PDA

View Full Version : tradeadxchange.com Removal-scan



eezv11
2015-09-09, 06:35
Hi,
I believe that I have it together, now.
I am attaching the following:
-aswMBR log
I received a message indicating that both FRST.txt and Addition.txt are to long to be attached.

I am copying them in the reply to the thread:

FRST.txt:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-09-2015
Ran by equipo2 (administrator) on EEZV-EQUIPO2-HP (08-09-2015 22:08:33)
Running from C:\Users\equipo2\Desktop
Loaded Profiles: equipo2 (Available Profiles: equipo2 & DefaultAppPool)
Platform: Windows 10 Home (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Microsoft Online Services\MSOIDSVC.EXE
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Microsoft Online Services\MSOIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\ioloGovernor64.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(CyberLink) C:\Program Files (x86)\Cyberlink\YouCam\YCMMirage.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Hewlett-Packard Co.) C:\Program Files\hp\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe
(Hewlett-Packard Co.) C:\Program Files\hp\HP Officejet Pro X476dw MFP\Bin\HPNetworkCommunicatorCom.exe
(Dropbox, Inc.) C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\LiveBoost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1508.14010.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.12711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-07-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2010-10-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [iolo Startup] => C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe [4536120 2015-07-24] (iolo technologies, LLC)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448520 2015-06-24] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861640 2015-06-26] (DivX, LLC)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911032 2015-03-18] (Microsoft Corporation)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1079592 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22344224 2015-07-29] (Google)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [09F184CEBFDA4849CA9645B600CD483758C4028F._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-08-27] (Google Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [ISUSPM] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [205480 2007-08-30] (Macrovision Corporation)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [OneDrive] => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-25] (Microsoft Corporation)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [HP Officejet Pro X476dw MFP (NET)] => C:\Program Files\hp\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [Dropbox Update] => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-24] (Dropbox, Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
SSODL: EldosMountNotificator-cbfs4 - {4BD75115-4D24-454C-9213-B9699D8C1893} - C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs4 - {4BD75115-4D24-454C-9213-B9699D8C1893} - C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [ !0Transporter] -> {D03C19B6-E652-4368-84EC-B86C800C452B} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !1Transporter] -> {F66A1D45-3345-425C-A62A-33081D7E0338} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !2Transporter] -> {18640773-7F8C-4F62-AAE1-862F1CCD3FB4} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !3Transporter] -> {FFB483B1-E093-4457-9547-73D9DDC546A8} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !4Transporter] -> {A16F6DC0-AB73-4068-8725-0AF867039A78} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !5Transporter] -> {6590B207-B84E-4054-9102-BE2118932B3B} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !6Transporter] -> {845192C8-8E68-4B0F-A871-712DEEFB2D16} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs4] -> {3EEF37CF-AABC-40B3-B6B0-EBD7DFFE78E7} => C:\Windows\system32\cbfsMntNtf4.dll [2013-01-30] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs4] -> {3EEF37CF-AABC-40B3-B6B0-EBD7DFFE78E7} => C:\Windows\SysWOW64\cbfsMntNtf4.dll [2013-01-30] (EldoS Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-05-19]
ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-13]
ShortcutTarget: Dropbox.lnk -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de pantalla y Selector de OneNote 2010.lnk [2014-02-25]
ShortcutTarget: Recorte de pantalla y Selector de OneNote 2010.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{1bd54d50-7b1a-4d78-9e99-76f3b53439c3}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{5edaff56-6c60-438c-b20d-1ab10bf61517}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{6ec1d726-53ee-4386-95ca-b57d32f4a517}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{91f4d237-9bb8-4106-ad8b-1261088f384c}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{c860732a-6130-453d-a27f-03278251d84b}: [DhcpNameServer] 172.20.10.1

Internet Explorer:
==================
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPALL/111
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://es.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-04-07] (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll [2011-06-09] (HP)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll No File
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-24] (Oracle Corporation)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll [2011-06-09] (HP)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-24] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: No Name -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> No File
Toolbar: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\equipo2\AppData\Roaming\Mozilla\Firefox\Profiles\lu9ej73p.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-23] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-03] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-23] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll [2014-01-28] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2015-08-05] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-12-19] (Nero AG)
FF Plugin-x32: @real.com/nppl3260;version=17.0.9.17 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-05-19] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.9 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2014-04-07] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.9 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-04-07] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.9 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2014-04-07] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.9.17 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-05-19] (RealPlayer Cloud)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-05-26] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-27] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-03] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2014-05-19] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2014-05-19] (RealPlayer Cloud)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npatgpc.dll [2015-01-14] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\equipo2\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-01-14] (Cisco WebEx LLC)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mercadolibre-mx.xml [2014-06-06]
FF Extension: anonymoX - C:\Users\equipo2\AppData\Roaming\Mozilla\Firefox\Profiles\lu9ej73p.default\Extensions\client@anonymox.net.xpi [2013-11-06]
FF Extension: Adblock Edge - C:\Users\equipo2\AppData\Roaming\Mozilla\Firefox\Profiles\lu9ej73p.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-06-26]
FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2014-10-02]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2012-10-15]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-05-19]
FF HKLM-x32\...\Firefox\Extensions: [{53D8DD28-1C83-41F3-B171-C2ED5B3E5DE8}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "about:blank","chrome://apps/","hxxp://mysearch.avg.com?cid={77ADA367-98CB-407E-B209-4EF99607BF1B}&mid=9a5a8c99e44047d29d2bbd72a3fc6142-c2e6da9e5645ab5026b71e1047dddfd883ea88b1&lang=en&ds=jt011&coid=avgtbdisjt&cmpid=&pr=sa&d=2014-06-06 07:07:41&v=18.1.0.443&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={77ADA367-98CB-407E-B209-4EF99607BF1B}&mid=9a5a8c99e44047d29d2bbd72a3fc6142-c2e6da9e5645ab5026b71e1047dddfd883ea88b1&lang=en&ds=jt011&coid=avgtbdisjt&cmpid=&pr=sa&d=2014-06-06 07:07:41&v=18.1.7.598&pid=safeguard&sg=&sap=hp"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (__MSG_ext_name__) - internal-remoting-viewer
CHR Plugin: (Remoting Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\gcswf32.dll No File
CHR Plugin: (Flash) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2191_0\plugins/avgnpss.dll No File
CHR Plugin: (AVG Internet Security) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_0\npwebsitelogon.dll No File
CHR Plugin: (Simple Pass 2011) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Java) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (RealPlayer) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (iTunes Application Detector) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll No File
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Profile: C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Translator for all languages) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\amdeidgbmcliegnpcbbkhlflkbdpomhk [2014-03-15]
CHR Extension: (Google Drive) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-23]
CHR Extension: (FVD Video Downloader) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjjnhlldkcmeabhjlopelfhidanhdicg [2015-02-16]
CHR Extension: (YouTube) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-04-24]
CHR Extension: (AddThis - Share & Bookmark (new)) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde [2012-06-01]
CHR Extension: (Google Search) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-04-24]
CHR Extension: (Ortografía, gramática y diccionario) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhindnacjeiaemdobfpmlbgjgbmkjcl [2014-06-16]
CHR Extension: (Google+) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2014-06-11]
CHR Extension: (Chrome Web Store Launcher (by Google)) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\gecgipfabdickgidpmbicneamekgbaej [2014-06-16]
CHR Extension: (Google Docs Offline) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Book Search) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidpecplnodokhjcplkeejdbmjfmlplm [2014-06-16]
CHR Extension: (Kindle Cloud Reader) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-01-10]
CHR Extension: (Dropbox) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2014-03-15]
CHR Extension: (Cisco WebEx Extension) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2014-06-26]
CHR Extension: (Adblock Super) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-08-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-16]
CHR Extension: (Google Mail Checker) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2012-08-03]
CHR Extension: (Google Play Books) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2014-06-16]
CHR Extension: (OneDrive) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2014-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (LogMeIn) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\omkjapkpkiciphacnalicgmmcelfolon [2013-09-05]
CHR Extension: (Gmail) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-04-24]
CHR HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\equipo2\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-10-22]
CHR HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-04-06]
CHR HKLM-x32\...\Chrome\Extension: [jpgfhihjicjofdejkbjgnjlaglaciobe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-06-03]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-07-07] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-07-07] (AVG Technologies CZ, s.r.o.)
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [129648 2011-05-26] (Portrait Displays, Inc.)
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [4682040 2015-07-24] (iolo technologies, LLC)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-05] (Microsoft Corporation)
R2 msoidsvc; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2079520 2012-05-17] (Microsoft Corp.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [File not signed]
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-05] (PDF Complete Inc)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [File not signed]
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-04-06] ()
S2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-05-19] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-04-07] () [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-05] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-05] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.)
R1 cbfs4; C:\Windows\system32\drivers\cbfs4.sys [381632 2013-01-30] (EldoS Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-05] (Microsoft Corporation)
R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-10-14] ()
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32912 2014-11-06] (EldoS Corporation)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-08 22:08 - 2015-09-08 22:12 - 00050073 _____ C:\Users\equipo2\Desktop\FRST.txt
2015-09-08 22:08 - 2015-09-08 22:08 - 00000000 ____D C:\FRST
2015-09-08 22:06 - 2015-09-08 22:07 - 05198336 _____ (AVAST Software) C:\Users\equipo2\Desktop\aswMBR.exe
2015-09-08 22:05 - 2015-09-08 22:07 - 02190336 _____ (Farbar) C:\Users\equipo2\Desktop\FRST64.exe
2015-09-08 22:03 - 2015-09-08 22:03 - 00000000 ____D C:\RegBackup
2015-09-08 22:01 - 2015-09-08 22:01 - 02023465 _____ C:\Users\equipo2\Downloads\tweaking.com_registry_backup_portable.zip
2015-09-08 21:56 - 2015-09-08 21:56 - 00016148 _____ C:\WINDOWS\system32\EEZV-EQUIPO2-HP_equipo2_HistoryPrediction.bin
2015-09-07 15:30 - 2015-09-07 15:30 - 00000000 ____D C:\Users\equipo2\AppData\Local\{9E834BE6-A87C-42D1-8ABA-8D4B90727D33}
2015-09-04 18:25 - 2015-09-04 18:25 - 00000051 _____ C:\Users\equipo2\Downloads\bajar audio y video.txt
2015-09-04 18:06 - 2015-09-08 10:46 - 00151552 _____ C:\WINDOWS\KMSEmulator.exe
2015-09-04 16:53 - 2015-09-04 18:04 - 00000000 ____D C:\AdwCleaner
2015-09-03 19:54 - 2015-09-03 19:54 - 00000000 ____D C:\Users\equipo2\AppData\Local\{338CFF5F-D4D9-4345-BE11-67E6BC93B099}
2015-09-03 17:13 - 2015-09-04 18:29 - 00000020 _____ C:\Users\equipo2\Downloads\virus.txt
2015-09-01 19:55 - 2015-09-01 19:55 - 00002040 _____ C:\Users\equipo2\Desktop\LMP771017AM6_SN_147351_ZEVE630620QZ3.pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00002020 _____ C:\Users\equipo2\Desktop\LMP771017AM6_SN_147351_ZEVE630620QZ3.xml - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001984 _____ C:\Users\equipo2\Desktop\Farmacia del Ahorro (hernia).pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001931 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020942.pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001931 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020915.pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001911 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020942.xml - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001911 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020915.xml - Acceso directo.lnk
2015-09-01 18:45 - 2015-09-01 18:45 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-29 03:02 - 2015-08-20 01:02 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-29 03:02 - 2015-08-20 00:21 - 21875200 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-08-29 03:02 - 2015-08-19 23:31 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-08-29 03:01 - 2015-08-20 01:07 - 08019296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-29 03:01 - 2015-08-20 01:06 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-29 03:01 - 2015-08-20 00:57 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-08-29 03:01 - 2015-08-20 00:26 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-29 03:01 - 2015-08-20 00:21 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-29 03:01 - 2015-08-20 00:16 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-29 03:01 - 2015-08-20 00:13 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-29 03:01 - 2015-08-18 02:56 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-29 03:01 - 2015-08-18 02:55 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-08-29 03:01 - 2015-08-18 02:54 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-29 03:01 - 2015-08-18 02:27 - 01771592 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-29 03:01 - 2015-08-18 02:24 - 00963920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-29 03:01 - 2015-08-18 02:13 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-08-29 03:01 - 2015-08-18 02:13 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-08-29 03:01 - 2015-08-18 02:12 - 02225664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-29 03:01 - 2015-08-18 02:07 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-08-29 03:01 - 2015-08-18 02:04 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-08-29 03:01 - 2015-08-18 02:04 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-29 03:01 - 2015-08-18 01:59 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-08-29 03:01 - 2015-08-18 01:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-08-29 03:01 - 2015-08-18 01:57 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-08-29 03:01 - 2015-08-18 01:56 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-08-29 03:01 - 2015-08-18 01:55 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-29 03:01 - 2015-08-18 01:54 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-08-29 03:01 - 2015-08-18 01:54 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-29 03:01 - 2015-08-18 01:52 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-29 03:01 - 2015-08-18 01:50 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-29 03:01 - 2015-08-18 01:49 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-29 03:01 - 2015-08-18 01:49 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-08-29 03:01 - 2015-08-18 01:49 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-08-29 03:01 - 2015-08-18 01:36 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-08-29 03:01 - 2015-08-18 01:35 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-08-29 03:01 - 2015-08-18 01:35 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-08-29 03:01 - 2015-08-18 01:34 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-08-29 03:01 - 2015-08-18 01:29 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-29 03:01 - 2015-08-18 01:26 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-08-29 03:01 - 2015-08-17 23:44 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-08-26 18:00 - 2015-08-26 18:00 - 00000000 ____D C:\Users\equipo2\AppData\Local\{511C519F-3849-4283-9AB5-C3A01D33851A}
2015-08-26 17:45 - 2015-08-26 17:45 - 00056415 _____ C:\Users\equipo2\Desktop\JRT.txt
2015-08-26 17:24 - 2015-08-26 12:34 - 01798560 _____ (Malwarebytes Corporation) C:\Users\equipo2\Desktop\JRT.exe
2015-08-25 23:17 - 2015-08-25 23:17 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-08-25 10:47 - 2015-08-25 10:47 - 00002378 _____ C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-21 13:58 - 2015-08-21 13:58 - 00003274 _____ C:\Users\equipo2\Downloads\PRESENTACIÓN MEDIACIÓN.txt
2015-08-19 15:21 - 2015-08-12 23:33 - 24593408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-19 15:21 - 2015-08-12 23:22 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-08-19 15:21 - 2015-08-12 23:07 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-19 15:21 - 2015-08-11 05:04 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-08-19 15:21 - 2015-08-11 04:50 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-19 15:21 - 2015-08-11 04:23 - 16706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-19 15:21 - 2015-08-11 04:16 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-19 15:21 - 2015-08-11 04:06 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-08-19 15:21 - 2015-08-11 04:06 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-19 15:21 - 2015-08-11 04:05 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-08-19 15:21 - 2015-08-11 04:03 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-08-19 15:21 - 2015-08-11 03:57 - 13024768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-19 15:21 - 2015-08-11 03:45 - 01820672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-08-19 15:20 - 2015-08-12 23:20 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-08-19 15:20 - 2015-08-12 22:53 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-08-19 15:20 - 2015-08-11 05:04 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-19 15:20 - 2015-08-11 05:04 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-08-19 15:20 - 2015-08-11 05:03 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-08-19 15:20 - 2015-08-11 05:02 - 00554744 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-08-19 15:20 - 2015-08-11 05:02 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-19 15:20 - 2015-08-11 05:02 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-08-19 15:20 - 2015-08-11 04:57 - 03622256 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-19 15:20 - 2015-08-11 04:52 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-08-19 15:20 - 2015-08-11 04:40 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-08-19 15:20 - 2015-08-11 04:40 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-08-19 15:20 - 2015-08-11 04:40 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-08-19 15:20 - 2015-08-11 04:38 - 00454000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-08-19 15:20 - 2015-08-11 04:37 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-08-19 15:20 - 2015-08-11 04:31 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-19 15:20 - 2015-08-11 04:26 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-08-19 15:20 - 2015-08-11 04:21 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-08-19 15:20 - 2015-08-11 04:21 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-08-19 15:20 - 2015-08-11 04:20 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-08-19 15:20 - 2015-08-11 04:19 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-08-19 15:20 - 2015-08-11 04:18 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-08-19 15:20 - 2015-08-11 04:14 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-08-19 15:20 - 2015-08-11 04:13 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-08-19 15:20 - 2015-08-11 04:11 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-08-19 15:20 - 2015-08-11 04:11 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-08-19 15:20 - 2015-08-11 04:10 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-19 15:20 - 2015-08-11 04:10 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 15:20 - 2015-08-11 04:10 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-19 15:20 - 2015-08-11 04:09 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-08-19 15:20 - 2015-08-11 04:08 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-08-19 15:20 - 2015-08-11 04:08 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-08-19 15:20 - 2015-08-11 04:07 - 01178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-08-19 15:20 - 2015-08-11 04:07 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-19 15:20 - 2015-08-11 04:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-08-19 15:20 - 2015-08-11 04:05 - 00996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-08-19 15:20 - 2015-08-11 04:02 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-08-19 15:20 - 2015-08-11 04:02 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-08-19 15:20 - 2015-08-11 04:02 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-08-19 15:20 - 2015-08-11 04:01 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-08-19 15:20 - 2015-08-11 04:00 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-08-19 15:20 - 2015-08-11 04:00 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-08-19 15:20 - 2015-08-11 03:58 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-08-19 15:20 - 2015-08-11 03:57 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-08-19 15:20 - 2015-08-11 03:51 - 01916928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-08-19 15:20 - 2015-08-11 03:51 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-08-19 15:20 - 2015-08-11 03:50 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-08-19 15:20 - 2015-08-11 03:50 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-08-19 15:20 - 2015-08-11 03:50 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-08-19 15:20 - 2015-08-11 03:49 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-19 15:20 - 2015-08-11 03:49 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 15:20 - 2015-08-11 03:48 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-08-19 15:20 - 2015-08-11 03:47 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-08-19 15:20 - 2015-08-11 03:43 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-08-19 15:20 - 2015-08-11 03:42 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-08-19 15:20 - 2015-08-11 03:40 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-08-19 15:20 - 2015-08-11 03:40 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-08-19 15:20 - 2015-08-11 03:39 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-08-19 15:20 - 2015-08-11 03:38 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-08-17 16:37 - 2015-08-17 16:38 - 00000000 ____D C:\Program Files (x86)\Tagscan5.1.668
2015-08-17 11:47 - 2015-08-17 11:47 - 00074703 _____ C:\WINDOWS\SysWOW64\mfc45.dat
2015-08-12 01:56 - 2015-08-08 01:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 01:56 - 2015-08-08 01:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 01:56 - 2015-08-08 01:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 01:56 - 2015-08-04 23:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-08-12 01:56 - 2015-08-03 23:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-08-12 01:56 - 2015-08-03 21:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 01:56 - 2015-08-03 21:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-08-12 01:56 - 2015-08-02 21:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 01:56 - 2015-08-02 21:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 01:56 - 2015-08-02 20:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 01:56 - 2015-08-02 20:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 01:56 - 2015-08-02 20:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-08-12 01:56 - 2015-08-02 20:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 01:56 - 2015-08-02 20:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 01:56 - 2015-08-02 20:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 01:56 - 2015-08-02 20:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-08-12 01:56 - 2015-08-02 20:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-08-12 01:56 - 2015-08-02 20:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 01:55 - 2015-08-08 02:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 01:55 - 2015-08-08 02:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-08-12 01:55 - 2015-08-08 02:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 01:55 - 2015-08-08 01:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-08-12 01:55 - 2015-08-08 01:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 01:55 - 2015-08-08 01:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 01:55 - 2015-08-05 22:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 01:55 - 2015-08-05 22:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 01:55 - 2015-08-05 21:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 01:55 - 2015-08-04 23:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 01:55 - 2015-08-04 23:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 01:55 - 2015-08-04 22:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 01:55 - 2015-08-04 22:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-08-12 01:55 - 2015-08-04 22:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-08-12 01:55 - 2015-08-03 23:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 01:55 - 2015-08-03 23:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-08-12 01:55 - 2015-08-03 22:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 01:55 - 2015-08-02 21:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 01:55 - 2015-08-02 21:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-08-12 01:55 - 2015-08-02 21:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 01:55 - 2015-08-02 21:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 01:55 - 2015-08-02 21:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 01:55 - 2015-08-02 21:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 01:55 - 2015-08-02 21:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 01:55 - 2015-08-02 21:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 01:55 - 2015-08-02 21:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 01:55 - 2015-08-02 20:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-08-12 01:55 - 2015-08-02 20:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 01:55 - 2015-08-02 20:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 01:55 - 2015-08-02 20:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 01:55 - 2015-08-02 20:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 01:55 - 2015-08-02 20:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 01:55 - 2015-08-02 20:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 01:55 - 2015-08-02 20:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 01:55 - 2015-08-02 20:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 01:55 - 2015-08-02 20:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 01:55 - 2015-08-02 20:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 01:55 - 2015-08-02 20:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 01:55 - 2015-08-02 20:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 01:55 - 2015-08-02 20:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 01:55 - 2015-08-02 20:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-08-12 01:55 - 2015-08-02 20:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-08-12 01:55 - 2015-08-02 20:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 01:55 - 2015-08-02 20:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 01:55 - 2015-08-02 20:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-08-12 01:55 - 2015-08-02 20:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 01:55 - 2015-08-02 19:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-08-09 01:46 - 2014-12-05 21:17 - 00450776 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20150809-014620.backup

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-08 22:13 - 2012-04-25 16:32 - 00000838 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-08 22:06 - 2013-05-08 19:17 - 00000000 ____D C:\Users\equipo2\Downloads\soporte
2015-09-08 22:01 - 2012-04-24 20:06 - 00001076 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-08 21:56 - 2012-04-17 17:37 - 00000000 ____D C:\Users\equipo2\Documents\Archivos de Outlook
2015-09-08 21:55 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-08 21:35 - 2013-06-05 20:21 - 00000000 ____D C:\Users\equipo2\AppData\Local\07EEFC3E-BFFF-4F02-A4B1-F6FAD94C9CFC.aplzod
2015-09-08 21:29 - 2015-06-24 11:18 - 00000968 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000UA.job
2015-09-08 16:57 - 2014-10-30 12:45 - 00000036 ____H C:\Users\equipo2\Documents\PP11Thumbs.ptn2
2015-09-08 16:57 - 2014-07-15 12:56 - 00806360 ____H C:\Users\equipo2\Documents\PP11Thumbs.ptn
2015-09-08 16:57 - 2013-11-04 14:36 - 00000142 ____H C:\Users\equipo2\Documents\maxdesk.ini2
2015-09-08 16:56 - 2013-11-28 12:10 - 00004224 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{341B1B07-5BFC-4DE2-AB2A-5B3A62028BA8}
2015-09-08 16:01 - 2012-04-24 20:06 - 00001072 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-08 14:03 - 2015-07-31 12:03 - 00000000 _____ C:\Users\equipo2\Documents\Nuance Image Printer Writer Port
2015-09-08 12:06 - 2015-07-10 07:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-08 10:51 - 2012-05-21 18:56 - 00000000 ____D C:\ProgramData\MFAData
2015-09-08 10:49 - 2014-08-18 11:24 - 00000000 ____D C:\Users\equipo2\OneDrive
2015-09-08 10:49 - 2013-10-22 18:24 - 00000000 ___RD C:\Users\equipo2\Google Drive
2015-09-08 10:49 - 2012-04-17 18:21 - 00000000 ___RD C:\Users\equipo2\Dropbox
2015-09-08 10:49 - 2012-04-17 18:20 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\Dropbox
2015-09-08 10:48 - 2014-09-22 10:56 - 00000000 ___RD C:\Users\equipo2\iCloudDrive
2015-09-08 10:47 - 2013-01-22 17:43 - 00000354 _____ C:\WINDOWS\Tasks\ROC_JAN2013_TB_rmv.job
2015-09-08 10:46 - 2015-08-05 11:35 - 00000000 ____D C:\Users\equipo2
2015-09-08 10:46 - 2015-07-10 07:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-08 10:46 - 2014-08-29 11:08 - 00003052 _____ C:\WINDOWS\System32\Tasks\AutoKMS
2015-09-08 10:46 - 2014-08-29 11:08 - 00000332 _____ C:\WINDOWS\Tasks\AutoKMS.job
2015-09-08 10:46 - 2011-10-14 05:12 - 00000000 ____D C:\ProgramData\truesuite
2015-09-08 10:46 - 2011-10-14 05:07 - 00000000 ____D C:\ProgramData\PDFC
2015-09-08 10:45 - 2015-08-05 11:28 - 00090144 _____ C:\WINDOWS\PFRO.log
2015-09-07 19:06 - 2015-07-10 07:20 - 00018033 _____ C:\WINDOWS\setupact.log
2015-09-07 18:25 - 2015-08-05 05:23 - 00000000 ____D C:\Windows.old
2015-09-07 13:56 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-07 02:29 - 2015-06-24 11:18 - 00000916 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000Core.job
2015-09-05 02:11 - 2012-04-19 19:10 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\Skype
2015-09-04 18:05 - 2015-07-10 04:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-09-04 13:15 - 2012-09-20 12:37 - 00003292 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$
2015-09-04 13:15 - 2012-09-20 12:37 - 00000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$.job
2015-09-03 22:33 - 2013-12-20 20:07 - 00000000 ____D C:\Doctos_Digitales
2015-09-03 14:42 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\rescache
2015-09-03 12:57 - 2013-12-20 20:59 - 00000636 _____ C:\Users\equipo2\CACUSERW.ini
2015-09-02 22:03 - 2015-07-10 04:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-09-02 18:31 - 2012-04-18 18:44 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2015-09-01 18:44 - 2014-01-28 14:41 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-09-01 03:00 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-09-01 03:00 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-31 06:20 - 2015-07-10 05:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-28 13:38 - 2015-07-10 11:26 - 00000000 ____D C:\WINDOWS\OCR
2015-08-27 15:56 - 2012-04-24 20:06 - 00004134 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-27 15:56 - 2012-04-24 20:06 - 00003902 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-27 14:48 - 2012-04-17 20:53 - 00000000 ____D C:\Users\equipo2\AppData\Local\Apple Computer
2015-08-26 19:47 - 2012-04-17 01:32 - 00000000 ____D C:\Users\equipo2\AppData\Local\Microsoft Help
2015-08-26 14:49 - 2012-04-17 22:13 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\BitTorrent
2015-08-25 10:39 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-08-24 21:27 - 2012-04-24 20:06 - 00000000 ____D C:\Users\equipo2\AppData\Local\Google
2015-08-24 19:32 - 2015-08-07 19:13 - 00001481 _____ C:\Users\equipo2\Desktop\DivX Movies.lnk
2015-08-24 19:32 - 2012-04-24 20:06 - 00000000 ____D C:\ProgramData\DivX
2015-08-24 19:32 - 2012-04-24 20:06 - 00000000 ____D C:\Program Files (x86)\DivX
2015-08-24 19:27 - 2014-12-01 11:24 - 00001141 _____ C:\Users\Public\Desktop\DivX Player.lnk
2015-08-24 19:27 - 2013-09-26 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-08-24 19:26 - 2013-09-26 17:44 - 00001206 _____ C:\Users\Public\Desktop\DivX Converter.lnk
2015-08-24 19:26 - 2012-04-24 20:08 - 00000000 ____D C:\Program Files\DivX
2015-08-21 18:19 - 2014-10-29 19:25 - 00003240 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForequipo2
2015-08-21 18:19 - 2014-10-29 19:25 - 00000340 _____ C:\WINDOWS\Tasks\HPCeeScheduleForequipo2.job
2015-08-20 19:05 - 2015-08-05 11:34 - 02138758 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-20 19:05 - 2015-07-10 11:26 - 00929740 _____ C:\WINDOWS\system32\perfh00A.dat
2015-08-20 19:05 - 2015-07-10 11:26 - 00207582 _____ C:\WINDOWS\system32\perfc00A.dat
2015-08-19 21:21 - 2015-08-05 18:25 - 00000000 ____D C:\Users\equipo2\AppData\Local\Comms
2015-08-17 18:30 - 2015-06-16 18:05 - 00000340 _____ C:\Users\equipo2\Downloads\pendientes.txt
2015-08-17 16:38 - 2012-11-09 11:53 - 00000000 ____D C:\Users\equipo2\AppData\Local\Packages
2015-08-17 11:47 - 2015-07-10 07:20 - 05009120 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-17 11:46 - 2013-03-13 09:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-17 11:46 - 2013-03-13 09:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-17 11:44 - 2015-07-10 06:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-17 11:44 - 2015-07-10 06:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-17 10:54 - 2012-04-19 19:10 - 00000000 ____D C:\ProgramData\Skype
2015-08-16 10:54 - 2013-10-22 18:20 - 00002117 _____ C:\Users\Public\Desktop\Google Slides.lnk
2015-08-16 10:54 - 2013-10-22 18:20 - 00002115 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2015-08-16 10:54 - 2013-10-22 18:20 - 00002105 _____ C:\Users\Public\Desktop\Google Docs.lnk
2015-08-16 10:54 - 2013-10-22 18:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-14 13:30 - 2015-04-20 17:39 - 00001042 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-08-14 13:30 - 2015-04-20 17:39 - 00001030 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-08-13 02:30 - 2012-04-17 01:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 02:30 - 2009-07-13 21:34 - 00000513 _____ C:\WINDOWS\win.ini
2015-08-13 02:26 - 2013-03-13 09:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 02:24 - 2013-08-09 17:33 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-13 01:59 - 2012-04-23 11:29 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-10 12:45 - 2015-08-05 13:50 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-08-09 01:45 - 2015-08-05 13:49 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2

==================== Files in the root of some directories =======

2011-10-14 05:12 - 2011-06-09 18:44 - 0002792 _____ () C:\Program Files\HP SimplePass 2011
2012-05-03 20:45 - 2012-05-03 20:45 - 0000701 _____ () C:\Users\equipo2\AppData\Roaming\ConvAPIPlugin.log
2012-04-18 12:55 - 2013-10-24 12:31 - 0003073 _____ () C:\Users\equipo2\AppData\Roaming\Rim.Desktop.Exception.log
2012-04-18 12:41 - 2012-04-18 12:41 - 0001153 _____ () C:\Users\equipo2\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-04-18 12:55 - 2013-10-24 12:31 - 0001232 _____ () C:\Users\equipo2\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-04-26 13:23 - 2014-12-05 16:25 - 0114688 _____ () C:\Users\equipo2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-28 16:49 - 2012-05-28 16:49 - 0034814 _____ () C:\Users\equipo2\AppData\Local\dt.dat
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx04e0
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx0d85
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx0e50
2015-06-17 15:05 - 2015-06-17 15:05 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx1411
2015-06-24 15:36 - 2015-06-24 15:36 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx2814
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx2b34
2015-06-16 14:38 - 2015-06-16 14:38 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3652
2015-06-17 14:57 - 2015-06-17 14:57 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3864
2015-06-29 14:11 - 2015-06-29 14:11 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3b1a
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3b32
2015-07-27 14:40 - 2015-07-27 14:40 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx4778
2015-08-07 14:46 - 2015-08-07 14:46 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx4afe
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx4d05
2015-06-24 15:33 - 2015-06-24 15:33 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx56a7
2015-06-16 14:35 - 2015-06-16 14:35 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx599c
2015-06-26 14:15 - 2015-06-26 14:15 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx5b3e
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx613c
2015-07-03 14:12 - 2015-07-03 14:12 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx679b
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx67f3
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx73f1
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx768d
2015-07-08 14:19 - 2015-07-08 14:19 - 0043485 _____ () C:\Users\equipo2\AppData\Local\Tempdivx7f41
2015-07-06 08:02 - 2015-07-06 08:02 - 0253160 _____ () C:\Users\equipo2\AppData\Local\Tempdivx82f1
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx8726
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx8b82
2015-08-03 14:53 - 2015-08-03 14:53 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx9060
2015-06-24 14:39 - 2015-06-24 14:39 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx9325
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx932f
2015-07-27 14:02 - 2015-07-27 14:02 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx9879
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxa66e
2015-06-26 14:25 - 2015-06-26 14:25 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxa794
2015-08-07 14:57 - 2015-08-07 14:57 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxb293
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxbc46
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivxbedd
2015-06-22 19:56 - 2015-06-22 19:56 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc020
2015-06-19 14:39 - 2015-06-19 14:39 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc52e
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc810
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc816
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxcec1
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxd342
2015-06-11 15:17 - 2015-06-11 15:17 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxddb4
2015-08-07 14:20 - 2015-08-07 14:20 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxe7a0
2015-06-23 14:11 - 2015-06-23 14:11 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxe7fc
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxebe7
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxec16
2015-08-07 19:11 - 2015-08-07 19:11 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxf228
2015-07-31 14:14 - 2015-07-31 14:14 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxf44c
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxf6dc
2012-10-15 17:01 - 2012-10-15 17:01 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-04-19 18:24 - 2012-12-13 22:32 - 0026774 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\equipo2\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9tr6sx.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-04 12:51

==================== End of FRST.txt ============================


2. Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-09-2015
Ran by equipo2 (2015-09-08 22:13:52)
Running from C:\Users\equipo2\Desktop
Windows 10 Home (X64) (2015-08-05 17:09:18)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-1836801894-3176324447-3799621063-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1836801894-3176324447-3799621063-503 - Limited - Disabled)
equipo2 (S-1-5-21-1836801894-3176324447-3799621063-1000 - Administrator - Enabled) => C:\Users\equipo2
Invitado (S-1-5-21-1836801894-3176324447-3799621063-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Spybot - Search and Destroy (Enabled - Out of date) {A16C3F68-9280-E053-1818-342707FECF4D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 15.2.1 - Hewlett-Packard) Hidden
802.11n Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.01.18.0 - Ralink)
8500A909_eDocs (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
8500A909_Help (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
8500A909a (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
ABC Amber Text Converter (HKLM-x32\...\ABC Amber Text Converter) (Version: - )
AC3Filter 1.62b (HKLM-x32\...\AC3Filter_is1) (Version: 1.62b - Alexander Vigovsky)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
Adobe Digital Editions 3.0 (HKLM-x32\...\Adobe Digital Editions 3.0) (Version: 3.0 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.9.149 - Adobe Systems, Inc.)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
Analizador y SDK de MSXML 4.0 SP2 (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Apple Application Support (32 bits) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64 bits) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft ShowBiz (HKLM-x32\...\{4653DA78-3DB2-4F38-A35D-675CA0AF49CA}) (Version: - ArcSoft)
Assemblies Redistribuibles de Terceros para GAC (HKLM-x32\...\InstallShield_{A3057FDA-7A5E-4978-A918-F526AC203383}) (Version: 1.00.0000 - Suprema Corte de Justicia de la Nación)
Assemblies Redistribuibles de Terceros para GAC (x32 Version: 1.00.0000 - Suprema Corte de Justicia de la Nación) Hidden
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AuthenTec TrueAPI (Version: 1.3.0.116 - AuthenTec, Inc.) Hidden
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6086 - AVG Technologies)
AVG 2015 (Version: 15.0.4409 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6086 - AVG Technologies) Hidden
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
BitTorrent (HKLM-x32\...\BitTorrent) (Version: 7.6.1 - BitTorrent Inc.)
BlackBerry Desktop Software 6.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 6.1.0.36 - Research In Motion Ltd.)
BlackBerry Desktop Software 6.1 (x32 Version: 6.1.0.36 - Research In Motion Ltd.) Hidden
Blasterball 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden
BPD_DSWizards (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
BPDSoftware (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
BPDSoftware_Ini (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Brother BRAdmin Light 1.18.0001 (HKLM-x32\...\{DB75941E-30C4-4D97-B000-D17C764B998C}) (Version: 1.18.0001 - Brother)
Brother MFL-Pro Suite MFC-7460DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.0.0.0 - Brother Industries, Ltd.)
Brother MFL-Pro Suite MFC-J6510DW (HKLM-x32\...\{17795164-3BC1-4D4F-8ADA-65C895EBFC9A}) (Version: 0.0.78.0 - Brother Industries, Ltd.)
BufferChm (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
CardRecovery 6.00 (HKLM-x32\...\{88D68A69-D247-466B-90DD-575F6BE16230}_is1) (Version: - WinRecovery Software)
CBR Reader (HKLM-x32\...\{EDAAC216-AC73-4152-9654-E12FE5A69F5D}_is1) (Version: - cbrreader.com)
Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
CONTPAQ i® FACTURA ELECTRONICA (Terminal) (HKLM-x32\...\{2BE30865-34B9-418C-84F3-2C9912C2E31E}) (Version: - )
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.8.5511 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.2.1.3922 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
DiskAid 6.7.6.0 (HKLM\...\DiskAid_is1) (Version: 6.7.6.0 - DigiDNA)
DocMgr (x32 Version: 140.0.65.000 - Nombre de su organización) Hidden
DocProc (x32 Version: 140.0.100.000 - Hewlett-Packard) Hidden
Documents To Go Desktop de iOS (HKLM-x32\...\DTGDesktop) (Version: 4.0001.010 - DataViz, Inc.)
DoubleCAD XT 5 - 32 bit (HKLM-x32\...\{62D7EE29-DCCB-4AC6-A491-753C2E01F480}) (Version: 5.0.302 - IMSIDesign)
Dropbox (HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Dropbox) (Version: 3.8.8 - Dropbox, Inc.)
DVD Flick 1.3.0.7 (HKLM-x32\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
ePUBee DRM Removal (HKLM-x32\...\ePUBee DRM Removal) (Version: 3.0.5.1 - ePUBee Inc.)
Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000049}) (Version: 11.0.09 - Adobe Systems Incorporated)
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Fax (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
FileMerlin (HKLM-x32\...\FileMerlin) (Version: - Advanced Computer Innovations, Inc.)
FLAC 1.2.1b (remove only) (HKLM-x32\...\FLAC) (Version: 1.2.1b - Xiph.org)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Books Downloader version 2.5 (HKLM-x32\...\{216729B6-014A-F413-814F-F17F74FBA113}_is1) (Version: 2.5 - GBOOKSDOWNLOADER.COM)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Drive (HKLM-x32\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Earth Pro (HKLM-x32\...\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
GPBaseService2 (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
hopTo (x32 Version: 2.2.8.99 - hopTo Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
hp LaserJet-all-in-one (HKLM-x32\...\hp LaserJet-all-in-one) (Version: - hp)
HP LinkUp (HKLM-x32\...\{DB3147AB-4024-4773-8EC0-A1FE5B44933D}) (Version: 2.01.028 - Hewlett-Packard)
HP My Display (HKLM-x32\...\{1F4DDC90-5923-4E49-A4C7-F3CCC954DCA0}) (Version: 1.03.026 - Portrait Displays, Inc.)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Officejet Pro X476dw MFP Ayuda (HKLM-x32\...\{34A5CFB7-5DD0-486B-9769-E0B2A40D54CB}) (Version: 29.0.0 - Hewlett Packard)
HP Officejet Pro X476dw MFP Software básico del dispositivo (HKLM\...\{35008C62-420F-475B-AD69-37A07E8EB5C7}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Product Detection (HKLM-x32\...\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
HP Setup (HKLM-x32\...\{D35B72B6-F0E4-462B-BDEB-E08032B3B681}) (Version: 8.7.4747.3786 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company)
HP SimplePass PE 2011 (HKLM-x32\...\{00FF4EB6-6AAC-4E9D-A60A-8F388691BB27}) (Version: 5.3.0.194 - Hewlett-Packard)
HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard)
HPProductAssistant (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
iDealshare VideoGo 5.4.3.5410 (HKLM-x32\...\{CC4C06C4-7C78-4aab-B5AF-33FB11CCD829}_is1) (Version: - iDealshare Corporation)
Instalación de DivX (HKLM-x32\...\DivX Setup) (Version: 2.7.0.77 - DivX, LLC)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2430 - Intel Corporation)
iolo technologies' System Mechanic (HKLM-x32\...\{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1) (Version: 14.6.0 - iolo technologies, LLC)
IRISCompressor Pro (HKLM\...\{8F9B92B7-4542-4B54-8957-B2CFCFA3A28F}) (Version: 1.03.0000 - I.R.I.S.)
iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest: The Sleepless Star - Collector's Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3925 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.3925 - CyberLink Corp.) Hidden
LaserAIO (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
liteCam HD (HKLM-x32\...\{49D77BFA-135A-49AD-9A8A-8488EADA562D}) (Version: 5.02.0000 - RSUPPORT)
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
MarketResearch (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Laguna (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft Mathematics (HKLM-x32\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Office Language Interface Pack 2010 - Català (HKLM-x32\...\{95140000-00FF-0403-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0C0A-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Online Services - Ayudante para el inicio de sesión (HKLM\...\{46E637E2-AC34-4B45-B5DF-D20903A3DB61}) (Version: 7.250.4303.0 - Microsoft Corporation)
Microsoft Outlook Hotmail Connector de 64 bits (HKLM\...\{95140000-0081-0C0A-1000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monkey's Audio (HKLM-x32\...\Monkey's Audio_is1) (Version: - )
Mozilla Firefox 30.0 (x86 es-MX) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 es-MX)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MPM (HKLM-x32\...\{8AEA6737-8AF3-47BB-95CE-AAB62BE68985}) (Version: 1.00.0000 - Hewlett-Packard)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MWSnap 3 (HKLM-x32\...\MWSnap 3) (Version: 3.0.0.74 - Mirek Wojtowicz)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.97 - WildTangent) Hidden
Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
Nero 12 (HKLM-x32\...\{80836C86-1305-40C9-B7C9-F3A75266070D}) (Version: 12.5.01900 - Nero AG)
Nero 12 Content Pack (HKLM-x32\...\{4E7AC009-5212-499F-942F-A5AA42AE359E}) (Version: 12.0.00400 - Nero AG)
Network64 (Version: 140.0.215.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation)
PC Suite 2.0 (HKLM-x32\...\PC Suite 2.0) (Version: 12 - Huawei Technologies Co.,Ltd)
PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.54 - PDF Complete, Inc)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.5331 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.5331 - CyberLink Corp.) Hidden
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
ProductContext (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
QFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
QGIS Chugiak 2.4.0 Chugiak (HKLM\...\QGIS Chugiak) (Version: - QGIS Development Team)
QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
RealDownloader (x32 Version: 17.0.9 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.9 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.82 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\...\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
RMP4 (HKLM-x32\...\{F78FC958-7354-43EA-BF26-AFCBFE7B9C18}) (Version: 1.05.0000 - RSUPPORT)
RSCC (HKLM-x32\...\{562CBD30-CA59-4640-862C-99C0ECED4B4C}) (Version: 2.02.0000 - RSUPPORT)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Scan (x32 Version: 140.0.167.000 - Hewlett-Packard) Hidden
Scansoft PDF Professional (x32 Version: - ) Hidden
SDK (x32 Version: 2.26.005 - Portrait Displays, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Sistema Único de Autodeterminación (HKLM-x32\...\{F5DF0EC4-EDCB-43A8-B153-2D1A084EC886}) (Version: 3.3.2 - Instituto Mexicano del Seguro Social)
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
SmartWebPrinting (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.5.43 - Safer-Networking Ltd.)
Status (x32 Version: 140.0.256.000 - Hewlett-Packard) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45862 - TeamViewer)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
Translation Wizard (HKLM-x32\...\ST6UNST #1) (Version: - )
Transporter Desktop (HKLM\...\{b195b641-ea6f-450a-af72-1cc9e8150f67}) (Version: 3.0.23.16902 - Connected Data)
TrayApp (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
Vacation Quest - The Hawaiian Islands (x32 Version: 2.2.0.97 - WildTangent) Hidden
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WebReg (x32 Version: 140.0.213.017 - Hewlett-Packard) Hidden
Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden
WildTangent Games App (HP Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinHTTrack Website Copier 3.46-1 (HKLM-x32\...\WinHTTrack Website Copier_is1) (Version: 3.46.1 - HTTrack)
WinMerge 2.14.0 (HKLM-x32\...\WinMerge_is1) (Version: 2.14.0 - Thingamahoochie Software)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
Xml Viewer (HKLM-x32\...\{F58E04CD-6E76-43C8-AAF1-482225C2910E}) (Version: 3 - MindFusion Limited)
Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1B}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)

==================== Restore Points =========================

31-08-2015 06:17:53 Windows Update
07-09-2015 21:00:38 Punto de control programado

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2015-08-09 01:46 - 00450892 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {006191C9-775F-4673-B578-AABA033E06A0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation)
Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation)
Task: {0E38F228-2857-4D99-88FC-690BE548996F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {189CA6A3-B3B8-4C0C-A8F1-B15CDDB8316E} - System32\Tasks\MirageAgent => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-23] (CyberLink)
Task: {18A5EAFF-70B9-45DF-B911-C5760DC40E7F} - System32\Tasks\HPCeeScheduleForequipo2 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {1DAA6CC7-49C9-45C8-B645-C9A27F6392E9} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: {271ED20E-013A-49C2-A6A4-6FA471DA7C76} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {290A84AC-3A74-4DEE-9A8A-206E00B6CBAC} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {2A0778E6-D680-4121-B7C7-217A3C744130} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {2E6D2F06-598C-409A-9E90-985D6459973E} - System32\Tasks\{DDB84190-CB82-4AAB-AB9A-3B9F7A7BBD94} => S:\HP Scanjet 8250\setup_full_8200.exe
Task: {307DC8E1-3453-447A-9909-83D07C6B7C06} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {34CE0038-9637-4678-9024-491DCB4DFDBF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-23] (Adobe Systems Incorporated)
Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation)
Task: {4644A635-D4A3-4C0E-9EF7-98A2D6AA94B3} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {497ECEE3-4A31-48AC-8C38-D141291AE86E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {4B14F45D-97BE-4BD8-8288-9DA13F859EED} - System32\Tasks\Spybot - Search & Destroy - Scheduled Task => C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
Task: {4BAF5E77-C14C-452B-BDB8-EF63B38A85BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4E8CE9A6-2CEE-4D74-9D3A-2A521D6065CB} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {572C995A-008E-4CF8-939D-9840EB1EC558} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {5D07D650-C6CC-41AE-9CB7-115408DF2120} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2015-06-16] (Safer-Networking Ltd.)
Task: {62EB1E4A-67A7-4012-8410-72B683E68BBC} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {6504B57E-3169-482D-A9E0-8F7EAB10F9CD} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000UA => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-24] (Dropbox, Inc.)
Task: {69205643-4A80-4EC5-A257-9243D2A8E5E1} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6BF60896-C741-4A8F-90B9-1B1F96359D8D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask
Task: {74993205-E975-4D15-9401-C902079B4FBF} - System32\Tasks\iolo Process Governor => C:\Program Files (x86)\iolo\System Mechanic\iologovernor64.exe [2015-07-25] (iolo technologies, LLC)
Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance
Task: {81498868-0FFC-45A8-A738-FE45A3A61771} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {8482C49E-578D-44E8-9BFF-5ACCD4ADDE01} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {8D6E827B-F416-4048-A2F0-B034DFD70A2D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2015-06-16] (Safer-Networking Ltd.)
Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-08-05] (Microsoft Corporation)
Task: {931BE731-178B-4F77-B064-A3227D2D877A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2015-06-16] (Safer-Networking Ltd.)
Task: {976F1F90-1724-4A36-8124-30F584A46022} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {9B0B90A0-57FB-49B9-A6D8-5140FA92FBC9} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {9F47B539-7830-4989-BAA6-4AFADF212E22} - System32\Tasks\{53CE4FEB-32B7-456B-8FBE-2582413AD833} => pcalua.exe -a "C:\Program Files (x86)\Real\RealPlayer\Update\r1puninst.exe" -c RealNetworks|RealPlayer|15.0
Task: {A05B959A-054F-440F-B11E-3E31FD077B33} - System32\Tasks\{7DD3D58F-DC20-4065-BAD9-22E2ADBAF0B0} => S:\HP Scanjet 8250\setup_full_8200.exe
Task: {A1AEA44F-F45F-4FF2-9E74-7D606735847E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {A38C9F11-9DEC-4773-AE74-8D79825B45C1} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager
Task: {B27B5690-5A31-4A5A-98A8-471A0EDF8AC8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B4FA781E-305B-4E67-83F0-164A3A4303D6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {BC560980-D3B9-4296-B243-74DF38CAC8AC} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-08-29] ()
Task: {C2B263D0-E185-4FA0-8FFF-1DFCB02285EB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000Core => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-24] (Dropbox, Inc.)
Task: {C46979B8-45E8-418B-AE41-D176FE0404BA} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr
Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation)
Task: {C8061E61-6883-4F1D-8D99-46162B98E72C} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-04-06] (RealNetworks, Inc.)
Task: {D03F5BC8-358C-496F-B6D1-E8D291EB978B} - System32\Tasks\BackItUp_Launch => C:\Program Files (x86)\Nero\Nero BackItUp\BackItUp.exe
Task: {D29E1030-441E-4C22-9744-CE6DE935EE09} - System32\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {D941DE45-E67D-4787-9EF8-067FD0475725} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {EDF7F459-4DF0-4902-B286-63933FD51365} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000Core.job => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000UA.job => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForequipo2.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\ROC_JAN2013_TB_rmv.job => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job => C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-05 05:22 - 2015-08-05 05:22 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-19 15:20 - 2015-08-11 04:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2014-04-07 03:06 - 2014-04-07 03:06 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2013-04-15 16:02 - 2010-03-15 18:04 - 00143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll
2015-08-29 03:01 - 2015-08-18 02:56 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-29 03:01 - 2015-08-18 02:56 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-07-10 05:59 - 2015-07-10 05:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 05:59 - 2015-07-10 05:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-08-12 01:55 - 2015-08-02 20:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-10 06:00 - 2015-07-10 11:34 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-19 15:21 - 2015-08-11 03:58 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-08-12 01:55 - 2015-08-02 20:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 06:00 - 2015-07-10 11:34 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-06-01 21:00 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-08-26 10:50 - 2015-08-26 10:50 - 03637248 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1508.14010.0_x64__8wekyb3d8bbwe\Calculator.exe
2015-08-05 13:50 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-08-05 13:50 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-08-05 13:50 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-08-05 13:50 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-05-15 16:27 - 2015-05-15 16:27 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-09-08 10:49 - 2015-09-08 10:49 - 00071168 _____ () c:\users\equipo2\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9tr6sx.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00012800 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00779776 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00056320 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00012288 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2012-11-07 14:02 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2015-09-08 10:48 - 2015-09-08 10:48 - 00098816 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32api.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00110080 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\pywintypes27.dll
2015-09-08 10:48 - 2015-09-08 10:48 - 00364544 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\pythoncom27.dll
2015-09-08 10:48 - 2015-09-08 10:48 - 00045568 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_socket.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 01161216 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_ssl.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00320512 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32com.shell.shell.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00713216 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_hashlib.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 01176576 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._core_.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00806400 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._gdi_.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00816128 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._windows_.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 01067008 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._controls_.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00733184 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._misc_.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00682496 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\pysqlite2._sqlite.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00087552 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_ctypes.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00119808 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32file.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00108544 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32security.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00007168 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\hashobjs_ext.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00068096 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\usb_ext.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00167936 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32gui.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00018432 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32event.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00128512 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_elementtree.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00127488 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\pyexpat.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00013824 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\common.time34.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00036864 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_psutil_windows.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00038912 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32inet.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00011264 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32crypt.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00077312 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._html2.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00027136 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_multiprocessing.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00020480 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\_yappi.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00035840 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32process.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00686080 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\unicodedata.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00123392 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._wizard.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00024064 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32pipe.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00010240 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\select.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00025600 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32pdh.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00525640 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\windows._lib_cacheinvalidation.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00017408 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32profile.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00022528 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\win32ts.pyd
2015-09-08 10:48 - 2015-09-08 10:48 - 00078848 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI78442\wx._animate.pyd
2015-09-03 05:02 - 2015-08-27 19:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll
2015-09-03 05:02 - 2015-08-27 19:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:18C06F28
AlternateDataStreams: C:\ProgramData\Temp:48C1F0D9
AlternateDataStreams: C:\ProgramData\Temp:54FC943C
AlternateDataStreams: C:\ProgramData\Temp:7EE134B6
AlternateDataStreams: C:\ProgramData\Temp:AA6D0077
AlternateDataStreams: C:\ProgramData\Temp:D2C8DFF8

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7867 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\equipo2\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Papel tapiz de Galería fotográfica de Windows Live.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^equipo2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk => C:\Windows\pss\Microsoft SharePoint Workspace.lnk.Startup
MSCONFIG\startupfolder: C:^Users^equipo2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^My Program.lnk => C:\Windows\pss\My Program.lnk.Startup
MSCONFIG\startupfolder: C:^Users^equipo2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Recorte de pantalla y Selector de OneNote 2010.lnk => C:\Windows\pss\Recorte de pantalla y Selector de OneNote 2010.lnk.Startup
MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: DT HPO => C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -HPO
MSCONFIG\startupreg: Easybits Recovery => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe
MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
MSCONFIG\startupreg: TkBellExe => "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
MSCONFIG\startupreg: ZumoCast => C:\Program Files (x86)\Zecter\ZumoCast(1.3.2)\ZumoLauncher.lnk
HKLM\...\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "mobilegeni daemon"
HKLM\...\StartupApproved\Run32: => "DivXMediaServer"
HKLM\...\StartupApproved\Run32: => "DivXUpdate"
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\StartupApproved\StartupFolder: => "Recorte de pantalla y Selector de OneNote 2010.lnk"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{602670B1-414B-4FD9-9D0D-A433ACA01190}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{9EF0DA04-7EB2-434D-8372-7864FE461F2E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{EA3D567F-6ED6-41FC-8A52-9CAA4234D00A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{C4568F58-DCE9-459D-B414-F30D05272655}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{3F41E0DC-ABBA-47E2-AEFE-2FACDA8AF2F0}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{ABAA59FE-ABE1-43D1-AD2F-AB1026824621}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{4619D0BD-B52F-47F0-86D7-8F3AE64A209D}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A65AF8B3-D47D-4D95-874C-5B3BEDDBEAB2}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{13C7C6C3-18BD-48C0-ABD1-CE0DA86AB4D5}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{90551A8F-06A0-4B8D-9C32-291735D01F5D}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{F6598A83-4BE8-4EF0-A9E2-4ACC5A4D1392}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{E0F5D52A-8A06-4E94-B8A1-AF047702CAA9}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{D12A4DED-285B-41E1-B890-26A29B61E1E9}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{56E32CA6-E4D7-4FF3-9E41-547CC22620E8}] => (Allow) LPort=5357
FirewallRules: [{D540AAC5-1C17-4643-A6A8-92B77D36E9BE}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\DeviceSetup.exe
FirewallRules: [{3B56BC6C-C0F3-400A-A7F1-C4E6082CCFCC}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\bin\SendAFax.exe
FirewallRules: [{D178DA30-B2D2-4680-8763-0C9314199739}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\bin\DigitalWizards.exe
FirewallRules: [{B3D96062-510B-4005-AAFE-A9CA6040BBB9}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\bin\FaxApplications.exe
FirewallRules: [{DE5BAF1A-524B-4A21-B4EC-BF228576E48C}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{7D3063DC-666F-4CB3-AAC4-3D0F71836533}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C6173889-D1C0-462E-914F-8232A938EB7D}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{1BDC3605-544F-4D8F-9239-6BC9C4FDFFC3}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{0B6EAAE3-680D-41E0-A5CF-53364B2CE701}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{90B6F2A8-2464-4BA4-B501-9D56C59DCB87}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{A867EE5F-B524-4614-A064-4B57A1713F78}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{03CC303E-B0F8-4459-ABF8-A981BFBB8BB5}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{2F7D2BE0-574B-44F4-ADF4-76CBC5C82143}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{DBC6725B-7AD7-4037-B5D8-9378F8F735A1}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{04FD52DB-401C-4BF2-B868-F62929628D68}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{EC4498B6-37C6-470F-A94E-E9D3ED13AD2F}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C2ABDBD0-082C-4EB9-B30C-6855C79774D6}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{4EE2AE59-40CA-49D7-8E15-FCBD02230C90}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{E5CDE0C8-1392-4CA3-AA12-4F4A1DB64B7A}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{6B7619BD-0ACD-4684-B908-10BA2A0AEFD1}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{D7BA6844-B4D6-4BC1-AB7F-4F91EBAAA1A6}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{6DD76C3C-6DB8-428F-9F6E-A95DC8EE9C26}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{4F414A8F-724B-41B6-836F-7D9138422E6F}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{463AF312-EAAD-4409-9F5D-15B59ECD75DA}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{BC370537-04B5-495E-B27E-EFC9AA89E522}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B5E51CA6-E31F-4316-AF94-DC9723C2FA55}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{05559FC2-036C-4778-90AB-E2FCB21F1A35}] => (Allow) C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{2F191DBE-70A7-4A5F-BD40-B94FECFC9777}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{9D4F038E-657C-45DF-8093-472ACD0ECA81}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{94FDA9B0-8CD3-4218-8BDC-EFE63EAE0B49}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{765E9C24-60B0-4A2A-9F81-E8A81067300E}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{1350EC8B-616A-4813-97C3-CE8D32A6DFC4}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{9135E5E8-CEC8-43EC-863A-235D2698D514}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B0167045-4531-4324-8C51-CF03768AA921}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{21B82B6A-6959-4003-B3D9-B35C2EFF27A5}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{EEFD998C-D074-4599-B368-0F4A237A23D0}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{07246634-E388-4904-B8F8-41731D54C091}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{03A3AD35-B5E3-4BE0-96D9-1FE8BC2C8810}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{64E8BDB5-18C8-40DA-BA46-457F663E06E1}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{72429B90-06DB-4A4A-B6C0-FAA62C5EAB00}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B95EEA77-A059-4C16-8F0B-8E41E95FA2BE}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{4C85EE3B-87DF-4C08-AB0A-9052BECC6D03}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{7ACC47BD-F892-4277-9602-F84FE1E5EEA2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{1AB2B9DB-91A4-4B76-99AB-EE52ECD716BA}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{6C001C1B-A909-4914-BC14-6A47411658FC}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C2BA24C7-0D16-406A-8655-70C9631FFFA0}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C01F28DC-7D39-4FCA-9D12-AE3D42C2E40C}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{65559B2A-5E3A-4FA0-9CF3-D6065B85CF29}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B1CC9843-9941-4F37-A3BC-17872AF9891C}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{CE630510-07EA-4BED-8743-78FDC7847722}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{DF6F4657-79A8-416B-891A-A183932B213F}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{3C7EDE0E-8744-4555-BDF4-2EDEE6904E88}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{08299849-C495-4E18-8FB1-481A1580F966}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{5A0B98DD-C180-41FC-9C24-A6EBA799D7AD}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{2D9492DA-4735-4257-9E80-8F372B308BFF}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [UDP Query User{0BBD4AB3-3459-4569-8DB8-1DFA03DADD07}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [TCP Query User{BC179648-AE58-40ED-9936-3083D58FCBD5}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [UDP Query User{9E27297B-4310-48F0-AF06-AFA34A686A7F}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [TCP Query User{E089E5DF-FBFF-4459-B8F1-CD449C8D5FE9}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [UDP Query User{AEBA4B43-86C8-4FEA-86C4-07D2DE523BDD}C:\program files (x86)\logmein\ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein\ignition\lmiignition.exe
FirewallRules: [TCP Query User{E84F1C21-144D-4D9E-A536-09C75F98237F}C:\program files (x86)\logmein\ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein\ignition\lmiignition.exe
FirewallRules: [UDP Query User{6A43DE16-6D88-445B-8C9F-1FC76745B121}C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe
FirewallRules: [TCP Query User{2188EABB-CBCA-478B-9730-7A905D1BE913}C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe
FirewallRules: [{B608C4BA-C864-4742-9AFF-612F771A1A2E}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{3C817A44-C518-4513-85DA-E42A28139AFB}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{025BB7D8-BBCF-45CB-86FD-522D77F329A6}] => (Allow) C:\Program Files (x86)\Connected Data\Transporter\Transporter Desktop.exe
FirewallRules: [UDP Query User{1833F072-94CB-410C-ACA2-D88E9D5EB30A}C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe
FirewallRules: [TCP Query User{0CD46CB2-6ADA-4C40-B43A-E00D4A5C6BF0}C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe
FirewallRules: [{4EBC6261-02A3-47B3-8844-2FB41BC352D4}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{FA89BB91-50EC-402E-B050-F505ED543201}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{4F19CBB7-58E1-43B3-ABEF-C03EC7E93C92}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [{2948DBF9-0757-488F-9AA0-D534C5493AEB}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [{654C287A-EA1C-4DCB-B894-D89581E017BF}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [{8F095B1E-CC56-47DA-A11F-B73F15240EDC}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [UDP Query User{38097A57-131C-453E-8A03-2BFC33DDAEE7}C:\users\equipo2\appdata\local\logmein client\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\logmein client\logmein client.exe
FirewallRules: [TCP Query User{25365052-EB66-4A93-9EF1-14DB17FB8259}C:\users\equipo2\appdata\local\logmein client\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\logmein client\logmein client.exe
FirewallRules: [UDP Query User{37E65D63-0252-4923-A778-9415D666428F}C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe
FirewallRules: [TCP Query User{4665D7E1-F2D1-4269-A94C-ADAFE9AD3DB5}C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe
FirewallRules: [{3F72E247-865D-44FC-A6AA-7DDFF295652A}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{34B9A1C2-D660-474B-A8E6-6C7B845EB10A}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{7AB7D975-AE28-4324-9867-73A91914651E}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{7A732070-C9B9-41C9-A830-FF6D81655FFC}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{2F8AF402-9E02-4B34-85E7-A03C0727B0E1}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe
FirewallRules: [{43376642-8294-45A8-8802-773C5766F83A}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe
FirewallRules: [UDP Query User{FC955311-9C96-4D94-8FC6-3EC64EE155EB}C:\users\equipo2\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\equipo2\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{D1410A63-11BF-4F44-BD99-C28A628B4A54}C:\users\equipo2\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\equipo2\appdata\roaming\spotify\spotify.exe
FirewallRules: [{E7663A1E-8003-412F-8C87-ADAA5B295FA6}] => (Allow) LPort=54925
FirewallRules: [{754582DE-71AD-4804-8EC0-2BBB616B1E21}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{E507F550-5D25-4F7C-B52E-8A7F5CF9D9E2}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{605478D8-8C32-4C8C-A773-86AE50419E36}] => (Allow) C:\Program Files (x86)\Brother\BRAdmin Light\BRAdmLight.exe
FirewallRules: [{955DEBE9-D2A1-4A90-8CB7-F8EF690C6989}] => (Allow) C:\Program Files (x86)\Brother\BRAdmin Light\BRAdmLight.exe
FirewallRules: [{9085D237-CA4A-4BD8-A758-88BD7069BCDA}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{D94EC7C4-6B42-4949-8C68-C7E7EDA38694}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{62049D99-A391-4D91-9566-E465D06991AF}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{F56986E6-BC07-4200-BD70-367DCA0A8563}] => (Allow) LPort=54925
FirewallRules: [{EF10913C-FCC3-430E-98B2-4E1569C75706}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{C7B8ACAA-C5DB-4AD8-AB64-094EADEF3F74}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{F31D639D-B73A-45A5-BF3A-91D1D3D49313}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{D2C83DF4-465D-41CA-B77B-AD4AA337EAE1}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{653E307D-3F07-45BF-B734-6B6C814E817A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EA18EE5F-9B7E-496E-8509-910F9D0AF196}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{41B5E0FA-9B38-4DD0-858F-550EC3040301}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6D34A4AB-6A69-40BE-8CB4-4C4E0D05468C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7828EAEA-7150-42B2-89DC-966F0D46697C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{54FF357B-B14B-4801-A99A-8E11B7AD6BB9}C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{F92B35F8-0C21-4DE6-93DC-0D00A7009A32}C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{2EEEDAB2-5103-4649-B978-58D722DDC1BF}] => (Allow) C:\Users\equipo2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{5A54F9FB-B61D-440B-876E-B2600E138529}] => (Allow) C:\Users\equipo2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{7429280E-0C5C-40E4-A41D-880F82D239D2}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{CC8023A0-1A9D-4DF1-B9CA-BA1E1DA58FAE}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{24958381-3093-434E-BB0D-4968D20ADB62}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{78D02479-FDEF-4BFB-B8D6-D49877BB9D3A}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{8C13627C-5605-40FF-BAD4-9353ED1ACFA0}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{8D0EED06-0876-4587-90BE-F2C5EEDF83B2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{189B5AC1-93F9-4EE4-9033-A3C9F3CF6948}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{77BE7ADB-12F4-41E9-A198-003C0334E968}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{C31A5A43-B510-4C4F-B116-84D57967A9A5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{FFE0A5A8-6B38-4C5E-974F-E21193999788}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{BA5583A6-633F-4582-A57F-0F689E9E351A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{F8DCCF01-3281-479D-9F0A-1F333DF476A4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{04FD3552-FE58-483E-BAC7-28E4B4C17960}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{A88F6FEA-CCF2-4E47-A590-733D7269FBAB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{BEB4433D-88BA-4BE7-9B9B-E55396FF3B76}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{57AC2DBB-A10B-42A4-BD05-3890B1157CF4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{D3FE9A6F-7787-4456-AAFA-888F90F19C12}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{ED034A66-C206-47B1-B945-8E1C03543A06}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{F973E62E-B4EC-4025-A7C6-B35C6225B168}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{A17567C6-5590-4FCB-96EB-58218C541409}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{124DDDCF-D36E-4D38-BCF0-3647CE9E03AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{43417169-D021-4F69-B4A7-875A86BE4403}] => (Allow) C:\Users\equipo2\AppData\Local\Temp\7zS47FD\OJP8500vA909_Full_14\setup\hpznui40.exe
FirewallRules: [{E2CA82A1-0617-460E-A7B3-6F332686646A}] => (Allow) LPort=4482
FirewallRules: [{C35ED76C-4409-42E8-AD89-6EC916F22FD1}] => (Allow) LPort=4482
FirewallRules: [{AB72EDCD-CF18-4148-B99A-E38CF7446458}] => (Allow) LPort=4481
FirewallRules: [{9D440BED-8346-4307-9052-249DA8AD363B}] => (Allow) LPort=4481
FirewallRules: [{705C06F5-0490-4F6F-9ED8-3E1C17691A22}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{05B1F651-B7D9-41B9-B077-D9920BA4A75E}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{E2AF41BF-3BE8-4C62-A739-D1D958B7D334}] => (Allow) C:\Program Files (x86)\BitTorrent\BitTorrent.exe
FirewallRules: [{DB13A562-E256-45AE-8736-21DCD61EF939}] => (Allow) C:\Program Files (x86)\BitTorrent\BitTorrent.exe
FirewallRules: [{71870BD2-0670-4C77-B701-1748E424A02C}] => (Allow) C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{E8FF83C9-3F7E-454E-AD44-52FB8BEDDFCE}] => (Allow) C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{807D0420-20D9-4E4F-8E95-35FC8C0C4B78}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{FF9635DD-8FD8-4E30-9865-81DF5A3BB4F7}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{7B8A9B38-A1DA-4025-A318-AAF279E5704B}] => (Allow) LPort=1900
FirewallRules: [{C524C2DE-430B-447B-AB62-A1EF73264CD6}] => (Allow) LPort=2869
FirewallRules: [{4B73E59D-3482-4B24-B2E6-39A3E104AE0D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{E3FCD2B5-C78B-4BFF-BCF6-3E475E04C1D1}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{E8F87674-6090-43F7-9A37-D212E932530F}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{98DB4464-E44E-4B2E-BF18-A9499232001F}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{4BE995B8-6C6A-4630-B25F-092BA2FB07B8}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{8557FB3D-A5D0-4A5B-A900-93A02EB5F1A5}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{0DCAC1C9-D53B-4811-A09B-0580517EF398}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{C4B7DC19-1EAA-4D1A-9E61-9A261AA0DB1E}] => (Allow) C:\Program Files (x86)\EasyBits For Kids\ezDesktop.exe
FirewallRules: [{2165EFE7-7347-4D7F-BA51-69688E898B8A}] => (Allow) C:\Windows\system32\ezSharedSvcHost.exe
FirewallRules: [{EAFFE664-1D01-4AE3-AF6A-8D16AED31156}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{FB9871E1-F6C4-4983-B78D-B6F5E2AC428D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{462059B2-51E4-489C-98C0-E2279C44664D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{48424CDA-75F3-4FB4-95DB-2BE2EF8B252A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{02BCB6C9-0961-4370-89AD-1DF3E2622A12}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/08/2015 06:54:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa WLXPhotoGallery.exe, versión 15.4.3555.308, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, comprueba el historial de problemas en la sección Seguridad y mantenimiento del Panel de control.

Identificador de proceso: 2ba0

Hora de inicio: 01d0ea9177c4c804

Hora de finalización: 59676

Ruta de la aplicación: C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe

Identificador de informe: bec7affb-5684-11e5-9bcd-e89a8fd5e356

Nombre completo de paquete con errores:

Identificador de aplicación relativa del paquete con errores:

Error: (09/08/2015 10:49:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: OneDrive.exe, versión: 17.3.5930.814, marca de tiempo: 0x55ce6c29
Nombre del módulo con errores: KERNELBASE.dll, versión: 10.0.10240.16384, marca de tiempo: 0x559f3b2a
Código de excepción: 0x80000003
Desplazamiento de errores: 0x00132bd2
Identificador del proceso con errores: 0x1db0
Hora de inicio de la aplicación con errores: 0xOneDrive.exe0
Ruta de acceso de la aplicación con errores: OneDrive.exe1
Ruta de acceso del módulo con errores: OneDrive.exe2
Identificador del informe: OneDrive.exe3
Nombre completo del paquete con errores: OneDrive.exe4
Identificador de aplicación relativa del paquete con errores: OneDrive.exe5

Error: (09/07/2015 11:23:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: backgroundTaskHost.exe, versión: 10.0.10240.16384, marca de tiempo: 0x559f38c5
Nombre del módulo con errores: twinapi.appcore.dll, versión: 10.0.10240.16397, marca de tiempo: 0x55af1390
Código de excepción: 0xc000027b
Desplazamiento de errores: 0x000000000006687f
Identificador del proceso con errores: 0x3130
Hora de inicio de la aplicación con errores: 0xbackgroundTaskHost.exe0
Ruta de acceso de la aplicación con errores: backgroundTaskHost.exe1
Ruta de acceso del módulo con errores: backgroundTaskHost.exe2
Identificador del informe: backgroundTaskHost.exe3
Nombre completo del paquete con errores: backgroundTaskHost.exe4
Identificador de aplicación relativa del paquete con errores: backgroundTaskHost.exe5

Error: (09/07/2015 09:00:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protocolo de detección de nivel de vínculo de Microsoft.

System Error:
Acceso denegado.
.

Error: (09/07/2015 08:59:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: backgroundTaskHost.exe, versión: 10.0.10240.16384, marca de tiempo: 0x559f38c5
Nombre del módulo con errores: twinapi.appcore.dll, versión: 10.0.10240.16397, marca de tiempo: 0x55af1390
Código de excepción: 0xc000027b
Desplazamiento de errores: 0x000000000006687f
Identificador del proceso con errores: 0x39d0
Hora de inicio de la aplicación con errores: 0xbackgroundTaskHost.exe0
Ruta de acceso de la aplicación con errores: backgroundTaskHost.exe1
Ruta de acceso del módulo con errores: backgroundTaskHost.exe2
Identificador del informe: backgroundTaskHost.exe3
Nombre completo del paquete con errores: backgroundTaskHost.exe4
Identificador de aplicación relativa del paquete con errores: backgroundTaskHost.exe5

Error: (09/07/2015 07:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: handle_resolve_request bad interfaceIndex 13

Error: (09/07/2015 07:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: handle_resolve_request bad interfaceIndex 13

Error: (09/07/2015 07:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: handle_resolve_request bad interfaceIndex 13

Error: (09/07/2015 05:07:51 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWN BrtTWN: [2015/09/07 17:07:51.049]: [00008812]: Initialize TwdsMain Class failed!

Error: (09/07/2015 05:07:51 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWN BrtTWN: [2015/09/07 17:07:51.048]: [00008812]: ##### Fatal ERROR!! Create STI-device failed! #####


System errors:
=============
Error: (09/08/2015 10:51:39 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: específico de la aplicaciónLocalActivación{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSERVICIO LOCALS-1-5-19LocalHost (con LRPC)No disponibleNo disponible

Error: (09/08/2015 10:46:40 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio RealPlayer Cloud Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (09/08/2015 10:46:13 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: El servicio Adaptador de escucha Net.Tcp depende del servicio Servicio de uso compartido de puertos Net.Tcp, el cual no pudo iniciarse debido al siguiente error:
%%1058

Error: (09/08/2015 10:46:07 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: El cierre anterior del sistema a las 23:36:23 del ‎07/‎09/‎2015 resultó inesperado.

Error: (09/04/2015 06:13:26 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: específico de la aplicaciónLocalActivación{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSERVICIO LOCALS-1-5-19LocalHost (con LRPC)No disponibleNo disponible

Error: (09/04/2015 06:06:57 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio RealPlayer Cloud Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (09/04/2015 06:06:30 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: El servicio Adaptador de escucha Net.Tcp depende del servicio Servicio de uso compartido de puertos Net.Tcp, el cual no pudo iniciarse debido al siguiente error:
%%1058

Error: (09/04/2015 06:04:46 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Windows Search, pero ocurrió el siguiente error:
%%1056

Error: (09/04/2015 06:04:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Acceso a datos de usuarios_Session1 terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.

Error: (09/04/2015 06:04:44 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Almacenamiento de datos de usuarios_Session1 terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.


Microsoft Office:
=========================
Error: (09/08/2015 06:54:23 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: WLXPhotoGallery.exe15.4.3555.3082ba001d0ea9177c4c80459676C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exebec7affb-5684-11e5-9bcd-e89a8fd5e356

Error: (09/08/2015 10:49:05 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: OneDrive.exe17.3.5930.81455ce6c29KERNELBASE.dll10.0.10240.16384559f3b2a8000000300132bd21db001d0ea4dcdb6ab93C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\OneDrive.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dllad0978e4-a809-4e1d-a95a-754fe52f5fc2

Error: (09/07/2015 11:23:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: backgroundTaskHost.exe10.0.10240.16384559f38c5twinapi.appcore.dll10.0.10240.1639755af1390c000027b000000000006687f313001d0e9edd1112d29C:\WINDOWS\system32\backgroundTaskHost.exeC:\Windows\System32\twinapi.appcore.dll22b35ac4-b7bc-4a12-82bd-7dd223dd8b9dMicrosoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbweApp

Error: (09/07/2015 09:00:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddLegacyDriverFiles: Unable to back up image of binary Protocolo de detección de nivel de vínculo de Microsoft.

System Error:
Acceso denegado.

Error: (09/07/2015 08:59:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: backgroundTaskHost.exe10.0.10240.16384559f38c5twinapi.appcore.dll10.0.10240.1639755af1390c000027b000000000006687f39d001d0e9d99dfbb7c0C:\WINDOWS\system32\backgroundTaskHost.exeC:\Windows\System32\twinapi.appcore.dll69666ae7-0198-4777-af62-c3813d4f9f2eMicrosoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbweApp

Error: (09/07/2015 07:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: handle_resolve_request bad interfaceIndex 13

Error: (09/07/2015 07:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: handle_resolve_request bad interfaceIndex 13

Error: (09/07/2015 07:07:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: ERROR: handle_resolve_request bad interfaceIndex 13

Error: (09/07/2015 05:07:51 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWNBrtTWN: [2015/09/07 17:07:51.049]: [00008812]: Initialize TwdsMain Class failed!

Error: (09/07/2015 05:07:51 PM) (Source: Brother BrLog) (EventID: 1001) (User: )
Description: TWNBrtTWN: [2015/09/07 17:07:51.048]: [00008812]: ##### Fatal ERROR!! Create STI-device failed! #####


CodeIntegrity:
===================================
Date: 2015-08-25 11:19:35.909
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.850
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.778
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.678
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.626
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.568
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:31.662
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:29.477
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:15:53.044
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:15:52.995
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
Percentage of memory in use: 85%
Total physical RAM: 4008.46 MB
Available physical RAM: 568.04 MB
Total Virtual: 5804.85 MB
Available Virtual: 2078.28 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:917.74 GB) (Free:469.92 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:13.24 GB) (Free:1.59 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive h: (EEZV-1TB) (Fixed) (Total:931.28 GB) (Free:92.25 GB) FAT32
Drive l: () (Network) (Total:1863.01 GB) (Free:1449.06 GB) NTFS
Drive r: () (Network) (Total:1863.01 GB) (Free:1449.06 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 825DA4EB)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=13.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 64C09F51)
Partition 1: (Active) - (Size=931.5 GB) - (Type=0C)

==================== End of Addition.txt ============================

Thanks

EEZV

PS. Please let me know what do later, for I have installed the Spybot - Search & Destroy version 2.5

ken545
2015-09-10, 14:04
:snwelcome:

You have markers in your log that suggest your running Microsoft Office without a valid license key ??


Download CKScanner by askey127 from Here (http://downloads.malwareremoval.com/CKScanner.exe) & save it to your Desktop.

Doubleclick CKScanner.exe then click Search For Files
When the cursor hourglass disappears, click Save List To File
A message box will verify the file saved
Please Run this program only once
Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

eezv11
2015-09-11, 03:10
Here is the CKFiles text log:

CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\aci programs (x86)\fmerlin\textures\marble - cracked.emf
c:\program files\qgis chugiak\apps\python27\lib\site-packages\numpy\f2py\crackfortran.py
c:\windows\kmsemulator.exe
c:\windows\autokms\autokms.exe
scanner sequence 3.CA.11.QMNAQZ
----- EOF -----



:snwelcome:
You have markers in your log that suggest your running Microsoft Office without a valid license key ??
[/list]

It's possible, at the office we use an MS Office 2010. I bought a license for the 2013 version for 5 PC, that I upgrade every year and I want to use one at the office, but I haven't because I don't want to lose may PST files from Outlook 2010. I have a lot of Emails saved there, probable since 2006 or before.

Thanks

eezv11

ken545
2015-09-11, 04:41
These two files on your system present when an illegal copy of Microsoft Office is installed, there purpose is to bypass the activation key and let Office run. They suggest that your copy of Office is cracked

c:\windows\kmsemulator.exe
c:\windows\autokms\autokms.exe

eezv11
2015-09-11, 20:36
Thanks.

I'll install my paid version of Office. I still have 1 license left. (I just have to see how to keep the PST files with my old Email messages)

But what about the problem with the opening of other browsers through an unwanted tradeadexchange dot com site? I use chrome and I haven't experieced it with the Iexplorer, safari or mozzilla installed. It doesn't mean that it could happen.

Did you find something in the logfiles that could be doing it?

Thanks again,

eezv11

ken545
2015-09-11, 20:48
Hi

https://support.microsoft.com/en-us/kb/291636

This is why I am concerned about Microsoft Office
https://forums.spybot.info/showthread.php?288-quot-BEFORE-You-POST-quot-(Please-read-this-Procedure-Before-Requesting-Assistance)-Updated
Read number 4 and 5

So back up your PST files, uninstall Office and reinstall a new legal copy


This is as far as we go until Office is legit

After you do the above, open up FRST, checkmark Additions , run a new scan and post both logs

eezv11
2015-09-11, 23:31
Thanks againg,

I understand #4 and I'll make the backup and new installation of the legit software.
Concerning #5, this computer is not part of network on a big enterprise with hundreds of workers. We don't have an IT department.
It's just a personal computer for doing my work.
Which is done during weekdays, so I won't be able to make the backup until Monday and I'll get back to you then.
Hopefully, you can still help me.
Thanks
eezv11

ken545
2015-09-11, 23:44
Thats fine, see you then

eezv11
2015-09-12, 04:30
Hi,

I couldn't wait and I've already made the backup of my PST files, uninstalled Office 2010, installed the legit Office 365 and run the FRST.

Thanks
eezv11


(Note: Unfortunately, I learned this hard way, that my Office 365 is for home use and it doesn't include Outlook which is what I need to read my PST files. I guess I'll have to get the office 365 for enterprise. Or use my legit Office 2007, unless there is no more support for it and/or there are safety risks)

This are the new LOG files:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-09-2015 01
Ran by equipo2 (administrator) on EEZV-EQUIPO2-HP (11-09-2015 20:22:12)
Running from C:\Users\equipo2\Desktop
Loaded Profiles: equipo2 (Available Profiles: equipo2 & DefaultAppPool)
Platform: Windows 10 Home (X64) Language: Español (España, internacional)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Microsoft Online Services\MSOIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Microsoft Online Services\MSOIDSVCM.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\ioloGovernor64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(CyberLink) C:\Program Files (x86)\Cyberlink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Hewlett-Packard Co.) C:\Program Files\hp\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe
(Hewlett-Packard Co.) C:\Program Files\hp\HP Officejet Pro X476dw MFP\Bin\HPNetworkCommunicatorCom.exe
(Dropbox, Inc.) C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Hewlett-Packard) C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(iolo technologies, LLC) C:\Program Files (x86)\iolo\System Mechanic\LiveBoost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\FIRSTRUN.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\AppVShNotify.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\WINWORD.EXE


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [hpsysdrv] => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3730344 2015-07-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2010-10-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [iolo Startup] => C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe [4536120 2015-07-24] (iolo technologies, LLC)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448520 2015-06-24] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861640 2015-06-26] (DivX, LLC)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [OfficeSyncProcess] => "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [AppleIEDAV] => C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1079592 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22344224 2015-07-29] (Google)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [09F184CEBFDA4849CA9645B600CD483758C4028F._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-08-27] (Google Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [ISUSPM] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [205480 2007-08-30] (Macrovision Corporation)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [OneDrive] => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\OneDrive.exe [404064 2015-08-25] (Microsoft Corporation)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [HP Officejet Pro X476dw MFP (NET)] => C:\Program Files\hp\HP Officejet Pro X476dw MFP\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [Dropbox Update] => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-24] (Dropbox, Inc.)
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
SSODL: EldosMountNotificator-cbfs4 - {4BD75115-4D24-454C-9213-B9699D8C1893} - C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs4 - {4BD75115-4D24-454C-9213-B9699D8C1893} - C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [ !0Transporter] -> {D03C19B6-E652-4368-84EC-B86C800C452B} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !1Transporter] -> {F66A1D45-3345-425C-A62A-33081D7E0338} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !2Transporter] -> {18640773-7F8C-4F62-AAE1-862F1CCD3FB4} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !3Transporter] -> {FFB483B1-E093-4457-9547-73D9DDC546A8} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !4Transporter] -> {A16F6DC0-AB73-4068-8725-0AF867039A78} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !5Transporter] -> {6590B207-B84E-4054-9102-BE2118932B3B} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ !6Transporter] -> {845192C8-8E68-4B0F-A871-712DEEFB2D16} => C:\Program Files (x86)\Connected Data\Transporter\TransporterExt.dll [2014-12-08] (Connected Data Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs4] -> {3EEF37CF-AABC-40B3-B6B0-EBD7DFFE78E7} => C:\Windows\system32\cbfsMntNtf4.dll [2013-01-30] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs4] -> {3EEF37CF-AABC-40B3-B6B0-EBD7DFFE78E7} => C:\Windows\SysWOW64\cbfsMntNtf4.dll [2013-01-30] (EldoS Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-05-19]
ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)
Startup: C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-05-13]
ShortcutTarget: Dropbox.lnk -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{1bd54d50-7b1a-4d78-9e99-76f3b53439c3}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{5edaff56-6c60-438c-b20d-1ab10bf61517}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{6ec1d726-53ee-4386-95ca-b57d32f4a517}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{91f4d237-9bb8-4106-ad8b-1261088f384c}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{c860732a-6130-453d-a27f-03278251d84b}: [DhcpNameServer] 172.20.10.1

Internet Explorer:
==================
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPALL/111
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://es.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-04-07] (RealDownloader)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-09-11] (Microsoft Corporation)
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll [2011-06-09] (HP)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll No File
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-24] (Oracle Corporation)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll [2011-06-09] (HP)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-24] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: No Name -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> No File
Toolbar: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-09-11] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\equipo2\AppData\Roaming\Mozilla\Firefox\Profiles\lu9ej73p.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_190.dll [2015-06-23] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-03] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll [2015-06-23] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll [2014-01-28] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2015-08-05] (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-09-11] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-12-19] (Nero AG)
FF Plugin-x32: @real.com/nppl3260;version=17.0.9.17 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-05-19] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.9 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2014-04-07] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.9 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-04-07] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.9 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2014-04-07] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.9.17 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-05-19] (RealPlayer Cloud)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-05-26] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-27] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-03] (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2014-05-19] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-07-24] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2014-05-19] (RealPlayer Cloud)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npatgpc.dll [2015-01-14] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\equipo2\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-01-14] (Cisco WebEx LLC)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mercadolibre-mx.xml [2014-06-06]
FF Extension: anonymoX - C:\Users\equipo2\AppData\Roaming\Mozilla\Firefox\Profiles\lu9ej73p.default\Extensions\client@anonymox.net.xpi [2013-11-06]
FF Extension: Adblock Edge - C:\Users\equipo2\AppData\Roaming\Mozilla\Firefox\Profiles\lu9ej73p.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-06-26]
FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2014-10-02]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2012-10-15]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-05-19]
FF HKLM-x32\...\Firefox\Extensions: [{53D8DD28-1C83-41F3-B171-C2ED5B3E5DE8}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "about:blank","chrome://apps/","hxxp://mysearch.avg.com?cid={77ADA367-98CB-407E-B209-4EF99607BF1B}&mid=9a5a8c99e44047d29d2bbd72a3fc6142-c2e6da9e5645ab5026b71e1047dddfd883ea88b1&lang=en&ds=jt011&coid=avgtbdisjt&cmpid=&pr=sa&d=2014-06-06 07:07:41&v=18.1.0.443&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={77ADA367-98CB-407E-B209-4EF99607BF1B}&mid=9a5a8c99e44047d29d2bbd72a3fc6142-c2e6da9e5645ab5026b71e1047dddfd883ea88b1&lang=en&ds=jt011&coid=avgtbdisjt&cmpid=&pr=sa&d=2014-06-06 07:07:41&v=18.1.7.598&pid=safeguard&sg=&sap=hp"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\gcswf32.dll => No File
CHR Plugin: (Flash) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2191_0\plugins/avgnpss.dll => No File
CHR Plugin: (AVG Internet Security) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_0\npwebsitelogon.dll => No File
CHR Plugin: (Simple Pass 2011) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL => No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL => No File
CHR Plugin: (Microsoft Office) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll => No File
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll => No File
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Java) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll => No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll => No File
CHR Plugin: (RealPlayer) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll => No File
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (iTunes Application Detector) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll => No File
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll => No File
CHR Profile: C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Translator for all languages) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\amdeidgbmcliegnpcbbkhlflkbdpomhk [2014-03-15]
CHR Extension: (Google Drive) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-23]
CHR Extension: (FVD Video Downloader) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjjnhlldkcmeabhjlopelfhidanhdicg [2015-02-16]
CHR Extension: (YouTube) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-04-24]
CHR Extension: (AddThis - Share & Bookmark (new)) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbogdmdefihhljhfeiklfiedefalcde [2012-06-01]
CHR Extension: (Google Search) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-04-24]
CHR Extension: (Ortografía, gramática y diccionario) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhindnacjeiaemdobfpmlbgjgbmkjcl [2014-06-16]
CHR Extension: (Google+) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm [2014-06-11]
CHR Extension: (Chrome Web Store Launcher (by Google)) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\gecgipfabdickgidpmbicneamekgbaej [2014-06-16]
CHR Extension: (Google Docs Offline) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Book Search) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidpecplnodokhjcplkeejdbmjfmlplm [2014-06-16]
CHR Extension: (Kindle Cloud Reader) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-01-10]
CHR Extension: (Dropbox) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2014-03-15]
CHR Extension: (Cisco WebEx Extension) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2014-06-26]
CHR Extension: (Adblock Super) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-08-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-16]
CHR Extension: (Google Mail Checker) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2012-08-03]
CHR Extension: (Google Play Books) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2014-06-16]
CHR Extension: (OneDrive) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2014-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (LogMeIn) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\omkjapkpkiciphacnalicgmmcelfolon [2013-09-05]
CHR Extension: (Gmail) - C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-04-24]
CHR HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\equipo2\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-10-22]
CHR HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-04-06]
CHR HKLM-x32\...\Chrome\Extension: [jpgfhihjicjofdejkbjgnjlaglaciobe] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-06-03]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3518376 2015-07-07] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [314304 2015-07-07] (AVG Technologies CZ, s.r.o.)
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2768472 2015-08-11] (Microsoft Corporation)
R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [129648 2011-05-26] (Portrait Displays, Inc.)
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 ioloSystemService; C:\Program Files (x86)\iolo\Common\Lib\ioloServiceManager.exe [4682040 2015-07-24] (iolo technologies, LLC)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-05] (Microsoft Corporation)
R2 msoidsvc; C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2079520 2012-05-17] (Microsoft Corp.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2013-05-16] (Hewlett-Packard) [File not signed]
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-05] (PDF Complete Inc)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2013-05-16] (Hewlett-Packard) [File not signed]
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-04-06] ()
S2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-05-19] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-04-07] () [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-06-24] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-05] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-05] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [293296 2015-06-26] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [253408 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [226784 2015-06-10] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [295400 2015-06-15] (AVG Technologies CZ, s.r.o.)
R1 cbfs4; C:\Windows\system32\drivers\cbfs4.sys [381632 2013-01-30] (EldoS Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-05] (Microsoft Corporation)
R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2011-10-14] ()
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [32912 2014-11-06] (EldoS Corporation)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-11 20:17 - 2015-09-11 20:17 - 00000000 ____D C:\Users\equipo2\Desktop\FRST-OlderVersion
2015-09-11 20:04 - 2015-09-11 20:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-09-11 20:03 - 2015-09-11 20:03 - 00076588 _____ C:\WINDOWSALGER.tt2
2015-09-11 20:03 - 2015-09-11 20:03 - 00066696 _____ C:\WINDOWSVIVALDII.tt2
2015-09-11 20:03 - 2015-09-11 20:03 - 00056596 _____ C:\WINDOWSHARLOWSI.tt2
2015-09-11 20:03 - 2015-09-11 20:03 - 00047644 _____ C:\WINDOWSBAUHS93.tt2
2015-09-11 20:03 - 2015-09-11 20:03 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-09-11 20:02 - 2015-09-11 20:02 - 01106040 _____ (Microsoft Corporation) C:\Users\equipo2\Downloads\Setup.X86.es-ES_O365HomePremRetail_c2cc5777-dc76-4485-ad25-3fd08a64a9a1_TX_PR_ (1).exe
2015-09-11 19:56 - 2015-09-11 19:56 - 00016148 _____ C:\WINDOWS\system32\EEZV-EQUIPO2-HP_equipo2_HistoryPrediction.bin
2015-09-11 19:37 - 2015-09-11 19:38 - 01106040 _____ (Microsoft Corporation) C:\Users\equipo2\Downloads\Setup.X86.es-ES_O365HomePremRetail_c2cc5777-dc76-4485-ad25-3fd08a64a9a1_TX_PR_.exe
2015-09-11 19:21 - 2015-09-11 19:21 - 78996480 _____ C:\Users\equipo2\Downloads\eezv2003@yahoo.com.pst
2015-09-11 19:21 - 2015-09-11 19:21 - 78742528 _____ C:\Users\equipo2\Downloads\eezv11@prodigy.net.mx.pst
2015-09-11 19:21 - 2015-09-11 19:21 - 4071498752 _____ C:\Users\equipo2\Downloads\Outlook.pst
2015-09-11 19:12 - 2015-09-11 19:21 - 00271360 _____ C:\Users\equipo2\Downloads\2015-09-11 -Mi archivo de datos de Outlook.pst
2015-09-10 19:03 - 2015-09-10 19:03 - 00000338 _____ C:\Users\equipo2\Desktop\ckfiles.txt
2015-09-10 18:58 - 2015-09-10 18:58 - 00468480 _____ () C:\Users\equipo2\Desktop\CKScanner.exe
2015-09-09 10:51 - 2015-08-27 01:04 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-09 10:51 - 2015-08-27 00:55 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-09 10:51 - 2015-08-27 00:16 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-09 10:50 - 2015-09-01 20:20 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-09 10:50 - 2015-09-01 19:25 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-09 10:50 - 2015-09-01 19:25 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-09 10:50 - 2015-08-27 01:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-09 10:50 - 2015-08-27 01:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-09 10:50 - 2015-08-27 00:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-09 10:50 - 2015-08-27 00:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-09 10:50 - 2015-08-27 00:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-09 10:50 - 2015-08-27 00:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-09 10:50 - 2015-08-27 00:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-09 10:50 - 2015-08-27 00:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-09 10:50 - 2015-08-27 00:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-09 10:50 - 2015-08-27 00:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-09 10:50 - 2015-08-27 00:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-09 10:50 - 2015-08-27 00:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-09 10:50 - 2015-08-27 00:42 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-09 10:50 - 2015-08-27 00:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-09 10:50 - 2015-08-27 00:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-09 10:50 - 2015-08-27 00:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-09 10:50 - 2015-08-27 00:23 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-09 10:50 - 2015-08-27 00:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-09 10:50 - 2015-08-27 00:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-09 10:50 - 2015-08-27 00:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-09 10:50 - 2015-08-27 00:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-09 10:50 - 2015-08-27 00:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-09 10:50 - 2015-08-27 00:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-09 10:50 - 2015-08-27 00:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-09 10:50 - 2015-08-27 00:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-09 10:50 - 2015-08-27 00:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-08 22:23 - 2015-09-08 22:23 - 00001846 _____ C:\Users\equipo2\Desktop\aswMBR.txt
2015-09-08 22:23 - 2015-09-08 22:23 - 00000512 _____ C:\Users\equipo2\Desktop\MBR.dat
2015-09-08 22:13 - 2015-09-08 22:16 - 00098419 _____ C:\Users\equipo2\Desktop\Addition.txt
2015-09-08 22:08 - 2015-09-11 20:22 - 00049283 _____ C:\Users\equipo2\Desktop\FRST.txt
2015-09-08 22:08 - 2015-09-11 20:22 - 00000000 ____D C:\FRST
2015-09-08 22:06 - 2015-09-08 22:19 - 05198336 _____ (AVAST Software) C:\Users\equipo2\Desktop\aswMBR.exe
2015-09-08 22:05 - 2015-09-11 20:17 - 02190848 _____ (Farbar) C:\Users\equipo2\Desktop\FRST64.exe
2015-09-08 22:03 - 2015-09-08 22:03 - 00000000 ____D C:\RegBackup
2015-09-07 15:30 - 2015-09-07 15:30 - 00000000 ____D C:\Users\equipo2\AppData\Local\{9E834BE6-A87C-42D1-8ABA-8D4B90727D33}
2015-09-04 18:25 - 2015-09-04 18:25 - 00000051 _____ C:\Users\equipo2\Downloads\bajar audio y video.txt
2015-09-04 16:53 - 2015-09-04 18:04 - 00000000 ____D C:\AdwCleaner
2015-09-03 19:54 - 2015-09-03 19:54 - 00000000 ____D C:\Users\equipo2\AppData\Local\{338CFF5F-D4D9-4345-BE11-67E6BC93B099}
2015-09-03 17:13 - 2015-09-04 18:29 - 00000020 _____ C:\Users\equipo2\Downloads\virus.txt
2015-09-01 19:55 - 2015-09-01 19:55 - 00002040 _____ C:\Users\equipo2\Desktop\LMP771017AM6_SN_147351_ZEVE630620QZ3.pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00002020 _____ C:\Users\equipo2\Desktop\LMP771017AM6_SN_147351_ZEVE630620QZ3.xml - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001984 _____ C:\Users\equipo2\Desktop\Farmacia del Ahorro (hernia).pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001931 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020942.pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001931 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020915.pdf - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001911 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020942.xml - Acceso directo.lnk
2015-09-01 19:55 - 2015-09-01 19:55 - 00001911 _____ C:\Users\equipo2\Desktop\SECFD_20150901_020915.xml - Acceso directo.lnk
2015-09-01 18:45 - 2015-09-01 18:45 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-29 03:02 - 2015-08-20 01:02 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-29 03:01 - 2015-08-20 01:07 - 08019296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-29 03:01 - 2015-08-20 01:06 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-29 03:01 - 2015-08-20 00:26 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-29 03:01 - 2015-08-20 00:21 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-29 03:01 - 2015-08-20 00:16 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-29 03:01 - 2015-08-20 00:13 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-29 03:01 - 2015-08-18 02:56 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-29 03:01 - 2015-08-18 02:55 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-08-29 03:01 - 2015-08-18 02:54 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-29 03:01 - 2015-08-18 02:27 - 01771592 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-29 03:01 - 2015-08-18 02:24 - 00963920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-29 03:01 - 2015-08-18 02:13 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-08-29 03:01 - 2015-08-18 02:13 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-08-29 03:01 - 2015-08-18 02:12 - 02225664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-29 03:01 - 2015-08-18 02:07 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-08-29 03:01 - 2015-08-18 02:04 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-08-29 03:01 - 2015-08-18 02:04 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-29 03:01 - 2015-08-18 01:59 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-08-29 03:01 - 2015-08-18 01:59 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-08-29 03:01 - 2015-08-18 01:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-08-29 03:01 - 2015-08-18 01:57 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-08-29 03:01 - 2015-08-18 01:56 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-08-29 03:01 - 2015-08-18 01:55 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-29 03:01 - 2015-08-18 01:54 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-08-29 03:01 - 2015-08-18 01:54 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-29 03:01 - 2015-08-18 01:52 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-29 03:01 - 2015-08-18 01:50 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-29 03:01 - 2015-08-18 01:49 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-29 03:01 - 2015-08-18 01:49 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-08-29 03:01 - 2015-08-18 01:49 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-08-29 03:01 - 2015-08-18 01:36 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-08-29 03:01 - 2015-08-18 01:35 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-08-29 03:01 - 2015-08-18 01:35 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-08-29 03:01 - 2015-08-18 01:34 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-08-29 03:01 - 2015-08-18 01:29 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-29 03:01 - 2015-08-18 01:26 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-08-29 03:01 - 2015-08-17 23:44 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-08-26 18:00 - 2015-08-26 18:00 - 00000000 ____D C:\Users\equipo2\AppData\Local\{511C519F-3849-4283-9AB5-C3A01D33851A}
2015-08-26 17:45 - 2015-08-26 17:45 - 00056415 _____ C:\Users\equipo2\Desktop\JRT.txt
2015-08-26 17:24 - 2015-08-26 12:34 - 01798560 _____ (Malwarebytes Corporation) C:\Users\equipo2\Desktop\JRT.exe
2015-08-25 23:17 - 2015-08-25 23:17 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-08-25 10:47 - 2015-08-25 10:47 - 00002378 _____ C:\Users\equipo2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-21 13:58 - 2015-08-21 13:58 - 00003274 _____ C:\Users\equipo2\Downloads\PRESENTACIÓN MEDIACIÓN.txt
2015-08-19 15:21 - 2015-08-12 23:22 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-08-19 15:21 - 2015-08-11 05:04 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-08-19 15:21 - 2015-08-11 04:50 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-19 15:21 - 2015-08-11 04:23 - 16706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-19 15:21 - 2015-08-11 04:16 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-19 15:21 - 2015-08-11 04:06 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-08-19 15:21 - 2015-08-11 04:06 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-19 15:21 - 2015-08-11 04:05 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-08-19 15:21 - 2015-08-11 04:03 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-08-19 15:21 - 2015-08-11 03:57 - 13024768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-19 15:21 - 2015-08-11 03:45 - 01820672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-08-19 15:20 - 2015-08-12 23:20 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-08-19 15:20 - 2015-08-12 22:53 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-08-19 15:20 - 2015-08-11 05:04 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-19 15:20 - 2015-08-11 05:04 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-08-19 15:20 - 2015-08-11 05:03 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-08-19 15:20 - 2015-08-11 05:02 - 00554744 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-08-19 15:20 - 2015-08-11 05:02 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-19 15:20 - 2015-08-11 05:02 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-08-19 15:20 - 2015-08-11 04:52 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-08-19 15:20 - 2015-08-11 04:40 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-08-19 15:20 - 2015-08-11 04:40 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-08-19 15:20 - 2015-08-11 04:40 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-08-19 15:20 - 2015-08-11 04:38 - 00454000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-08-19 15:20 - 2015-08-11 04:37 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-08-19 15:20 - 2015-08-11 04:26 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-08-19 15:20 - 2015-08-11 04:21 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-08-19 15:20 - 2015-08-11 04:21 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-08-19 15:20 - 2015-08-11 04:20 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-08-19 15:20 - 2015-08-11 04:19 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-08-19 15:20 - 2015-08-11 04:18 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-08-19 15:20 - 2015-08-11 04:14 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-08-19 15:20 - 2015-08-11 04:13 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-08-19 15:20 - 2015-08-11 04:11 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-08-19 15:20 - 2015-08-11 04:11 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-08-19 15:20 - 2015-08-11 04:10 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-19 15:20 - 2015-08-11 04:10 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 15:20 - 2015-08-11 04:10 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-19 15:20 - 2015-08-11 04:09 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-08-19 15:20 - 2015-08-11 04:08 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-08-19 15:20 - 2015-08-11 04:08 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-08-19 15:20 - 2015-08-11 04:07 - 01178112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-08-19 15:20 - 2015-08-11 04:07 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-19 15:20 - 2015-08-11 04:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-08-19 15:20 - 2015-08-11 04:05 - 00996352 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-08-19 15:20 - 2015-08-11 04:05 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-08-19 15:20 - 2015-08-11 04:02 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-08-19 15:20 - 2015-08-11 04:02 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-08-19 15:20 - 2015-08-11 04:01 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-08-19 15:20 - 2015-08-11 04:00 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-08-19 15:20 - 2015-08-11 04:00 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-08-19 15:20 - 2015-08-11 03:59 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-08-19 15:20 - 2015-08-11 03:58 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-08-19 15:20 - 2015-08-11 03:57 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-08-19 15:20 - 2015-08-11 03:51 - 01916928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-08-19 15:20 - 2015-08-11 03:51 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-08-19 15:20 - 2015-08-11 03:50 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-08-19 15:20 - 2015-08-11 03:50 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-08-19 15:20 - 2015-08-11 03:50 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-08-19 15:20 - 2015-08-11 03:49 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-19 15:20 - 2015-08-11 03:49 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-19 15:20 - 2015-08-11 03:48 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-08-19 15:20 - 2015-08-11 03:47 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-08-19 15:20 - 2015-08-11 03:43 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-08-19 15:20 - 2015-08-11 03:42 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-08-19 15:20 - 2015-08-11 03:40 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-08-19 15:20 - 2015-08-11 03:40 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-08-19 15:20 - 2015-08-11 03:39 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-08-19 15:20 - 2015-08-11 03:38 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-08-17 16:37 - 2015-08-17 16:38 - 00000000 ____D C:\Program Files (x86)\Tagscan5.1.668
2015-08-17 11:47 - 2015-08-17 11:47 - 00074703 _____ C:\WINDOWS\SysWOW64\mfc45.dat
2015-08-12 01:56 - 2015-08-08 01:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 01:56 - 2015-08-08 01:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 01:56 - 2015-08-08 01:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 01:56 - 2015-08-04 23:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-08-12 01:56 - 2015-08-03 23:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-08-12 01:56 - 2015-08-03 21:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 01:56 - 2015-08-03 21:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-08-12 01:56 - 2015-08-02 21:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 01:56 - 2015-08-02 21:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 01:56 - 2015-08-02 20:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 01:56 - 2015-08-02 20:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 01:56 - 2015-08-02 20:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 01:56 - 2015-08-02 20:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 01:56 - 2015-08-02 20:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-08-12 01:56 - 2015-08-02 20:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-08-12 01:55 - 2015-08-08 02:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 01:55 - 2015-08-08 02:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 01:55 - 2015-08-05 22:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 01:55 - 2015-08-05 22:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 01:55 - 2015-08-05 21:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 01:55 - 2015-08-04 23:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 01:55 - 2015-08-04 23:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 01:55 - 2015-08-04 22:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 01:55 - 2015-08-04 22:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-08-12 01:55 - 2015-08-03 23:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 01:55 - 2015-08-03 23:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-08-12 01:55 - 2015-08-03 22:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 01:55 - 2015-08-02 21:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 01:55 - 2015-08-02 21:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-08-12 01:55 - 2015-08-02 21:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 01:55 - 2015-08-02 21:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 01:55 - 2015-08-02 21:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 01:55 - 2015-08-02 21:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 01:55 - 2015-08-02 21:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 01:55 - 2015-08-02 21:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 01:55 - 2015-08-02 21:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 01:55 - 2015-08-02 20:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-08-12 01:55 - 2015-08-02 20:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 01:55 - 2015-08-02 20:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 01:55 - 2015-08-02 20:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 01:55 - 2015-08-02 20:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 01:55 - 2015-08-02 20:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 01:55 - 2015-08-02 20:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 01:55 - 2015-08-02 20:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 01:55 - 2015-08-02 20:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 01:55 - 2015-08-02 20:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 01:55 - 2015-08-02 20:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 01:55 - 2015-08-02 20:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 01:55 - 2015-08-02 20:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 01:55 - 2015-08-02 20:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 01:55 - 2015-08-02 20:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 01:55 - 2015-08-02 20:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-08-12 01:55 - 2015-08-02 20:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-08-12 01:55 - 2015-08-02 20:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 01:55 - 2015-08-02 20:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 01:55 - 2015-08-02 20:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-08-12 01:55 - 2015-08-02 20:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 01:55 - 2015-08-02 19:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-11 20:13 - 2012-04-25 16:32 - 00000838 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-09-11 20:05 - 2011-10-14 04:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-09-11 20:04 - 2012-04-17 00:49 - 00000000 ____D C:\Users\equipo2\AppData\Local\VirtualStore
2015-09-11 20:01 - 2012-04-24 20:06 - 00001076 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-11 19:59 - 2015-07-10 07:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-11 19:59 - 2012-04-17 18:21 - 00000000 ___RD C:\Users\equipo2\Dropbox
2015-09-11 19:59 - 2012-04-17 18:20 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\Dropbox
2015-09-11 19:58 - 2014-08-18 11:24 - 00000000 ____D C:\Users\equipo2\OneDrive
2015-09-11 19:58 - 2013-10-22 18:24 - 00000000 ___RD C:\Users\equipo2\Google Drive
2015-09-11 19:58 - 2012-04-24 20:06 - 00001072 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-11 19:57 - 2014-09-22 10:56 - 00000000 ___RD C:\Users\equipo2\iCloudDrive
2015-09-11 19:56 - 2013-01-22 17:43 - 00000354 _____ C:\WINDOWS\Tasks\ROC_JAN2013_TB_rmv.job
2015-09-11 19:55 - 2015-07-10 07:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-09-11 19:55 - 2015-07-10 07:20 - 05006016 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-11 19:55 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-09-11 19:55 - 2014-08-29 11:08 - 00003052 _____ C:\WINDOWS\System32\Tasks\AutoKMS
2015-09-11 19:55 - 2014-08-29 11:08 - 00000332 _____ C:\WINDOWS\Tasks\AutoKMS.job
2015-09-11 19:55 - 2011-10-14 05:07 - 00000000 ____D C:\ProgramData\PDFC
2015-09-11 19:54 - 2015-08-05 11:28 - 00096222 _____ C:\WINDOWS\PFRO.log
2015-09-11 19:53 - 2015-07-10 04:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-09-11 19:51 - 2015-07-10 11:34 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-11 19:51 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-09-11 19:49 - 2012-04-17 01:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-11 19:47 - 2015-08-05 05:16 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-09-11 19:47 - 2015-07-10 11:34 - 00000000 ____D C:\WINDOWS\ShellNew
2015-09-11 19:47 - 2015-07-10 06:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-11 19:47 - 2013-06-04 19:37 - 00000000 ____D C:\Program Files\Microsoft Office
2015-09-11 19:44 - 2009-07-13 21:34 - 00000422 _____ C:\WINDOWS\win.ini
2015-09-11 19:29 - 2015-06-24 11:18 - 00000968 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000UA.job
2015-09-11 19:21 - 2012-04-17 17:37 - 00000000 ____D C:\Users\equipo2\Documents\Archivos de Outlook
2015-09-11 15:26 - 2013-11-28 12:10 - 00004224 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{341B1B07-5BFC-4DE2-AB2A-5B3A62028BA8}
2015-09-11 11:49 - 2015-07-31 12:03 - 00000000 _____ C:\Users\equipo2\Documents\Nuance Image Printer Writer Port
2015-09-11 11:49 - 2014-10-30 12:45 - 00000036 ____H C:\Users\equipo2\Documents\PP11Thumbs.ptn2
2015-09-11 11:49 - 2014-07-15 12:56 - 00806360 ____H C:\Users\equipo2\Documents\PP11Thumbs.ptn
2015-09-11 11:49 - 2013-11-04 14:36 - 00000142 ____H C:\Users\equipo2\Documents\maxdesk.ini2
2015-09-11 10:53 - 2012-05-21 18:56 - 00000000 ____D C:\ProgramData\MFAData
2015-09-11 10:14 - 2013-06-05 20:21 - 00000000 ____D C:\Users\equipo2\AppData\Local\07EEFC3E-BFFF-4F02-A4B1-F6FAD94C9CFC.aplzod
2015-09-11 10:05 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-09-11 06:34 - 2011-10-14 05:12 - 00000000 ____D C:\ProgramData\truesuite
2015-09-11 02:29 - 2015-06-24 11:18 - 00000916 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000Core.job
2015-09-10 09:54 - 2015-07-10 05:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-09 22:52 - 2015-07-10 04:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-09-09 18:51 - 2012-04-18 18:44 - 00000052 _____ C:\WINDOWS\SysWOW64\DOErrors.log
2015-09-09 14:19 - 2012-11-09 11:53 - 00000000 ____D C:\Users\equipo2\AppData\Local\Packages
2015-09-09 13:21 - 2013-05-08 19:17 - 00000000 ____D C:\Users\equipo2\Downloads\soporte
2015-09-09 12:05 - 2013-08-09 17:33 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-08 10:46 - 2015-08-05 11:35 - 00000000 ____D C:\Users\equipo2
2015-09-07 19:06 - 2015-07-10 07:20 - 00018033 _____ C:\WINDOWS\setupact.log
2015-09-07 18:25 - 2015-08-05 05:23 - 00000000 ____D C:\Windows.old
2015-09-05 02:11 - 2012-04-19 19:10 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\Skype
2015-09-04 13:15 - 2012-09-20 12:37 - 00003292 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$
2015-09-04 13:15 - 2012-09-20 12:37 - 00000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$.job
2015-09-03 22:33 - 2013-12-20 20:07 - 00000000 ____D C:\Doctos_Digitales
2015-09-03 14:42 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\rescache
2015-09-03 12:57 - 2013-12-20 20:59 - 00000636 _____ C:\Users\equipo2\CACUSERW.ini
2015-09-01 18:44 - 2014-01-28 14:41 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-09-01 03:00 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-08-28 13:38 - 2015-07-10 11:26 - 00000000 ____D C:\WINDOWS\OCR
2015-08-27 15:56 - 2012-04-24 20:06 - 00004134 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-27 15:56 - 2012-04-24 20:06 - 00003902 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-27 14:48 - 2012-04-17 20:53 - 00000000 ____D C:\Users\equipo2\AppData\Local\Apple Computer
2015-08-26 19:47 - 2012-04-17 01:32 - 00000000 ____D C:\Users\equipo2\AppData\Local\Microsoft Help
2015-08-26 18:37 - 2012-04-23 11:29 - 134753440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-26 14:49 - 2012-04-17 22:13 - 00000000 ____D C:\Users\equipo2\AppData\Roaming\BitTorrent
2015-08-25 10:39 - 2015-07-10 06:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-08-24 21:27 - 2012-04-24 20:06 - 00000000 ____D C:\Users\equipo2\AppData\Local\Google
2015-08-24 19:32 - 2015-08-07 19:13 - 00001481 _____ C:\Users\equipo2\Desktop\DivX Movies.lnk
2015-08-24 19:32 - 2012-04-24 20:06 - 00000000 ____D C:\ProgramData\DivX
2015-08-24 19:32 - 2012-04-24 20:06 - 00000000 ____D C:\Program Files (x86)\DivX
2015-08-24 19:27 - 2014-12-01 11:24 - 00001141 _____ C:\Users\Public\Desktop\DivX Player.lnk
2015-08-24 19:27 - 2013-09-26 17:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-08-24 19:26 - 2013-09-26 17:44 - 00001206 _____ C:\Users\Public\Desktop\DivX Converter.lnk
2015-08-24 19:26 - 2012-04-24 20:08 - 00000000 ____D C:\Program Files\DivX
2015-08-21 18:19 - 2014-10-29 19:25 - 00003240 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForequipo2
2015-08-21 18:19 - 2014-10-29 19:25 - 00000340 _____ C:\WINDOWS\Tasks\HPCeeScheduleForequipo2.job
2015-08-20 19:05 - 2015-08-05 11:34 - 02138758 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-20 19:05 - 2015-07-10 11:26 - 00929740 _____ C:\WINDOWS\system32\perfh00A.dat
2015-08-20 19:05 - 2015-07-10 11:26 - 00207582 _____ C:\WINDOWS\system32\perfc00A.dat
2015-08-19 21:21 - 2015-08-05 18:25 - 00000000 ____D C:\Users\equipo2\AppData\Local\Comms
2015-08-17 18:30 - 2015-06-16 18:05 - 00000340 _____ C:\Users\equipo2\Downloads\pendientes.txt
2015-08-17 11:46 - 2013-03-13 09:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-17 11:46 - 2013-03-13 09:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-17 11:44 - 2015-07-10 06:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-17 11:44 - 2015-07-10 06:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-17 10:54 - 2012-04-19 19:10 - 00000000 ____D C:\ProgramData\Skype
2015-08-16 10:54 - 2013-10-22 18:20 - 00002117 _____ C:\Users\Public\Desktop\Google Slides.lnk
2015-08-16 10:54 - 2013-10-22 18:20 - 00002115 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2015-08-16 10:54 - 2013-10-22 18:20 - 00002105 _____ C:\Users\Public\Desktop\Google Docs.lnk
2015-08-16 10:54 - 2013-10-22 18:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-14 13:30 - 2015-04-20 17:39 - 00001042 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-08-14 13:30 - 2015-04-20 17:39 - 00001030 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-08-13 02:26 - 2013-03-13 09:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight

==================== Files in the root of some directories =======

2011-10-14 05:12 - 2011-06-09 18:44 - 0002792 _____ () C:\Program Files\HP SimplePass 2011
2012-05-03 20:45 - 2012-05-03 20:45 - 0000701 _____ () C:\Users\equipo2\AppData\Roaming\ConvAPIPlugin.log
2012-04-18 12:55 - 2013-10-24 12:31 - 0003073 _____ () C:\Users\equipo2\AppData\Roaming\Rim.Desktop.Exception.log
2012-04-18 12:41 - 2012-04-18 12:41 - 0001153 _____ () C:\Users\equipo2\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2012-04-18 12:55 - 2013-10-24 12:31 - 0001232 _____ () C:\Users\equipo2\AppData\Roaming\Rim.DesktopHelper.Exception.log
2012-04-26 13:23 - 2014-12-05 16:25 - 0114688 _____ () C:\Users\equipo2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-28 16:49 - 2012-05-28 16:49 - 0034814 _____ () C:\Users\equipo2\AppData\Local\dt.dat
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx04e0
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx0d85
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx0e50
2015-06-17 15:05 - 2015-06-17 15:05 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx1411
2015-06-24 15:36 - 2015-06-24 15:36 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx2814
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx2b34
2015-06-16 14:38 - 2015-06-16 14:38 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3652
2015-06-17 14:57 - 2015-06-17 14:57 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3864
2015-06-29 14:11 - 2015-06-29 14:11 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3b1a
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx3b32
2015-07-27 14:40 - 2015-07-27 14:40 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx4778
2015-08-07 14:46 - 2015-08-07 14:46 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx4afe
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx4d05
2015-06-24 15:33 - 2015-06-24 15:33 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx56a7
2015-06-16 14:35 - 2015-06-16 14:35 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx599c
2015-06-26 14:15 - 2015-06-26 14:15 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx5b3e
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx613c
2015-07-03 14:12 - 2015-07-03 14:12 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx679b
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx67f3
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivx73f1
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx768d
2015-07-08 14:19 - 2015-07-08 14:19 - 0043485 _____ () C:\Users\equipo2\AppData\Local\Tempdivx7f41
2015-07-06 08:02 - 2015-07-06 08:02 - 0253160 _____ () C:\Users\equipo2\AppData\Local\Tempdivx82f1
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx8726
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx8b82
2015-08-03 14:53 - 2015-08-03 14:53 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx9060
2015-06-24 14:39 - 2015-06-24 14:39 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivx9325
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivx932f
2015-07-27 14:02 - 2015-07-27 14:02 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivx9879
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxa66e
2015-06-26 14:25 - 2015-06-26 14:25 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxa794
2015-08-07 14:57 - 2015-08-07 14:57 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxb293
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxbc46
2015-07-08 02:08 - 2015-07-08 02:08 - 0253196 _____ () C:\Users\equipo2\AppData\Local\Tempdivxbedd
2015-06-22 19:56 - 2015-06-22 19:56 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc020
2015-06-19 14:39 - 2015-06-19 14:39 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc52e
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc810
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxc816
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxcec1
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxd342
2015-06-11 15:17 - 2015-06-11 15:17 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxddb4
2015-08-07 14:20 - 2015-08-07 14:20 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxe7a0
2015-06-23 14:11 - 2015-06-23 14:11 - 0043682 _____ () C:\Users\equipo2\AppData\Local\Tempdivxe7fc
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxebe7
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxec16
2015-08-07 19:11 - 2015-08-07 19:11 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxf228
2015-07-31 14:14 - 2015-07-31 14:14 - 0043494 _____ () C:\Users\equipo2\AppData\Local\Tempdivxf44c
2015-05-19 02:43 - 2015-05-19 02:43 - 0247298 _____ () C:\Users\equipo2\AppData\Local\Tempdivxf6dc
2012-10-15 17:01 - 2012-10-15 17:01 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-04-19 18:24 - 2012-12-13 22:32 - 0026774 _____ () C:\ProgramData\hpzinstall.log

Some files in TEMP:
====================
C:\Users\equipo2\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplzzzbf.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-04 12:51

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-09-2015 01
Ran by equipo2 (2015-09-11 20:23:12)
Running from C:\Users\equipo2\Desktop
Windows 10 Home (X64) (2015-08-05 17:09:18)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrador (S-1-5-21-1836801894-3176324447-3799621063-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1836801894-3176324447-3799621063-503 - Limited - Disabled)
equipo2 (S-1-5-21-1836801894-3176324447-3799621063-1000 - Administrator - Enabled) => C:\Users\equipo2
Invitado (S-1-5-21-1836801894-3176324447-3799621063-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Spybot - Search and Destroy (Enabled - Up to date) {A16C3F68-9280-E053-1818-342707FECF4D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 15.2.1 - Hewlett-Packard) Hidden
802.11n Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.01.18.0 - Ralink)
8500A909_eDocs (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
8500A909_Help (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
8500A909a (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
ABC Amber Text Converter (HKLM-x32\...\ABC Amber Text Converter) (Version: - )
AC3Filter 1.62b (HKLM-x32\...\AC3Filter_is1) (Version: 1.62b - Alexander Vigovsky)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19120 - Adobe Systems Incorporated)
Adobe Digital Editions 3.0 (HKLM-x32\...\Adobe Digital Editions 3.0) (Version: 3.0 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.190 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.9.149 - Adobe Systems, Inc.)
Agatha Christie - Peril at End House (x32 Version: 2.2.0.95 - WildTangent) Hidden
Analizador y SDK de MSXML 4.0 SP2 (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Apple Application Support (32 bits) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64 bits) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft ShowBiz (HKLM-x32\...\{4653DA78-3DB2-4F38-A35D-675CA0AF49CA}) (Version: - ArcSoft)
Assemblies Redistribuibles de Terceros para GAC (HKLM-x32\...\InstallShield_{A3057FDA-7A5E-4978-A918-F526AC203383}) (Version: 1.00.0000 - Suprema Corte de Justicia de la Nación)
Assemblies Redistribuibles de Terceros para GAC (x32 Version: 1.00.0000 - Suprema Corte de Justicia de la Nación) Hidden
Audacity 2.0.2 (HKLM-x32\...\Audacity_is1) (Version: 2.0.2 - Audacity Team)
AuthenTec TrueAPI (Version: 1.3.0.116 - AuthenTec, Inc.) Hidden
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6086 - AVG Technologies)
AVG 2015 (Version: 15.0.4419 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6086 - AVG Technologies) Hidden
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
BitTorrent (HKLM-x32\...\BitTorrent) (Version: 7.6.1 - BitTorrent Inc.)
BlackBerry Desktop Software 6.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 6.1.0.36 - Research In Motion Ltd.)
BlackBerry Desktop Software 6.1 (x32 Version: 6.1.0.36 - Research In Motion Ltd.) Hidden
Blasterball 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden
BPD_DSWizards (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
BPDSoftware (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
BPDSoftware_Ini (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Brother BRAdmin Light 1.18.0001 (HKLM-x32\...\{DB75941E-30C4-4D97-B000-D17C764B998C}) (Version: 1.18.0001 - Brother)
Brother MFL-Pro Suite MFC-7460DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.0.0.0 - Brother Industries, Ltd.)
Brother MFL-Pro Suite MFC-J6510DW (HKLM-x32\...\{17795164-3BC1-4D4F-8ADA-65C895EBFC9A}) (Version: 0.0.78.0 - Brother Industries, Ltd.)
BufferChm (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Cake Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
CardRecovery 6.00 (HKLM-x32\...\{88D68A69-D247-466B-90DD-575F6BE16230}_is1) (Version: - WinRecovery Software)
CBR Reader (HKLM-x32\...\{EDAAC216-AC73-4152-9654-E12FE5A69F5D}_is1) (Version: - cbrreader.com)
Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
CONTPAQ i® FACTURA ELECTRONICA (Terminal) (HKLM-x32\...\{2BE30865-34B9-418C-84F3-2C9912C2E31E}) (Version: - )
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation)
Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CyberLink PowerDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.8.5511 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.2.1.3922 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
DiskAid 6.7.6.0 (HKLM\...\DiskAid_is1) (Version: 6.7.6.0 - DigiDNA)
DocMgr (x32 Version: 140.0.65.000 - Nombre de su organización) Hidden
DocProc (x32 Version: 140.0.100.000 - Hewlett-Packard) Hidden
Documents To Go Desktop de iOS (HKLM-x32\...\DTGDesktop) (Version: 4.0001.010 - DataViz, Inc.)
DoubleCAD XT 5 - 32 bit (HKLM-x32\...\{62D7EE29-DCCB-4AC6-A491-753C2E01F480}) (Version: 5.0.302 - IMSIDesign)
Dropbox (HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\Dropbox) (Version: 3.8.8 - Dropbox, Inc.)
DVD Flick 1.3.0.7 (HKLM-x32\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
ePUBee DRM Removal (HKLM-x32\...\ePUBee DRM Removal) (Version: 3.0.5.1 - ePUBee Inc.)
Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000049}) (Version: 11.0.09 - Adobe Systems Incorporated)
Farm Frenzy (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Fax (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
FileMerlin (HKLM-x32\...\FileMerlin) (Version: - Advanced Computer Innovations, Inc.)
FLAC 1.2.1b (remove only) (HKLM-x32\...\FLAC) (Version: 1.2.1b - Xiph.org)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Books Downloader version 2.5 (HKLM-x32\...\{216729B6-014A-F413-814F-F17F74FBA113}_is1) (Version: 2.5 - GBOOKSDOWNLOADER.COM)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Drive (HKLM-x32\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Earth Pro (HKLM-x32\...\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
GPBaseService2 (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
hopTo (x32 Version: 2.2.8.99 - hopTo Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
hp LaserJet-all-in-one (HKLM-x32\...\hp LaserJet-all-in-one) (Version: - hp)
HP LinkUp (HKLM-x32\...\{DB3147AB-4024-4773-8EC0-A1FE5B44933D}) (Version: 2.01.028 - Hewlett-Packard)
HP My Display (HKLM-x32\...\{1F4DDC90-5923-4E49-A4C7-F3CCC954DCA0}) (Version: 1.03.026 - Portrait Displays, Inc.)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Officejet Pro X476dw MFP Ayuda (HKLM-x32\...\{34A5CFB7-5DD0-486B-9769-E0B2A40D54CB}) (Version: 29.0.0 - Hewlett Packard)
HP Officejet Pro X476dw MFP Software básico del dispositivo (HKLM\...\{35008C62-420F-475B-AD69-37A07E8EB5C7}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Product Detection (HKLM-x32\...\{A436F67F-687E-4736-BD2B-537121A804CF}) (Version: 11.14.0001 - HP)
HP Setup (HKLM-x32\...\{D35B72B6-F0E4-462B-BDEB-E08032B3B681}) (Version: 8.7.4747.3786 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.1.13880.3792 - Hewlett-Packard Company)
HP SimplePass PE 2011 (HKLM-x32\...\{00FF4EB6-6AAC-4E9D-A60A-8F388691BB27}) (Version: 5.3.0.194 - Hewlett-Packard)
HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.9.0.0 - Hewlett-Packard)
HPProductAssistant (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
iDealshare VideoGo 5.4.3.5410 (HKLM-x32\...\{CC4C06C4-7C78-4aab-B5AF-33FB11CCD829}_is1) (Version: - iDealshare Corporation)
Instalación de DivX (HKLM-x32\...\DivX Setup) (Version: 2.7.0.77 - DivX, LLC)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2430 - Intel Corporation)
iolo technologies' System Mechanic (HKLM-x32\...\{55FD1D5A-7AEF-4DA3-8FAF-A71B2A52FFC7}_is1) (Version: 14.6.0 - iolo technologies, LLC)
IRISCompressor Pro (HKLM\...\{8F9B92B7-4542-4B54-8957-B2CFCFA3A28F}) (Version: 1.03.0000 - I.R.I.S.)
iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jewel Quest Solitaire (x32 Version: 2.2.0.95 - WildTangent) Hidden
Jewel Quest: The Sleepless Star - Collector's Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3925 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.3925 - CyberLink Corp.) Hidden
LaserAIO (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
liteCam HD (HKLM-x32\...\{49D77BFA-135A-49AD-9A8A-8488EADA562D}) (Version: 5.02.0000 - RSUPPORT)
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
MarketResearch (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Laguna (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft Mathematics (HKLM-x32\...\{4D090F70-6F08-4B60-9357-A1DFD4458F09}) (Version: 4.0 - Microsoft Corporation)
Microsoft Office 365 - es-es (HKLM\...\O365HomePremRetail - es-es) (Version: 15.0.4753.1002 - Microsoft Corporation)
Microsoft Office Language Interface Pack 2010 - Català (HKLM-x32\...\{95140000-00FF-0403-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0C0A-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Online Services - Ayudante para el inicio de sesión (HKLM\...\{46E637E2-AC34-4B45-B5DF-D20903A3DB61}) (Version: 7.250.4303.0 - Microsoft Corporation)
Microsoft Outlook Hotmail Connector de 64 bits (HKLM\...\{95140000-0081-0C0A-1000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monkey's Audio (HKLM-x32\...\Monkey's Audio_is1) (Version: - )
Mozilla Firefox 30.0 (x86 es-MX) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 es-MX)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MPM (HKLM-x32\...\{8AEA6737-8AF3-47BB-95CE-AAB62BE68985}) (Version: 1.00.0000 - Hewlett-Packard)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MWSnap 3 (HKLM-x32\...\MWSnap 3) (Version: 3.0.0.74 - Mirek Wojtowicz)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.97 - WildTangent) Hidden
Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
Nero 12 (HKLM-x32\...\{80836C86-1305-40C9-B7C9-F3A75266070D}) (Version: 12.5.01900 - Nero AG)
Nero 12 Content Pack (HKLM-x32\...\{4E7AC009-5212-499F-942F-A5AA42AE359E}) (Version: 12.0.00400 - Nero AG)
Network64 (Version: 140.0.215.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4753.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4753.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4753.1002 - Microsoft Corporation) Hidden
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Paquete de idioma de Microsoft Visual Studio 2010 Tools para Office Runtime (x64) - ESN (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - ESN) (Version: 10.0.50903 - Microsoft Corporation)
PC Suite 2.0 (HKLM-x32\...\PC Suite 2.0) (Version: 12 - Huawei Technologies Co.,Ltd)
PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.54 - PDF Complete, Inc)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.5331 - CyberLink Corp.)
Power2Go (x32 Version: 6.1.5331 - CyberLink Corp.) Hidden
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
ProductContext (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
QFolder (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
QGIS Chugiak 2.4.0 Chugiak (HKLM\...\QGIS Chugiak) (Version: - QGIS Development Team)
QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
RealDownloader (x32 Version: 17.0.9 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.9 - RealNetworks)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.82 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Recovery Manager (x32 Version: 5.5.0.4320 - CyberLink Corp.) Hidden
Remote Graphics Receiver (HKLM-x32\...\{16FC3056-90C0-4757-8A68-64D8DA846ADA}) (Version: 5.4.5 - Hewlett-Packard)
RMP4 (HKLM-x32\...\{F78FC958-7354-43EA-BF26-AFCBFE7B9C18}) (Version: 1.05.0000 - RSUPPORT)
RSCC (HKLM-x32\...\{562CBD30-CA59-4640-862C-99C0ECED4B4C}) (Version: 2.02.0000 - RSUPPORT)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Scan (x32 Version: 140.0.167.000 - Hewlett-Packard) Hidden
Scansoft PDF Professional (x32 Version: - ) Hidden
SDK (x32 Version: 2.26.005 - Portrait Displays, Inc.) Hidden
Sistema Único de Autodeterminación (HKLM-x32\...\{F5DF0EC4-EDCB-43A8-B153-2D1A084EC886}) (Version: 3.3.2 - Instituto Mexicano del Seguro Social)
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
SmartWebPrinting (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.5.43 - Safer-Networking Ltd.)
Status (x32 Version: 140.0.256.000 - Hewlett-Packard) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45862 - TeamViewer)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
Translation Wizard (HKLM-x32\...\ST6UNST #1) (Version: - )
Transporter Desktop (HKLM\...\{b195b641-ea6f-450a-af72-1cc9e8150f67}) (Version: 3.0.23.16902 - Connected Data)
TrayApp (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
Vacation Quest - The Hawaiian Islands (x32 Version: 2.2.0.97 - WildTangent) Hidden
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Virtual Villagers - The Secret City (x32 Version: 2.2.0.95 - WildTangent) Hidden
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WebReg (x32 Version: 140.0.213.017 - Hewlett-Packard) Hidden
Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden
WildTangent Games App (HP Games) (x32 Version: 4.0.5.2 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinHTTrack Website Copier 3.46-1 (HKLM-x32\...\WinHTTrack Website Copier_is1) (Version: 3.46.1 - HTTrack)
WinMerge 2.14.0 (HKLM-x32\...\WinMerge_is1) (Version: 2.14.0 - Thingamahoochie Software)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
Xml Viewer (HKLM-x32\...\{F58E04CD-6E76-43C8-AAF1-482225C2910E}) (Version: 3 - MindFusion Limited)
Zinio Reader 4 (HKLM-x32\...\ZinioReader4) (Version: 4.2.4164 - Zinio LLC)
Zinio Reader 4 (x32 Version: 4.2.4164 - Zinio LLC) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1B}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1836801894-3176324447-3799621063-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\equipo2\AppData\Roaming\Dropbox\bin\DropboxExt64.27.dll (Dropbox, Inc.)

==================== Restore Points =========================

31-08-2015 06:17:53 Windows Update
07-09-2015 21:00:38 Punto de control programado
11-09-2015 19:42:02 Removed Microsoft Office Professional Plus 2010

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2015-08-09 01:46 - 00450892 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {006191C9-775F-4673-B578-AABA033E06A0} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation)
Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation)
Task: {0E38F228-2857-4D99-88FC-690BE548996F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {104C2C01-6A4C-46D2-8F00-356A1005F20B} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-09-11] (Microsoft Corporation)
Task: {189CA6A3-B3B8-4C0C-A8F1-B15CDDB8316E} - System32\Tasks\MirageAgent => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-23] (CyberLink)
Task: {18A5EAFF-70B9-45DF-B911-C5760DC40E7F} - System32\Tasks\HPCeeScheduleForequipo2 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {1DAA6CC7-49C9-45C8-B645-C9A27F6392E9} - System32\Tasks\ROC_JAN2013_TB_rmv => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: {271ED20E-013A-49C2-A6A4-6FA471DA7C76} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {290A84AC-3A74-4DEE-9A8A-206E00B6CBAC} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {2A0778E6-D680-4121-B7C7-217A3C744130} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {2E6D2F06-598C-409A-9E90-985D6459973E} - System32\Tasks\{DDB84190-CB82-4AAB-AB9A-3B9F7A7BBD94} => S:\HP Scanjet 8250\setup_full_8200.exe
Task: {307DC8E1-3453-447A-9909-83D07C6B7C06} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {34CE0038-9637-4678-9024-491DCB4DFDBF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-23] (Adobe Systems Incorporated)
Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation)
Task: {4644A635-D4A3-4C0E-9EF7-98A2D6AA94B3} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {497ECEE3-4A31-48AC-8C38-D141291AE86E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {4B14F45D-97BE-4BD8-8288-9DA13F859EED} - System32\Tasks\Spybot - Search & Destroy - Scheduled Task => C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
Task: {4BAF5E77-C14C-452B-BDB8-EF63B38A85BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4E8CE9A6-2CEE-4D74-9D3A-2A521D6065CB} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {572C995A-008E-4CF8-939D-9840EB1EC558} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {5D07D650-C6CC-41AE-9CB7-115408DF2120} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2015-06-16] (Safer-Networking Ltd.)
Task: {62EB1E4A-67A7-4012-8410-72B683E68BBC} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {6504B57E-3169-482D-A9E0-8F7EAB10F9CD} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000UA => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-24] (Dropbox, Inc.)
Task: {69205643-4A80-4EC5-A257-9243D2A8E5E1} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6BF60896-C741-4A8F-90B9-1B1F96359D8D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask
Task: {74993205-E975-4D15-9401-C902079B4FBF} - System32\Tasks\iolo Process Governor => C:\Program Files (x86)\iolo\System Mechanic\iologovernor64.exe [2015-07-25] (iolo technologies, LLC)
Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance
Task: {81498868-0FFC-45A8-A738-FE45A3A61771} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {8482C49E-578D-44E8-9BFF-5ACCD4ADDE01} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {88D696A1-6F27-483B-9BC2-B8A686425647} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-08-11] (Microsoft Corporation)
Task: {8D6E827B-F416-4048-A2F0-B034DFD70A2D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2015-06-16] (Safer-Networking Ltd.)
Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-08-05] (Microsoft Corporation)
Task: {931BE731-178B-4F77-B064-A3227D2D877A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2015-06-16] (Safer-Networking Ltd.)
Task: {976F1F90-1724-4A36-8124-30F584A46022} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {9B0B90A0-57FB-49B9-A6D8-5140FA92FBC9} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-04-07] (RealNetworks, Inc.)
Task: {9F47B539-7830-4989-BAA6-4AFADF212E22} - System32\Tasks\{53CE4FEB-32B7-456B-8FBE-2582413AD833} => pcalua.exe -a "C:\Program Files (x86)\Real\RealPlayer\Update\r1puninst.exe" -c RealNetworks|RealPlayer|15.0
Task: {A05B959A-054F-440F-B11E-3E31FD077B33} - System32\Tasks\{7DD3D58F-DC20-4065-BAD9-22E2ADBAF0B0} => S:\HP Scanjet 8250\setup_full_8200.exe
Task: {A1AEA44F-F45F-4FF2-9E74-7D606735847E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {A38C9F11-9DEC-4773-AE74-8D79825B45C1} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager
Task: {B27B5690-5A31-4A5A-98A8-471A0EDF8AC8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B4FA781E-305B-4E67-83F0-164A3A4303D6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {BC560980-D3B9-4296-B243-74DF38CAC8AC} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe
Task: {C289061F-B726-46B2-9858-82D5CD9DA227} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {C2B263D0-E185-4FA0-8FFF-1DFCB02285EB} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000Core => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-24] (Dropbox, Inc.)
Task: {C46979B8-45E8-418B-AE41-D176FE0404BA} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr
Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation)
Task: {C8061E61-6883-4F1D-8D99-46162B98E72C} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-1836801894-3176324447-3799621063-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-04-06] (RealNetworks, Inc.)
Task: {D03F5BC8-358C-496F-B6D1-E8D291EB978B} - System32\Tasks\BackItUp_Launch => C:\Program Files (x86)\Nero\Nero BackItUp\BackItUp.exe
Task: {D29E1030-441E-4C22-9744-CE6DE935EE09} - System32\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
Task: {D941DE45-E67D-4787-9EF8-067FD0475725} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {E9E20B68-C77D-4AB4-9A18-9C7E41595C63} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-08-11] (Microsoft Corporation)
Task: {EDF7F459-4DF0-4902-B286-63933FD51365} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000Core.job => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1836801894-3176324447-3799621063-1000UA.job => C:\Users\equipo2\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForEEZV-EQUIPO2-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForequipo2.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\ROC_JAN2013_TB_rmv.job => C:\Program Files (x86)\AVG Secure Search\PostInstall\ROC.exe
Task: C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job => C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-05 05:22 - 2015-08-05 05:22 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-08-19 15:20 - 2015-08-11 04:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-04-15 16:02 - 2010-03-15 18:04 - 00143360 _____ () C:\WINDOWS\system32\BrSNMP64.dll
2014-04-07 03:06 - 2014-04-07 03:06 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2015-08-29 03:01 - 2015-08-18 02:56 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-29 03:01 - 2015-08-18 02:56 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-07-10 05:59 - 2015-07-10 05:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-08-12 01:55 - 2015-08-02 20:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-10 06:00 - 2015-07-10 11:34 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-19 15:21 - 2015-08-11 03:58 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-08-12 01:55 - 2015-08-02 20:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-06-01 21:00 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-09-11 20:03 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-08-05 13:50 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-08-05 13:50 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-08-05 13:50 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-08-05 13:50 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-05-15 16:27 - 2015-05-15 16:27 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-09-11 19:58 - 2015-09-11 19:58 - 00071168 _____ () c:\users\equipo2\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplzzzbf.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00012800 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick.2\qtquick2plugin.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00779776 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00056320 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-09-01 18:45 - 2015-08-05 00:26 - 00012288 _____ () C:\Users\equipo2\AppData\Roaming\Dropbox\bin\QtQuick\Window.2\windowplugin.dll
2012-11-07 14:02 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2015-09-11 19:57 - 2015-09-11 19:57 - 00098816 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32api.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00110080 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\pywintypes27.dll
2015-09-11 19:57 - 2015-09-11 19:57 - 00364544 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\pythoncom27.dll
2015-09-11 19:57 - 2015-09-11 19:57 - 00045568 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_socket.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 01161216 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_ssl.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00320512 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32com.shell.shell.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00713216 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_hashlib.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 01176576 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._core_.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00806400 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._gdi_.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00816128 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._windows_.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 01067008 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._controls_.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00733184 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._misc_.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00682496 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\pysqlite2._sqlite.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00087552 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_ctypes.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00119808 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32file.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00108544 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32security.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00007168 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\hashobjs_ext.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00068096 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\usb_ext.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00167936 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32gui.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00018432 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32event.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00128512 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_elementtree.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00127488 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\pyexpat.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00013824 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\common.time34.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00036864 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_psutil_windows.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00038912 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32inet.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00011264 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32crypt.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00077312 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._html2.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00027136 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_multiprocessing.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00020480 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\_yappi.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00035840 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32process.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00686080 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\unicodedata.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00123392 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._wizard.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00024064 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32pipe.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00010240 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\select.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00025600 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32pdh.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00525640 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\windows._lib_cacheinvalidation.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00017408 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32profile.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00022528 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\win32ts.pyd
2015-09-11 19:57 - 2015-09-11 19:57 - 00078848 _____ () C:\Users\equipo2\AppData\Local\Temp\_MEI24602\wx._animate.pyd
2015-09-03 05:02 - 2015-08-27 19:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll
2015-09-03 05:02 - 2015-08-27 19:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll
2015-09-11 20:03 - 2015-09-11 20:03 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2015-09-11 20:03 - 2015-09-11 20:04 - 00194728 _____ () C:\Program Files\Microsoft Office 15\root\office15\IEAWSDC.DLL
2015-09-11 20:03 - 2015-09-11 20:03 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\Office15\AppVIsvStream32.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:18C06F28
AlternateDataStreams: C:\ProgramData\Temp:48C1F0D9
AlternateDataStreams: C:\ProgramData\Temp:54FC943C
AlternateDataStreams: C:\ProgramData\Temp:7EE134B6
AlternateDataStreams: C:\ProgramData\Temp:AA6D0077
AlternateDataStreams: C:\ProgramData\Temp:D2C8DFF8

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7867 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\equipo2\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Papel tapiz de Galería fotográfica de Windows Live.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^equipo2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft SharePoint Workspace.lnk => C:\Windows\pss\Microsoft SharePoint Workspace.lnk.Startup
MSCONFIG\startupfolder: C:^Users^equipo2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^My Program.lnk => C:\Windows\pss\My Program.lnk.Startup
MSCONFIG\startupfolder: C:^Users^equipo2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Recorte de pantalla y Selector de OneNote 2010.lnk => C:\Windows\pss\Recorte de pantalla y Selector de OneNote 2010.lnk.Startup
MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: DT HPO => C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -HPO
MSCONFIG\startupreg: Easybits Recovery => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe
MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
MSCONFIG\startupreg: TkBellExe => "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
MSCONFIG\startupreg: ZumoCast => C:\Program Files (x86)\Zecter\ZumoCast(1.3.2)\ZumoLauncher.lnk
HKLM\...\StartupApproved\StartupFolder: => "RealPlayer Cloud Service UI.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "mobilegeni daemon"
HKLM\...\StartupApproved\Run32: => "DivXMediaServer"
HKLM\...\StartupApproved\Run32: => "DivXUpdate"
HKU\S-1-5-21-1836801894-3176324447-3799621063-1000\...\StartupApproved\StartupFolder: => "Recorte de pantalla y Selector de OneNote 2010.lnk"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{602670B1-414B-4FD9-9D0D-A433ACA01190}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{9EF0DA04-7EB2-434D-8372-7864FE461F2E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{EA3D567F-6ED6-41FC-8A52-9CAA4234D00A}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{C4568F58-DCE9-459D-B414-F30D05272655}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{3F41E0DC-ABBA-47E2-AEFE-2FACDA8AF2F0}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{ABAA59FE-ABE1-43D1-AD2F-AB1026824621}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{4619D0BD-B52F-47F0-86D7-8F3AE64A209D}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{A65AF8B3-D47D-4D95-874C-5B3BEDDBEAB2}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{13C7C6C3-18BD-48C0-ABD1-CE0DA86AB4D5}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{90551A8F-06A0-4B8D-9C32-291735D01F5D}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{F6598A83-4BE8-4EF0-A9E2-4ACC5A4D1392}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{E0F5D52A-8A06-4E94-B8A1-AF047702CAA9}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{D12A4DED-285B-41E1-B890-26A29B61E1E9}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{56E32CA6-E4D7-4FF3-9E41-547CC22620E8}] => (Allow) LPort=5357
FirewallRules: [{D540AAC5-1C17-4643-A6A8-92B77D36E9BE}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\Bin\DeviceSetup.exe
FirewallRules: [{3B56BC6C-C0F3-400A-A7F1-C4E6082CCFCC}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\bin\SendAFax.exe
FirewallRules: [{D178DA30-B2D2-4680-8763-0C9314199739}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\bin\DigitalWizards.exe
FirewallRules: [{B3D96062-510B-4005-AAFE-A9CA6040BBB9}] => (Allow) C:\Program Files\HP\HP Officejet Pro X476dw MFP\bin\FaxApplications.exe
FirewallRules: [{DE5BAF1A-524B-4A21-B4EC-BF228576E48C}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{7D3063DC-666F-4CB3-AAC4-3D0F71836533}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C6173889-D1C0-462E-914F-8232A938EB7D}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{1BDC3605-544F-4D8F-9239-6BC9C4FDFFC3}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{0B6EAAE3-680D-41E0-A5CF-53364B2CE701}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{90B6F2A8-2464-4BA4-B501-9D56C59DCB87}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{A867EE5F-B524-4614-A064-4B57A1713F78}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{03CC303E-B0F8-4459-ABF8-A981BFBB8BB5}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{2F7D2BE0-574B-44F4-ADF4-76CBC5C82143}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{DBC6725B-7AD7-4037-B5D8-9378F8F735A1}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{04FD52DB-401C-4BF2-B868-F62929628D68}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{EC4498B6-37C6-470F-A94E-E9D3ED13AD2F}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C2ABDBD0-082C-4EB9-B30C-6855C79774D6}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{4EE2AE59-40CA-49D7-8E15-FCBD02230C90}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{E5CDE0C8-1392-4CA3-AA12-4F4A1DB64B7A}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{6B7619BD-0ACD-4684-B908-10BA2A0AEFD1}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{D7BA6844-B4D6-4BC1-AB7F-4F91EBAAA1A6}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{6DD76C3C-6DB8-428F-9F6E-A95DC8EE9C26}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{4F414A8F-724B-41B6-836F-7D9138422E6F}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{463AF312-EAAD-4409-9F5D-15B59ECD75DA}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{BC370537-04B5-495E-B27E-EFC9AA89E522}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B5E51CA6-E31F-4316-AF94-DC9723C2FA55}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{05559FC2-036C-4778-90AB-E2FCB21F1A35}] => (Allow) C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{2F191DBE-70A7-4A5F-BD40-B94FECFC9777}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{9D4F038E-657C-45DF-8093-472ACD0ECA81}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{94FDA9B0-8CD3-4218-8BDC-EFE63EAE0B49}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{765E9C24-60B0-4A2A-9F81-E8A81067300E}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{1350EC8B-616A-4813-97C3-CE8D32A6DFC4}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{9135E5E8-CEC8-43EC-863A-235D2698D514}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B0167045-4531-4324-8C51-CF03768AA921}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{21B82B6A-6959-4003-B3D9-B35C2EFF27A5}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{EEFD998C-D074-4599-B368-0F4A237A23D0}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{07246634-E388-4904-B8F8-41731D54C091}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{03A3AD35-B5E3-4BE0-96D9-1FE8BC2C8810}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{64E8BDB5-18C8-40DA-BA46-457F663E06E1}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{72429B90-06DB-4A4A-B6C0-FAA62C5EAB00}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B95EEA77-A059-4C16-8F0B-8E41E95FA2BE}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{4C85EE3B-87DF-4C08-AB0A-9052BECC6D03}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{7ACC47BD-F892-4277-9602-F84FE1E5EEA2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{1AB2B9DB-91A4-4B76-99AB-EE52ECD716BA}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{6C001C1B-A909-4914-BC14-6A47411658FC}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C2BA24C7-0D16-406A-8655-70C9631FFFA0}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{C01F28DC-7D39-4FCA-9D12-AE3D42C2E40C}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{65559B2A-5E3A-4FA0-9CF3-D6065B85CF29}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{B1CC9843-9941-4F37-A3BC-17872AF9891C}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{CE630510-07EA-4BED-8743-78FDC7847722}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{DF6F4657-79A8-416B-891A-A183932B213F}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{3C7EDE0E-8744-4555-BDF4-2EDEE6904E88}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{08299849-C495-4E18-8FB1-481A1580F966}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{5A0B98DD-C180-41FC-9C24-A6EBA799D7AD}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [{2D9492DA-4735-4257-9E80-8F372B308BFF}] => (Allow) C:\Program Files (x86)\Nero\Nero BackItUp\NBService.exe
FirewallRules: [UDP Query User{0BBD4AB3-3459-4569-8DB8-1DFA03DADD07}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [TCP Query User{BC179648-AE58-40ED-9936-3083D58FCBD5}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [UDP Query User{9E27297B-4310-48F0-AF06-AFA34A686A7F}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [TCP Query User{E089E5DF-FBFF-4459-B8F1-CD449C8D5FE9}C:\program files (x86)\divx\divx media server\divxmediaserver.exe] => (Allow) C:\program files (x86)\divx\divx media server\divxmediaserver.exe
FirewallRules: [UDP Query User{AEBA4B43-86C8-4FEA-86C4-07D2DE523BDD}C:\program files (x86)\logmein\ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein\ignition\lmiignition.exe
FirewallRules: [TCP Query User{E84F1C21-144D-4D9E-A536-09C75F98237F}C:\program files (x86)\logmein\ignition\lmiignition.exe] => (Allow) C:\program files (x86)\logmein\ignition\lmiignition.exe
FirewallRules: [UDP Query User{6A43DE16-6D88-445B-8C9F-1FC76745B121}C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe
FirewallRules: [TCP Query User{2188EABB-CBCA-478B-9730-7A905D1BE913}C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaba4.tmp\logmein client.exe
FirewallRules: [{B608C4BA-C864-4742-9AFF-612F771A1A2E}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{3C817A44-C518-4513-85DA-E42A28139AFB}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe
FirewallRules: [{025BB7D8-BBCF-45CB-86FD-522D77F329A6}] => (Allow) C:\Program Files (x86)\Connected Data\Transporter\Transporter Desktop.exe
FirewallRules: [UDP Query User{1833F072-94CB-410C-ACA2-D88E9D5EB30A}C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe
FirewallRules: [TCP Query User{0CD46CB2-6ADA-4C40-B43A-E00D4A5C6BF0}C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmiaeeb.tmp\logmein client.exe
FirewallRules: [{4EBC6261-02A3-47B3-8844-2FB41BC352D4}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{FA89BB91-50EC-402E-B050-F505ED543201}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{4F19CBB7-58E1-43B3-ABEF-C03EC7E93C92}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [{2948DBF9-0757-488F-9AA0-D534C5493AEB}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [{654C287A-EA1C-4DCB-B894-D89581E017BF}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [{8F095B1E-CC56-47DA-A11F-B73F15240EDC}] => (Allow) C:\Program Files (x86)\Compacw\Servidor de Licencias\Facturacion\AppKeyLicenseServerFacturacionI.exe
FirewallRules: [UDP Query User{38097A57-131C-453E-8A03-2BFC33DDAEE7}C:\users\equipo2\appdata\local\logmein client\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\logmein client\logmein client.exe
FirewallRules: [TCP Query User{25365052-EB66-4A93-9EF1-14DB17FB8259}C:\users\equipo2\appdata\local\logmein client\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\logmein client\logmein client.exe
FirewallRules: [UDP Query User{37E65D63-0252-4923-A778-9415D666428F}C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe
FirewallRules: [TCP Query User{4665D7E1-F2D1-4269-A94C-ADAFE9AD3DB5}C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe] => (Allow) C:\users\equipo2\appdata\local\temp\lmi3b60.tmp\logmein client.exe
FirewallRules: [{3F72E247-865D-44FC-A6AA-7DDFF295652A}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{34B9A1C2-D660-474B-A8E6-6C7B845EB10A}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{7AB7D975-AE28-4324-9867-73A91914651E}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{7A732070-C9B9-41C9-A830-FF6D81655FFC}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe
FirewallRules: [{2F8AF402-9E02-4B34-85E7-A03C0727B0E1}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe
FirewallRules: [{43376642-8294-45A8-8802-773C5766F83A}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe
FirewallRules: [UDP Query User{FC955311-9C96-4D94-8FC6-3EC64EE155EB}C:\users\equipo2\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\equipo2\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{D1410A63-11BF-4F44-BD99-C28A628B4A54}C:\users\equipo2\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\equipo2\appdata\roaming\spotify\spotify.exe
FirewallRules: [{E7663A1E-8003-412F-8C87-ADAA5B295FA6}] => (Allow) LPort=54925
FirewallRules: [{754582DE-71AD-4804-8EC0-2BBB616B1E21}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{E507F550-5D25-4F7C-B52E-8A7F5CF9D9E2}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{605478D8-8C32-4C8C-A773-86AE50419E36}] => (Allow) C:\Program Files (x86)\Brother\BRAdmin Light\BRAdmLight.exe
FirewallRules: [{955DEBE9-D2A1-4A90-8CB7-F8EF690C6989}] => (Allow) C:\Program Files (x86)\Brother\BRAdmin Light\BRAdmLight.exe
FirewallRules: [{9085D237-CA4A-4BD8-A758-88BD7069BCDA}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{D94EC7C4-6B42-4949-8C68-C7E7EDA38694}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10g\FAXRX.exe
FirewallRules: [{62049D99-A391-4D91-9566-E465D06991AF}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{F56986E6-BC07-4200-BD70-367DCA0A8563}] => (Allow) LPort=54925
FirewallRules: [{EF10913C-FCC3-430E-98B2-4E1569C75706}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{C7B8ACAA-C5DB-4AD8-AB64-094EADEF3F74}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{F31D639D-B73A-45A5-BF3A-91D1D3D49313}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{D2C83DF4-465D-41CA-B77B-AD4AA337EAE1}] => (Allow) C:\Program Files (x86)\AVG\AVG2013\avgmfapx.exe
FirewallRules: [{653E307D-3F07-45BF-B734-6B6C814E817A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EA18EE5F-9B7E-496E-8509-910F9D0AF196}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{41B5E0FA-9B38-4DD0-858F-550EC3040301}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{6D34A4AB-6A69-40BE-8CB4-4C4E0D05468C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7828EAEA-7150-42B2-89DC-966F0D46697C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{54FF357B-B14B-4801-A99A-8E11B7AD6BB9}C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [TCP Query User{F92B35F8-0C21-4DE6-93DC-0D00A7009A32}C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe] => (Block) C:\users\equipo2\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{2EEEDAB2-5103-4649-B978-58D722DDC1BF}] => (Allow) C:\Users\equipo2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{5A54F9FB-B61D-440B-876E-B2600E138529}] => (Allow) C:\Users\equipo2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{7429280E-0C5C-40E4-A41D-880F82D239D2}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{CC8023A0-1A9D-4DF1-B9CA-BA1E1DA58FAE}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe
FirewallRules: [{24958381-3093-434E-BB0D-4968D20ADB62}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{78D02479-FDEF-4BFB-B8D6-D49877BB9D3A}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{8C13627C-5605-40FF-BAD4-9353ED1ACFA0}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{8D0EED06-0876-4587-90BE-F2C5EEDF83B2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{189B5AC1-93F9-4EE4-9033-A3C9F3CF6948}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{77BE7ADB-12F4-41E9-A198-003C0334E968}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{C31A5A43-B510-4C4F-B116-84D57967A9A5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{FFE0A5A8-6B38-4C5E-974F-E21193999788}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{BA5583A6-633F-4582-A57F-0F689E9E351A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{F8DCCF01-3281-479D-9F0A-1F333DF476A4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{04FD3552-FE58-483E-BAC7-28E4B4C17960}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{A88F6FEA-CCF2-4E47-A590-733D7269FBAB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{BEB4433D-88BA-4BE7-9B9B-E55396FF3B76}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{57AC2DBB-A10B-42A4-BD05-3890B1157CF4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{D3FE9A6F-7787-4456-AAFA-888F90F19C12}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{ED034A66-C206-47B1-B945-8E1C03543A06}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{F973E62E-B4EC-4025-A7C6-B35C6225B168}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{A17567C6-5590-4FCB-96EB-58218C541409}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{124DDDCF-D36E-4D38-BCF0-3647CE9E03AD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{43417169-D021-4F69-B4A7-875A86BE4403}] => (Allow) C:\Users\equipo2\AppData\Local\Temp\7zS47FD\OJP8500vA909_Full_14\setup\hpznui40.exe
FirewallRules: [{E2CA82A1-0617-460E-A7B3-6F332686646A}] => (Allow) LPort=4482
FirewallRules: [{C35ED76C-4409-42E8-AD89-6EC916F22FD1}] => (Allow) LPort=4482
FirewallRules: [{AB72EDCD-CF18-4148-B99A-E38CF7446458}] => (Allow) LPort=4481
FirewallRules: [{9D440BED-8346-4307-9052-249DA8AD363B}] => (Allow) LPort=4481
FirewallRules: [{705C06F5-0490-4F6F-9ED8-3E1C17691A22}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{05B1F651-B7D9-41B9-B077-D9920BA4A75E}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{E2AF41BF-3BE8-4C62-A739-D1D958B7D334}] => (Allow) C:\Program Files (x86)\BitTorrent\BitTorrent.exe
FirewallRules: [{DB13A562-E256-45AE-8736-21DCD61EF939}] => (Allow) C:\Program Files (x86)\BitTorrent\BitTorrent.exe
FirewallRules: [{71870BD2-0670-4C77-B701-1748E424A02C}] => (Allow) C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{E8FF83C9-3F7E-454E-AD44-52FB8BEDDFCE}] => (Allow) C:\Users\equipo2\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{807D0420-20D9-4E4F-8E95-35FC8C0C4B78}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{FF9635DD-8FD8-4E30-9865-81DF5A3BB4F7}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{7B8A9B38-A1DA-4025-A318-AAF279E5704B}] => (Allow) LPort=1900
FirewallRules: [{C524C2DE-430B-447B-AB62-A1EF73264CD6}] => (Allow) LPort=2869
FirewallRules: [{4B73E59D-3482-4B24-B2E6-39A3E104AE0D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{E3FCD2B5-C78B-4BFF-BCF6-3E475E04C1D1}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{E8F87674-6090-43F7-9A37-D212E932530F}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{98DB4464-E44E-4B2E-BF18-A9499232001F}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{4BE995B8-6C6A-4630-B25F-092BA2FB07B8}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP LinkUp\HP LinkUp Viewer.exe
FirewallRules: [{8557FB3D-A5D0-4A5B-A900-93A02EB5F1A5}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{0DCAC1C9-D53B-4811-A09B-0580517EF398}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\Remote Graphics Receiver\rgreceiver.exe
FirewallRules: [{C4B7DC19-1EAA-4D1A-9E61-9A261AA0DB1E}] => (Allow) C:\Program Files (x86)\EasyBits For Kids\ezDesktop.exe
FirewallRules: [{2165EFE7-7347-4D7F-BA51-69688E898B8A}] => (Allow) C:\Windows\system32\ezSharedSvcHost.exe
FirewallRules: [{EAFFE664-1D01-4AE3-AF6A-8D16AED31156}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{FB9871E1-F6C4-4983-B78D-B6F5E2AC428D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{462059B2-51E4-489C-98C0-E2279C44664D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{48424CDA-75F3-4FB4-95DB-2BE2EF8B252A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{02BCB6C9-0961-4370-89AD-1DF3E2622A12}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{F81FB36D-95E8-4E20-B79D-9F76447B15FB}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/11/2015 08:00:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: chrome.exe, versión: 45.0.2454.85, marca de tiempo: 0x55df881b
Nombre del módulo con errores: SHELL32.dll, versión: 10.0.10240.16463, marca de tiempo: 0x55d55b9f
Código de excepción: 0xc0000005
Desplazamiento de errores: 0x0018b992
Identificador del proceso con errores: 0x2268
Hora de inicio de la aplicación con errores: 0xchrome.exe0
Ruta de acceso de la aplicación con errores: chrome.exe1
Ruta de acceso del módulo con errores: chrome.exe2
Identificador del informe: chrome.exe3
Nombre completo del paquete con errores: chrome.exe4
Identificador de aplicación relativa del paquete con errores: chrome.exe5

Error: (09/11/2015 07:58:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: OneDrive.exe, versión: 17.3.5930.814, marca de tiempo: 0x55ce6c29
Nombre del módulo con errores: KERNELBASE.dll, versión: 10.0.10240.16384, marca de tiempo: 0x559f3b2a
Código de excepción: 0x80000003
Desplazamiento de errores: 0x00132bd2
Identificador del proceso con errores: 0x1e64
Hora de inicio de la aplicación con errores: 0xOneDrive.exe0
Ruta de acceso de la aplicación con errores: OneDrive.exe1
Ruta de acceso del módulo con errores: OneDrive.exe2
Identificador del informe: OneDrive.exe3
Nombre completo del paquete con errores: OneDrive.exe4
Identificador de aplicación relativa del paquete con errores: OneDrive.exe5

Error: (09/11/2015 07:49:46 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplicación: Explorer.EXE
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: código de la excepción c0000005, dirección de la excepción 00007FF8F1B2CF8D

Error: (09/11/2015 07:42:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Error en Servicios de cifrado mientras se procesaba el objeto "System Writer" de la llamada OnIdentity().

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protocolo de detección de nivel de vínculo de Microsoft.

System Error:
Acceso denegado.
.

Error: (09/11/2015 06:20:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: backgroundTaskHost.exe, versión: 10.0.10240.16384, marca de tiempo: 0x559f38c5
Nombre del módulo con errores: twinapi.appcore.dll, versión: 10.0.10240.16397, marca de tiempo: 0x55af1390
Código de excepción: 0xc000027b
Desplazamiento de errores: 0x000000000006687f
Identificador del proceso con errores: 0x2c14
Hora de inicio de la aplicación con errores: 0xbackgroundTaskHost.exe0
Ruta de acceso de la aplicación con errores: backgroundTaskHost.exe1
Ruta de acceso del módulo con errores: backgroundTaskHost.exe2
Identificador del informe: backgroundTaskHost.exe3
Nombre completo del paquete con errores: backgroundTaskHost.exe4
Identificador de aplicación relativa del paquete con errores: backgroundTaskHost.exe5

Error: (09/11/2015 05:57:03 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa Microsoft.Photos.exe, versión 15.827.16340.0, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, comprueba el historial de problemas en la sección Seguridad y mantenimiento del Panel de control.

Identificador de proceso: 4450

Hora de inicio: 01d0ece51d84c463

Hora de finalización: 4294967295

Ruta de la aplicación: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe

Identificador de informe: 69e071e6-58d8-11e5-9bcd-e89a8fd5e356

Nombre completo de paquete con errores: Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe

Identificador de aplicación relativa del paquete con errores: App

Error: (09/11/2015 05:57:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: EEZV-EQUIPO2-HP)
Description: Se detuvo el paquete Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe+App porque se tardó demasiado en suspender.

Error: (09/11/2015 04:45:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: El programa Microsoft.Photos.exe, versión 15.827.16340.0, dejó de interactuar con Windows y se cerró. Para ver si hay más información disponible acerca del problema, comprueba el historial de problemas en la sección Seguridad y mantenimiento del Panel de control.

Identificador de proceso: 4480

Hora de inicio: 01d0ecdb168cafc6

Hora de finalización: 4294967295

Ruta de la aplicación: C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe

Identificador de informe: 6295f3db-58ce-11e5-9bcd-e89a8fd5e356

Nombre completo de paquete con errores: Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe

Identificador de aplicación relativa del paquete con errores: App

Error: (09/11/2015 04:45:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: EEZV-EQUIPO2-HP)
Description: Se detuvo el paquete Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe+App porque se tardó demasiado en suspender.

Error: (09/11/2015 01:01:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: backgroundTaskHost.exe, versión: 10.0.10240.16384, marca de tiempo: 0x559f38c5
Nombre del módulo con errores: twinapi.appcore.dll, versión: 10.0.10240.16397, marca de tiempo: 0x55af1390
Código de excepción: 0xc000027b
Desplazamiento de errores: 0x000000000006687f
Identificador del proceso con errores: 0x4994
Hora de inicio de la aplicación con errores: 0xbackgroundTaskHost.exe0
Ruta de acceso de la aplicación con errores: backgroundTaskHost.exe1
Ruta de acceso del módulo con errores: backgroundTaskHost.exe2
Identificador del informe: backgroundTaskHost.exe3
Nombre completo del paquete con errores: backgroundTaskHost.exe4
Identificador de aplicación relativa del paquete con errores: backgroundTaskHost.exe5


System errors:
=============
Error: (09/11/2015 08:03:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: específico de la aplicaciónLocalActivación{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSERVICIO LOCALS-1-5-19LocalHost (con LRPC)No disponibleNo disponible

Error: (09/11/2015 07:55:59 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: El servicio RealPlayer Cloud Service se terminó de manera inesperada. Esto ha sucedido 1 veces.

Error: (09/11/2015 07:55:31 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: El servicio Adaptador de escucha Net.Tcp depende del servicio Servicio de uso compartido de puertos Net.Tcp, el cual no pudo iniciarse debido al siguiente error:
%%1058

Error: (09/11/2015 07:49:56 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Sincronizar host_Session1.

Error: (09/11/2015 07:49:55 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Se agotó el tiempo de espera (30000 ms) para la conexión con el servicio Almacenamiento de datos de usuarios_Session1.

Error: (09/11/2015 07:49:55 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Almacenamiento de datos de usuarios_Session1, pero ocurrió el siguiente error:
%%1056

Error: (09/11/2015 07:49:47 PM) (Source: DCOM) (EventID: 10010) (User: EEZV-EQUIPO2-HP)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (09/11/2015 07:49:47 PM) (Source: DCOM) (EventID: 10010) (User: EEZV-EQUIPO2-HP)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (09/11/2015 07:49:47 PM) (Source: DCOM) (EventID: 10010) (User: EEZV-EQUIPO2-HP)
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}

Error: (09/11/2015 07:49:45 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: El servicio Acceso a datos de usuarios_Session1 terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 10000 milisegundos: Reiniciar el servicio.


Microsoft Office:
=========================
Error: (09/11/2015 08:00:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe45.0.2454.8555df881bSHELL32.dll10.0.10240.1646355d55b9fc00000050018b992226801d0ecf621c3c003C:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\WINDOWS\SYSTEM32\SHELL32.dll327e7fb7-ba4f-438d-911b-5012884db5b0

Error: (09/11/2015 07:58:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: OneDrive.exe17.3.5930.81455ce6c29KERNELBASE.dll10.0.10240.16384559f3b2a8000000300132bd21e6401d0ecf60b09eac5C:\Users\equipo2\AppData\Local\Microsoft\OneDrive\OneDrive.exeC:\WINDOWS\SYSTEM32\KERNELBASE.dlleb1b32c7-2968-41b8-b3b3-418a18cc84da

Error: (09/11/2015 07:49:46 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplicación: Explorer.EXE
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: código de la excepción c0000005, dirección de la excepción 00007FF8F1B2CF8D

Error: (09/11/2015 07:42:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddLegacyDriverFiles: Unable to back up image of binary Protocolo de detección de nivel de vínculo de Microsoft.

System Error:
Acceso denegado.

Error: (09/11/2015 06:20:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: backgroundTaskHost.exe10.0.10240.16384559f38c5twinapi.appcore.dll10.0.10240.1639755af1390c000027b000000000006687f2c1401d0ece7e32dafb4C:\WINDOWS\system32\backgroundTaskHost.exeC:\Windows\System32\twinapi.appcore.dll69536a7a-3be9-479b-931d-c41bc3d7bc45Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbweApp

Error: (09/11/2015 05:57:03 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Microsoft.Photos.exe15.827.16340.0445001d0ece51d84c4634294967295C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe69e071e6-58d8-11e5-9bcd-e89a8fd5e356Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbweApp

Error: (09/11/2015 05:57:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: EEZV-EQUIPO2-HP)
Description: Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe+App

Error: (09/11/2015 04:45:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Microsoft.Photos.exe15.827.16340.0448001d0ecdb168cafc64294967295C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe6295f3db-58ce-11e5-9bcd-e89a8fd5e356Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbweApp

Error: (09/11/2015 04:45:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: EEZV-EQUIPO2-HP)
Description: Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe+App

Error: (09/11/2015 01:01:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: backgroundTaskHost.exe10.0.10240.16384559f38c5twinapi.appcore.dll10.0.10240.1639755af1390c000027b000000000006687f499401d0ecbaeca39271C:\WINDOWS\system32\backgroundTaskHost.exeC:\Windows\System32\twinapi.appcore.dll3d7720de-9d92-4b62-873a-bdd00944ba93Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbweApp


CodeIntegrity:
===================================
Date: 2015-08-25 11:19:35.909
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.850
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.778
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.678
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.626
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:35.568
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:31.662
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:19:29.477
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:15:53.044
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-25 11:15:52.995
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz
Percentage of memory in use: 65%
Total physical RAM: 4008.46 MB
Available physical RAM: 1397.57 MB
Total Virtual: 6056.46 MB
Available Virtual: 2525.48 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:917.74 GB) (Free:467.8 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:13.24 GB) (Free:1.59 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive h: (EEZV-1TB) (Fixed) (Total:931.28 GB) (Free:92.24 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 825DA4EB)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=917.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=13.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 64C09F51)
Partition 1: (Active) - (Size=931.5 GB) - (Type=0C)

==================== End of Addition.txt ============================

eezv11
2015-09-12, 04:53
I noticed that my copy of office 365 includes Outlook and it seems that it didn't do anything to the old files!!

Thanks

eezv11

ken545
2015-09-12, 05:28
Thats good.

Just a heads up, your using Bit Torrent , most everything that is downloaded with a torrent will have some sort of malicious code attached to it. If you look at the Firewall Rules on your Addition log, Bit Torrent has free access in and out of your computer and can bring along anything it likes, my self I would uninstall it.

Lets get to work



-AdwCleaner-by Xplode


Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers




Do not click on any links in the top Advertisment.


http://i24.photobucket.com/albums/c30/ken545/AdwCleaner4.201_zpsxrbk2llq.jpg (http://s24.photobucket.com/user/ken545/media/AdwCleaner4.201_zpsxrbk2llq.jpg.html)




Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.






===============================================================================






http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://www.bleepingcomputer.com/download/junkware-removal-tool/) TO YOUR DESKTOP


Download the one from Bleeping Computer
Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.








===============================================================================


Download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) TO YOUR DESKTOP




Windows XP : Double click on the icon to run it.
Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"




http://i24.photobucket.com/albums/c30/ken545/0841859c-1a35-4dbd-b41a-e720629e3e22_zpst0yckuua.png (http://s24.photobucket.com/user/ken545/media/0841859c-1a35-4dbd-b41a-e720629e3e22_zpst0yckuua.png.html)




On the Dashboard click on Update Now
Go to the Setting Tab
Under Setting go to Detection and Protection
Under PUP and PUM make sure both are set to show Treat Detections as Malware
Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
Then on the Dashboard click on Scan
Make sure to select THREAT SCAN
Then click on Scan
When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
Please paste the log back into this thread for review
Exit Malwarebytes

eezv11
2015-09-14, 21:38
Thanks! These are the last log files:

1) # AdwCleaner v5.007 - Registro generado 14/09/2015 en 10:44:25
# Actualizado 08/09/2015 por Xplode
# Base de datos : 2015-09-10.1 [Servidor]
# Sistema operativo : Windows 10 Home (x64)
# Nombre de usuario : equipo2 - EEZV-EQUIPO2-HP
# Ejecutado desde : C:\Users\equipo2\Desktop\AdwCleaner.exe
# Opción : Escanear
# Apoyo : http://toolslib.net/forum

***** [ Servicios ] *****


***** [ Carpetas ] *****

Carpeta Encontrar : C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
Carpeta Encontrar : C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}

***** [ Archivos ] *****


***** [ Accesos directos ] *****


***** [ Tareas programadas ] *****


***** [ Registro ] *****

Llave Encontrado : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Llave Encontrado : HKU\.DEFAULT\Software\Avg Secure Update
Llave Encontrado : HKCU\Software\Avg Secure Update
Llave Encontrado : [x64] HKCU\Software\Avg Secure Update

***** [ Navegadores Web ] *****

[C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrar : aol.com
[C:\Users\equipo2\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Encontrar : ask.com

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1259 bytes] ##########

2) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.1 (09.08.2015:1)
OS: Windows 10 Home x64
Ran by equipo2 on 14/09/2015 at 11:17:47,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\equipo2\Appdata\Local\{338CFF5F-D4D9-4345-BE11-67E6BC93B099}
Successfully deleted: [Empty Folder] C:\Users\equipo2\Appdata\Local\{511C519F-3849-4283-9AB5-C3A01D33851A}
Successfully deleted: [Empty Folder] C:\Users\equipo2\Appdata\Local\{9E834BE6-A87C-42D1-8ABA-8D4B90727D33}



~~~ Chrome


[C:\Users\equipo2\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\equipo2\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\equipo2\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\equipo2\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14/09/2015 at 11:41:28,57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

3. I don't know if these are the log files that you need. I couldn't save the to the clipboard immediately after the scanning and correction. I see two logs in xml formats and other reports that the main software lets me export which I am transcribing:

a) Malwarebytes Anti-Malware
www.malwarebytes.org

Fecha del análisis: 14/09/2015
Hora del análisis: 11:45
Archivo de registro:
Administrador: Sí

Versión: 2.1.8.1057
Base de datos de malwares: v2015.09.14.04
Base de datos de rootkits: v2015.08.16.01
Licencia: Prueba
Protección contra el malware: Activado
Protección contra sitios web maliciosos: Activado
Autoprotección: Desactivado

SO: Windows 10
CPU: x64
Sistema de archivos: NTFS
Usuario: equipo2

Tipo de análisis: Análisis de amenazas
Resultado: Completado
Objetos analizados: 564406
Tiempo transcurrido: 1 hr, 21 min, 37 seg

Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Activado
PUM: Activado

Procesos: 0
(No hay elementos maliciosos detectados)

Módulos: 0
(No hay elementos maliciosos detectados)

Claves del registro: 0
(No hay elementos maliciosos detectados)

Valores del registro: 0
(No hay elementos maliciosos detectados)

Datos del registro: 0
(No hay elementos maliciosos detectados)

Carpetas: 0
(No hay elementos maliciosos detectados)

Archivos: 0
(No hay elementos maliciosos detectados)

Sectores físicos: 0
(No hay elementos maliciosos detectados)


(end)

b) Malwarebytes Anti-Malware
www.malwarebytes.org


Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malware Protection, Starting,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malware Protection, Started,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Starting,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Started,
Error, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Update, Bad md5 or size: akadomains, 11,
Error, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Update, Bad md5 or size: akaips, 11,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, AKA IP Database, 0.0.0.0, 2015.9.11.2,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, Rootkit Database, 2015.6.2.1, 2015.8.16.1,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, Remediation Database, 2015.5.13.1, 2015.9.11.1,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, AKA Domain Database, 0.0.0.0, 2015.9.11.2,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, Domain Database, 0.0.0.0, 2015.9.14.7,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, IP Database, 0.0.0.0, 2015.9.11.5,
Update, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Manual, Malware Database, 2015.6.3.3, 2015.9.14.4,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Refresh, Starting,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Stopping,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Stopped,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Refresh, Success,
Protection, 14/09/2015 11:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Starting,
Protection, 14/09/2015 11:44, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Started,
Update, 14/09/2015 12:42, SYSTEM, EEZV-EQUIPO2-HP, Scheduler, Malware Database, 2015.9.14.4, 2015.9.14.5,
Protection, 14/09/2015 12:42, SYSTEM, EEZV-EQUIPO2-HP, Protection, Refresh, Starting,
Protection, 14/09/2015 12:42, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Stopping,
Protection, 14/09/2015 12:42, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Stopped,
Protection, 14/09/2015 12:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Refresh, Success,
Protection, 14/09/2015 12:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Starting,
Protection, 14/09/2015 12:43, SYSTEM, EEZV-EQUIPO2-HP, Protection, Malicious Website Protection, Started,
Scan, 14/09/2015 13:06, SYSTEM, EEZV-EQUIPO2-HP, Manual, Inicio:14/09/2015 11:45, Duración:1 h, 21 min, 37 seg, Análisis de amenazas, Completado, Detecciones de malware de 0, Detecciones de códigos no de malware de 0,

(end)


Thank you very much!

ken545
2015-09-14, 23:29
Is Tradeadexchange gone , if not what browsers has it infected

eezv11
2015-09-15, 03:45
Tradeadexchange's gone, but now my chrome browser opened a new page with onclickads.net or something like that. I couldn't see it because it appeared and disappear faster, leaving the merchant's page. I think this time it was an internet provider. With tradeadexchange it was an online store.
Thanks
eezv11

ken545
2015-09-15, 04:09
Lets do this

Download Chrome Cleanup Tool (https://www.google.com/chrome/cleanup-tool/) to your desktop




Open the Chrome Cleanup Tool. It will immediately start searching your computer for programs known to cause problems with Chrome.
A message will tell you if any programs were found.
Click Remove programs. Wait until you see the message "Removal complete." Some open applications may be closed in the process.
Click Continue to quit the tool. (If your computer needs to reboot, the button will say Restart.)
Chrome will automatically reopen asking if you want to reset your browser settings.
Click Reset.





If that didn't fix it than lets set Chome back to defaults



Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Select Settings.
Scroll down to Show advanced settings...
Down on the bottom you will see an option for RESET BROWSER SETTINGS
Click on it and it will set Chome back to defaults

eezv11
2015-09-15, 04:54
I guess this is it!!
It didn't open a new browser.
Thank you very much.
eezv11

ken545
2015-09-15, 12:28
Good Morning eezv11

Thats good to hear. I am going to have you run a program to remove the tools we used to clean up your system because these tools are updated on a regular basis and you dont want to use a tool on your own that is outdated, I will also keep this thread open for you for about 3 days in case it reappears and you have to post back. If after that time and you need help again with this computer if the thread is closed just send me a PM and I will reopen it for you


Double click on AdwCleaner.exe to run the tool again.


Click on the Uninstall button.
Click Yes when asked are you sure you want to uninstall.
Both AdwCleaner.exe, its folder and all logs will be removed.






==========================================================




Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.


http://i24.photobucket.com/albums/c30/ken545/DelFix_zps139e2ea1.jpg (http://s24.photobucket.com/user/ken545/media/DelFix_zps139e2ea1.jpg.html)




Windows XP Double Click DelFix.exe to run the program.
Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR
Checkmark " Remove Disinfection Tools"
Click the Run button




This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually






==========================================================






So How did I get infected in the first place (https://forums.spybot.info/showthread.php?279-So-how-did-I-get-infected-in-the-first-place&quot;)




Safe Surfn
Ken

eezv11
2015-09-16, 00:31
Hi Ken,
Onclickads dot net redirected my browser to the internet provider webpage again.
Just a few minutes before downloading delfix_1.011 dot exe.
Should we try something new again?
I don't think I should run the delfix app for now.
Thanks
eezv11

ken545
2015-09-16, 01:09
Yes, hang off from removing those tools

Right click on the Start Button ( its on the bottom left on your taskbar) and click on Task Manager. Look on the Process tab and see if Onclickads is present, if it is click it once to select it and then on the bottom click End Process,then ok your way out to close Task Manager

Then right click on the Start button again, this time click on Control Panel, when it loads click on Programs and Features and see if Onclickads is present, if so uninstall it





Open Chrome
Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Click on Settings
Then Manage Search Engines
Highlite Onclickads and select Delete
Then go to Other Search Engines and remove all you dont want






Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Click on Settings
Open a specific page or set of pages.
Set Pages
Remove Onclickads if present
You can copy and paste the url from a page you like or if you have that page open select use current
OK your way out and close chome.
Reopen Chrome and make sure your start page is the one you want






Open Chrome
Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Click on History
Click on Clear Browsing History
Check
1. Browsing History
2. Cookies and Site Plug Ins
3. Cached Images and Files
Then ok your way out and close Chrome






Open Chrome
Click the Chrome menu http://i24.photobucket.com/albums/c30/ken545/Clipboard01_zps2e55f676.jpgon the browser toolbar.
Then go to Settings > Show Advanced Settings
Then go to Privacy > Content Settings
Plug Ins > Manage Exceptions > Delete any reference to Onclickads
Pop Ups > Manage Exceptions > Remove any reference to Onclickads
Ok your way out and close Chome, then reopen it and see if Onclickads are gone from your pages

eezv11
2015-09-16, 05:43
Unfortunately, I couldn't find the onclickads in the task bar or in chrome's configuration.
Thanks
eezv11

ken545
2015-09-16, 12:16
Then lets completely uninstall and then reinstall Chome



1. Close all Chrome windows and tabs.
2. Right click on the Start menu > Control Panel.
3. Click Programs and Features.
4. Double-click Google Chrome.
5. Click Uninstall from the confirmation dialog.
6. Select "Also delete your browsing data" <----- Do this
7. Right click on Start and go to File Explorer
8. Click on your C:\ Drive
9. Go to Program Files (86) Google and delete Google if still present
10. Ok your way out and then reboot your system


Download and reinstall Chrome
https://www.google.com/intl/en/chrome/browser/desktop/index.html

eezv11
2015-09-17, 19:12
Hi,
I checked if the google folder was still there and it was.
Notwithstanding, before deleting it, I had to uninstall the google drive and goggle earth apps for there were folders for those applications.
After uninstalling them, I noticed that their folders were gone but I saw that the following there still left:
- Chrome;
- Crash reports; and
- Update

Due to the fact that I couldn't remove them I reboot and tried again.

Then, it showed that some files were being deleted (about 164) but it stopped. I checked and all the files from the Chrome folder were erased, but not Crash reports nor Update.

I deleted the chrome folder without incidents but weren't able to delete Crash reports nor Update.

After a minutes (while I was typing these post), I checked again and one of them was automatically deleted. I was going to try with the other but decided to go directly to the Google root and it worked.

I am on my way to reinstall google chrome.

Regards,
eezv11

ken545
2015-09-19, 14:11
How are you coming along ?

eezv11
2015-09-20, 08:40
It looks fine, it seems that it stopped opening the other browser.
BUt I'm still checking
Regards
eezv11

eezv11
2015-09-23, 03:21
Hi again!
I could'nt write it down, but it seems that the address opened this time is rdsa2012 DOT com / static / lprdr.html?r= AND then the http: www videodownloadconverter com
Thanks
eezv11

ken545
2015-09-23, 03:38
Lets run AdwCleaner again, here are the instructions and download link

-AdwCleaner-by Xplode


Click on this link to download : ADWCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers




Do not click on any links in the top Advertisment.


http://i24.photobucket.com/albums/c30/ken545/AdwCleaner4.201_zpsxrbk2llq.jpg (http://s24.photobucket.com/user/ken545/media/AdwCleaner4.201_zpsxrbk2llq.jpg.html)




Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Scan.
After the scan is complete click on "Clean"
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please post the content of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.







--RogueKiller--




Download & SAVE to your Desktop RogueKiller (http://www.bleepingcomputer.com/download/roguekiller/) or 32 BIT (http://tigzy.geekstogo.com/Tools/RogueKiller.exe)


Quit all programs that you may have started.
Please disconnect any USB or external drives from the computer before you run this scan!
For Vista or Windows 7, right-click and select "Run as Administrator to start"
For Windows XP, double-click to start.
Wait until Prescan has finished ...
Then Click on "Scan" button
Wait until the Status box shows "Scan Finished"
Click on "Report" and copy/paste the content of the Notepad into your next reply.
The log should be found in RKreport[1].txt on your Desktop
Exit/Close RogueKiller+

eezv11
2015-09-23, 04:01
Now, using the incognito pages it open something like track ad absolute. This time I couldn't write it down.
Thanks
eezv11

eezv11
2015-09-23, 19:29
These are the logs:
The first and second are AdwCleaner's. But the first is [C] and the second [S]
The third is the RogueKiller log. I don't want to delete anything yet. For example, eventhough I almost never use it, it found some extensions in Firefox that are resourceful. For example when I want to open webpages in the US that I cannot open from home I use the anonymoX and I wouldn't want to eliminate it. I also like to block ads and there is the Adblock Edge. I don't use the Real Downloader nor the HP SmartPrintButton, so it doesn't matter.

These I don't know what they mean nor if they should be deleted:
- Registry
a) One RUN Type "Suspicious Path" and
b) Six PUM.Dns DNS that refer to a an 172.20.10.1 ip address.

Finally, it's possible that the scanner was reading all my files but it seems that I cannot open my hotmail account in Oulook. (Only the internal ones)
I also cannot open any drive in the network.

I want to close the scanner and maybe that will release everything, but I don't know if I should do it, for that is going to make it take longer to eliminate a threat (If there is one).

Hopefully, you can answer to this fast.

1. # AdwCleaner v5.008 - Registro generado 22/09/2015 en 20:11:40
# Actualizado 18/09/2015 por Xplode
# Base de datos : 2015-09-22.3 [Servidor]
# Sistema operativo : Windows 10 Home (x64)
# Nombre de usuario : equipo2 - EEZV-EQUIPO2-HP
# Ejecutado desde : C:\Users\equipo2\Desktop\AdwCleaner.exe
# Opción : Limpiar
# Apoyo : http://toolslib.net/forum

***** [ Servicios ] *****

***** [ Carpetas ] *****

***** [ Archivos ] *****

***** [ Accesos directos ] *****

***** [ Tareas programadas ] *****

***** [ Registro ] *****

***** [ Navegadores Web ] *****

*************************

:: Winsock Configuración borrada

########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [658 bytes] ##########

2. # AdwCleaner v5.008 - Registro generado 22/09/2015 en 20:10:17
# Actualizado 18/09/2015 por Xplode
# Base de datos : 2015-09-22.3 [Servidor]
# Sistema operativo : Windows 10 Home (x64)
# Nombre de usuario : equipo2 - EEZV-EQUIPO2-HP
# Ejecutado desde : C:\Users\equipo2\Desktop\AdwCleaner.exe
# Opción : Escanear
# Apoyo : http://toolslib.net/forum

***** [ Servicios ] *****

***** [ Carpetas ] *****

***** [ Archivos ] *****

***** [ Accesos directos ] *****

***** [ Tareas programadas ] *****

***** [ Registro ] *****

***** [ Navegadores Web ] *****

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [594 bytes] ##########

3. RogueKiller V10.10.6.0 [Sep 21 2015] by Adlice Software
correo : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Sitio web : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Sistema Operativo : Windows 10 (10.0.10240) 64 bits version
Iniciado en : Modo Normal
Usuario : equipo2 [Administrador]
Started from : C:\Users\equipo2\Desktop\RogueKiller.exe
Modo : Escanear -- Fecha : 09/23/2015 11:03:25

¤¤¤ Procesos : 0 ¤¤¤

¤¤¤ Registro : 7 ¤¤¤
[Suspicious.Path|VT.Unknown] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | PPort12reminder : "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini" [7][x][-] -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1bd54d50-7b1a-4d78-9e99-76f3b53439c3} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5edaff56-6c60-438c-b20d-1ab10bf61517} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{c860732a-6130-453d-a27f-03278251d84b} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1bd54d50-7b1a-4d78-9e99-76f3b53439c3} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5edaff56-6c60-438c-b20d-1ab10bf61517} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Encontrado
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c860732a-6130-453d-a27f-03278251d84b} | DhcpNameServer : 172.20.10.1 ([(Private Address) (XX)]) -> Encontrado

¤¤¤ Tareas : 0 ¤¤¤

¤¤¤ Archivos : 0 ¤¤¤

¤¤¤ Archivo de hosts : 0 [Too big!] ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: No cargado [0xc000036b]) ¤¤¤

¤¤¤ Navegadores Web : 0 ¤¤¤

¤¤¤ Chequeo MBR : ¤¤¤
+++++ PhysicalDrive0: Hitachi HDS721010CLA632 +++++
--- User ---
[MBR] bc6b87ba5bc054481cae162c8e9c8559
[BSP] 740cc1fa5f9ba34bd24afc6afd52852f : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 939761 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1924837376 | Size: 450 MB
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1925758976 | Size: 13556 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

eezv11
2015-09-23, 20:18
Hi,
I closed the Rogue Killer scanner and every thing worked perfect.
Now, I guess that in order to make the clean up or deletion of malware, I'll have to do another scan. Unless there is an easier and faster way (for dummys) to enter the registry and clean them by hand.
I can leave the PC all night to do the scan again, though.
Thanks
eezv11

PS. Maybe the answer is obvious, but ... If I use chrome or any other google app with my user id, is it possible that the browser could bring the malware to another computer / gadget?

ken545
2015-09-23, 22:17
AdwCleaner didn't find anything bad and there is nothing to remove with RogueKiller

I will bet that you will think twice about downloading any cracked programs in the future, you can see what a disaster this has been for your computer

We are trying to remove some malware and you cant name it so I dont know what where looking for.

My advice would be to just uninstall Chome and use another browser

Another option would be to do a complete format of your hard drive and install windows nice and clean and be done with all this nonsense, the call is yours, let me know what you want to do

eezv11
2015-09-23, 22:38
I guess the easiest way to deal with this is to uninstall chrome.

At least now I know that there's no Malware and if another browser window opens, it's just a matter to be careful and close it and not download anything that could be harmful.

Thanks!

eezv11

ken545
2015-09-23, 23:47
You can use any or all of these if you wish


Firefox
https://www.mozilla.org/en-US/firefox/new/


SeaMonkey
http://www.seamonkey-project.org/


Opera
http://www.opera.com/



Double click on AdwCleaner.exe to run the tool again.


Click on the Uninstall button.
Click Yes when asked are you sure you want to uninstall.
Both AdwCleaner.exe, its folder and all logs will be removed.






==========================================================




Please download DelFix (http://general-changelog-team.fr/en/downloads/finish/20-outils-de-xplode/9-delfix) and save the file to your Desktop.


http://i24.photobucket.com/albums/c30/ken545/DelFix_zps139e2ea1.jpg (http://s24.photobucket.com/user/ken545/media/DelFix_zps139e2ea1.jpg.html)




Windows XP Double Click DelFix.exe to run the program.
Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR
Checkmark " Remove Disinfection Tools"
Click the Run button




This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually






==========================================================






So How did I get infected in the first place (https://forums.spybot.info/showthread.php?279-So-how-did-I-get-infected-in-the-first-place&quot;)




Safe Surfn
Ken