Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03.05.2018 Ran by RONALD (03-05-2018 14:25:43) Running from C:\Users\RONALD\Desktop Windows 10 Pro Version 1709 16299.371 (X64) (2018-04-23 01:58:21) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-3231412593-2045808636-640187329-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-3231412593-2045808636-640187329-503 - Limited - Disabled) Invitado (S-1-5-21-3231412593-2045808636-640187329-501 - Limited - Disabled) RONALD (S-1-5-21-3231412593-2045808636-640187329-1001 - Administrator - Enabled) => C:\Users\RONALD WDAGUtilityAccount (S-1-5-21-3231412593-2045808636-640187329-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC - Español (HKLM-x32\...\{AC76BA86-7AD7-1034-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated) Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.4.1.298 - Adobe Systems Incorporated) Adobe Flash Player 29 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 29.0.0.140 - Adobe Systems Incorporated) Adobe Flash Player 29 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 29.0.0.140 - Adobe Systems Incorporated) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.3.2333 - AVAST Software) CCleaner (HKLM\...\CCleaner) (Version: 5.42 - Piriform) CrystalDiskInfo 7.0.5 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.0.5 - Crystal Dew World) Dropbox (HKLM-x32\...\Dropbox) (Version: 48.4.58 - Dropbox, Inc.) Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden Eines de correcció del Microsoft Office 2013: català (HKLM\...\{90150000-001F-0403-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Ferramentas de verificación de Microsoft Office 2013 - Galego (HKLM\...\{90150000-001F-0456-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Free Video Call Recorder for Skype (HKLM-x32\...\Free Video Call Recorder for Skype_is1) (Version: 1.2.69.1027 - Digital Wave Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.139 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden Intel Security True Key (HKLM\...\TrueKey) (Version: 4.20.110.1 - Intel Security) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) Malwarebytes versión 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.717.1 - McAfee, Inc.) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft Office Proofing Tools 2013 - English (HKLM-x32\...\{90150000-001F-0409-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3231412593-2045808636-640187329-1001\...\OneDriveSetup.exe) (Version: 18.065.0329.0002 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\...\OneDriveSetup.exe) (Version: 18.065.0329.0002 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation) Mozilla Firefox 58.0.2 (x86 es-ES) (HKLM-x32\...\Mozilla Firefox 58.0.2 (x86 es-ES)) (Version: 58.0.2 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.4 - Mozilla) Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Revisores de Texto do Microsoft Office 2013 – Português do Brasil (HKLM\...\{90150000-001F-0416-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden Skype™ 7.41 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.41.101 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.4.3.38 - Synaptics Incorporated) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{54228DC1-0B27-4215-B2BE-4D07C521F242}) (Version: 2.33.0.0 - Microsoft Corporation) UpdateAssistant (HKLM\...\{F3874F6F-EA00-487D-BEAD-5FAA010E78F2}) (Version: 1.15.0.0 - Microsoft Corporation) Hidden USB Disk Security (HKLM-x32\...\USB Disk Security_is1) (Version: - Zbshareware Lab) Windows 10-Update-Assistent (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22402 - Microsoft Corporation) Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - ) WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-3231412593-2045808636-640187329-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-05] (AVAST Software) ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-05] (AVAST Software) ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-12-01] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-12-01] (Alexander Roshal) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-05] (AVAST Software) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes) ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2018-04-23] (Dropbox, Inc.) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\WINDOWS\system32\igfxpph.dll [2017-03-11] (Intel Corporation) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-04-05] (AVAST Software) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-12-01] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-12-01] (Alexander Roshal) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0039E317-1633-4B6E-9B05-7C00B77449F6} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_140_pepper.exe [2018-04-10] (Adobe Systems Incorporated) Task: {04694A9F-AED8-4B5B-B4F2-E9D813E75A49} - System32\Tasks\{72157136-116F-413E-8995-54E9DE83905A} => "c:\windows\system32\launchwinapp.exe" hxxp://ui.skype.com/ui/0/6.14.0.104/es/go/help.faq.installer?LastError=1618 Task: {2FB630D0-DCDE-47AD-904A-AEAFE12C650C} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {3932759E-208C-42B7-A8D3-EAAB138ADEE5} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_140_Plugin.exe [2018-04-10] (Adobe Systems Incorporated) Task: {3C8EE79A-8994-47BA-A420-48B5326549D3} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-04-05] (AVAST Software) Task: {44079172-DE50-4511-96ED-F9D15FE0E163} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-03-08] (Dropbox, Inc.) Task: {5C792367-A26B-4C80-915D-9BCB933E2F21} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-04-12] (Piriform Ltd) Task: {6097122D-E5E1-4CBE-94D1-18AD4EAEC2FB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated) Task: {71582D3C-4578-496C-A751-B853D1070E69} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-Q4526BL-RONALD DESKTOP-Q4526BL => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation) Task: {75FF15CA-FF6C-48B5-8AD6-681D62F6ABEA} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {82B8A2D3-49A2-4130-BD3D-A5C27532928B} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {84313931-D762-4902-8979-47333AACB21A} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe Task: {896AA9B6-29E8-4052-ADF2-A324924D40B5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-04-14] (AVAST Software) Task: {9133A27E-3F81-4656-A1EE-309A086F452E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-08] (Google Inc.) Task: {920982E4-4310-4271-B56F-86CBF426B23A} - System32\Tasks\AutoPico Daily Restart => C:\Program [Argument = Files\KMSpico\AutoPico.exe /silent] Task: {9E9D5DD3-AD8F-4332-898F-17F844656DA1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-04-10] (Adobe Systems Incorporated) Task: {B8AC99B9-E1AD-48AD-B76D-BA7715CD26F4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-08] (Google Inc.) Task: {BB5D396E-0D06-46E3-9F4D-D7AF83C797CE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {BDDE4DBB-DA1B-44F7-A53E-931FE6F397E3} - System32\Tasks\AdobeGCInvoker-1.0-DESKTOP-Q4526BL-RONALD => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated) Task: {D8A188D6-9868-4776-8914-F368CCE7F972} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-04-12] (Piriform Ltd) Task: {F9417FAE-EDAA-4B6F-AB59-45D7E2CBDD83} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-03-08] (Dropbox, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2018-05-01 11:00 - 2018-03-12 15:09 - 002300192 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-05-01 11:00 - 2018-03-27 13:47 - 002492704 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-09-29 08:41 - 2017-09-29 08:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll 2018-04-24 10:10 - 2018-02-21 19:26 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2018-04-24 10:11 - 2018-02-21 19:21 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-03-11 16:42 - 2017-03-11 16:42 - 000112264 _____ () C:\Windows\System32\IccLibDll_x64.dll 2018-05-01 10:35 - 2018-05-01 10:41 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2018-05-01 10:35 - 2018-05-01 10:41 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2018-05-01 10:35 - 2018-05-01 10:41 - 022320128 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2018-05-01 10:35 - 2018-05-01 10:41 - 002603008 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\skypert.dll 2018-05-01 10:35 - 2018-05-01 10:41 - 000657408 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll 2018-04-26 20:15 - 2018-04-25 22:14 - 004443992 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.139\libglesv2.dll 2018-04-26 20:15 - 2018-04-25 22:14 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.139\libegl.dll 2018-04-10 08:10 - 2018-04-10 08:10 - 031256576 _____ () C:\WINDOWS\system32\Macromed\Flash\pepflashplayer64_29_0_0_140.dll 2017-08-02 19:47 - 2017-03-20 17:20 - 000114664 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\zlib1.dll 2017-08-02 19:48 - 2017-03-20 17:20 - 000024040 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_system-vc120-mt-1_56.dll 2017-08-02 19:48 - 2017-03-20 17:20 - 000048104 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_date_time-vc120-mt-1_56.dll 2017-08-02 19:48 - 2017-03-20 17:20 - 000108008 _____ () C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\boost_filesystem-vc120-mt-1_56.dll 2018-04-05 09:05 - 2018-04-05 09:05 - 000282840 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2018-04-02 18:48 - 2018-04-02 18:48 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2018-04-05 09:05 - 2018-04-05 09:05 - 000349912 _____ () C:\Program Files\AVAST Software\Avast\streamback_avast.dll 2018-04-05 09:05 - 2018-04-05 09:05 - 000295640 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2018-04-05 09:05 - 2018-04-05 09:05 - 000281816 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-09-26 21:22 - 2017-09-26 21:22 - 001984000 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll 2018-02-22 11:57 - 2018-02-22 11:57 - 024028656 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll 2018-02-11 17:53 - 2018-02-11 17:53 - 000392688 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\sqlite.dll 2017-08-10 10:24 - 2017-08-10 10:24 - 072940016 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\libcef.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 06:04 - 2018-04-29 11:41 - 000000875 _____ C:\WINDOWS\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416224\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416505\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg HKU\S-1-5-21-3231412593-2045808636-640187329-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\RONALD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\Control Panel\Desktop\\Wallpaper -> C:\Users\RONALD\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper DNS Servers: 186.160.41.224 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "USB Security" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run32: => "AdobeGCInvoker-1.0" HKU\S-1-5-21-3231412593-2045808636-640187329-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3231412593-2045808636-640187329-1001\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_44FD5784EF91081D9C284400DBDF2EA5" HKU\S-1-5-21-3231412593-2045808636-640187329-1001\...\StartupApproved\Run: => "DVSFreeVideoCallRecorder" HKU\S-1-5-21-3231412593-2045808636-640187329-1001\...\StartupApproved\Run: => "BingSvc" HKU\S-1-5-21-3231412593-2045808636-640187329-1001\...\StartupApproved\Run: => "CCleaner Monitoring" HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_44FD5784EF91081D9C284400DBDF2EA5" HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\...\StartupApproved\Run: => "DVSFreeVideoCallRecorder" HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\...\StartupApproved\Run: => "BingSvc" HKU\S-1-5-21-3231412593-2045808636-640187329-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-05022018025416882\...\StartupApproved\Run: => "CCleaner Monitoring" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{CF1D8C24-1ADA-469C-9D19-CBD17527D57B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{3DFB7FF4-F898-4831-B3F3-3F8F181DD45A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{FDB52D52-8282-45B4-ADFA-8DE70DE3CD8B}] => (Allow) LPort=1688 FirewallRules: [{0C10A5DB-EA0E-4C3A-BF9D-00BEF68C43BF}] => (Allow) %systemroot%\system32\alg.exe FirewallRules: [{A5CABCFB-F54D-40F6-BD4E-BE58DB3DB3A2}] => (Allow) %systemroot%\system32\alg.exe FirewallRules: [{89872A8C-08A6-4268-AD93-48F477EC6681}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{82E9B611-133F-40A8-AB9E-3D00349028E8}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{298ED952-5019-495C-B637-5ED2D55E6D59}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{28C30497-FBC0-47AC-9E56-D06EE3C175E3}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{18F18B03-F681-4AC8-A09A-C18403390F20}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{850340BB-32B3-4666-8659-3943E86B672D}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [{5C57D9BB-1E0C-408A-BACC-FCACF60E2C01}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{4BFCD0A1-FA42-4C1D-BE1B-14F96B1E14EF}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{863FFA2C-F2F0-466F-867A-658C6FBEA946}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ==================== Restore Points ========================= 24-04-2018 08:25:12 Instalador de Módulos de Windows 28-04-2018 08:34:55 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/03/2018 12:55:52 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: DESKTOP-Q4526BL) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.16299.371_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (05/01/2018 10:16:32 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: DESKTOP-Q4526BL) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.16299.371_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (04/29/2018 12:17:04 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: DESKTOP-Q4526BL) Description: Das Paket „Microsoft.Windows.ShellExperienceHost_10.0.16299.15_neutral_neutral_cw5n1h2txyewy+App“ wurde beendet, da das Anhalten zu lange dauerte. Error: (04/28/2018 03:21:48 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FreeVideoCallRecorder.exe, Version 1.2.69.1027 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1834 Startzeit: 01d3defec69d4d74 Beendigungszeit: 184 Anwendungspfad: D:\rescate de datos\DVDVideoSoft\Free Video Call Recorder for Skype\FreeVideoCallRecorder.exe Berichts-ID: 1fd679c7-f17e-4c0c-ba2a-31cec012a5d3 Vollständiger Name des fehlerhaften Pakets: Auf das fehlerhafte Paket bezogene Anwendungs-ID: Error: (04/28/2018 12:27:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: AutoPico.exe, Version: 5.3.0.0, Zeitstempel: 0x520270d8 Name des fehlerhaften Moduls: RPCRT4.dll, Version: 10.0.16299.15, Zeitstempel: 0x9f4b6439 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000323a7 ID des fehlerhaften Prozesses: 0x19f4 Startzeit der fehlerhaften Anwendung: 0x01d3df1234c46257 Pfad der fehlerhaften Anwendung: C:\Program Files\KMSpico\AutoPico.exe Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\RPCRT4.dll Berichtskennung: 54adf1e7-1c50-43bf-bb80-24317632a0c7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (04/28/2018 12:27:53 PM) (Source: Software Protection Platform Service) (EventID: 1017) (User: ) Description: Fehler bei der Installation des Kaufnachweises. 0x80070057 Teil-Pkey=? ACID=? Genauer Fehler[?] Error: (04/28/2018 12:27:53 PM) (Source: Software Protection Platform Service) (EventID: 1017) (User: ) Description: Fehler bei der Installation des Kaufnachweises. 0x80070057 Teil-Pkey=? ACID=? Genauer Fehler[?] Error: (04/28/2018 12:27:53 PM) (Source: Software Protection Platform Service) (EventID: 1017) (User: ) Description: Fehler bei der Installation des Kaufnachweises. 0x80070057 Teil-Pkey=? ACID=? Genauer Fehler[?] System errors: ============= Error: (05/03/2018 02:00:50 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-Q4526BL) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "DESKTOP-Q4526BL\RONALD" (SID: S-1-5-21-3231412593-2045808636-640187329-1001) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (05/03/2018 01:56:45 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-Q4526BL) Description: Der Server "{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (05/03/2018 01:08:52 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "NT AUTHORITY\SERVICIO LOCAL" (SID: S-1-5-19) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (05/03/2018 12:53:36 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "NT AUTHORITY\SERVICIO LOCAL" (SID: S-1-5-19) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (05/03/2018 12:50:26 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-Q4526BL) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "DESKTOP-Q4526BL\RONALD" (SID: S-1-5-21-3231412593-2045808636-640187329-1001) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} und der APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (05/03/2018 12:48:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "NT AUTHORITY\SERVICIO LOCAL" (SID: S-1-5-19) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (05/03/2018 12:48:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "NT AUTHORITY\SERVICIO LOCAL" (SID: S-1-5-19) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. Error: (05/03/2018 12:48:20 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: Durch die Berechtigungseinstellungen für "específico de la aplicación" wird dem Benutzer "NT AUTHORITY\SERVICIO LOCAL" (SID: S-1-5-19) unter der Adresse "LocalHost (con LRPC)" keine Berechtigung vom Typ "Local Activación" für die COM-Serveranwendung mit der CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} und der APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} im Anwendungscontainer "No disponible" (SID: No disponible) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden. CodeIntegrity: =================================== Date: 2018-05-01 11:03:08.542 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU 847 @ 1.10GHz Percentage of memory in use: 86% Total physical RAM: 1948.36 MB Available physical RAM: 265.32 MB Total Virtual: 4252.36 MB Available Virtual: 1382.34 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:230.07 GB) (Free:130.6 GB) NTFS Drive d: () (Fixed) (Total:234.37 GB) (Free:211.22 GB) NTFS \\?\Volume{cb7ca56d-0000-0000-0000-100000000000}\ (Reservado para el sistema) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS \\?\Volume{cb7ca56d-0000-0000-0000-20a439000000}\ () (Fixed) (Total:0.82 GB) (Free:0.33 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: CB7CA56D) Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=230.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=841 MB) - (Type=27) Partition 4: (Not Active) - (Size=234.4 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================