Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-10-2019 02 Ran by [removed] (15-10-2019 02:38:08) Running from C:\Users\[removed]\Downloads Windows 10 Pro Version 1903 18362.356 (X64) (2019-07-12 18:35:49) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-2937623597-1657547211-2391554280-500 - Administrator - Disabled) Bernardo (S-1-5-21-2937623597-1657547211-2391554280-1001 - Administrator - Enabled) => C:\Users\Bernardo DefaultAccount (S-1-5-21-2937623597-1657547211-2391554280-503 - Limited - Disabled) Invitado (S-1-5-21-2937623597-1657547211-2391554280-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-2937623597-1657547211-2391554280-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {EA21BCE8-A461-99C3-3A0D-4C964E75494E} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Antivirus Free Antimalware (Enabled - Up to date) {51405D0C-825B-964D-00BD-77E435F203F3} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 19.012.20040 - Adobe Systems Incorporated) Adobe After Effects 2019 (HKLM-x32\...\AEFT_16_1_2) (Version: 16.1.2 - Adobe Systems Incorporated) Adobe Bridge 2019 (HKLM-x32\...\KBRG_9_1) (Version: 9.1 - Adobe Systems Incorporated) Adobe Character Animator 2019 (HKLM-x32\...\CHAR_2_1) (Version: 2.1 - Adobe Systems Incorporated) Adobe Character Animator CC 2018 (HKLM-x32\...\CHAR_1_5) (Version: 1.5.0 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.9.0.504 - Adobe Systems Incorporated) Adobe Dimension (HKLM-x32\...\ESHR_2_2) (Version: 2.2 - Adobe Systems Incorporated) Adobe Illustrator 2019 (HKLM-x32\...\ILST_23_0_6) (Version: 23.0.6 - Adobe Systems Incorporated) Adobe Illustrator CC 2018 (HKLM-x32\...\ILST_22_1) (Version: 22.1 - Adobe Systems Incorporated) Adobe Media Encoder 2019 (HKLM-x32\...\AME_13_1) (Version: 13.1 - Adobe Systems Incorporated) Adobe Photoshop CC 2019 (HKLM-x32\...\PHSP_20_0_6) (Version: 20.0.6 - Adobe Systems Incorporated) Adobe Premiere Pro 2019 (HKLM-x32\...\PPRO_13_1_4) (Version: 13.1.4 - Adobe Systems Incorporated) Adobe Premiere Rush (HKLM-x32\...\RUSH_1_2) (Version: 1.2 - Adobe Systems Incorporated) ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.8.0 - ASUS) Bitdefender Agent (HKLM\...\Bitdefender Agent) (Version: 1.0.1 - Bitdefender) Bitdefender Antivirus Free (HKLM\...\{1FCCF41D-5F00-4FE2-9653-162D0486C8B4}) (Version: 1.0.13.56 - Bitdefender) Chrome Remote Desktop Host (HKLM-x32\...\{507238FB-1F1F-4E97-8478-29951A0F7DDD}) (Version: 78.0.3904.7 - Google Inc.) Cisco Webex Meetings (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\ActiveTouchMeetingClient) (Version: - Cisco Webex LLC) ClickOnce Bootstrapper Package for Microsoft .NET Framework (HKLM-x32\...\{D256A5B9-68DA-4F6C-A447-A93E5639A46D}) (Version: 4.7.03083 - Microsoft Corporation) Hidden CrystalDiskMark 6.0.1 (HKLM\...\CrystalDiskMark6_is1) (Version: 6.0.1 - Crystal Dew World) DiagnosticsHub_CollectionService (HKLM\...\{6840890C-56A9-4C6B-AF9D-78787B5265D8}) (Version: 16.0.28621 - Microsoft Corporation) Hidden Dictate (HKLM-x32\...\{8475267E-D7DF-4A6D-A126-2C6B519E6F74}) (Version: 5.00.0000 - Microsoft) Driver Booster 6 (HKLM-x32\...\Driver Booster_is1) (Version: 6.5.0 - IObit) Dropbox (HKLM-x32\...\Dropbox) (Version: 82.4.155 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.241.1 - Dropbox, Inc.) Hidden EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS) Entity Framework 6.2.0 Tools for Visual Studio 2017 (HKLM-x32\...\{B843915F-00A1-44B1-994C-1AE0A6400AE3}) (Version: 6.2.61807.0 - Microsoft Corporation) Hidden File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version: - Pow Tools) FlashBack Express 5 (HKLM-x32\...\FlashBack Express 5) (Version: 5.35.0.4408 - Blueberry Software (UK) Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.120 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden GoTo Opener (HKLM-x32\...\{665DF231-32BE-46BA-ABD2-B0D69F8314FF}) (Version: 1.0.494 - LogMeIn, Inc.) GoToMeeting 10.0.1.14649 (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\GoToMeeting) (Version: 10.0.1.14649 - LogMeIn, Inc.) icecap_collection_neutral (HKLM-x32\...\{6764C62A-6131-4B7A-BA82-0DA658B86718}) (Version: 16.0.28622 - Microsoft Corporation) Hidden icecap_collection_x64 (HKLM\...\{416506DB-700F-418D-9604-45A261FB14BB}) (Version: 16.0.28622 - Microsoft Corporation) Hidden icecap_collectionresources (HKLM-x32\...\{11CB8137-33FB-4DBD-A072-4B9F764438B5}) (Version: 16.0.28622 - Microsoft Corporation) Hidden icecap_collectionresourcesx64 (HKLM-x32\...\{CC9D7D71-19B8-4346-9B2B-B9D0D8DFCFD4}) (Version: 16.0.28622 - Microsoft Corporation) Hidden Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 25.20.100.6373 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.7.0.1014 - Intel Corporation) IntelliTraceProfilerProxy (HKLM-x32\...\{7D94CF67-6666-4111-B027-D7AB7F189F70}) (Version: 15.0.18198.01 - Microsoft Corporation) Hidden JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) Mailspring (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\Mailspring) (Version: 1.4.2 - Foundry 376, LLC) Mendeley Desktop 1.19.3 (HKLM-x32\...\Mendeley Desktop) (Version: 1.19.3 - Mendeley Ltd.) Microsoft .NET Core SDK 2.1.602 (x64) (HKLM-x32\...\{ce5d125b-e426-441b-a83f-d6ef6825aa77}) (Version: 2.1.602 - Microsoft Corporation) Microsoft Edge Dev (HKLM-x32\...\Microsoft Edge Dev) (Version: 79.0.287.3 - Microsoft Corporation) Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.111.43 - ) Microsoft Office 365 ProPlus - es-es (HKLM\...\O365ProPlusRetail - es-es) (Version: 16.0.11328.20420 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\OneDriveSetup.exe) (Version: 19.152.0801.0009 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2019 CTP2.2 (HKLM\...\{8D7CE3B0-5379-46FE-9F4B-A65D9F4CC1F1}) (Version: 15.0.1200.24 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2019 CTP2.2 (HKLM-x32\...\{725CC962-98BD-42C7-87D8-51C680FB1779}) (Version: 15.0.1200.24 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.15.26706 (HKLM-x32\...\{95ac1cfa-f4fb-4d1b-8912-7f9d5fbb140d}) (Version: 14.15.26706.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (HKLM-x32\...\{7e9fae12-5bbf-47fb-b944-09c49e75c061}) (Version: 14.15.26706.0 - Microsoft Corporation) Microsoft Visual Studio Installer (HKLM\...\{6F320B93-EE3C-4826-85E0-ADF79F8D4C61}) (Version: 2.0.3287.312 - Microsoft Corporation) Mozilla Firefox 69.0.2 (x64 es-MX) (HKLM\...\Mozilla Firefox 69.0.2 (x64 es-MX)) (Version: 69.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.5.3 - Mozilla) Mozilla Thunderbird 60.5.3 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 60.5.3 (x86 en-US)) (Version: 60.5.3 - Mozilla) Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.11328.20420 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.11328.20420 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0C0A-1000-0000000FF1CE}) (Version: 16.0.11328.20420 - Microsoft Corporation) Hidden Opera Stable 63.0.3368.94 (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\Opera 63.0.3368.94) (Version: 63.0.3368.94 - Opera Software) PDFsam Basic (HKLM\...\{1304BB7D-3790-4FA3-AF8B-76499669F543}) (Version: 4.0.1.0 - Sober Lemur S.a.s. di Vacondio Andrea) Popcorn Time (HKLM-x32\...\Popcorn Time_is1) (Version: 6.1.0.0 - Popcorn Time) <==== ATTENTION Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.21299 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8555 - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform) ShareX (HKLM\...\82E6AC09-0FEF-4390-AD9F-0DD3F5561EFC_is1) (Version: 12.4.1 - ShareX Team) Slack (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\slack) (Version: 4.0.2 - Slack Technologies) TeamViewer 14 (HKLM-x32\...\TeamViewer) (Version: 14.5.5819 - TeamViewer) Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) vcpp_crt.redist.clickonce (HKLM-x32\...\{0A254C80-7D04-4B03-B44B-E179D713D2B9}) (Version: 14.20.27508 - Microsoft Corporation) Hidden Visual Studio Community 2019 (HKLM-x32\...\aef8f93b) (Version: 16.0.28729.10 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.6 - VideoLAN) VS Immersive Activate Helper (HKLM-x32\...\{54FBC9A9-CCA1-417E-ACA6-203A32A39F37}) (Version: 16.0.95.0 - Microsoft Corporation) Hidden VS JIT Debugger (HKLM\...\{4B816AD0-D12B-498A-8148-7CBE3ED328DE}) (Version: 16.0.95.0 - Microsoft Corporation) Hidden vs_BlendMsi (HKLM-x32\...\{B5E3A3E1-1529-4D5A-9E95-34971FA07825}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_clickoncebootstrappermsi (HKLM-x32\...\{BAF91847-0A64-405E-98EC-A0BA6FB4BC4E}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_clickoncebootstrappermsires (HKLM-x32\...\{271F1F42-B547-4498-825F-590DBB1774F7}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_clickoncesigntoolmsi (HKLM-x32\...\{30D97A69-3C0F-4552-9A72-60E591B210C7}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_communitymsi (HKLM-x32\...\{9F0E32BE-3119-4871-AD86-383A021B0124}) (Version: 16.0.28711 - Microsoft Corporation) Hidden vs_communitymsires (HKLM-x32\...\{95E79BBC-97FD-4FEB-91B5-CC0231324812}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_devenvmsi (HKLM-x32\...\{AD0C92A4-1514-4BC1-A723-A272A8343924}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_filehandler_amd64 (HKLM-x32\...\{37D994EA-A13D-48B0-9948-062E0C350270}) (Version: 16.0.28707 - Microsoft Corporation) Hidden vs_filehandler_x86 (HKLM-x32\...\{FFE3CC65-76D3-4D54-A22E-6BDF4C21CB6E}) (Version: 16.0.28707 - Microsoft Corporation) Hidden vs_FileTracker_Singleton (HKLM-x32\...\{F08DA172-0777-40C6-A8BA-D0F314560BEE}) (Version: 16.0.28518 - Microsoft Corporation) Hidden vs_minshellinteropmsi (HKLM-x32\...\{57F29F55-7B37-45AF-B554-45D8C1A1FD03}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_minshellmsi (HKLM-x32\...\{2DB4A4FB-3DDD-4924-AF39-3FC5EDEC335A}) (Version: 16.0.28711 - Microsoft Corporation) Hidden vs_minshellmsires (HKLM-x32\...\{EC04CD66-C03A-470D-B0D2-4BBC87F6382D}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_SQLClickOnceBootstrappermsi (HKLM-x32\...\{92B3118C-3214-4BFA-89A0-5FF5EDFA2AEA}) (Version: 16.0.28329 - Microsoft Corporation) Hidden vs_tipsmsi (HKLM-x32\...\{E208E682-50EE-4F2F-9860-C91B906B8A03}) (Version: 16.0.28329 - Microsoft Corporation) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden WebM for Premiere (HKLM\...\{7BCAE84F-ACE9-4089-87BB-75B914551743}) (Version: 1.0.0 - fnord software) WhatsApp (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\WhatsApp) (Version: 0.3.4941 - WhatsApp) WinRAR 5.61 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.0 - win.rar GmbH) Xamarin Offline Packages (HKLM-x32\...\{70245D14-3A69-4210-8C4E-ADB75293615A}) (Version: 16.1.43 - Xamarin) Hidden Xamarin PCL Profiles v1.0.9 (HKLM-x32\...\{5E6844AB-A867-419C-A376-B12B574AA5F7}) (Version: 1.0.9.0 - Xamarin) Hidden Xamarin Remoted iOS Simulator (HKLM-x32\...\{61E16C26-66ED-436E-9E05-50A74E57D693}) (Version: 1.3.0.18 - Xamarin) Hidden Zoom (HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\ZoomUMX) (Version: 4.4 - Zoom Video Communications, Inc.) Packages: ========= Acrobat Notification Client -> C:\Program Files\WindowsApps\AcrobatNotificationClient_1.0.4.0_x86__e1rzdqpraam7r [2018-10-26] (Adobe Systems Incorporated) Adobe Notification Client -> C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc [2019-08-08] (Adobe Systems Incorporated) Adobe XD -> C:\Program Files\WindowsApps\Adobe.CC.XD_19.2.22.3_x64__adky2gkssdxte [2019-06-05] (Adobe Systems Incorporated) Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1600.3.0_x86__kgqvnymyfvs32 [2019-09-19] (king.com) Complemento de Fotos -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2017.39121.36610.0_x64__8wekyb3d8bbwe [2019-08-15] (Microsoft Corporation) Correo y Calendario -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-10-02] (Microsoft Corporation) [MS Ad] Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.0.3566.0_x64__rz1tebttyb220 [2019-10-04] (Dolby Laboratories) Hidden City: Aventura de objetos ocultos -> C:\Program Files\WindowsApps\828B5831.HiddenCityMysteryofShadows_1.30.3003.0_x86__ytsefhwckbdv6 [2019-09-09] (G5 Entertainment AB) HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_100.1.581.0_x64__v10z8vjag6ke6 [2019-07-21] (HP Inc.) March of Empires: War of Lords -> C:\Program Files\WindowsApps\A278AB0D.MarchofEmpires_4.3.1.1_x86__h6adky7gbf63m [2019-09-20] (Gameloft.) Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-12] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.8204.0_x64__8wekyb3d8bbwe [2019-09-01] (Microsoft Studios) [MS Ad] Microsoft To Do -> C:\Program Files\WindowsApps\Microsoft.Todos_2.0.22483.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Corporation) Minecraft for Windows 10 -> C:\Program Files\WindowsApps\Microsoft.MinecraftUWP_1.12.101.0_x64__8wekyb3d8bbwe [2019-09-09] (Microsoft Studios) MSN El tiempo -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-16] (Microsoft Corporation) [MS Ad] Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0 [2019-10-02] (Spotify AB) Windows Terminal (Preview) -> C:\Program Files\WindowsApps\Microsoft.WindowsTerminal_0.5.2681.0_x64__8wekyb3d8bbwe [2019-10-02] (Microsoft Corporation) Xbox One SmartGlass -> C:\Program Files\WindowsApps\Microsoft.XboxOneSmartGlass_2.2.1702.2004_x64__8wekyb3d8bbwe [2019-07-29] (Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2937623597-1657547211-2391554280-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-03732193237A} -> [Creative Cloud Files] => C:\Users\Bernardo\Creative Cloud Files [2019-01-30 21:35] CustomCLSID: HKU\S-1-5-21-2937623597-1657547211-2391554280-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Bernardo\AppData\Local\GoToMeeting\13190\G2MOutlookAddin64.dll => No File CustomCLSID: HKU\S-1-5-21-2937623597-1657547211-2391554280-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A} -> [Dropbox] => C:\Users\Bernardo\Dropbox [2018-10-04 23:51] CustomCLSID: HKU\S-1-5-21-2937623597-1657547211-2391554280-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe Systems) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers1: [BB FlashBack 2] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> No File ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers1: [QuickShare] -> {A8065B9E-193F-4797-B62D-8F6321E7FCCB} => -> No File ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [DeleteFiles] -> {736AF091-C361-49B4-A928-87C586130D33} => C:\Program Files\File Shredder\fsshell.dll [2012-04-01] () [File not signed] ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.0.dll [2019-05-07] (Dropbox, Inc -> Dropbox, Inc.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_24de78387e6208e4\igfxDTCM.dll [2018-11-21] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-03-05] (Adobe Systems Incorporated -> ) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems, Incorporated -> Adobe Systems Inc.) ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd -> Piriform Ltd) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-30] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ================== ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Bernardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\user.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /c explorer hxxp://www2.savemax.store/ ShortcutWithArgument: C:\Users\Bernardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\ARC Welder.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=emfinbmielocnlhgmfkkmkngdoccbadn ==================== Loaded Modules (Whitelisted) ============== 2019-09-17 02:16 - 2019-05-29 14:51 - 000293888 _____ () [File not signed] C:\Users\Bernardo\AppData\Local\php7\libsodium.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 000186880 _____ () [File not signed] C:\Users\Bernardo\AppData\Local\php7\libssh2.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 000156672 _____ (hxxps://nghttp2.org/) [File not signed] C:\Users\Bernardo\AppData\Local\php7\nghttp2.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 002548736 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Users\Bernardo\AppData\Local\php7\libcrypto-1_1.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 000530432 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [File not signed] C:\Users\Bernardo\AppData\Local\php7\libssl-1_1.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 000466432 _____ (The PHP Group) [File not signed] C:\Users\Bernardo\AppData\Local\php7\ext\php_curl.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 000059392 _____ (The PHP Group) [File not signed] C:\Users\Bernardo\AppData\Local\php7\ext\php_sodium.dll 2019-09-17 02:16 - 2019-05-29 14:51 - 007548928 _____ (The PHP Group) [File not signed] C:\Users\Bernardo\AppData\Local\php7\php7ts.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2018-09-15 02:31 - 2018-09-15 02:31 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts 2019-04-05 02:55 - 2019-10-14 12:46 - 000000619 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics 172.17.154.225 RISEN-P.mshome.net # 2024 10 6 12 17 46 24 667 019 9 1 23 19 39 17 726 172.17.154.232 d43a4e21-43c7-47c8-90a0-9ab702373d88.mshome.net # 2019 9 2 24 6 54 48 332 172.17.154.225 RISEN-P.mshome.net # 2024 9 0 15 6 55 0 414 287 ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %INTEL_DEV_REDIST%redist\intel64\compiler;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\dotnet\ HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bernardo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\Run: => "SecurityHealth" HKLM\...\StartupApproved\Run: => "AdobeGCInvoker-1.0" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0" HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\StartupApproved\StartupFolder: => "Enviar a OneNote.lnk" HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\StartupApproved\StartupFolder: => "Mailspring.lnk" HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\StartupApproved\Run: => "com.squirrel.slack.slack" HKU\S-1-5-21-2937623597-1657547211-2391554280-1001\...\StartupApproved\Run: => "Adobe Acrobat Synchronizer" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [VIRT-MIGL-In-TCP-NoScope] => (Allow) %systemroot%\system32\vmms.exe No File FirewallRules: [VIRT-REMOTEDESKTOP-In-TCP-NoScope] => (Allow) %systemroot%\system32\vmms.exe No File FirewallRules: [DNS Server Forward Rule - UDP - 111E521B-8F9B-457D-A05D-F725BEC6C482 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 111E521B-8F9B-457D-A05D-F725BEC6C482 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - A4AB4537-7297-4325-8545-717A382795D5 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - A4AB4537-7297-4325-8545-717A382795D5 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - C70AB16F-1588-454C-B162-26932C1EB23E - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - C70AB16F-1588-454C-B162-26932C1EB23E - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - CE573512-CADB-470D-A18D-F6AA5FF4DF66 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - CE573512-CADB-470D-A18D-F6AA5FF4DF66 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 36CCFE75-A237-4701-8B20-EBA96A87FBF8 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 36CCFE75-A237-4701-8B20-EBA96A87FBF8 - 0] => (Allow) LPort=53 FirewallRules: [{0C9124B4-3085-46F5-B15C-6D9151B3F011}] => (Allow) C:\Users\Bernardo\AppData\Roaming\Zoom\bin\airhost.exe No File FirewallRules: [{B71EED3B-B5A7-46C9-8300-9B26F805BA0B}] => (Allow) C:\Users\Bernardo\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.) FirewallRules: [DNS Server Forward Rule - UDP - C4F9037B-F008-49B5-ABC6-2B06ABF8069E - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - C4F9037B-F008-49B5-ABC6-2B06ABF8069E - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 1C831A87-BE86-41C7-8A40-BCCDC259E647 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 1C831A87-BE86-41C7-8A40-BCCDC259E647 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 59CB6FD7-64C8-4A12-92B0-420E0C252A75 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 59CB6FD7-64C8-4A12-92B0-420E0C252A75 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - EC67D0F1-F548-48B6-842F-5E447291A91A - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - EC67D0F1-F548-48B6-842F-5E447291A91A - 0] => (Allow) LPort=53 FirewallRules: [{3D12B9ED-763D-48C4-AC7C-EA9A98961707}] => (Allow) C:\Program Files (x86)\Popcorn Time\nodejs\node.exe (Node.js Foundation -> Node.js) FirewallRules: [{B9474F81-9D29-45B6-9FDC-B12D81BF5173}] => (Allow) C:\Program Files (x86)\Popcorn Time\nodejs\node.exe (Node.js Foundation -> Node.js) FirewallRules: [{D32A8631-9470-4822-B5E2-FFFEFD53F83A}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe () [File not signed] FirewallRules: [{8955C878-50EA-4B38-BB14-E898BFD797D2}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe () [File not signed] FirewallRules: [{94019B22-3C25-4C3D-A02F-06209969E3AD}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe (Popcorn Time) [File not signed] FirewallRules: [{79093FD5-5B1B-45EF-A374-8F6C10C37A25}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe (Popcorn Time) [File not signed] FirewallRules: [{AA799ADF-E2A3-44B5-A37C-C6D594275021}] => (Allow) C:\Users\Bernardo\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [{449CF881-2AD1-4271-ACF9-CDCAE8B7AD2B}] => (Allow) C:\Users\Bernardo\AppData\Roaming\uTorrent\uTorrent.exe No File FirewallRules: [DNS Server Forward Rule - UDP - 797B0304-FF6F-4239-B745-71EF4C6DC9AB - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 797B0304-FF6F-4239-B745-71EF4C6DC9AB - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - DB18B218-B9EF-44CC-BD2F-47BAEB39D790 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - DB18B218-B9EF-44CC-BD2F-47BAEB39D790 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 2F2DCD3A-D3AA-4C5C-A63C-89DD778D6DD3 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 2F2DCD3A-D3AA-4C5C-A63C-89DD778D6DD3 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - UDP - 547925D6-1E28-432C-A08C-87A93F1FC988 - 0] => (Allow) LPort=53 FirewallRules: [DNS Server Forward Rule - TCP - 547925D6-1E28-432C-A08C-87A93F1FC988 - 0] => (Allow) LPort=53 FirewallRules: [{A63D57D1-E7CE-4B1D-956F-8AECB3E312A0}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe (ASUSTeK COMPUTER INC.) [File not signed] FirewallRules: [{1E6532DB-E004-40C3-B4B7-CE0A2FF79495}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe (ASUSTeK COMPUTER INC.) [File not signed] FirewallRules: [{0716F734-B6EF-4309-9620-23EE9116747A}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{51775F45-62E4-4B8E-B758-01863D83C589}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{0B63ED83-30AA-4A07-8EE9-96563C11DCDE}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{71D0DDA8-FA7B-4EFE-B5E8-3C05AD1490BC}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{A9D38A11-B78B-454A-8146-4B6D5433180D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{07202FAC-B728-4829-AC92-9D83E6C49459}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{42E6A3FD-4634-4877-9B8F-0C4BA9171ECE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{E879B91C-DDE6-42B1-B8FF-20B00C444BBF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{174C7A7B-8A38-481E-B95E-3CBB75E5B619}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{D114885C-3CA0-43A7-AC95-B02F2DA3590F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{4F4D5D8C-2443-4DFA-A4C5-D6C7B117ABD8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{58BAD167-4FE0-4F5E-959B-5C2F9A452CB4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.5.0\DriverBooster.exe (IObit Information Technology -> IObit) FirewallRules: [{52C7DA1D-4DE1-4774-9E0A-32298D905784}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.5.0\DriverBooster.exe (IObit Information Technology -> IObit) FirewallRules: [{3559AB26-E7EC-4F54-AF2A-F644430A03BE}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.5.0\DBDownloader.exe (IObit Information Technology -> IObit) FirewallRules: [{A47F7FD1-A2B8-48D3-A35E-22312F8963E4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.5.0\DBDownloader.exe (IObit Information Technology -> IObit) FirewallRules: [{E5320F20-F1CB-4C65-B7A2-6DCE0C220F78}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.5.0\AutoUpdate.exe (IObit Information Technology -> IObit) FirewallRules: [{7A39BE14-458D-4175-8500-6900EC7EA7CB}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.5.0\AutoUpdate.exe (IObit Information Technology -> IObit) FirewallRules: [{2216E664-153B-4794-9E91-A568D686FE04}] => (Allow) C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{108A9566-F54A-4D53-AC66-E64FDFC515ED}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{962F8399-7CDD-4100-9694-4B873DE7144C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{AD265D79-F442-431D-A5AC-CEEB287B78C6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [{1F0DAD55-E339-4100-95DA-40459D760537}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer GmbH) FirewallRules: [HNS Container Networking - DNS (UDP-In) - 5B9C531F-62C1-43A0-9F89-EA5DEDF0A2DE - 0] => (Allow) LPort=53 FirewallRules: [{34FF8349-7E46-452B-8796-0827F68E506D}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\78.0.3904.7\remoting_host.exe (Google LLC -> Google Inc.) FirewallRules: [{4E0EEFC2-5243-4E11-B50A-7ED56BA81CCD}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{C90B9190-A4AD-4CB3-A4FD-4532AB72FF61}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{C9FBCDC6-D083-4AF3-B08F-FFA85BB06D9B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{16A2499C-1604-434C-A784-24BD8DE72AF6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{B9E59D55-D15E-4315-95CE-9C15EF10A88F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{B287873E-8C33-4896-9FDA-608C4ED00DBC}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{2579D150-274F-404A-A92C-9F0DAA4C2C31}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{72EDCDFC-A674-467A-99E1-6B9FC6CD7555}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.116.522.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd) FirewallRules: [{B17E24C6-D718-4171-B089-B4E31DEA045B}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.) FirewallRules: [{BBF68327-558C-4A99-8784-CEC51BA8A14E}] => (Allow) C:\Program Files (x86)\Microsoft\Edge Dev\Application\msedge.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{54E26259-B8D1-47D5-A4C5-80D08BAA2EB8}] => (Block) %USERPROFILE%\AppData\Local\php7\php.exe (The PHP Group) [File not signed] FirewallRules: [{BDDD307F-993F-4762-AE1D-D2C47CF01571}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 04-10-2019 11:02:35 Punto de control programado 15-10-2019 02:25:36 Windows Update ==================== Faulty Device Manager Devices ============= Name: Detection Verification Description: Detection Verification Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (10/15/2019 02:38:34 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (2608,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/15/2019 02:06:57 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (21184,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/15/2019 01:43:36 AM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (11796,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/14/2019 10:19:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nombre de la aplicación con errores: AdobeNotificationClient.exe, versión: 4.9.0.484, marca de tiempo: 0x5d0b467b Nombre del módulo con errores: AdobeNotificationClient.exe, versión: 4.9.0.484, marca de tiempo: 0x5d0b467b Código de excepción: 0x80000003 Desplazamiento de errores: 0x0000b311 Identificador del proceso con errores: 0x4f7c Hora de inicio de la aplicación con errores: 0x01d582d506a29a54 Ruta de acceso de la aplicación con errores: C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe Ruta de acceso del módulo con errores: C:\Program Files\WindowsApps\AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc\AdobeNotificationClient.exe Identificador del informe: b5e7861e-4677-4135-9488-0816f101e593 Nombre completo del paquete con errores: AdobeNotificationClient_1.0.1.22_x86__enpm4xejd91yc Identificador de aplicación relativa del paquete con errores: App Error: (10/14/2019 07:19:14 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (16744,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/14/2019 01:09:34 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (15824,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/14/2019 12:54:24 PM) (Source: ESENT) (EventID: 455) (User: ) Description: svchost (2612,R,98) TILEREPOSITORYS-1-5-18: Error -1023 (0xfffffc01) al abrir un archivo de registro C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log. Error: (10/14/2019 12:49:23 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: ) Description: Event-ID 0 System errors: ============= Error: (10/02/2019 04:15:00 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:15:00 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:15:00 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:15:00 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:15:00 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:15:00 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:14:57 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. Error: (10/02/2019 04:14:55 PM) (Source: DCOM) (EventID: 10010) (User: RISEN-P) Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido. CodeIntegrity: =================================== Date: 2019-10-15 02:36:13.195 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-14 13:15:18.248 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-14 12:46:48.836 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-14 12:46:48.828 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-14 12:46:48.816 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-14 12:46:48.802 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-14 12:46:48.729 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. Date: 2019-10-05 00:02:54.785 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bitdefender Antivirus Free\bdamsi\264196747288332313\antimalware_provider64.dll that did not meet the Windows signing level requirements. ==================== Memory info =========================== BIOS: Insyde Corp. V1.15 01/08/2018 Motherboard: KBL Charmander_KL Processor: Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz Percentage of memory in use: 61% Total physical RAM: 12163.6 MB Available physical RAM: 4698.7 MB Total Virtual: 25987.6 MB Available Virtual: 17110.3 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:464.6 GB) (Free:288.14 GB) NTFS \\?\Volume{6493ae6a-0386-49d8-9dec-4e16bddd4c6a}\ (Recuperación) (Fixed) (Total:0.49 GB) (Free:0.47 GB) NTFS \\?\Volume{75604f2d-9b02-4eed-95fd-fd3c177dc7fe}\ () (Fixed) (Total:0.56 GB) (Free:0.08 GB) NTFS \\?\Volume{629458e4-0000-0000-0000-010000000000}\ (PortableBaseLayer) (Fixed) (Total:8 GB) (Free:7.6 GB) NTFS \\?\Volume{49329ec4-9f23-4fde-8b0a-5e1dc1d22284}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000) Partition: GPT. ======================================================== Disk: 1 (MBR Code: Windows 7/8/10) (Size: 8 GB) (Disk ID: 629458E4) Partition 1: (Not Active) - (Size=8 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================