Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Infected computers

hacker spyware

  • This topic is locked This topic is locked
6 replies to this topic

#1 bussw83

bussw83

    New Member

  • New Member
  • Pip
  • 3 posts

Posted 07 March 2022 - 09:43 PM

I have had someone hacking me, spying on me and harrasing me for years now.

This person used to tell me things that I have in my computer and no one else know.

Even though I blocked him he always keeps doing the same stuff. He even deleted messages sent to me on my whatsapp 

when I used to connect my phone to the wifi in my house.

 

My cpu over Works and my computer gets stuck, the internet gets slow and there is a bold black mark around some of the programs in my PC like my VPN, Firefox etc.

 

I have a desktop with Windows 7 and a laptop with Windows 10.

 

Please help me to get rid of this person for Good.

 

This are the results for my laptop:

 

 

FRST

 

Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 27-02-2022
Ejecutado por usuario (administrador) sobre DESKTOP-4OO4NRC (Dell Inc. Latitude E6220) (07-03-2022 20:29:35)
Ejecutado desde C:\Users\usuario\Desktop
Perfiles cargados: usuario
Plataforma: Microsoft Windows 10 Pro Versión 21H2 19044.1526 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: Edge
Modo de Inicio: Normal
 
==================== Procesos (Lista blanca) =================
 
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
 
(Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(C:\Program Files (x86)\Windscribe\Windscribe.exe ->) (Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeEngine.exe
(C:\Program Files (x86)\Windscribe\WindscribeService.exe ->) (Windscribe Limited -> The OpenVPN Project) C:\Program Files (x86)\Windscribe\windscribeopenvpn_2_5_4.exe
(C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe <2>
(C:\Program Files\DellTPad\Apoint.exe ->) (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(C:\Program Files\DellTPad\Apoint.exe ->) (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(C:\Program Files\DellTPad\HidMonitorSvc.exe ->) (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(C:\Users\usuario\Desktop\opera\opera.exe ->) (Opera Software AS -> Opera Software) C:\Users\usuario\Desktop\opera\84.0.4316.31\opera_crashreporter.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
(explorer.exe ->) (Intel® pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Telegram FZ-LLC -> Telegram FZ-LLC) C:\Users\usuario\AppData\Roaming\Telegram Desktop\Telegram.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
(Opera Software AS -> Opera Software) C:\Users\usuario\Desktop\opera\opera.exe <39>
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(services.exe ->) (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidMonitorSvc.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe
(services.exe ->) (Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe
(svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2103.8.0_x64__8wekyb3d8bbwe\Calculator.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\Windscribe.exe
(Windscribe Limited -> Windscribe Limited) C:\Users\usuario\AppData\Local\Temp\_iu14D2N.tmp
 
==================== Registro (Lista blanca) ===================
 
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
 
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [727896 2014-03-13] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
HKLM-x32\...\RunOnce: [GrpConv] => grpconv -o (Ningún archivo)
HKU\S-1-5-21-3735610940-3711455475-3248009252-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2618248 2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-3735610940-3711455475-3248009252-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35646080 2022-02-14] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3735610940-3711455475-3248009252-1001\...\Run: [MicrosoftEdgeAutoLaunch_4A601B1257B2F39E22044BE56AC4339E] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
Startup: C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Jarvee.lnk [2021-12-22]
ShortcutTarget: Jarvee.lnk -> C:\Users\usuario\AppData\Roaming\Jarvee\Jarvee.exe (ABC E-COMMERCE SERVICES -> Jarvee)
 
==================== Tareas programadas (Lista blanca) ============
 
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
 
Task: {1DFCBB60-53B1-44BB-ACB7-B439DB10E015} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\RUXIMDisplay => C:\Program Files\ruxim\ruximics.exe [477512 2021-05-19] (Microsoft Windows -> Microsoft Corporation)
Task: {1FC4DDD5-0403-4F07-BBCA-7641316C7931} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8307120 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {2C6D4991-972C-4D9D-ADCF-C0CA36944161} - System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\RUXIMSync => C:\Program Files\ruxim\ruximics.exe [477512 2021-05-19] (Microsoft Windows -> Microsoft Corporation)
Task: {37A46D47-C58C-44ED-93C3-729421078709} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {493AF638-DE6E-49AB-85FA-CDE997EE601E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-02-14] (Piriform Software Ltd -> Piriform)
Task: {4A2602E9-155E-41FD-848D-88D263E5D5D4} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138160 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {72924BEF-4849-430A-84F2-F867D365C226} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {75776275-F8D3-4E48-9F5D-2B86A9CF3DD3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22580640 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {7D99FFD4-A44A-4576-9F9D-57F8794D732E} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [59232 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {AA7660F8-2A85-4E7D-8B9C-7CD5D8C1EDE6} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [138160 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {ADC51C0E-BCA6-4EF4-A67A-0042C1BE67BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [8307120 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {C186D9FD-58E8-49A0-A860-86EBE85FD9E9} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4158856 2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
Task: {CBDFE05D-79D0-4D1E-B5B9-3BA7C276D172} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [22580640 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {D3052549-CF5E-4C9D-9F1A-B098E0038F10} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E6976EE4-1460-43FA-86C0-A9D2CD729E78} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCmdRun.exe [925848 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E79242BD-0B3C-4902-9B1D-8C583151E9D4} - System32\Tasks\CCleanerSkipUAC - usuario => C:\Program Files\CCleaner\CCleaner.exe [29764224 2022-02-14] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {E8E7755A-07B2-451F-9796-9C60F7763DBA} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-3735610940-3711455475-3248009252-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4158856 2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
 
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
 
 
==================== Internet (Lista blanca) ====================
 
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
 
Tcpip\..\Interfaces\{2a8b176c-d8cc-40bb-9136-05ad249595ef}: [DhcpNameServer] 190.113.97.11 190.113.97.3
Tcpip\..\Interfaces\{2be1fad5-6e81-4f43-a45e-1b1edcba35df}: [DhcpNameServer] 192.168.44.1
Tcpip\..\Interfaces\{e8ca9627-cc2a-485c-8c87-877705fbeb97}: [NameServer] 10.255.255.2
Tcpip\..\Interfaces\{f0d06277-d941-457b-8f3c-5908149b9384}: [DhcpNameServer] 192.168.43.1
 
Edge: 
=======
Edge Extension: (Sin Nombre) -> AutoFormFill_5ED10D46BD7E47DEB1F3685D2C0FCE08 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\AutoFormFill [no encontrado]
Edge Extension: (Sin Nombre) -> BookReader_B171F20233094AC88D05A8EF7B9763E8 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\BookViewer [no encontrado]
Edge Extension: (Sin Nombre) -> LearningTools_7706F933-971C-41D1-9899-8A026EB5D824 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\LearningTools [no encontrado]
Edge Extension: (Sin Nombre) -> PinJSAPI_EC01B57063BE468FAB6DB7EBFC3BF368 => C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Assets\HostExtensions\PinJSAPI [no encontrado]
Edge DefaultProfile: Default
Edge Profile: C:\Users\usuario\AppData\Local\Microsoft\Edge\User Data\Default [2022-03-07]
 
FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
 
Chrome: 
=======
CHR Profile: C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default [2022-03-07]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-03-03]
 
==================== Servicios (Lista blanca) ===================
 
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
 
R2 ApHidMonitorService; C:\Program Files\DellTPad\HidMonitorSvc.exe [87384 2014-03-27] (Alps Electric Co., LTD. -> Alps Electric Co., Ltd.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11649952 2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncHelper.exe [3380616 2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\22.022.0130.0001\OneDriveUpdaterService.exe [3851128 2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [6136536 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe [2909208 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe [128376 2022-02-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [1337216 2022-03-03] (Windscribe Limited -> Windscribe Limited)
 
===================== Controladores (Lista blanca) ===================
 
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
 
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [160376 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [49272 2014-12-28] (ManyCam -> Visicom Media Inc.)
R3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-28] (ManyCam -> Visicom Media Inc.)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [167544 2021-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R3 tapwindscribe0901; C:\WINDOWS\System32\drivers\tapwindscribe0901.sys [57768 2022-02-20] (Windscribe Limited -> The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [48536 2022-02-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [438520 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [90360 2022-02-10] (Microsoft Windows -> Microsoft Corporation)
S3 WinDivert1.1; C:\Program Files\KMSpico\WinDivert.sys [35376 2021-10-05] (Nemea Mjukvaruutveckling AB -> Basil Projects)
S3 WindscribeSplitTunnel; C:\WINDOWS\system32\DRIVERS\WindscribeSplitTunnel.sys [35752 2022-03-03] (Windscribe Limited -> )
R3 windtun420; C:\WINDOWS\System32\drivers\windtun420.sys [47544 2022-02-20] (Windscribe Limited -> WireGuard LLC)
 
==================== NetSvcs (Lista blanca) ===================
 
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
 
 
==================== Un mes (creado) (Lista blanca) =========
 
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
 
2022-03-07 20:29 - 2022-03-07 20:31 - 000015609 _____ C:\Users\usuario\Desktop\FRST.txt
2022-03-07 20:27 - 2022-03-07 20:30 - 000000000 ____D C:\FRST
2022-03-07 20:26 - 2022-03-07 20:26 - 002312192 _____ (Farbar) C:\Users\usuario\Desktop\FRST64.exe
2022-03-06 18:55 - 2022-03-06 18:55 - 000071212 _____ C:\Users\usuario\Downloads\FIvwQN_WUAIdMVk.jfif
2022-03-06 02:03 - 2022-03-06 02:03 - 000064371 _____ C:\Users\usuario\Downloads\FNJL2ZHVIAQLPYX.jfif
2022-03-06 02:03 - 2022-03-06 02:03 - 000056803 _____ C:\Users\usuario\Downloads\FNJL2YgVcAIig1s.jfif
2022-03-06 01:49 - 2022-03-06 01:49 - 000880172 _____ C:\Users\usuario\Downloads\FL_hzGZXEAMasbL.jfif
2022-03-05 14:40 - 2022-03-05 22:25 - 000000000 ____D C:\Users\usuario\Downloads\Telegram Desktop
2022-03-05 00:31 - 2022-03-05 00:31 - 000000000 ____D C:\Users\usuario\Downloads\Snapchat
2022-03-05 00:30 - 2022-03-05 00:30 - 000000022 _____ C:\Users\usuario\Downloads\Nuevo WinRAR ZIP archive.zip
2022-03-04 00:35 - 2022-03-04 00:36 - 064569444 _____ C:\Users\usuario\Downloads\Snapchat.zip
2022-03-03 22:50 - 2022-03-07 19:34 - 000000000 ____D C:\Users\usuario\AppData\Roaming\Telegram Desktop
2022-03-03 22:50 - 2022-03-03 22:50 - 000000000 ____D C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram Desktop
2022-03-03 22:47 - 2022-03-03 22:49 - 035090144 _____ (Telegram FZ-LLC ) C:\Users\usuario\Downloads\tsetup-x64.3.5.1.exe
2022-03-03 14:27 - 2022-03-03 14:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windscribe
2022-03-03 14:26 - 2022-03-03 14:26 - 000001144 _____ C:\Users\Public\Desktop\Windscribe.lnk
2022-03-03 14:25 - 2022-03-03 14:27 - 000000000 ____D C:\Program Files (x86)\Windscribe
2022-03-03 14:25 - 2022-03-03 14:25 - 000035752 _____ C:\WINDOWS\system32\Drivers\WindscribeSplitTunnel.sys
2022-03-03 14:24 - 2022-03-03 14:25 - 019552128 _____ (Windscribe Limited) C:\Users\usuario\Downloads\Windscribe (1).exe
2022-03-03 03:28 - 2022-03-03 03:28 - 099090432 _____ C:\WINDOWS\system32\config\SOFTWARE
2022-03-03 00:46 - 2022-03-03 00:46 - 000170727 _____ C:\Users\usuario\Downloads\FM0p3QnXIAIDCcj.jfif
2022-03-02 19:52 - 2022-03-02 19:54 - 010623636 _____ (Google) C:\Users\usuario\Downloads\picasa39-setup.exe.opdownload
2022-03-02 19:50 - 2022-03-02 19:50 - 001077248 _____ C:\Users\usuario\Downloads\Setup_EXIFeditor_en.msi
2022-03-02 16:39 - 2022-03-02 16:39 - 000137229 _____ C:\Users\usuario\Downloads\FM0Yq-FXIAwNUrP.jfif
2022-03-02 09:09 - 2022-03-02 09:09 - 000063352 _____ C:\Users\usuario\Downloads\FMv7PQHXwAIJup3.jfif
2022-03-01 23:47 - 2022-03-01 23:47 - 000151079 _____ C:\Users\usuario\Downloads\FM0WRdAVUAUqMLt.jfif
2022-03-01 13:57 - 2022-03-01 13:57 - 000220988 _____ C:\Users\usuario\Downloads\FMs1zkfXsAAq8Yo.jfif
2022-03-01 12:44 - 2022-03-01 12:44 - 000389745 _____ C:\Users\usuario\Downloads\FD-FhRNVIAAbkyx.jfif
2022-03-01 12:44 - 2022-03-01 12:44 - 000283722 _____ C:\Users\usuario\Downloads\FMtFg3KXEAMvzH9.jfif
2022-02-28 18:47 - 2022-02-28 18:47 - 000230492 _____ C:\Users\usuario\Downloads\FMdq15FWYAUO1pw.jfif
2022-02-28 18:47 - 2022-02-28 18:47 - 000147456 _____ C:\Users\usuario\Downloads\FMdq15OWQAEGHYF.jfif.opdownload
2022-02-28 17:31 - 2022-02-28 17:31 - 000263531 _____ C:\Users\usuario\Downloads\FMmZDqSVkAMTroS.jfif
2022-02-28 17:18 - 2022-02-28 17:18 - 000184443 _____ C:\Users\usuario\Downloads\FMtx9H8XsAAWktr.jfif
2022-02-28 16:55 - 2022-02-28 16:55 - 000000780 _____ C:\Users\usuario\Downloads\Documentos - Acceso directo (2).lnk
2022-02-28 15:29 - 2022-02-28 15:29 - 000211292 _____ C:\Users\usuario\Downloads\FMYbCHdUUAYawiO.jfif
2022-02-27 23:30 - 2022-02-27 23:30 - 000250042 _____ C:\Users\usuario\Downloads\FLupUSdXIAAOQNd.jfif
2022-02-27 13:47 - 2022-02-27 13:47 - 000193488 _____ C:\Users\usuario\Downloads\FLZpci8WQAA0_vK.jfif
2022-02-27 12:22 - 2022-02-28 15:44 - 000000000 ____D C:\Users\usuario\Downloads\SFS
2022-02-27 12:17 - 2022-02-27 12:17 - 000166412 _____ C:\Users\usuario\Downloads\insta story sfs.jfif
2022-02-26 19:55 - 2022-02-26 19:55 - 000326778 _____ C:\Users\usuario\Downloads\E_QKyHpWQAMMsVM.jfif
2022-02-26 19:51 - 2022-02-26 19:51 - 000489222 _____ C:\Users\usuario\Downloads\E6e606yVIAEcTGp.jfif
2022-02-26 15:56 - 2022-02-26 15:56 - 000248346 _____ C:\Users\usuario\Downloads\FMc8Fc7WYAcyXTT.jfif
2022-02-26 11:37 - 2022-02-26 11:37 - 000310411 _____ C:\Users\usuario\Downloads\FMYQFXKXMAIycmb.jfif
2022-02-26 09:24 - 2022-02-26 09:24 - 000293419 _____ C:\Users\usuario\Downloads\FLzqo8bVgAcYjEK.jfif
2022-02-26 07:26 - 2022-02-26 07:26 - 004365897 _____ C:\Users\usuario\Downloads\watermarked-images.zip
2022-02-25 23:49 - 2022-02-25 23:50 - 027897365 _____ C:\Users\usuario\Downloads\Playboy USA - November 1968 ( PDFDrive ).pdf
2022-02-25 23:47 - 2022-02-25 23:47 - 002017973 _____ C:\Users\usuario\Downloads\Specialist of Boobs Growth Your Boobs Look Very Sexy Within 2 Weeks - HOW TO GET SEXY BREAST NATURALLY ( PDFDrive ).pdf
2022-02-25 23:45 - 2022-02-25 23:48 - 040735845 _____ C:\Users\usuario\Downloads\FHM Special Collectors Edition 2016 ( PDFDrive ).pdf
2022-02-25 23:42 - 2022-02-25 23:45 - 060659314 _____ C:\Users\usuario\Downloads\Penthouse Australia - July - August 2015 ( PDFDrive ).pdf
2022-02-25 23:38 - 2022-02-25 23:41 - 062035751 _____ C:\Users\usuario\Downloads\Playboy Special Collector's Edition Country Girls ( PDFDrive ).pdf
2022-02-25 23:37 - 2022-02-25 23:38 - 023465038 _____ C:\Users\usuario\Downloads\Playboy Special Collector's Edition 2015 10 ( PDFDrive ).pdf
2022-02-25 23:36 - 2022-02-25 23:37 - 024259534 _____ C:\Users\usuario\Downloads\Playboys Sexy 100 - 2010.pdf ( PDFDrive ).pdf
2022-02-25 23:36 - 2022-02-25 23:37 - 021212889 _____ C:\Users\usuario\Downloads\Playboy Special Collectors edition Wet & Wild ( PDFDrive ).pdf
2022-02-25 23:33 - 2022-02-25 23:33 - 004091947 _____ C:\Users\usuario\Downloads\Studio Lightingfor Nude - Nude Photography Blog - StudioPrague.com ( PDFDrive ) (1).pdf
2022-02-25 23:32 - 2022-02-25 23:33 - 004091947 _____ C:\Users\usuario\Downloads\Studio Lightingfor Nude - Nude Photography Blog - StudioPrague.com ( PDFDrive ).pdf
2022-02-25 23:31 - 2022-02-25 23:31 - 004641780 _____ C:\Users\usuario\Downloads\Garage Glamour_ Digital Nude and Beauty Photography Made Simple ( PDFDrive ).pdf
2022-02-25 20:15 - 2022-02-25 20:15 - 000540562 _____ C:\Users\usuario\Downloads\FIDOOmlXIAEjjvw.jfif
2022-02-25 19:12 - 2022-02-25 19:12 - 000120358 _____ C:\Users\usuario\Downloads\FMP9ntqXoAI3mcO.jfif
2022-02-25 19:10 - 2022-02-25 19:10 - 000022187 _____ C:\Users\usuario\Downloads\FMUMBuCWQAYNZY9.jfif
2022-02-25 19:09 - 2022-02-25 19:09 - 000459148 _____ C:\Users\usuario\Downloads\FMUMBuCWQAE_Sh8.jfif
2022-02-25 19:09 - 2022-02-25 19:09 - 000215621 _____ C:\Users\usuario\Downloads\FMZ5_EVVkA8r1Hj.jfif
2022-02-25 19:02 - 2022-02-25 19:02 - 000310174 _____ C:\Users\usuario\Downloads\FLlw1efVEAA1mAx.jfif
2022-02-25 19:02 - 2022-02-25 19:02 - 000125746 _____ C:\Users\usuario\Downloads\FMdwWzIXoAIOUbi.jfif
2022-02-25 19:01 - 2022-02-25 19:01 - 000500472 _____ C:\Users\usuario\Downloads\FJ98fsLWQA0Qo-0.jfif
2022-02-25 18:55 - 2022-02-25 18:55 - 000365712 _____ C:\Users\usuario\Downloads\FJUx_oeVgAIgqeq.jfif
2022-02-25 18:52 - 2022-02-25 18:52 - 000230038 _____ C:\Users\usuario\Downloads\FMS-kBiVgAECeYZ.jfif
2022-02-25 18:50 - 2022-02-25 18:50 - 000111589 _____ C:\Users\usuario\Downloads\FMeMCXOVUAM83PY.jfif
2022-02-25 18:48 - 2022-02-25 18:48 - 000253380 _____ C:\Users\usuario\Downloads\FL-MNEjWQAUjroP.jfif
2022-02-25 18:27 - 2022-02-25 18:27 - 000076855 _____ C:\Users\usuario\Downloads\FMOZAD4WYAMssXV.jfif
2022-02-25 18:25 - 2022-02-25 18:25 - 000182571 _____ C:\Users\usuario\Downloads\FMZ0-H4XEAQT0pw.jfif
2022-02-25 18:24 - 2022-02-25 18:24 - 000189794 _____ C:\Users\usuario\Downloads\FMUolDwXMAc5X_u.jfif
2022-02-25 18:23 - 2022-02-25 18:23 - 000216802 _____ C:\Users\usuario\Downloads\FMTbcxjXEAUdam8.jfif
2022-02-25 18:23 - 2022-02-25 18:23 - 000025602 _____ C:\Users\usuario\Downloads\FMdcnIlVIAAHSkd.jfif
2022-02-25 18:23 - 2022-02-25 18:23 - 000023856 _____ C:\Users\usuario\Downloads\FMdcnIjUYAABEoo.jfif
2022-02-25 18:22 - 2022-02-25 18:22 - 000178621 _____ C:\Users\usuario\Downloads\FMLbc6SX0AEdK6X.jfif
2022-02-25 18:22 - 2022-02-25 18:22 - 000166262 _____ C:\Users\usuario\Downloads\FMLbc5fXEAASYTD.jfif
2022-02-25 18:22 - 2022-02-25 18:22 - 000165105 _____ C:\Users\usuario\Downloads\FMLbc5gXEAYxrUC.jfif
2022-02-25 18:22 - 2022-02-25 18:22 - 000158471 _____ C:\Users\usuario\Downloads\FMLbc5hXIAAweZn.jfif
2022-02-25 18:21 - 2022-02-25 18:21 - 000097147 _____ C:\Users\usuario\Downloads\FMZcvnbXEAE0uJO.jfif
2022-02-25 18:21 - 2022-02-25 18:21 - 000048286 _____ C:\Users\usuario\Downloads\FMEkkhNXoAM5wdO.jfif
2022-02-25 18:20 - 2022-02-25 18:20 - 000159106 _____ C:\Users\usuario\Downloads\FMUnnNbVEAAjRBG.jfif
2022-02-25 18:20 - 2022-02-25 18:20 - 000149407 _____ C:\Users\usuario\Downloads\FMToAyQXIAgNSI2.jfif
2022-02-25 18:20 - 2022-02-25 18:20 - 000130987 _____ C:\Users\usuario\Downloads\FMd3qdsUUAAkl2p.jfif
2022-02-25 18:19 - 2022-02-25 18:19 - 000176732 _____ C:\Users\usuario\Downloads\FMKGxT4XsAAHSXT.jfif
2022-02-25 18:18 - 2022-02-25 18:18 - 000344110 _____ C:\Users\usuario\Downloads\FMd2KuiXoAE4n6f.jfif
2022-02-25 18:17 - 2022-02-25 18:17 - 000223106 _____ C:\Users\usuario\Downloads\FMJOaQoXIAwOeFl.jfif
2022-02-25 18:15 - 2022-02-25 18:15 - 000176445 _____ C:\Users\usuario\Downloads\FMeLVApWQAYIOM6.jfif
2022-02-25 18:15 - 2022-02-25 18:15 - 000123099 _____ C:\Users\usuario\Downloads\FMeLVAnXMAAniVi.jfif
2022-02-25 18:15 - 2022-02-25 18:15 - 000123099 _____ C:\Users\usuario\Downloads\FMeLVAnXMAAniVi (1).jfif
2022-02-25 18:14 - 2022-02-25 18:14 - 000181114 _____ C:\Users\usuario\Downloads\FMZ0KqhXIAMM1yM (1).jfif
2022-02-25 18:14 - 2022-02-25 18:14 - 000161809 _____ C:\Users\usuario\Downloads\FMZ0KqiWUAU17au.jfif
2022-02-25 18:13 - 2022-02-25 18:13 - 000181114 _____ C:\Users\usuario\Downloads\FMZ0KqhXIAMM1yM.jfif
2022-02-24 23:14 - 2022-02-28 00:59 - 000000000 ____D C:\Users\usuario\Downloads\sources IG
2022-02-24 22:37 - 2022-02-24 22:37 - 000006682 _____ C:\Users\usuario\Downloads\full-list-of-bad-words_comma-separated-text-file_2021_01_18.zip
2022-02-24 22:36 - 2022-02-24 22:36 - 000006465 _____ C:\Users\usuario\Downloads\full-list-of-bad-words_text-file_2021_01_18.zip
2022-02-24 22:36 - 2022-02-24 22:36 - 000001135 _____ C:\Users\usuario\Downloads\spanish-bad-words-list_comma-separated-text-file.zip
2022-02-24 22:36 - 2022-02-24 22:36 - 000001110 _____ C:\Users\usuario\Downloads\spanish-bad-words-list_text-file.zip
2022-02-24 22:36 - 2022-02-24 22:36 - 000000715 _____ C:\Users\usuario\Downloads\base-list-of-bad-words_text-file_2021_01_18.zip
2022-02-24 00:13 - 2022-02-24 00:13 - 000167064 _____ C:\Users\usuario\Downloads\FMVt1pqXMAEzTVn.jfif
2022-02-23 16:16 - 2022-02-23 16:16 - 000000874 _____ C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\more sw resources.lnk
2022-02-23 15:32 - 2022-02-23 15:32 - 000590199 _____ C:\Users\usuario\Downloads\FIxuU2HVIAICp2O.jfif
2022-02-23 15:32 - 2022-02-23 15:32 - 000506389 _____ C:\Users\usuario\Downloads\FIxuU2GVUAE1vUz.jfif
2022-02-23 15:32 - 2022-02-23 15:32 - 000453795 _____ C:\Users\usuario\Downloads\FIxuU2GVkAQvLtA.jfif
2022-02-22 23:01 - 2022-02-22 23:01 - 000298364 _____ C:\Users\usuario\Downloads\FMQISM8XEAIf8EA.jfif
2022-02-22 23:00 - 2022-02-22 23:00 - 000381084 _____ C:\Users\usuario\Downloads\FMQISM-XwAIh58h.jfif
2022-02-22 23:00 - 2022-02-22 23:00 - 000238691 _____ C:\Users\usuario\Downloads\FMQIR_sWUAE0kCF.jfif
2022-02-22 13:48 - 2022-02-22 13:48 - 000761962 _____ C:\Users\usuario\Downloads\codigos sagrados ventas.pdf
2022-02-22 10:14 - 2022-02-22 10:14 - 000105118 _____ C:\Users\usuario\Downloads\tTCENbFB.jpg_medium
2022-02-22 00:32 - 2022-02-22 00:32 - 000123388 _____ C:\Users\usuario\Downloads\limpieza profunda 9 dias.jfif
2022-02-22 00:29 - 2022-02-22 00:31 - 051035520 _____ C:\Users\usuario\Downloads\Y2Mate.is - LIMPIEZA PROFUNDA de 9 DÍAS con CÓDIGOS SAGRADOS 📿de Agesta-z8YaqXVXn-Y-160k-1645511167290.mp3.opdownload
2022-02-21 23:44 - 2022-02-21 23:44 - 034333039 _____ C:\Users\usuario\Downloads\remover implantes.mp4
2022-02-21 12:44 - 2022-02-21 12:44 - 000077006 _____ C:\Users\usuario\Downloads\FLMczE6XIAcql99.jfif
2022-02-21 11:19 - 2022-02-21 11:19 - 000090762 _____ C:\Users\usuario\Downloads\FMEzLCaXsAYLY2n.jfif
2022-02-20 06:47 - 2022-03-03 03:28 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2022-02-20 02:03 - 2022-02-20 02:03 - 000057768 _____ (The OpenVPN Project) C:\WINDOWS\system32\Drivers\tapwindscribe0901.sys
2022-02-20 02:03 - 2022-02-20 02:03 - 000047544 _____ (WireGuard LLC) C:\WINDOWS\system32\Drivers\windtun420.sys
2022-02-20 02:02 - 2022-02-20 02:02 - 000000000 ____D C:\Users\usuario\AppData\Local\Windscribe
2022-02-19 12:46 - 2022-02-19 12:46 - 000104688 _____ C:\Users\usuario\Downloads\RT group.jfif
2022-02-18 11:43 - 2022-02-18 11:43 - 000006544 _____ C:\Users\usuario\Downloads\posting day 2 Updated.csv
2022-02-18 11:41 - 2022-02-18 11:41 - 000006576 _____ C:\Users\usuario\Downloads\posting day 1 Updated.csv
2022-02-18 01:17 - 2022-02-18 01:17 - 000008772 _____ C:\Users\usuario\Documents\posts_export_bg1golh1.csv
2022-02-18 01:06 - 2022-02-18 01:06 - 000000261 _____ C:\Users\usuario\Downloads\PowerDeleteSuiteExport.csv
2022-02-16 13:04 - 2022-02-16 13:04 - 000006207 _____ C:\Users\usuario\Downloads\posting day 1.csv
2022-02-15 13:51 - 2022-02-15 13:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mass Watermark
2022-02-15 13:51 - 2022-02-15 13:51 - 000000000 ____D C:\Program Files (x86)\Mass Watermark
2022-02-15 13:49 - 2022-02-15 13:50 - 045773608 _____ (masswatermark.com ) C:\Users\usuario\Downloads\setup.exe
2022-02-15 13:36 - 2022-02-15 13:36 - 000001140 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\123watermark.lnk
2022-02-15 13:36 - 2022-02-15 13:36 - 000000000 ____D C:\Users\usuario\Documents\123 Watermark
2022-02-15 13:36 - 2022-02-15 13:36 - 000000000 ____D C:\Users\usuario\AppData\Roaming\123Watermark
2022-02-15 13:36 - 2022-02-15 13:36 - 000000000 ____D C:\Users\usuario\AppData\Local\123_Watermark
2022-02-15 13:36 - 2022-02-15 13:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\123watermark
2022-02-15 13:36 - 2022-02-15 13:36 - 000000000 ____D C:\ProgramData\123 Watermark
2022-02-15 13:36 - 2022-02-15 13:36 - 000000000 ____D C:\Program Files (x86)\123watermark
2022-02-15 13:35 - 2022-02-15 13:36 - 012194680 _____ (123watermark ) C:\Users\usuario\Downloads\123watermark.exe
2022-02-14 18:47 - 2022-02-14 18:47 - 000007081 _____ C:\Users\usuario\Downloads\posting day 3.csv
2022-02-14 18:41 - 2022-02-14 18:41 - 000007080 _____ C:\Users\usuario\Downloads\posting day 2.csv
2022-02-14 15:21 - 2022-02-14 15:21 - 000120114 _____ C:\Users\usuario\Downloads\scanerator.html
2022-02-14 10:22 - 2022-02-14 10:22 - 019552128 _____ (Windscribe Limited) C:\Users\usuario\Downloads\Windscribe.exe
2022-02-13 20:23 - 2022-02-13 20:23 - 000101258 _____ C:\Users\usuario\Downloads\inspo.jfif
2022-02-12 21:10 - 2022-02-12 21:46 - 000000000 ____D C:\Users\usuario\FastCopy
2022-02-12 21:10 - 2022-02-12 21:10 - 003423024 _____ (FastCopy Lab, LLC.) C:\Users\usuario\Downloads\FastCopy4.0.5_installer.exe
2022-02-12 21:10 - 2022-02-12 21:10 - 000000929 _____ C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FastCopy.lnk
2022-02-11 21:09 - 2022-02-11 21:09 - 000056897 _____ C:\Users\usuario\Downloads\semiphemeral-export-angel_caribe-2022-02-12.csv
2022-02-10 15:03 - 2022-02-10 15:03 - 000007080 _____ C:\Users\usuario\Downloads\posts_export_24zs5nrt final week.csv
2022-02-10 13:12 - 2022-02-10 13:12 - 000011813 _____ C:\WINDOWS\system32\DrtmAuthTxt.wim
2022-02-10 13:11 - 2022-02-10 13:11 - 000223744 _____ C:\WINDOWS\SysWOW64\TpmTool.exe
2022-02-10 13:10 - 2022-02-10 13:10 - 000288768 _____ C:\WINDOWS\system32\Windows.Management.InprocObjects.dll
2022-02-10 13:10 - 2022-02-10 13:10 - 000272384 _____ C:\WINDOWS\system32\TpmTool.exe
2022-02-10 13:10 - 2022-02-10 13:10 - 000162816 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2022-02-10 12:19 - 2022-02-10 12:19 - 000000000 ___HD C:\$WinREAgent
2022-02-10 00:44 - 2022-03-03 02:48 - 000000000 ____D C:\Users\usuario\AppData\Local\Google
2022-02-10 00:29 - 2022-02-10 00:29 - 000003217 _____ C:\Users\usuario\Downloads\Comprobante637800497972732354.pdf
2022-02-10 00:29 - 2022-02-10 00:29 - 000003148 _____ C:\Users\usuario\Downloads\Comprobante637800497550003572.pdf
2022-02-08 00:11 - 2022-02-08 00:13 - 109234365 _____ C:\Users\usuario\Downloads\limpieza codigos sagrados.mp4
2022-02-07 11:05 - 2022-02-07 11:05 - 010120448 _____ C:\Users\usuario\Downloads\Photo Exif Editor Metadata Editor_v2.2.11_apkpure.com.apk
2022-02-06 23:55 - 2022-02-06 23:55 - 000000000 ____D C:\Users\usuario\Downloads\GoogleChromePortable 3
2022-02-06 23:33 - 2022-02-06 23:34 - 000000000 ____D C:\Users\usuario\Downloads\GoogleChromePortable2
2022-02-06 23:26 - 2022-02-06 23:26 - 000027819 _____ C:\Users\usuario\Downloads\pexels-photo-736230.jpeg
2022-02-06 23:10 - 2022-02-06 23:12 - 000000000 ____D C:\Users\usuario\Downloads\GoogleChromePortable
2022-02-06 23:10 - 2022-02-06 23:10 - 001409720 _____ (PortableApps.com) C:\Users\usuario\Downloads\GoogleChromePortable_98.0.4758.80_online.paf.exe
2022-02-06 22:29 - 2022-02-06 22:29 - 000001022 _____ C:\Users\usuario\Downloads\Personal_data_9722971.zip
2022-02-06 21:05 - 2022-02-06 21:05 - 000190011 _____ C:\Users\usuario\Downloads\Factura Telecable-2pdf.com-edit-metadata.pdf
2022-02-06 21:01 - 2022-02-06 21:01 - 000189262 _____ C:\Users\usuario\Downloads\Factura Telecable.pdf
2022-02-06 20:59 - 2022-02-06 20:59 - 000208108 _____ C:\Users\usuario\Downloads\Factura Telecable Marzo (2) (1).pdf
2022-02-06 20:51 - 2022-02-06 20:51 - 000198273 _____ C:\Users\usuario\Downloads\Factura Telecable Marzo (2).pdf
2022-02-06 20:32 - 2022-02-06 20:34 - 000143150 _____ C:\Users\usuario\Downloads\Factura Telecable Enero.pdf
2022-02-06 20:26 - 2022-02-06 20:26 - 000173951 _____ C:\Users\usuario\Downloads\Factura Telecable Marzo (1).pdf
2022-02-06 20:10 - 2022-02-06 20:10 - 000190831 _____ C:\Users\usuario\Downloads\Factura Telecable Marzo.pdf
2022-02-06 11:43 - 2022-02-06 11:43 - 000000000 ____D C:\Users\usuario\Documents\Archivos perdidos (1674)
2022-02-06 10:57 - 2022-02-06 10:57 - 000000000 ____D C:\Users\usuario\AppData\Roaming\QtProject
2022-02-06 10:56 - 2022-02-06 11:41 - 000000000 ____D C:\Program Files (x86)\MiniToolPowerDataRecovery
2022-02-06 10:56 - 2022-02-06 10:56 - 000000226 _____ C:\Users\usuario\Downloads\pdr-ol-log.txt
2022-02-06 10:56 - 2022-02-06 10:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Power Data Recovery
2022-02-06 10:56 - 2021-12-13 20:28 - 045064712 _____ (MiniTool Software Limited ) C:\Users\usuario\Downloads\pdr-free-x64.exe
2022-02-06 10:55 - 2022-02-06 10:55 - 002318176 _____ (MiniTool Software Limited) C:\Users\usuario\Downloads\pdr-free-online.exe
 
==================== Un mes (modificado) ==================
 
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
 
2022-03-07 19:23 - 2021-12-28 12:14 - 000004224 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{23BAA7FA-4138-4721-9D23-2B595BA857C2}
2022-03-07 19:04 - 2021-08-14 19:07 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2022-03-07 19:04 - 2019-12-07 03:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2022-03-07 12:25 - 2021-10-14 14:05 - 000000000 ____D C:\Program Files\CCleaner
2022-03-07 11:25 - 2021-10-14 14:05 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2022-03-06 11:56 - 2021-08-05 20:34 - 000000000 ____D C:\Program Files\Microsoft Office
2022-03-06 02:18 - 2021-12-03 13:08 - 000000000 ____D C:\Users\usuario\Documents\SW
2022-03-06 00:38 - 2022-01-13 14:45 - 000000000 ____D C:\Users\usuario\Desktop\Nueva carpeta
2022-03-05 23:55 - 2021-12-22 14:28 - 000000000 ____D C:\Users\usuario\AppData\Roaming\Jarvee
2022-03-05 21:09 - 2019-12-07 03:14 - 000000000 ___HD C:\Program Files\WindowsApps
2022-03-05 21:09 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2022-03-05 20:06 - 2021-12-22 14:28 - 000000000 ____D C:\Users\usuario\AppData\Roaming\ucs
2022-03-04 11:26 - 2021-08-14 19:12 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2022-03-04 11:12 - 2021-10-14 13:22 - 000000000 ____D C:\Users\usuario\Desktop\opera
2022-03-03 14:15 - 2021-08-03 15:24 - 000000000 ____D C:\Users\usuario\AppData\Local\Packages
2022-03-03 10:37 - 2021-08-14 19:22 - 001683676 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2022-03-03 10:37 - 2019-12-07 08:55 - 000753390 _____ C:\WINDOWS\system32\perfh00A.dat
2022-03-03 10:37 - 2019-12-07 08:55 - 000148032 _____ C:\WINDOWS\system32\perfc00A.dat
2022-03-03 10:37 - 2019-12-07 03:13 - 000000000 ____D C:\WINDOWS\INF
2022-03-03 10:29 - 2021-08-14 19:33 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2022-03-03 10:29 - 2021-08-14 19:06 - 000008192 ___SH C:\DumpStack.log.tmp
2022-03-03 10:17 - 2021-08-14 19:12 - 000000000 ____D C:\Users\usuario
2022-03-03 10:17 - 2019-12-07 03:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2022-03-03 10:10 - 2021-10-07 15:54 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2022-03-02 08:34 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2022-02-26 20:26 - 2021-08-05 20:20 - 000000000 ____D C:\Users\usuario\AppData\Local\PlaceholderTileLogoFolder
2022-02-24 12:21 - 2021-08-14 19:33 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task
2022-02-24 12:20 - 2021-12-11 14:02 - 000003596 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3735610940-3711455475-3248009252-1001
2022-02-24 12:20 - 2021-08-05 20:42 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2022-02-18 12:14 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2022-02-18 03:16 - 2021-10-07 16:15 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2022-02-16 12:49 - 2022-01-24 21:25 - 000041614 ____H C:\Users\usuario\Documents\~WRL0005.tmp
2022-02-14 00:43 - 2022-01-13 15:49 - 000000000 ____D C:\Users\usuario\AppData\Local\ElevatedDiagnostics
2022-02-11 12:44 - 2021-08-14 17:07 - 000000000 ____D C:\WINDOWS\system32\MRT
2022-02-11 12:38 - 2021-08-14 17:07 - 149611728 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2022-02-11 12:36 - 2021-08-03 15:25 - 000002354 _____ C:\Users\usuario\Desktop\Microsoft Edge.lnk
2022-02-11 12:29 - 2021-08-14 19:07 - 000436080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2022-02-10 23:32 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2022-02-10 23:32 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\SystemResources
2022-02-10 23:32 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2022-02-10 23:32 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2022-02-10 23:32 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2022-02-10 23:32 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2022-02-10 23:31 - 2019-12-07 08:58 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2022-02-10 23:31 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2022-02-10 23:31 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2022-02-10 23:31 - 2019-12-07 03:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2022-02-10 23:31 - 2019-12-07 03:03 - 000000000 ____D C:\WINDOWS\servicing
2022-02-10 23:14 - 2022-01-02 13:43 - 000000000 ____D C:\Users\usuario\AppData\Local\ManyCam
2022-02-10 13:10 - 2021-08-14 19:10 - 002877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2022-02-10 10:46 - 2021-08-03 15:08 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2022-02-05 22:53 - 2022-01-13 14:38 - 000000000 ____D C:\Users\usuario\Documents\switch
 
==================== SigCheck ============================
 
(No existe una corrección automática para los archivos que no pasan la verificación.)
 
 
BCD (recoveryenabled=No -> recoveryenabled=Yes) <==== restaurado correctamente
==================== Final de FRST.txt ========================
 
 
ADDITION

 

Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 27-02-2022
Ejecutado por usuario (07-03-2022 20:34:05)
Ejecutado desde C:\Users\usuario\Desktop
Microsoft Windows 10 Pro Versión 21H2 19044.1526 (X64) (2021-08-15 01:35:33)
Modo de Inicio: Normal
==========================================================
 
 
==================== Cuentas: =============================
 
 
(Si una entrada es incluida en el fixlist, será eliminada.)
 
Administrador (S-1-5-21-3735610940-3711455475-3248009252-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3735610940-3711455475-3248009252-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-3735610940-3711455475-3248009252-1000 - Limited - Disabled)
Invitado (S-1-5-21-3735610940-3711455475-3248009252-501 - Limited - Disabled)
usuario (S-1-5-21-3735610940-3711455475-3248009252-1001 - Administrator - Enabled) => C:\Users\usuario
WDAGUtilityAccount (S-1-5-21-3735610940-3711455475-3248009252-504 - Limited - Disabled)
 
==================== Centro de Seguridad ========================
 
(Si una entrada es incluida en el fixlist, será eliminada.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Programas instalados ======================
 
(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)
 
123watermark 3.0.0 (HKLM-x32\...\{2F588905-719A-4599-A775-087C8FE045FC}}_is1) (Version: 3.0.0 - 123watermark)
CCleaner (HKLM\...\CCleaner) (Version: 5.90 - Piriform)
Comprobación de estado de PC Windows (HKLM\...\{75741B4B-FC87-494A-A380-0EBA06DB89F9}) (Version: 3.2.2110.14001 - Microsoft Corporation)
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 8.1206.101.112 - ALPS ELECTRIC CO., LTD.)
FastCopy (HKU\S-1-5-21-3735610940-3711455475-3248009252-1001\...\FastCopy) (Version: 4.0.5 - H.Shirouzu & FastCopy Lab, LLC.)
Jarvee (HKLM-x32\...\{CB42768B-7BF0-47BC-8278-23892EC6DF1D}) (Version: 19.3 - Jarvee) Hidden
Jarvee (HKLM-x32\...\Jarvee 19.3) (Version: 19.3 - Jarvee)
ManyCam 5.0.5 (HKLM-x32\...\ManyCam) (Version: 5.0.5 - Visicom Media Inc.)
Mass Watermark version 1.9.2 (HKLM-x32\...\{25BB9D52-8471-4C26-BC79-D3B33BB1A4A7}_is1) (Version: 1.9.2 - masswatermark.com)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 99.0.1150.30 - Microsoft Corporation)
Microsoft Office Profesional Plus 2016 - es-es (HKLM\...\ProPlusRetail - es-es) (Version: 16.0.14931.20120 - Microsoft Corporation)
Microsoft Office Profesional Plus 2019 - es-es (HKLM\...\ProPlus2019Retail - es-es) (Version: 16.0.14931.20120 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 22.022.0130.0001 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{16E50919-B07A-4B4E-994A-476D4773F5BF}) (Version: 3.65.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.29.30139 (HKLM-x32\...\{8d5fdf81-7022-423f-bd8b-b513a1050ae1}) (Version: 14.29.30139.0 - Microsoft Corporation)
MiniTool Power Data Recovery 10.2 (HKLM\...\{E1BCD081-4BF4-4E2F-832A-911EC42EF3C5}_is1) (Version: 10.2 - MiniTool Software Limited)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.14931.20010 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.14931.20094 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\...\{90160000-008C-0C0A-1000-0000000FF1CE}) (Version: 16.0.14931.20072 - Microsoft Corporation) Hidden
Socinator (HKLM-x32\...\{A0DC4487-E552-4C75-AF45-949F8E99F084}) (Version: 1.0.125 - Socinator)
SysTools XPS Viewer v3.0 (HKLM-x32\...\{172915EF-82C5-4A1D-8305-5909B67938D2}_is1) (Version:  - SysTools Software Pvt. Ltd.)
Telegram Desktop (HKU\S-1-5-21-3735610940-3711455475-3248009252-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 3.5.1 - Telegram FZ-LLC)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{3800CCFC-4006-4B30-A103-416AF26A885C}) (Version: 2.71.0.0 - Microsoft Corporation)
Windscribe (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 2.3 Build 16 - Windscribe Limited)
WinRAR 6.02 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.02.0 - win.rar GmbH)
 
Packages:
=========
Complemento de Fotos -> C:\Program Files\WindowsApps\Microsoft.Windows.Photos.DLC.Main_2021.39122.10110.0_x64__8wekyb3d8bbwe [2022-02-26] (Microsoft Corporation)
Complemento de motor del medio de Fotos -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2022-02-17] (Microsoft Corporation)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2021-08-14] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2021-08-14] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.2180.0_x64__8wekyb3d8bbwe [2022-02-25] (Microsoft Studios) [MS Ad]
 
==================== Personalizado CLSID (Lista blanca): ==============
 
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
 
CustomCLSID: HKU\S-1-5-21-3735610940-3711455475-3248009252-1001_Classes\CLSID\{04271989-C4D2-BC0B-9DEB-54F884EEFFB4} -> [OneDrive] => {a52bba46-e9e1-435f-b3d9-28daa648c0f6}
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncShell64.dll [2022-02-24] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-09] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2021-06-11] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Lista blanca) ====================
 
==================== Accesos directos & WMI ========================
 
(Las entradas pueden ser listadas para ser restauradas o eliminadas.)
 
Shortcut: C:\Users\usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Users\usuario\Downloads\GoogleChromePortable\App\Chrome-bin\chrome.exe (Google LLC)
ShortcutWithArgument: C:\Users\usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e5fad960c7874134\Google Chrome.lnk -> C:\Users\usuario\Downloads\GoogleChromePortable\App\Chrome-bin\chrome.exe (Google LLC) -> --profile-directory=Default
 
==================== Módulos cargados (Lista blanca) =============
 
2022-03-03 14:25 - 2022-03-03 14:25 - 002854912 _____ () [Archivo no firmado] C:\Program Files (x86)\Windscribe\libGLESv2.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 000074752 _____ () [Archivo no firmado] C:\Program Files (x86)\Windscribe\zlib1.dll
2021-08-05 20:40 - 2021-08-05 20:40 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\root\Office16\AppVIsvSubsystems64.dll
2021-08-05 20:40 - 2021-08-05 20:40 - 000000000 ____L (Microsoft Corporation) [simlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll] C:\Program Files\Microsoft Office\root\Office16\c2r64.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 000168448 _____ (The c-ares library, hxxps://c-ares.haxx.se/) [Archivo no firmado] C:\Program Files (x86)\Windscribe\cares.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 000419840 _____ (The curl library, hxxps://curl.se/) [Archivo no firmado] C:\Program Files (x86)\Windscribe\libcurl.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 002227200 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [Archivo no firmado] C:\Program Files (x86)\Windscribe\libcrypto-1_1.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 000532480 _____ (The OpenSSL Project, hxxps://www.openssl.org/) [Archivo no firmado] C:\Program Files (x86)\Windscribe\libssl-1_1.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 000025600 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\imageformats\qico.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 001171456 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\platforms\qwindows.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 005104640 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\Qt5Core.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 004101120 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\Qt5Gui.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 001072128 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\Qt5Network.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 000270336 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\Qt5Svg.dll
2022-03-03 14:25 - 2022-03-03 14:25 - 004573696 _____ (The Qt Company Ltd.) [Archivo no firmado] C:\Program Files (x86)\Windscribe\Qt5Widgets.dll
 
==================== Alternate Data Streams (Lista blanca) ========
 
==================== Modo Seguro (Lista blanca) ==================
 
==================== Asociación (Lista blanca) =================
 
==================== Internet Explorer (Lista blanca) ==========
 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2022-03-04] (Microsoft Corporation -> Microsoft Corporation)
 
==================== Hosts contenido: =========================
 
(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)
 
2022-02-20 12:51 - 2022-02-20 12:51 - 000000824 _____ C:\WINDOWS\system32\drivers\etc\hosts
 
==================== Otras Áreas ===========================
 
(Actualmente no existe una corrección automática para esta sección.)
 
HKU\S-1-5-21-3735610940-3711455475-3248009252-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\usuario\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 10.255.255.2 - 190.113.97.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Firewall de Windows está habilitado.
 
==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==
 
==================== Reglas de firewall (Lista blanca) ================
 
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
 
FirewallRules: [{26701E90-FF61-44D9-9937-3ACD1AD54470}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3CE1086A-FC50-4A91-991E-92C3826DFC2D}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3F5D4FA7-A2FA-4014-BF7B-E62A6ADF217E}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A3F8CA52-2DE4-4183-B3C5-7F14A53BE150}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B9082581-EC02-45D0-BABD-560922FBEFE4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{759C9465-0123-4232-82FA-66538ADAC965}C:\users\usuario\desktop\opera\opera.exe] => (Block) C:\users\usuario\desktop\opera\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [UDP Query User{B58A0DB9-9DE9-4889-A3D7-D8B7D7FE7EF1}C:\users\usuario\desktop\opera\opera.exe] => (Block) C:\users\usuario\desktop\opera\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [TCP Query User{C548F041-0E16-4279-A39B-3F05A22DFB7A}C:\users\usuario\desktop\opera\opera.exe] => (Block) C:\users\usuario\desktop\opera\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [UDP Query User{2ED6FDBA-BA4C-4D37-B087-CDA42C7749BE}C:\users\usuario\desktop\opera\opera.exe] => (Block) C:\users\usuario\desktop\opera\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{A2DF6123-C05A-48E8-B6C6-BE1BF8FD4211}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1F8173BB-0FB3-4547-9F64-7ABD043B192F}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7732D452-5004-4926-A399-D716704DF26E}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7E3596EB-DF6C-47D6-9789-C4B04E5BA8B8}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.80.194.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{CDB1572B-E382-40E9-8720-26F8F117E904}C:\users\usuario\downloads\googlechromeportable\app\chrome-bin\chrome.exe] => (Block) C:\users\usuario\downloads\googlechromeportable\app\chrome-bin\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{D7F84EB9-EDB6-406F-A2DA-05146D9C86AC}C:\users\usuario\downloads\googlechromeportable\app\chrome-bin\chrome.exe] => (Block) C:\users\usuario\downloads\googlechromeportable\app\chrome-bin\chrome.exe (Google LLC -> Google LLC)
 
==================== Puntos de Restauración =========================
 
22-02-2022 20:10:43 Punto de control programado
02-03-2022 08:32:20 Instalador de Módulos de Windows
 
==================== Dispositivos defectuosos en el Administrador de dispositivos ============
 
Name: Broadcom USH
Description: Broadcom USH
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Puerto serie PCI
Description: Puerto serie PCI
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Controladora de dispositivo de almacenamiento
Description: Controladora de dispositivo de almacenamiento
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Errores del registro de eventos: ========================
 
Errores de aplicación:
==================
Error: (03/07/2022 08:38:23 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 08:19:23 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 07:05:52 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 07:05:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 07:05:07 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 07:04:58 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 05:26:39 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (03/07/2022 05:26:32 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0xC004F074
Argumentos de línea de comandos:
RuleId=dca14e37-0c5c-444f-9b35-1e2f161f5ac3;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=2de67392-b7a7-462a-b1ca-108dd189f588;NotificationInterval=1440;Trigger=NetworkAvailable
 
 
Errores del sistema:
=============
Error: (03/07/2022 11:48:47 AM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-4OO4NRC)
Description: No se puede iniciar un servidor DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Error 
"2147942767"
al iniciar este comando:
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
 
Error: (03/05/2022 10:20:15 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4OO4NRC)
Description: El servidor microsoft.windowscommunicationsapps_16005.14326.20544.0_x64__8wekyb3d8bbwe!microsoft.windowslive.calendar.AppXwkn9j84yh1kvnt49k5r8h6y1ecsv09hs.mca no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (03/03/2022 07:01:11 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80073d02: 9NMPJ99VJBWV-Microsoft.YourPhone.
 
Error: (03/03/2022 02:24:12 PM) (Source: Server) (EventID: 2505) (User: )
Description: El servidor no pudo enlazarse al transporte \Device\NetBT_Tcpip_{2A8B176C-D8CC-40BB-9136-05AD249595EF} debido a que otro equipo en la red tiene el mismo nombre. No se puede iniciar el servidor.
 
Error: (03/03/2022 02:18:38 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-4OO4NRC)
Description: No se puede iniciar un servidor DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Error 
"2147942767"
al iniciar este comando:
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
 
Error: (03/03/2022 12:47:46 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4OO4NRC)
Description: El servidor Microsoft.Windows.Photos_2021.21090.10008.0_x64__8wekyb3d8bbwe!App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (03/03/2022 10:17:08 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4OO4NRC)
Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido.
 
Error: (03/03/2022 10:17:08 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-4OO4NRC)
Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con DCOM dentro del tiempo de espera requerido.
 
 
Windows Defender:
================
Date: 2022-03-07 11:18:31
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {6B800F67-FD02-4A1E-887F-C1BE7E80E3AD}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2022-03-06 13:48:20
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {686B2C80-5C1D-47F0-9C52-F285BFE54ECF}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2022-03-06 11:57:21
Description: 
El acceso controlado a carpetas bloqueó C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE para que no pueda modificar %userprofile%\Documents\SW\.
Hora de detección: 2022-03-06T17:57:21.352Z
Usuario: DESKTOP-4OO4NRC\usuario
Ruta de acceso: %userprofile%\Documents\SW\
Nombre del proceso: C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
Versión de inteligencia de seguridad: 1.359.1468.0
Versión del motor: 1.1.18900.3
Versión del producto: 4.18.2201.10
 
Date: 2022-03-05 12:00:57
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {41270EB6-0F45-43DA-BF56-3B90B1B0C979}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM
 
Date: 2022-03-04 16:13:17
Description: 
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {F295F063-4D21-41DC-9896-63D00EC6961A}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM

==================== Información de la memoria =========================== 
 
BIOS: Dell Inc. A13 11/17/2013
Placa base: Dell Inc. 0R97MN
Procesador: Intel® Core™ i5-2520M CPU @ 2.50GHz
Porcentaje de memoria en uso: 62%
RAM física total: 8073.01 MB
RAM física disponible: 3026.89 MB
Virtual total: 14217.01 MB
Virtual disponible: 7463.83 MB
 
==================== Unidades ================================
 
Drive c: () (Fixed) (Total:465.19 GB) (Free:270.96 GB) NTFS
 
\\?\Volume{dc2a8805-0000-0000-0000-100000000000}\ (Reservado para el sistema) (Fixed) (Total:0.57 GB) (Free:0.1 GB) NTFS
 
==================== MBR & Tabla de particiones ====================
 
==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: DC2A8805)
Partition 1: (Active) - (Size=579 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.2 GB) - (Type=07 NTFS)
 
==================== Final de Addition.txt =======================

 

I was no able to run farbar in my desktop with Windows 7, it Will stay stuck in backing up registry.

 

I downloaded the 64 bit version which should be compatible with my desktop.

Thank you so much in advance.

 

 


    Advertisements

Register to Remove


#2 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 09 March 2022 - 11:30 AM

I don't know if I can help because I don't actually see a way of entry or malware.
 
I need to ask a question
I see a ton of files that are maybe pictures? They have a file extension ending jfif
Do you recognize or did you download these files yourself?
 
C:\Users\usuario\Downloads\FIvwQN_WUAIdMVk.jfif
C:\Users\usuario\Downloads\FNJL2ZHVIAQLPYX.jfif
C:\Users\usuario\Downloads\FNJL2YgVcAIig1s.jfif
C:\Users\usuario\Downloads\FL_hzGZXEAMasbL.jfif
C:\Users\usuario\Downloads\FM0p3QnXIAIDCcj.jfif
C:\Users\usuario\Downloads\FM0Yq-FXIAwNUrP.jfif
C:\Users\usuario\Downloads\FMv7PQHXwAIJup3.jfif
C:\Users\usuario\Downloads\FM0WRdAVUAUqMLt.jfif
C:\Users\usuario\Downloads\FMs1zkfXsAAq8Yo.jfif
C:\Users\usuario\Downloads\FD-FhRNVIAAbkyx.jfif
C:\Users\usuario\Downloads\FMtFg3KXEAMvzH9.jfif
C:\Users\usuario\Downloads\FMdq15FWYAUO1pw.jfif

~~~~

First, please reboot your router to your wireless connection.
Second, if you can, change your passwords on all of your sensitive personal accounts from a known clean computer this will add a level of security.

Don't forget to write down or keep new passwords safe.

~~~~~~~~~~~~~~~~~
AdwCleaner - Clean
here

  • Double click AdwCleaner.exe to run it.
  • Click Scan Now
  • When the scan has finished a Scan Results window will open.
  • Please check all boxes and then click Quarantine
  • Click Next
  • If any pre-installed software was found on your machine, a prompt window will open ...
  • Click OK to close it
  • Check any pre-installed software items you want to remove (if they're not causing you a problem I recommend you don't select any)
  • Click Quarantine
  • A prompt to save your work will appear ...
  • Click Continue when you're ready to proceed.
  • A prompt to restart your computer will appear ...
  • Click Restart Now
  • Once your computer has restarted ...
  • If it doesn't open automatically, please start AdwCleaner ...
  • Click the Log Files tab ...
  • Double click on the latest Clean log (Clean logs have a [C0*] suffix, where * is replaced by a number, the latest scan will have the largest number)
  • A Notepad file will open containing the results of the removal.

Please post the contents of the file in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The below scanner has been updated, instructions might have changed a bit but, if you run the tool and it asks to quarantine please allow it.

Run Malwarebytes Anti-Malware

You may have Malwarebytes Anti-Malware installed but if not, you can download it from here:

  • run the program
  • click on the ‘Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the ‘Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the ‘Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

 

Please post both logs when finished.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#3 bussw83

bussw83

    New Member

  • New Member
  • Pip
  • 3 posts

Posted 15 March 2022 - 08:10 PM

Hello I want to sincerely apologize for the long wait and thank you for looking into this.

 

This are the logs 

 

====================================FARBAR DESKT TOP COMPUTER WITH WIN 7=================================

 

 
Conversación abierta. 1 mensaje sin leer.
 
Ir al contenido
Uso de Gmail con lectores de pantalla
 
Buscar
Buscar correo
 
 
Meet
Nueva reunión
Unirse a una reunión
Hangouts
 
1 de 2.942
logs
Recibidos
 
Serena Love
Adjuntos
19:44 (hace 23 minutos)
para mí
 
   
Traducir mensaje
Desactivar para: inglés
 
2 archivos adjuntos
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-02-2022 (ATTENTION: ====> FRST version is 249 days old and could be outdated)
Ran by cherishedlady (administrator) on SERENA (Hewlett-Packard HP Compaq dc5800 Microtower) (03-11-2022 20:57:58)
Running from C:\Users\Mantenida.Serena\Desktop
Loaded Profiles: cherishedlady
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Safe Mode (with Networking)
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [123672 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\...\RunOnce: [GrpConv] => grpconv -o (No File)
HKU\S-1-5-21-3609342701-1927152815-2929608412-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3609342701-1927152815-2929608412-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\Run: [MyDesktopTherapist] => C:\Users\Mantenida.Serena\AppData\Roaming\mydesktoptherapist.com\MyDesktopTherapist\1.7.0.0 [0 2021-09-03] () <==== ATTENTION [zero byte File/Folder]
HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3609342701-1927152815-2929608412-501\...\Run: [Windscribe] => "C:\Program Files (x86)\Windscribe\Windscribe.exe" -os_restart (No File)
BootExecute: autocheck autochk *  
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3609342701-1927152815-2929608412-1003\User: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Policies: C:\Users\cherishedlady\NTUSER.pol: Restriction <==== ATTENTION
Policies: C:\Users\Mantenida.Serena\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {039FE55A-2205-455E-9425-4C9B882CC6D4} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {2937DDE7-E8F4-4B17-B013-150FEA87C663} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [4903192 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
Task: {5F5B3354-5886-4C6E-953C-83FB49E7A1F0} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [919936 2021-09-06] (Glarysoft LTD -> Glarysoft Ltd)
Task: {6A59A976-58AF-49EE-8496-5E45FB4D1581} - \CheckPointUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {8420101E-7A92-4B24-A44B-CB0DF65DFCBD} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2296088 2022-03-09] (Avast Software s.r.o. -> Avast Software)
Task: {897809AC-4B8E-434A-84B6-2AC2E40F8582} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {9182A8F5-50C9-4E02-9E92-FBBCE099C721} - \CheckPointUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {98D556BC-683E-4312-8447-F4C9D5DFCDC8} - System32\Tasks\CCleanerSkipUAC - cherishedlady => C:\Users\cherishedlady\Desktop\ccsetup582\CCleaner.exe [28880512 2021-06-16] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {9E87384B-69C5-4D8F-A405-4C9DA0233B1F} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1907712 2021-05-20] () [File not signed]
Task: {A1E3D1ED-D75C-46EC-9CAC-859682571C76} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [137088 2021-09-06] (Glarysoft LTD -> Glarysoft Ltd)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Tweaking.com - Windows Repair Tray Icon.job => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)Tweaking.com - Windows Repair)Created By Tweaking.com
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [S-1-5-21-3609342701-1927152815-2929608412-1003] => http=127.0.0.1:8888; https=127.0.0.1:8888
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Tcpip\Parameters: [DhcpNameServer] 190.113.97.11 190.113.97.3
Tcpip\..\Interfaces\{CEE6D970-E6A6-45EF-BB84-E11E7E555AD8}: [DhcpNameServer] 190.113.97.11 190.113.97.3
 
FireFox:
========
FF DefaultProfile: hkvx3dxl.default
FF ProfilePath: C:\Users\cherishedlady\AppData\Roaming\Mozilla\Firefox\Profiles\hkvx3dxl.default [2021-11-12]
FF ProfilePath: C:\Users\cherishedlady\AppData\Roaming\Mozilla\Firefox\Profiles\jjow1ik1.default-release [2022-01-26]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\plugins\npFoxitReaderPlugin.dll [2021-04-26] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.cpdf -> C:\Program Files (x86)\plugins\npFoxitReaderPlugin.dll [2021-04-26] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\plugins\npFoxitReaderPlugin.dll [2021-04-26] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\plugins\npFoxitReaderPlugin.dll [2021-04-26] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\plugins\npFoxitReaderPlugin.dll [2021-04-26] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @tools.google.com/CheckPoint Update;version=3 -> C:\Program Files (x86)\CheckPoint\Update\1.3.99.0\npZoneAlarmUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/CheckPoint Update;version=9 -> C:\Program Files (x86)\CheckPoint\Update\1.3.99.0\npZoneAlarmUpdate3.dll [No File]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [8249936 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [625432 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [373528 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S2 clr_optimization_v2.0.50727_64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [89920 2009-06-10] (Microsoft Corporation -> Microsoft Corporation)
S2 clr_optimization_v4.0.30319_64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [158912 2019-03-28] (Microsoft Dynamic Code Publisher -> Microsoft Corporation)
S4 FoxitReaderUpdateService; C:\Program Files (x86)\FoxitReaderUpdateService.exe [2356800 2021-04-20] (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
S3 GUBootService; C:\Program Files (x86)\Glary Utilities 5\GUBootService.exe [867712 2021-09-06] (Glarysoft LTD -> Glarysoft Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
S4 rkrtservice; C:\Program Files\RogueKiller\RogueKillerSvc.exe [13921616 2021-06-15] (Adlice -> )
S2 VoodooShieldService; C:\Program Files\VoodooShield\VoodooShieldService.exe [158432 2021-12-29] (VoodooSoft, LLC -> VoodooSoft, LLC)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [35720 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [216928 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [366616 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [250392 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [99352 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [41352 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [182600 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [524400 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [38152 2021-07-23] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [107848 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [82912 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [851192 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S1 aswSP; C:\Windows\System32\drivers\aswSP.sys [471920 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S2 aswStm; C:\Windows\System32\drivers\aswStm.sys [215384 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [327536 2021-07-23] (Avast Software s.r.o. -> AVAST Software)
S2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-04-06] (Bluestack Systems, Inc -> Bluestack System Inc.)
S2 cpbak; C:\Windows\System32\DRIVERS\cpbak.sys [83248 2020-09-03] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
S1 CPEPMon; C:\Windows\System32\DRIVERS\CPEPMon.sys [150968 2021-05-30] (Microsoft Windows Hardware Compatibility Publisher -> Check Point Software Technologies)
R3 e1express; C:\Windows\System32\DRIVERS\e1e6032e.sys [278016 2009-06-10] (Microsoft Windows -> Intel Corporation)
S1 epnetflt; C:\Windows\system32\drivers\epnetflt.sys [135984 2020-12-06] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
S1 epregflt; C:\Windows\system32\drivers\epregflt.sys [133416 2020-12-02] (Check Point Software Technologies Ltd. -> Check Point Software Technologies)
S1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [28936 2021-09-25] (Glarysoft LTD -> Glarysoft Ltd)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [49264 2014-07-28] (Visicom Media Inc. -> Visicom Media Inc.)
S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [260480 2021-09-25] (Malwarebytes Corporation -> Malwarebytes)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35440 2014-05-13] (Visicom Media Inc. -> Visicom Media Inc.)
S3 nlwt; C:\Windows\System32\DRIVERS\nlwt.sys [29888 2020-06-10] (TEFINCOM S.A. -> WireGuard LLC)
S3 RkFlt; C:\Windows\System32\drivers\rkflt.sys [42056 2021-06-24] (Adlice -> )
S3 tapnordvpn; C:\Windows\System32\DRIVERS\tapnordvpn.sys [35592 2020-06-09] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tapwindscribe0901; C:\Windows\System32\DRIVERS\tapwindscribe0901.sys [48544 2021-06-17] (Windscribe Limited -> The OpenVPN Project)
S3 UVC; C:\Windows\System32\DRIVERS\usbcam_295.sys [1131520 2018-05-02] (The Imaging Source Europe GmbH -> The Imaging Source Europe GmbH)
S3 voxaldriver; C:\Windows\System32\DRIVERS\voxaldriverx64.sys [55976 2021-12-13] (NCH Software, Inc. -> )
R1 vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [636808 2020-12-24] (Check Point Software Technologies Ltd. -> Check Point Software Technologies Ltd.)
S3 VSScanner; C:\Windows\System32\DRIVERS\vsscanner.sys [21064 2016-08-19] (VoodooSoft, LLC -> VoodooSoft, LLC)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
S3 windtun420; C:\Windows\System32\DRIVERS\windtun420.sys [38312 2021-06-17] (Windscribe Limited -> WireGuard LLC)
S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X]
S2 ISWKL; \??\C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Common\bin\ISWKL.sys [X]
U3 TrueSight; \??\C:\Windows\System32\drivers\truesight.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-11-03 20:57 - 2022-11-03 20:59 - 000014399 _____ C:\Users\Mantenida.Serena\Desktop\FRST.txt
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-11-03 20:58 - 2022-03-07 21:17 - 000000000 ____D C:\FRST
2022-11-03 20:55 - 2022-02-18 11:37 - 000248778 _____ C:\Windows\ntbtlog.txt
2022-11-03 20:55 - 2021-08-26 14:42 - 000065536 _____ C:\Windows\system32\Ikeext.etl
2022-11-03 20:55 - 2021-06-30 16:26 - 000012288 _____ C:\Windows\system32\Drivers\vsparam.reg
2022-11-03 20:55 - 2021-06-30 16:26 - 000008192 _____ C:\Windows\system32\Drivers\vsflt.reg
2022-11-03 20:55 - 2010-11-21 01:16 - 000000000 ____D C:\Windows\CSC
2022-11-03 20:55 - 2009-07-13 22:45 - 000274320 _____ C:\Windows\system32\FNTCACHE.DAT
2022-11-03 20:54 - 2009-07-13 23:13 - 000858336 _____ C:\Windows\system32\PerfStringBackup.INI
2022-11-03 20:54 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\inf
2022-11-03 20:48 - 2009-07-13 20:34 - 000000439 _____ C:\Windows\win.ini
2022-11-03 20:44 - 2021-05-10 13:49 - 000858336 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2022-11-03 20:35 - 2021-07-23 15:19 - 000000000 ____D C:\ProgramData\Avast Software
2022-11-03 20:35 - 2009-07-13 23:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-11-03 20:34 - 2022-01-26 18:49 - 000000000 ____D C:\ProgramData\VoodooShield
2022-11-03 20:31 - 2021-05-10 12:07 - 000057560 _____ C:\Users\cherishedlady\AppData\Local\GDIPFONTCACHEV1.DAT
2022-11-03 20:24 - 2021-11-12 08:35 - 000000000 ____D C:\Users\Mantenida.Serena\Desktop\ccsetup582
2022-11-03 20:22 - 2009-07-13 22:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-11-03 20:22 - 2009-07-13 22:45 - 000026352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-11-03 20:18 - 2021-07-23 15:22 - 000004168 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2022-11-03 20:06 - 2021-06-27 17:16 - 000000000 ____D C:\Users\Mantenida.Serena\AppData\LocalLow\Mozilla
2022-11-03 19:45 - 2009-07-13 23:08 - 000032550 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2022-11-03 16:58 - 2022-03-09 19:10 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-11-03 16:58 - 2021-11-12 09:13 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
 
==================== Files in the root of some directories ========
 
2001-08-10 09:00 - 2001-08-10 09:00 - 000000000 ____H () C:\ProgramData\sdpsenv.dat
2021-05-10 13:52 - 2021-03-18 20:43 - 000497216 _____ (Foxit Software Inc.) C:\Program Files (x86)\64BitMailAgent.exe
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-console-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-datetime-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-debug-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-errorhandling-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000021768 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-file-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-file-l1-2-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-file-l2-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-handle-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-heap-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-interlocked-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000019208 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-libraryloader-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000020744 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-localization-l1-2-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-memory-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-namedpipe-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000019208 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-processenvironment-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000020232 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-processthreads-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-processthreads-l1-1-1.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000017672 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-profile-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000017672 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-rtlsupport-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-string-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000020232 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-synch-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-synch-l1-2-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000019208 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-sysinfo-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-timezone-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018184 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-core-util-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000002560 _____ (Microsoft Corporation) C:\Program Files (x86)\API-MS-Win-core-xstate-l2-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000019208 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-conio-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000022280 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-convert-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-environment-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000020232 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-filesystem-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000019208 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-heap-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-locale-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000028936 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-math-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000026376 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-multibyte-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000072968 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-private-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000019208 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-process-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000022792 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-runtime-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000024328 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-stdio-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000024328 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-string-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000020744 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-time-l1-1-0.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000018696 _____ (Microsoft Corporation) C:\Program Files (x86)\api-ms-win-crt-utility-l1-1-0.dll
2021-05-10 14:12 - 2021-03-19 00:43 - 000001756 _____ () C:\Program Files (x86)\CollectStrategy.host
2021-05-10 13:52 - 2021-04-26 23:45 - 105434192 _____ (Foxit Software Inc.) C:\Program Files (x86)\FoxitReader.exe
2021-05-10 13:52 - 2021-04-27 04:23 - 000074588 _____ () C:\Program Files (x86)\FoxitReader.exe.man
2021-05-10 13:52 - 2021-04-26 19:29 - 002008144 _____ (Foxit Software Inc.) C:\Program Files (x86)\FoxitReaderConnectedPDFService.exe
2021-05-10 13:52 - 2021-04-20 10:05 - 002356800 _____ (Foxit Software Inc.) C:\Program Files (x86)\FoxitReaderUpdateService.exe
2021-05-10 13:52 - 2021-04-26 19:30 - 005906512 _____ (Foxit Corporation) C:\Program Files (x86)\FoxitUpdater.exe
2021-05-10 13:52 - 2021-04-26 19:29 - 002780752 _____ (Foxit Software Inc.) C:\Program Files (x86)\FPCSDK.dll
2021-05-10 13:52 - 2021-04-26 19:29 - 003671632 _____ (Foxit Software Inc.) C:\Program Files (x86)\FPCSDK64.dll
2021-05-10 13:52 - 2021-03-19 00:43 - 002154416 _____ (TODO: <公司名>) C:\Program Files (x86)\FXCUSTOM.dll
2021-05-10 13:52 - 2020-08-13 20:19 - 001036464 _____ (Foxit Software Inc.) C:\Program Files (x86)\fxLuceneLib.dll
2021-05-10 13:52 - 2021-03-19 00:44 - 010410272 _____ () C:\Program Files (x86)\icudtl.dat
2021-05-10 13:52 - 2021-03-19 00:44 - 000001478 _____ () C:\Program Files (x86)\legal.txt
2021-05-10 13:52 - 2021-04-26 19:29 - 002147408 _____ (Foxit Software Inc.) C:\Program Files (x86)\LocalService.dll
2021-05-10 13:52 - 2020-08-13 20:19 - 001982128 _____ (Foxit Software Inc.) C:\Program Files (x86)\lucene++-contrib.dll
2021-05-10 13:52 - 2020-08-13 20:19 - 007557296 _____ (Foxit Software Inc.) C:\Program Files (x86)\lucene++.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 005122704 _____ (Microsoft Corporation) C:\Program Files (x86)\mfc140u.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000092816 _____ (Microsoft Corporation) C:\Program Files (x86)\mfcm140u.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000457512 _____ (Microsoft Corporation) C:\Program Files (x86)\msvcp140.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000027076 _____ () C:\Program Files (x86)\notice.txt
2021-05-10 13:52 - 2021-03-19 00:44 - 000051888 _____ () C:\Program Files (x86)\opentracing.dll
2021-05-10 13:52 - 2021-03-19 00:44 - 000060080 _____ () C:\Program Files (x86)\opentracing64.dll
2021-05-10 13:52 - 2021-04-12 02:01 - 003095616 _____ (Foxit Corporation) C:\Program Files (x86)\SendCrashReport.exe
2021-05-10 13:52 - 2021-04-26 19:29 - 002786896 _____ (Foxit Corporation) C:\Program Files (x86)\Sensor.dll
2021-05-10 13:52 - 2021-04-26 19:29 - 003991632 _____ (Foxit Corporation) C:\Program Files (x86)\Sensor64.dll
2021-05-10 13:52 - 2021-04-26 19:29 - 002501200 _____ (Foxit Software Inc.) C:\Program Files (x86)\ServiceMiniNotice.exe
2021-05-10 13:52 - 2021-04-12 02:02 - 003220032 _____ (Foxit Software Inc.) C:\Program Files (x86)\TrackReview.exe
2021-05-10 13:52 - 2020-07-10 01:11 - 001172232 _____ (Microsoft Corporation) C:\Program Files (x86)\ucrtbase.dll
2021-05-10 13:52 - 2021-05-10 14:12 - 000422480 _____ () C:\Program Files (x86)\unins000.dat
2021-05-10 14:12 - 2021-05-10 14:11 - 001487248 _____ () C:\Program Files (x86)\unins000.exe
2021-05-10 13:53 - 2021-05-10 14:12 - 000022709 _____ () C:\Program Files (x86)\unins000.msg
2021-05-10 13:52 - 2021-05-10 14:12 - 000001160 _____ () C:\Program Files (x86)\UpdaterInfo.xml
2021-05-10 13:52 - 2020-07-10 01:11 - 000267592 _____ (Microsoft Corporation) C:\Program Files (x86)\vccorlib140.dll
2021-05-10 13:52 - 2020-07-10 01:11 - 000083784 _____ (Microsoft Corporation) C:\Program Files (x86)\vcruntime140.dll
2021-05-13 15:12 - 2021-12-02 14:25 - 000001456 _____ () C:\Users\cherishedlady\AppData\Local\Adobe Save for Web 13.0 Prefs
2021-05-19 18:50 - 2022-03-06 10:44 - 000007605 _____ () C:\Users\cherishedlady\AppData\Local\Resmon.ResmonCfg
 
==================== FLock ==============================
 
2021-07-02 23:52 C:\SandBlastBackup
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
 
LastRegBack: 2022-11-03 18:01
==================== End of FRST.txt ========================
FRST.txt
Mostrando FRST.txt.
 
 
 
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-02-2022
Ran by cherishedlady (03-11-2022 20:59:33)
Running from C:\Users\Mantenida.Serena\Desktop
Microsoft Windows 7 Ultimate  Service Pack 1 (X64) (2021-05-10 15:51:07)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-3609342701-1927152815-2929608412-500 - Administrator - Disabled)
cherishedlady (S-1-5-21-3609342701-1927152815-2929608412-1000 - Administrator - Enabled) => C:\Users\cherishedlady
Guest (S-1-5-21-3609342701-1927152815-2929608412-501 - Limited - Disabled) => C:\Users\Guest
Mantenida (S-1-5-21-3609342701-1927152815-2929608412-1003 - Limited - Enabled) => C:\Users\Mantenida.Serena
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {5078598A-1FA2-C888-AA5F-A9C66537DB12}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
4Media Video Joiner 2 (HKLM-x32\...\4Media Video Joiner 2) (Version: 2.2.0.20170209 - 4Media)
Adobe Photoshop CC 2019 (HKLM-x32\...\PHSP_20_0_5) (Version: 20.0.5 - Adobe Systems Incorporated)
Any Video Converter 7.1.4 (HKLM-x32\...\Any Video Converter) (Version: 7.1.4 - Anvsoft)
Audacity 3.0.4 (HKLM\...\Audacity_is1) (Version: 3.0.4 - Audacity Team)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 21.5.2470 - Avast Software)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 21.5.2470 - Avast Software)
Balabolka (HKLM-x32\...\Balabolka) (Version: 2.01 - Ilya Morozov)
Bandicam (HKLM-x32\...\Bandicam) (Version: 5.1.1.1837 - Bandicam.com)
Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version:  - Bandicam.com)
BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.200.0.5201 - BlueStack Systems, Inc.)
CDisplay 1.8 (HKLM-x32\...\CDisplay_is1) (Version:  - dvd8n)
Charles 3.12.3 (HKLM\...\{89C65CCA-E5F4-4503-84D2-CBA7F0833C46}) (Version: 3.12.3.1 - XK72 Ltd)
Cute Video Watermark 1.1.0.1 (HKLM-x32\...\Cute Video Watermark_is1) (Version:  - )
Directory Opus (HKLM\...\{6CFA061F-1A4C-4569-963F-2ACFC60F5CAD}_is1) (Version: 12.24 - GPSoftware)
Exif Pilot 5.19.2 (HKLM-x32\...\Exif Pilot 5.19.2_is1) (Version: 5.19.2 - Two Pilots)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 10.1.4.37651 - Foxit Software Inc.)
Free Video Watermark Maker 3.0 (HKLM-x32\...\{DDEE3052-2DBB-4431-A315-2EDC139C54BB}}_is1) (Version: 3.0 - yyzsoft, Inc.)
Freedom (HKLM-x32\...\{107DFB71-C022-4C04-9882-C75BF424361F}) (Version: 2.5.7 - Freedom.to) Hidden
Freedom (HKLM-x32\...\Freedom 2.5.7) (Version: 2.5.7 - Freedom.to)
Glary Utilities 5.173 (HKLM-x32\...\Glary Utilities 5) (Version: 5.173.0.201 - Glarysoft Ltd)
HandBrake 1.0.7 (HKLM-x32\...\HandBrake) (Version: 1.0.7 - )
K-Lite Codec Pack 16.2.0 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 16.2.0 - KLCP)
Loquendo TTS: Carmen (Spanish) (HKLM-x32\...\LoqTTS-Carmen_is1) (Version:  - )
Loquendo TTS: Esperanza (Spanish-Mexican) (HKLM-x32\...\LoqTTS-Esperanza_is1) (Version:  - )
Loquendo TTS: Jorge (Spanish) (HKLM-x32\...\LoqTTS-Jorge_is1) (Version:  - )
Malwarebytes version 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
ManyCam 4.0.110 (HKLM-x32\...\ManyCam) (Version: 4.0.110 - Visicom Media Inc.)
MediaJoin (HKLM-x32\...\MediaJoin) (Version:  - Mystik Media)
Microsoft .NET Framework 4.8 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.8.03761 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.29.30133 (HKLM-x32\...\{295d1583-fdb9-414b-a4c8-da539362a26b}) (Version: 14.29.30133.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 98.0 (x64 en-US)) (Version: 98.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 94.0.1 - Mozilla)
NextUp-ScanSoft Tom US English Voice (HKLM-x32\...\{7613D584-C5FA-4961-AFEA-7E4AF7C41F79}) (Version: 4.0.0 - NextUp.com)
ocenaudio (HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\ocenaudio) (Version: 3.10.11 - Ocenaudio Team)
Python 3.8.0 (64-bit) (HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\{06afee40-d856-48c5-8ff2-bd1c3655edca}) (Version: 3.8.150.0 - Python Software Foundation)
Python 3.8.0 Add to Path (64-bit) (HKLM\...\{5A2EADD1-0723-47C5-A156-C8E6A922BC72}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Core Interpreter (64-bit) (HKLM\...\{0AD20F5D-4228-48F6-9314-F42EBD9DCBC8}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Development Libraries (64-bit) (HKLM\...\{700DB3F0-C5C0-4160-A513-C33B5B20F877}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Documentation (64-bit) (HKLM\...\{7B7ED49A-2149-4035-BFB1-910BE25D799E}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Executables (64-bit) (HKLM\...\{A8C1C406-A3AF-41CC-81BD-217FDF1668B2}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 pip Bootstrap (64-bit) (HKLM\...\{F31907FF-A97B-402E-A629-2BD98D30AC4F}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Standard Library (64-bit) (HKLM\...\{682627D4-757B-42BE-B2D3-94AB0F3D08FF}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Tcl/Tk Support (64-bit) (HKLM\...\{2DE0FB10-3895-4887-BD32-36CCFD3189CE}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Test Suite (64-bit) (HKLM\...\{FFE5B55B-7ED0-4E24-85C3-AB9BCD6881EE}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python 3.8.0 Utility Scripts (64-bit) (HKLM\...\{4420515A-062F-40AF-BFA6-04631B60ED22}) (Version: 3.8.150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{7DBA9B7D-924F-4CE8-8AE8-65977EF62744}) (Version: 3.8.6860.0 - Python Software Foundation)
RogueKiller version 15.0.3.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 15.0.3.0 - Adlice Software)
Screencast-O-Matic Web Launcher v2.18.1 (JRE14) (HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\Screencast-O-Matic v2 (WebLauncher-JRE14)) (Version:  - Screencast-O-Matic)
ScreenRec (HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\ScreenRec) (Version: 00.01.00.58 - StreamingVideoProvider)
simplewall (HKLM\...\simplewall) (Version: 3.3.5 - Henry++)
Telegram Desktop (HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 3.0.1 - Telegram FZ-LLC)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.4.2 - Tweaking.com)
Video Watermark Maker 2.1 (HKLM-x32\...\Video Watermark Maker_is1) (Version: 2.1 - SoftOrbits)
VoodooShield version 7.00 (HKLM\...\{A8644328-A66F-490E-B8FA-901FF649189D}_is1) (Version: 7.00 - VoodooSoft, LLC)
Voxal Voice Changer (HKLM-x32\...\Voxal) (Version: 6.22 - NCH Software)
VSDC Free Video Editor version 6.8.6.352 (HKLM\...\VSDC Free Video Editor_is1) (Version: 6.8.6.352 - Flash-Integro LLC)
WavePad Sound Editor (HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\...\WavePad) (Version: 13.22 - NCH Software)
WinRAR 6.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.01.0 - win.rar GmbH)
ZoneAlarm Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.99.0 - Check Point Software Ltd.) Hidden
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\Windows\system32\wpdshserviceobj.dll (Microsoft Windows -> Microsoft Corporation)
ShellExecuteHooks: Directory Opus Shell Execute Hook - {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\GPSoftware\Directory Opus\dopuslib.dll [1942640 2021-06-25] (GP Software -> GP Software)
ShellExecuteHooks-x32: Directory Opus Shell Execute Hook - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\GPSoftware\Directory Opus\dopuslib32.dll [389232 2021-06-25] (GP Software -> GP Software)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-07-23] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-07-23] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-07-23] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [Balabolka] -> [CC]{6CB83A5A-AA68-4895-9F54-175E789AE149} =>  -> No File
ContextMenuHandlers1: [Glary Utilities] -> [CC]{B3C418F8-922B-4faf-915E-59BC14448CF7} =>  -> No File
ContextMenuHandlers2: [Glary Utilities] -> [CC]{B3C418F8-922B-4faf-915E-59BC14448CF7} =>  -> No File
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-07-23] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> [CC]{57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2021-07-23] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> [CC]{B3C418F8-922B-4faf-915E-59BC14448CF7} =>  -> No File
ContextMenuHandlers6: [MBAMShlExt] -> [CC]{57CE581A-0CB6-4266-9CA0-19364C90A0B3} =>  -> No File
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\system32\bdmjpeg64.dll [75248 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\system32\bdmpegv64.dll [75272 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\system32\bdmpega64.acm [75784 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.voxacm160] => C:\Windows\system32\vct3216.acm [82944 2003-05-21] (Voxware, Inc.) [File not signed]
HKLM\...\Drivers32: [msacm.scg726] => C:\Windows\system32\scg726.acm [13239 2000-03-14] (SHARP Corporation) [File not signed]
HKLM\...\Drivers32: [msacm.alf2cd] => C:\Windows\system32\alf2cd.acm [38912 2003-05-21] (NCT Company) [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\AC3ACM.acm [81920 2004-02-04] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.lame] => C:\Windows\system32\lame.ax [245760 2005-08-01] () [File not signed]
HKLM\...\Drivers32: [vidc.dvsd] => C:\Windows\system32\mcdvd_32.dll [261632 2003-05-21] (MainConcept) [File not signed]
HKLM\...\Drivers32: [vidc.mpg4] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp42] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.mp43] => C:\Windows\system32\mpg4c32.dll [413760 2002-08-19] (Microsoft Corporation) [File not signed]
HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\system32\xvidvfw.dll [139264 2004-07-03] () [File not signed]
HKLM\...\Drivers32: [vidc.DIVX] => C:\Windows\system32\DivX.dll [638976 2003-05-22] (DivXNetworks, Inc.) [File not signed]
HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.VP62] => C:\Windows\system32\vp6vfw.dll [438272 2004-12-10] (On2.com) [File not signed]
HKLM\...\Drivers32: [vidc.LAGS] => C:\Windows\system32\lagarith.dll [216064 2011-12-07] () [File not signed]
HKLM\...\Drivers32: [vidc.mjpg] => C:\Windows\SysWOW64\bdmjpeg.dll [71152 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [vidc.mpeg] => C:\Windows\SysWOW64\bdmpegv.dll [71176 2017-01-26] (Bandicam Company -> )
HKLM\...\Drivers32: [msacm.bdmpeg] => C:\Windows\SysWOW64\bdmpega.acm [71176 2017-01-26] (Bandicam Company -> )
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
==================== Alternate Data Streams (Whitelisted) ========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\sdpsenv.dat:naughtypirates [322]
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Version 8) (Whitelisted) ==========
 
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Windows -> Microsoft Corporation)
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2021-09-15 00:10 - 2022-11-03 20:48 - 000000855 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1       localhost
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3609342701-1927152815-2929608412-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\cherishedlady\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3609342701-1927152815-2929608412-1003\Control Panel\Desktop\\Wallpaper -> C:\Users\Mantenida.Serena\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3609342701-1927152815-2929608412-501\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: Media is not connected to internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: FoxitReaderUpdateService => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: RasAuto => 3
MSCONFIG\Services: RasMan => 3
MSCONFIG\Services: RemoteRegistry => 3
MSCONFIG\Services: rkrtservice => 3
MSCONFIG\Services: RpcLocator => 3
MSCONFIG\Services: SessionEnv => 3
MSCONFIG\Services: TermService => 2
MSCONFIG\Services: UmRdpService => 3
MSCONFIG\startupreg: Directory Opus Desktop Dblclk => "C:\Program Files\GPSoftware\Directory Opus\dopusrt.exe" /dblclk
MSCONFIG\startupreg: Freedom => C:\Program Files (x86)\Freedom\FreedomBlocker.exe
MSCONFIG\startupreg: GUDelayStartup => "C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun
MSCONFIG\startupreg: ManyCam => "C:\Program Files (x86)\ManyCam\ManyCam.exe" --silent
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{B03BE1F7-66D0-460C-8724-6662826D885C}] => (Allow) LPort=443
FirewallRules: [{297BA812-66A1-43EE-967F-00CC959D963E}] => (Allow) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{A9E08759-FDEC-4F4D-95F1-6C273E2F22B1}] => (Block) C:\Windows\System32\WF.msc (Microsoft Windows -> )
FirewallRules: [{9387C3FF-033B-4CDD-9E42-39156BC8393F}] => (Allow) C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E8707073-082C-40BA-AF64-3C42106CCE3C}] => (Block) C:\Windows\winsxs\wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.1.7601.17514_none_73e472e09a1a05d1\wmplayer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{03FC86DF-6040-44CD-BB0F-11224EAD6106}] => (Block) C:\Program Files\Adobe\Adobe Photoshop CC 2019\Photoshop.exe (Adobe Inc. -> Adobe Systems Incorporated) [File not signed]
FirewallRules: [{49C86536-DBDE-45EE-B910-47E7E6E54C25}] => (Block) C:\Program Files\Adobe\Adobe Photoshop CC 2019\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe (Adobe Inc. -> Adobe Systems Incorporated)
FirewallRules: [{7B17D234-84D2-41BA-9C24-F34D48ACC420}] => (Block) C:\Program Files\Adobe\Adobe Photoshop CC 2019\Photoshop.exe (Adobe Inc. -> Adobe Systems Incorporated) [File not signed]
FirewallRules: [{B6E13AEF-1250-42A5-96BF-ED45FD0E4427}] => (Block) C:\Program Files\Adobe\Adobe Photoshop CC 2019\Required\CEP\CEPHtmlEngine\CEPHtmlEngine.exe (Adobe Inc. -> Adobe Systems Incorporated)
FirewallRules: [WMP-Out-TCP-x86] => (Block) C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WMP-Out-UDP-x86] => (Block) C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [WMP-In-UDP-x86] => (Block) C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{6D17217A-8230-4C58-8A0A-3CDF4F4B5C60}] => (Block) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
FirewallRules: [{0B2C554B-4D60-4552-AA92-F72544B61D95}] => (Block) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
FirewallRules: [{E05E58F5-1832-4FB2-9492-79CDE69055FA}] => (Block) c:\users\mantenida\desktop\tor browser\browser\firefox.exe (Mozilla Corporation) [File not signed]
FirewallRules: [{259B821E-EF48-4781-9EC4-2B1F9497F084}] => (Block) c:\users\mantenida\desktop\tor browser\browser\torbrowser\tor\tor.exe () [File not signed]
FirewallRules: [{E2E0750B-04D4-4215-A8B1-19F046DA10AC}] => (Block) c:\program files (x86)\foxitreaderconnectedpdfservice.exe (FOXIT SOFTWARE INC. -> Foxit Software Inc.)
FirewallRules: [{A1EC56CF-3424-43A4-BF2F-E6BC216BEDA2}] => (Block) c:\users\mantenida\documents\back up\docs\blessed\desktop\jdownloader portable\jdownloader 2 (64-bit)\jdownloader2.exe (Appwork GmbH -> AppWork GmbH)
FirewallRules: [{6B688FD2-57A1-4882-8CD2-336D14515F4C}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{5D2F345D-912E-47D1-AD7B-48DFE4ED023C}] => (Block) c:\program files\simplewall\simplewall.exe (Henry++) [File not signed]
FirewallRules: [{C93DB644-56F7-4CB9-9056-82D38A976215}] => (Block) c:\program files\simplewall\simplewall.exe (Henry++) [File not signed]
FirewallRules: [TCP Query User{EFCF37A2-410F-4B8E-9BC0-96FDDB9D69AB}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe (XK72 Ltd) [File not signed]
FirewallRules: [UDP Query User{FDAA50DB-12A9-46F5-9963-AAE7B5A2C8F0}C:\program files\charles\charles.exe] => (Allow) C:\program files\charles\charles.exe (XK72 Ltd) [File not signed]
FirewallRules: [{21456DD8-47F5-4286-AD95-72A0D7D997CC}] => (Block) c:\users\mantenida.serena\downloads\mydesktoptherapist.1.7.0\mydesktoptherapist.1.7.0\mydesktoptherapist.msi () [File not signed]
FirewallRules: [{61C73693-228A-4DB0-A5A5-E3D4FEC190B4}] => (Block) c:\users\mantenida.serena\downloads\mydesktoptherapist.1.3.8\mydesktoptherapist.msi () [File not signed]
FirewallRules: [{A9F2AAF4-931E-44B5-B2B2-226F68564A71}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{9359A1F4-7AD7-4844-A741-2EFAE56D5982}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{ADA92E8D-F520-4413-94FB-D86E6E931DAD}] => (Block) c:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A3EBA40E-5E93-400D-B132-9E630E47FD9E}] => (Block) c:\users\mantenida.serena\desktop\tor browser\browser\firefox.exe (Mozilla Corporation) [File not signed]
FirewallRules: [{2AA24BC1-B698-4BCE-B349-7919A3E003FE}] => (Block) c:\users\mantenida.serena\desktop\tor browser\browser\torbrowser\tor\tor.exe => No File
FirewallRules: [{292FAEA9-8720-4B9E-B4E5-F25BD280E4E9}] => (Block) c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FE764BD7-D62B-4225-BED9-4E98037E8414}] => (Block) c:\windows\microsoft.net\framework64\v2.0.50727\csc.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{0EDEA382-3CB4-43E3-8640-CCDC4AE0371D}] => (Block) c:\windows\system32\spoolsv.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{2ABB1878-9230-40CE-BC45-FC684B8B4435}] => (Block) c:\windows\system32\spoolsv.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{614299DB-FF0C-4D12-8AA8-10E737CEA329}] => (Block) c:\windows\system32\sdclt.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{52850F4E-6106-4F88-8CA6-579D880618C1}] => (Block) c:\windows\system32\sdclt.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{653B35AC-B2D0-4F0C-876A-8FF8AF838AE3}] => (Block) c:\programdata\bluestacks\client\bluestacks.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{92B2B27D-C7A5-4CF2-BF11-8E2B7B0ECA5A}] => (Block) c:\program files\bluestacks\hd-agent.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{B1D24A26-26DC-462C-9B29-19F0EE09CAB2}] => (Block) c:\windows\system32\svchost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C4713674-11F9-49EB-ABEA-66AB32ACA28A}] => (Block) c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation)
FirewallRules: [{5E148790-F494-48CA-95E5-1527DD9B22CA}] => (Block) c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation)
FirewallRules: [{4A949EB7-B1C9-4217-B8DB-C01DCEBE9C82}] => (Block) c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation)
FirewallRules: [{127A2A62-ED6A-44C3-8D88-4391174BE3D5}] => (Block) c:\windows\microsoft.net\framework64\v4.0.30319\mscorsvw.exe (Microsoft Dynamic Code Publisher -> Microsoft Corporation)
FirewallRules: [{45AF9D21-FAEF-47DF-9CF3-C46B8399658F}] => (Block) c:\windows\system32\sc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{5F6686EE-9F7D-42DD-87C7-D581CB5D3B36}] => (Block) c:\windows\system32\sc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{B5C47135-5F74-4076-926D-6E6D4E08FA3F}] => (Block) c:\windows\system32\aitagent.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{9347A5DC-877E-42E8-954A-BEC874B4A5E0}] => (Block) c:\windows\system32\aitagent.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{D950F604-17A0-45D9-97E2-438A1AED9A96}] => (Block) c:\windows\syswow64\dllhost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E315C065-4193-4122-8A82-1782B6B0613F}] => (Block) c:\windows\syswow64\dllhost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{13927703-DA78-4B22-B286-F1BDEA8F38D2}] => (Block) c:\windows\system32\cisvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{CC4C254B-CCE1-4C05-94E2-869C6528A388}] => (Block) c:\windows\system32\cisvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{8472BEA4-E15E-4467-8BEC-FE697EEE300A}] => (Block) c:\windows\system32\dwm.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{0A067D84-E23F-4F3E-9884-4195AC66D0E8}] => (Block) c:\windows\system32\dwm.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{B515C469-769A-4ABB-B9C1-2815568DC951}] => (Block) c:\windows\system32\devicedisplayobjectprovider.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{95E97CB7-5BBE-498D-8DC4-6C9819054A71}] => (Block) c:\windows\system32\devicedisplayobjectprovider.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{A028DB83-423E-4977-8A09-316BD7516142}] => (Block) c:\windows\system32\msdt.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{D4150617-F0A3-4BC1-AA61-F7F6CA0F2CD3}] => (Block) c:\windows\system32\msdt.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{CF655984-6F86-4831-8FE2-6322B5AD999F}] => (Block) c:\windows\system32\defrag.exe (Microsoft Windows -> Microsoft Corp.)
FirewallRules: [{E1C22708-9540-4E11-A27E-C7778A183045}] => (Block) c:\windows\system32\defrag.exe (Microsoft Windows -> Microsoft Corp.)
FirewallRules: [{1311A7B8-77CF-4D21-8BAB-72B4C2D1C73D}] => (Block) c:\windows\system32\ipconfig.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{1B3ED734-2705-4E93-BBC0-E49F8DD8C48F}] => (Block) c:\windows\system32\lsass.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{24E1D98E-A383-4009-B8D7-F3626C778779}] => (Block) c:\windows\system32\lsass.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{6A16618B-42B7-4087-AFC9-0AFF8D516E7D}] => (Block) c:\windows\system32\lsm.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{0EFDEEF1-5F72-41FB-ADBC-96CCBFE66961}] => (Block) c:\windows\system32\lsm.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{B66DB711-64B1-4AFE-9714-59F084153223}] => (Block) c:\windows\system32\schtasks.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{472C4530-879C-40BF-B0A1-CD3D7936A9AB}] => (Block) c:\windows\system32\schtasks.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{BBEFC08E-727E-4E85-841A-6CA9574430FF}] => (Block) c:\windows\system32\magnify.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{72B74D55-8F4C-4869-A844-7C048F99CC71}] => (Block) c:\windows\system32\magnify.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{A2668D2A-549A-4D29-B172-AACC9EC29813}] => (Block) c:\windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{F2163EBF-32BF-4140-94B4-9E0FEC8B9F8C}] => (Block) c:\windows\system32\sppsvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{281E28F2-9EE7-4712-B943-8C2BF742FE42}] => (Block) c:\windows\system32\makecab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{F2CC4D06-C2C6-4A79-89C3-D43710DEAA0F}] => (Block) c:\windows\system32\makecab.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C6CD60BC-23D8-4B4C-B5D4-A8C7ECDFA4AA}] => (Block) c:\windows\microsoft.net\framework64\v2.0.50727\cvtres.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{4DBB09A5-F7B4-4A24-8FA4-AEBBA867B90B}] => (Block) c:\windows\microsoft.net\framework64\v2.0.50727\cvtres.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A3AE60AD-8291-4441-A0DD-8AE6271597E3}] => (Block) c:\windows\system32\vssvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{539A3564-A66E-43D2-B611-9D1D801BEB83}] => (Block) c:\windows\system32\vssvc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{1D6346CA-0013-4B95-97E9-2DACBF837094}] => (Block) c:\windows\system32\mspaint.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{168EFA12-5462-4A6A-8B7C-DD666D62B883}] => (Block) c:\windows\system32\mspaint.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{A2FAD174-1BC2-4FF8-8169-260D1255D1F3}] => (Block) c:\windows\system32\powercfg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{E59D0D2E-806F-4DF6-9996-935895E5E80B}] => (Block) c:\windows\system32\powercfg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{047BA346-E88A-4740-BDFD-703EE9438C02}] => (Block) c:\users\mantenida.serena\appdata\local\programs\python\python38\python.exe (Python Software Foundation -> Python Software Foundation)
FirewallRules: [{875D4B72-16DF-473E-9CEE-48DE716E68D6}] => (Block) c:\users\mantenida.serena\appdata\local\programs\python\python38\python.exe (Python Software Foundation -> Python Software Foundation)
FirewallRules: [{2E99D08B-4A83-42E1-8624-ADD7E9E38BA2}] => (Block) c:\windows\system32\perfmon.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{FA074694-2365-47C9-BB11-652E9DC00457}] => (Block) c:\windows\system32\perfmon.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{42ED94A2-1F92-4A2F-BB6F-C1058DACE0C2}] => (Block) c:\windows\system32\csrss.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{F777A42A-B276-4FBA-B8B6-40966519767B}] => (Block) c:\windows\syswow64\sc.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{B2A4AEDB-9555-4F52-8099-45792DC774E5}] => (Block) c:\windows\system32\consent.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{8B7F55EF-67F6-43E9-9E46-C1862A135D83}] => (Block) c:\windows\system32\conhost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{2DE63479-E905-4EB6-8193-B9EE14DC9EA8}] => (Block) c:\windows\system32\drvinst.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{5C9F8619-E688-4F5E-A6FD-59892899248E}] => (Block) c:\windows\system32\taskhost.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{B946D8FE-AD7F-4E2A-AA33-5D99D7A853A1}] => (Block) c:\windows\system32\wininet.dll (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{60D3DA01-33BA-43F5-A77B-29043B8AE929}] => (Block) c:\windows\system32\mobsync.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{044AC414-1B72-4714-BCB1-6D8354114B7B}] => (Block) c:\windows\system32\searchindexer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{EE3014E4-DF3F-4729-9154-F4F727D67B09}] => (Block) c:\windows\syswow64\netsh.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{CD17C8E4-98DF-4CB4-B6AB-E8DD3A246982}] => (Block) c:\windows\system32\runonce.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C9393634-6DC7-4C30-80DE-89118CF6B464}] => (Block) c:\windows\system32\wbem\unsecapp.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{C5906E54-EE28-4AAB-9902-C5E3302F7517}] => (Block) c:\windows\system32\audiodg.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{D5996EFA-ED82-49EF-92C8-42132B49BDA5}] => (Block) c:\windows\explorer.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{BB172275-1A44-4318-AE2F-1F7FFFAD3637}] => (Block) c:\windows\system32\logonui.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{5C5CC926-32BB-4ECF-B13D-4527C688E2FE}] => (Block) c:\windows\system32\smss.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{8BDF3D06-94F1-4A40-8E79-A8901DCC6BC6}] => (Block) c:\windows\system32\wbem\wmiprvse.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [{32960C9E-6B0B-4C04-9D7F-AF48975922D7}] => (Block) c:\windows\system32\wbem\wmic.exe
 
==================== Restore Points =========================
 
16-02-2022 13:08:03 Scheduled Checkpoint
03-03-2022 14:26:48 Scheduled Checkpoint
03-11-2022 18:08:31 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices ============
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: AMSDK Driver
Description: AMSDK Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: amsdk
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: PS/2 Compatible Mouse
Description: PS/2 Compatible Mouse
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: aswRvrt
Description: aswRvrt
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: aswRvrt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: aswVmm
Description: aswVmm
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: aswVmm
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (11/03/2022 08:50:29 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007043c, This service cannot be started in Safe Mode
.
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {460ad61c-5c79-44c6-8e76-52f7791c6bc0}
 
Error: (11/03/2022 08:50:29 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {460ad61c-5c79-44c6-8e76-52f7791c6bc0}
 
Error: (11/03/2022 08:50:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007043c, This service cannot be started in Safe Mode
.
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Writer Name: Shadow Copy Optimization Writer
   Writer Instance ID: {95a54baa-acc7-4411-a68e-2747947eed18}
 
Error: (11/03/2022 08:50:25 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Writer Name: Shadow Copy Optimization Writer
   Writer Instance ID: {95a54baa-acc7-4411-a68e-2747947eed18}
 
Error: (11/03/2022 08:50:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007043c, This service cannot be started in Safe Mode
.
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {be000cbe-11fe-4426-9c58-531aa6355fc4}
   Writer Name: ASR Writer
   Writer Instance ID: {f3f35a0f-065a-4f6f-aeae-0e36b8efb914}
 
Error: (11/03/2022 08:50:25 PM) (Source: VSS) (EventID: 18) (User: )
Description: Volume Shadow Copy Service error: The COM Server with CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} and name CEventSystem cannot be started during Safe Mode.
The Volume Shadow Copy service cannot start while in safe mode. [0x8007043c, This service cannot be started in Safe Mode
]
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {be000cbe-11fe-4426-9c58-531aa6355fc4}
   Writer Name: ASR Writer
   Writer Instance ID: {f3f35a0f-065a-4f6f-aeae-0e36b8efb914}
 
Error: (11/03/2022 08:50:25 PM) (Source: VSS) (EventID: 12346) (User: )
Description: Volume Shadow Copy Error: An error 0x80042302, A Volume Shadow Copy Service component encountered an unexpected error.
Check the Application event log for more information.
 was encountered while trying to initialize the Registry Writer.  This may cause
future shadow-copy creations to fail.
 
Error: (11/03/2022 08:50:25 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007043c, This service cannot be started in Safe Mode
.
 
 
Operation:
   Subscribing Writer
 
Context:
   Writer Class Id: {542da469-d3e1-473c-9f4f-7847f01fc64f}
   Writer Name: COM+ REGDB Writer
   Writer Instance ID: {6897c289-18eb-4aaf-a60c-758e840a1bac}
 
 
System errors:
=============
Error: (11/03/2022 09:00:19 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server:
{4991D34B-80A1-4291-83B6-3328366B9097}
 
Error: (11/03/2022 09:00:19 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server:
{F087771F-D74F-4C1A-BB8A-E16ACA9124EA}
 
Error: (11/03/2022 09:00:19 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server:
{6D18AD12-BDE3-4393-B311-099C346E6DF9}
 
Error: (11/03/2022 09:00:19 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server:
{03CA98D6-FF5D-49B8-ABC6-03DD84127020}
 
Error: (11/03/2022 09:00:19 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server:
{659CDEA7-489E-11D9-A9CD-000D56965251}
 
Error: (11/03/2022 09:00:19 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server:
{BB6DF56B-CACE-11DC-9992-0019B93A3A84}
 
Error: (11/03/2022 08:56:34 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
 
Error: (11/03/2022 08:56:34 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server:
{9E175B6D-F52A-11D8-B9A5-505054503030}
 
 
Windows Defender:
================Event[0]:
 
Date: 2021-05-20 14:48:31.976
Description: 
%1 engine has been terminated due to an unexpected error.
Failure Type:%5
Exception code:%6
Resource:%3
 
Date: 2021-05-20 14:34:39.637
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x8050a005
Error description:The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. 
Signature version:1.95.191.0
Engine version:1.1.6402.0
 
==================== Memory info =========================== 
 
BIOS: Hewlett-Packard 786F2 v01.04 01/31/2008
Motherboard: Hewlett-Packard 2820h
Processor: Intel® Core™2 Duo CPU E8300 @ 2.83GHz
Percentage of memory in use: 86%
Total physical RAM: 3045.3 MB
Available physical RAM: 402.55 MB
Total Virtual: 6088.79 MB
Available Virtual: 3374.2 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:465.66 GB) (Free:191.53 GB) NTFS ==>[drive with boot components (obtained from BCD)]
 
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 000344AE)
Partition 1: (Active) - (Size=465.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt =======================
 
 
 


#4 bussw83

bussw83

    New Member

  • New Member
  • Pip
  • 3 posts

Posted 15 March 2022 - 08:15 PM

====================== Adware logs Win 10 laptop =====================================

 

# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build:    11-18-2021
# Database: 2022-03-15.3 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    03-15-2022
# Duration: 00:00:24
# OS:       Windows 10 Pro
# Scanned:  32033
# Detected: 0
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
No malicious folders found.
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries found.
 
***** [ Preinstalled Software ] *****
 
No Preinstalled Software found.
 
 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 
 
===========  Malware Bytes Win 10 laptop  ===================
 
Malwarebytes
www.malwarebytes.com
 
-Detalles del registro-
Fecha del análisis: 15/3/22
Hora del análisis: 19:59
Archivo de registro: a8485a6e-a4cc-11ec-93ed-642737844a1e.json
 
-Información del software-
Versión: 4.5.2.157
Versión de los componentes: 1.0.1562
Versión del paquete de actualización: 1.0.52398
Licencia: Prueba
 
-Información del sistema-
SO: Windows 10 (Build 19044.1586)
CPU: x64
Sistema de archivos: NTFS
Usuario: DESKTOP-4OO4NRC\usuario
 
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 280398
Amenazas detectadas: 6
Amenazas en cuarentena: 6
Tiempo transcurrido: 5 min, 50 seg
 
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
 
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
 
Módulo: 0
(No hay elementos maliciosos detectados)
 
Clave del registro: 1
HackTool.KMSpico, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinDivert1.1, En cuarentena, 6815, 921550, , , , , , 
 
Valor del registro: 0
(No hay elementos maliciosos detectados)
 
Datos del registro: 0
(No hay elementos maliciosos detectados)
 
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
 
Carpeta: 2
HackTool.KMSpico, C:\PROGRAM FILES\KMSPICO, En cuarentena, 6815, 921550, 1.0.52398, , ame, , , 
HackTool.KMSpico, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\KMSPICO, En cuarentena, 6815, 921555, 1.0.52398, , ame, , , 
 
Archivo: 3
HackTool.KMSpico, C:\PROGRAM FILES\KMSPICO\WINDIVERT.SYS, En cuarentena, 6815, 921550, , , , , A0D15D8727D0780C51628DF46B7268B3, 5E23F3ED1D6620C39A644F9879404A22DED86B3B076EC4A898B4B6BE244AFD64
HackTool.KMSpico, C:\PROGRAM FILES\KMSPICO\WINDIVERT.SYS, En cuarentena, 6815, 921550, 1.0.52398, , ame, , A0D15D8727D0780C51628DF46B7268B3, 5E23F3ED1D6620C39A644F9879404A22DED86B3B076EC4A898B4B6BE244AFD64
PUP.Optional.DotSetupIo, C:\USERS\USUARIO\APPDATA\LOCAL\TEMP\SETUP\DS.DLL, En cuarentena, 865, 1016023, 1.0.52398, , ame, , EF28DD094C99E503E1ED2D3D540A9CC8, 34CE7B9620DE9E976A8BF792DFC44A3781B411C282B77A9D3BA69F7E862AD1E3
 
Sector físico: 0
(No hay elementos maliciosos detectados)
 
WMI: 0
(No hay elementos maliciosos detectados)
 
 
(end)

Edited by bussw83, 15 March 2022 - 08:21 PM.


#5 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 16 March 2022 - 04:13 PM

I can only work on 1 computer at a time so I do not get confused.

This information you provided says this is a windows 7?
Microsoft no longer offers support for this outdated version of windows which means it can be a struggle to keep it clean and operating.
 
The Farbar scan should had been run in normal mode, when you attempt to run the script I create below please have your computer in normal mode.
 
Also, it said you might have an outdated version of Farbar Recovery Scanner,  how old is the version you have on your desktop?
 
Please delete the version you have now and download a more current version from here

Just download it to your desktop and wait, I've created a script to run through the tool.

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator, just open it and let it wait)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3609342701-1927152815-2929608412-1003\User: Restriction <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
Policies: C:\Users\cherishedlady\NTUSER.pol: Restriction <==== ATTENTION
Policies: C:\Users\Mantenida.Serena\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
Task: {6A59A976-58AF-49EE-8496-5E45FB4D1581} - \CheckPointUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {9182A8F5-50C9-4E02-9E92-FBBCE099C721} - \CheckPointUpdateTaskMachineUA -> No File <==== ATTENTION
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
FF Plugin-x32: @tools.google.com/CheckPoint Update;version=3 -> C:\Program Files (x86)\CheckPoint\Update\1.3.99.0\npZoneAlarmUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/CheckPoint Update;version=9 -> C:\Program Files (x86)\CheckPoint\Update\1.3.99.0\npZoneAlarmUpdate3.dll [No File]
S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X]
S2 ISWKL; \??\C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Common\bin\ISWKL.sys [X]
U3 TrueSight; \??\C:\Windows\System32\drivers\truesight.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
ContextMenuHandlers1: [Balabolka] -> [CC]{6CB83A5A-AA68-4895-9F54-175E789AE149} => -> No File
ContextMenuHandlers1: [Glary Utilities] -> [CC]{B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers2: [Glary Utilities] -> [CC]{B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers3: [MBAMShlExt] -> [CC]{57CE581A-0CB6-4266-9CA0-19364C90A0B3} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers6: [Glary Utilities] -> [CC]{B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers6: [MBAMShlExt] -> [CC]{57CE581A-0CB6-4266-9CA0-19364C90A0B3} => -> No File
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Press the Fix button.
FRST will process the lines copied above from the clipboard.
When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#6 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 23 March 2022 - 08:36 AM

bump
Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#7 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 29 March 2022 - 06:34 AM

Glad we could help. SakDYGv.gif
Since this issue appears resolved ... this Topic is closed.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

Related Topics




Also tagged with one or more of these keywords: hacker, spyware

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users