flash Player PPAPI" = Adobe Flash Player 28 PPAPI
      "Avast Antivirus" = Avast Free Antivirus
      "ESET Online Scanner" = ESET Online Scanner v3
      "Opera 51.0.2830.55" = Opera Stable 51.0.2830.55
      "PROPLUS" = Microsoft Office Professional Plus 2007
      "RXO 2019_is1" = RXO 2019
      "VLC media player" = VLC media player

      ========== HKEY_CURRENT_USER Uninstall List ==========

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{20BF67A8-D81A-4489-8225-FABAA0896E2D}_is1" = Apowersoft Online Launcher versión 1.4.4
      "uTorrent" = µTorrent

      ========== Last 20 Event Log Errors ==========

      [ Application Events ]
      Error - 22/03/2018 14:18:02 | Computer Name = admin-PC | Source = Windows Search Service | ID = 3006
      Description =

      Error - 22/03/2018 14:18:02 | Computer Name = admin-PC | Source = Windows Search Service | ID = 3007
      Description =

      Error - 22/03/2018 14:18:13 | Computer Name = admin-PC | Source = Windows Search Service | ID = 10021
      Description =

      Error - 23/03/2018 9:13:08 | Computer Name = admin-PC | Source = Microsoft-Windows-EapHost | ID = 2002
      Description = Omitiendo: error de validación de Eap method DLL path name. Error:
      typeId=25, authorId=9, vendorId=0, vendorType=0

      Error - 23/03/2018 9:13:08 | Computer Name = admin-PC | Source = Microsoft-Windows-EapHost | ID = 2002
      Description = Omitiendo: error de validación de Eap method DLL path name. Error:
      typeId=43, authorId=9, vendorId=0, vendorType=0

      Error - 23/03/2018 9:13:26 | Computer Name = admin-PC | Source = RalinkRegistryWriter | ID = 0
      Description =

      Error - 23/03/2018 9:14:12 | Computer Name = admin-PC | Source = Windows Search Service | ID = 3006
      Description =

      Error - 23/03/2018 9:14:12 | Computer Name = admin-PC | Source = Windows Search Service | ID = 3007
      Description =

      Error - 23/03/2018 9:14:46 | Computer Name = admin-PC | Source = Windows Search Service | ID = 10021
      Description =

      Error - 23/03/2018 10:43:50 | Computer Name = admin-PC | Source = Application Hang | ID = 1002
      Description = El programa OTL.exe, versión 3.2.70.2, dejó de interactuar con Windows
      y se cerró. Para ver si hay más información disponible acerca del problema, compruebe
      el historial de problemas en el panel de control Centro de actividades. Identificador
      de proceso: 958 Hora de inicio: 01d3c2b4f0ccc7a4 Hora de finalización: 0 Ruta de acceso
      de la aplicación: C:\Users\admin\Desktop\OTL.exe Identificador de informe: 6bc380fc-2ea8-11e8-aeb1-001a6b49bf24


      [ COMODO Internet Security Events ]
      Error - 17/11/2014 11:59:23 | Computer Name = admin-PC | Source = CisTray | ID = 1
      Description =

      [ OSession Events ]
      Error - 04/11/2015 13:29:03 | Computer Name = admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
      12.0.6712.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2505
      seconds with 300 seconds of active time. This session ended with a crash.

      [ System Events ]
      Error - 21/03/2018 9:42:59 | Computer Name = admin-PC | Source = WMPNetworkSvc | ID = 866300
      Description =

      Error - 21/03/2018 10:20:39 | Computer Name = admin-PC | Source = Schannel | ID = 36887
      Description = Se recibió la siguiente alerta irrecuperable: 20.

      Error - 22/03/2018 13:06:30 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7023
      Description = El servicio Ralink Registry Writer se cerró con el siguiente error:
      %%231

      Error - 22/03/2018 13:07:14 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7034
      Description = El servicio Ralink Registry Writer 64 se terminó de manera inesperada.
      Esto ha sucedido 1 veces.

      Error - 22/03/2018 14:17:47 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7023
      Description = El servicio Ralink Registry Writer se cerró con el siguiente error:
      %%231

      Error - 22/03/2018 14:18:15 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7034
      Description = El servicio Ralink Registry Writer 64 se terminó de manera inesperada.
      Esto ha sucedido 1 veces.

      Error - 22/03/2018 15:26:04 | Computer Name = admin-PC | Source = Schannel | ID = 36887
      Description = Se recibió la siguiente alerta irrecuperable: 20.

      Error - 23/03/2018 9:13:26 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7023
      Description = El servicio Ralink Registry Writer se cerró con el siguiente error:
      %%231

      Error - 23/03/2018 9:14:06 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7009
      Description = Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio
      Wondershare Application Framework Service.

      Error - 23/03/2018 9:15:09 | Computer Name = admin-PC | Source = Service Control Manager | ID = 7034
      Description = El servicio Ralink Registry Writer 64 se terminó de manera inesperada.
      Esto ha sucedido 1 veces.


      < End of report >