Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-08-2016 01 Ran by Kiri Leo (2016-08-13 19:40:40) Running from D:\Descargas\Programas bajados Microsoft Windows 7 Ultimate Service Pack 1 (X86) (2016-04-11 21:13:01) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-2123057250-984275833-1413642234-500 - Administrator - Disabled) HomeGroupUser$ (S-1-5-21-2123057250-984275833-1413642234-1002 - Limited - Enabled) Invitado (S-1-5-21-2123057250-984275833-1413642234-501 - Limited - Disabled) Kiri Leo (S-1-5-21-2123057250-984275833-1413642234-1000 - Administrator - Enabled) => C:\Users\Kiri Leo ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 16.02 (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov) Adobe AIR (HKLM\...\Adobe AIR) (Version: 23.0.0.230 - Adobe Systems Incorporated) Adobe Flash Player 23 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 23.0.0.134 - Adobe Systems Incorporated) Adobe Flash Player 23 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 23.0.0.134 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM\...\Adobe Shockwave Player) (Version: 12.2.4.194 - Adobe Systems, Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.20 - Piriform) Comodo Dragon (HKLM\...\Comodo Dragon) (Version: 50.14.22.465 - Comodo) Internet Download Manager (HKLM\...\Internet Download Manager) (Version: - Tonec Inc.) Microsoft .NET Framework 4.6.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {80A956F1-9DBB-44DC-9BA7-5B493C47C2CC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\Mantenimiento\Limpiador de residuos\CCleaner.exe [2016-07-13] (Piriform Ltd) Task: {8DB3F670-146C-44D6-BB7D-5D1C218EEB4F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2016-08-12] (Adobe Systems Incorporated) Task: {A6394592-54CE-4E93-8D64-1A068F462632} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator => C:\Windows\System32\wsqmcons.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-08-12 13:50 - 2016-08-12 13:50 - 17741504 _____ () C:\Windows\system32\Macromed\Flash\pepflashplayer32_23_0_0_134.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 23:04 - 2016-08-13 12:07 - 00001790 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 tonec.com 127.0.0.1 www.tonec.com 127.0.0.1 registeridm.com 127.0.0.1 www.registeridm.com 127.0.0.1 secure.registeridm.com 127.0.0.1 internetdownloadmanager.com 127.0.0.1 www.internetdownloadmanager.com 127.0.0.1 secure.internetdownloadmanager.com 127.0.0.1 www.secure.internetdownloadmanager.com 127.0.0.1 mirror.internetdownloadmanager.com 127.0.0.1 www.mirror.internetdownloadmanager.com 127.0.0.1 mirror2.internetdownloadmanager.com 127.0.0.1 www.mirror2.internetdownloadmanager.com 127.0.0.1 mirror3.internetdownloadmanager.com 127.0.0.1 www.mirror3.internetdownloadmanager.com 127.0.0.1 star.tonec.com 127.0.0.1 rev.dyxnet.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2123057250-984275833-1413642234-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Kiri Leo\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{01EDC90B-863B-4293-B4D4-6AB5BFB92B05}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [TCP Query User{AB6551E5-E96E-42BB-80C6-7B9D6C0D8311}C:\program files\navegadores\comodo dragon\dragon.exe] => (Allow) C:\program files\navegadores\comodo dragon\dragon.exe FirewallRules: [UDP Query User{FA476841-64E9-4ECF-BF63-DD996BFE7782}C:\program files\navegadores\comodo dragon\dragon.exe] => (Allow) C:\program files\navegadores\comodo dragon\dragon.exe ==================== Restore Points ========================= ATTENTION: System Restore is disabled Check "winmgmt" service or repair WMI. ==================== Faulty Device Manager Devices ============= Name: Controladora de vídeo Description: Controladora de vídeo Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/13/2016 07:26:46 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0". Use sxstrace.exe para obtener un diagnóstico detallado. Error: (08/13/2016 06:05:10 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/13/2016 12:14:17 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.101.0"1". No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.101.0". Use sxstrace.exe para obtener un diagnóstico detallado. Error: (08/12/2016 07:56:38 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2016 01:31:07 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Error al generar el contexto de activación para "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.101.0"1". No se encontró el ensamblado dependiente Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.101.0". Use sxstrace.exe para obtener un diagnóstico detallado. Error: (08/12/2016 01:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/12/2016 08:56:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/11/2016 06:10:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/11/2016 06:04:28 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=x86 . Error code = 0x80070002 Error: (04/11/2016 06:04:28 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=x86 . Error code = 0x80070002 System errors: ============= Error: (08/13/2016 06:07:40 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Instalador de módulos de Windows, pero ocurrió el siguiente error: %%1056 = Ya se está ejecutando una instancia de este servicio. Error: (08/13/2016 06:06:30 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Instrumental de administración de Windows, pero ocurrió el siguiente error: %%1056 = Ya se está ejecutando una instancia de este servicio. Error: (08/13/2016 06:06:29 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Examinador de equipos, pero ocurrió el siguiente error: %%1056 = Ya se está ejecutando una instancia de este servicio. Error: (08/13/2016 06:05:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: El servicio Instalador de módulos de Windows terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 120000 milisegundos: Reiniciar el servicio. Error: (08/13/2016 06:05:29 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Windows Update, pero ocurrió el siguiente error: %%1056 = Ya se está ejecutando una instancia de este servicio. Error: (08/13/2016 06:05:29 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: El Administrador de control de servicios intentó realizar una acción correctora (Reiniciar el servicio) después de la terminación inesperada del servicio Servidor, pero ocurrió el siguiente error: %%1056 = Ya se está ejecutando una instancia de este servicio. Error: (08/13/2016 06:04:57 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} Error: (08/13/2016 06:04:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: El servicio COMODO Dragon Update Service se terminó de manera inesperada. Esto ha sucedido 1 veces. Error: (08/13/2016 06:04:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: El servicio Adobe Flash Player Feedback Service se terminó de manera inesperada. Esto ha sucedido 1 veces. Error: (08/13/2016 06:04:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: El servicio Windows Update terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 60000 milisegundos: Reiniciar el servicio. ==================== Memory info =========================== Processor: Intel(R) Atom(TM) CPU N270 @ 1.60GHz Percentage of memory in use: 88% Total physical RAM: 1011.95 MB Available physical RAM: 112.25 MB Total Virtual: 2563.95 MB Available Virtual: 481.07 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:48.57 GB) (Free:42.31 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (DATOS) (Fixed) (Total:100.47 GB) (Free:100.04 GB) NTFS Drive e: (JUAN) (Fixed) (Total:465.75 GB) (Free:7.99 GB) NTFS Drive f: (KIRI) (Fixed) (Total:465.76 GB) (Free:98.29 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 11A8BA38) Partition 1: (Active) - (Size=48.6 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100.5 GB) - (Type=OF Extended) ======================================================== Disk: 1 (Size: 931.5 GB) (Disk ID: AF5EE9BB) Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.8 GB) - (Type=OF Extended) ==================== End of Addition.txt ============================