ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__cjggiimjnmpealmdjcibaifffhcdljfa\Cursos de Inglés Gratis Online por Internet.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=cjggiimjnmpealmdjcibaifffhcdljfa --app-url=hxxp://www.mansioningles.com/NuevoCurso.htm
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__cgppjnaehclgppcbmipkgcppiakdnkhb\Curso de inglés gratis para principiantes comprobado.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=cgppjnaehclgppcbmipkgcppiakdnkhb --app-url=hxxps://www.aprenderinglesrapidoyfacil.com/curso-de-ingles-gratis-para-principiantes-aprender-ingle/
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__cdphhacaibbdhbcbojopgkpffhkgikkf\El Confidencial.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=cdphhacaibbdhbcbojopgkpffhkgikkf --app-url=hxxps://www.elconfidencial.com/ultima-hora-en-vivo/
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__bdcbnmhcpiklfgbfkommllgcglfpomkp\Diario Córdoba.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bdcbnmhcpiklfgbfkommllgcglfpomkp --app-url=hxxps://www.diariocordoba.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__aidhhokabhpiknkcccjmembbhlijeikl\LA VANGUARDIA.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=aidhhokabhpiknkcccjmembbhlijeikl --app-url=hxxps://www.lavanguardia.com/
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__agimnkijcaahngcdmfeangaknmldooml\ANDREA BOCELLI.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml --app-url=hxxps://www.youtube.com/?feature=ytca
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__agimnkijcaahngcdmfeangaknmldooml\ATLETISMO CALENTAMINETO.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml --app-url=hxxps://www.youtube.com/?feature=ytca
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__agimnkijcaahngcdmfeangaknmldooml\ATLETISMO.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml --app-url=hxxps://www.youtube.com/?feature=ytca
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__agimnkijcaahngcdmfeangaknmldooml\CURSO CAMERA RAW.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml --app-url=hxxps://www.youtube.com/?feature=ytca
ShortcutWithArgument: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Web Applications\_crx__agimnkijcaahngcdmfeangaknmldooml\YouTube.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml --app-url=hxxps://www.youtube.com/?feature=ytca
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\ADSLZone.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=mhedilkgpbmdkmnbncfakeoeloeljkhm
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Blog de fotografía para principiantes – Descubre como ser fotógrafo profesional.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=pgfaaleoimjgaaiohlahfdjoiolgljmf
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\GUILLERMO FLORES CURSOS DE FOTOGRAFIA.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=agimnkijcaahngcdmfeangaknmldooml
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\MARCA - Diario online líder en información deportiva (1).lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=efahgkcpjghlgfpjdededafpmbjnlbhb
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\MARCA - Diario online líder en información deportiva.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=efahgkcpjghlgfpjdededafpmbjnlbhb
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Mundo Deportivo el diario deportivo Online (1).lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnobkabombgamininiophcapampkddpe
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Mundo Deportivo el diario deportivo Online.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnobkabombgamininiophcapampkddpe
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Outlook (PWA) (1).lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=eigpmdhekjlgjgcppnanaanbdmnlnagl
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Outlook (PWA).lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=eigpmdhekjlgjgcppnanaanbdmnlnagl
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicaciones de Chrome\Runner's World España La revista para corredores.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=ppokphelfbpdedilkdkbjkdalnhcmolm
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ADSLZone.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=mhedilkgpbmdkmnbncfakeoeloeljkhm
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Blog de fotografía para principiantes – Descubre como ser fotógrafo profesional.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=pgfaaleoimjgaaiohlahfdjoiolgljmf
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ComputerHoy.com_ Todo sobre tecnología, gadgets y novedades.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://computerhoy.com/ --profile-directory=Default
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ComputerWorld _ Innovación, negocio y tecnología.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://www.computerworld.es/home --profile-directory=Default
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Cursos de Inglés Gratis Online por Internet.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxp://www.mansioningles.com/NuevoCurso.htm --profile-directory=Default
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MARCA - Diario online líder en información deportiva.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=efahgkcpjghlgfpjdededafpmbjnlbhb
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mundo Deportivo el diario deportivo Online.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=gnobkabombgamininiophcapampkddpe
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Noticias de tecnología, hardware, software, juegos, criptomonedas y móviles - islaBit.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxps://www.islabit.com/ --profile-directory=Default
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Revista de deportes, salud y fitness online _ Sportlife.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --profile-directory=Default --app-id=bchgmiiflefkmjpebhdchnhhbpepjbdl --app-url=hxxps://www.sportlife.es/
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Runner's World España La revista para corredores.lnk -> C:\Program Files\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> --profile-directory=Default --app-id=ppokphelfbpdedilkdkbjkdalnhcmolm
ShortcutWithArgument: C:\Users\Usuario\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Videotutoriales y Cursos Gratuitos de informática Online.lnk -> C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe (Microsoft Corporation) -> --pin-url=hxxp://www.videotutoriales.es/ --profile-directory=Default
==================== Módulos cargados (Lista blanca) =============
2020-07-08 18:42 - 2020-07-08 18:42 - 000477696 _____ () [Archivo no firmado] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ffi-napi\prebuilds\win32-ia32\node.napi.node
2020-07-08 18:42 - 2020-07-08 18:42 - 000471040 _____ () [Archivo no firmado] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\ref-napi\prebuilds\win32-ia32\node.napi.node
2020-07-14 18:16 - 2020-07-14 18:16 - 000454656 _____ () [Archivo no firmado] \\?\C:\Program Files (x86)\ASUS\ArmouryDevice\node_modules\registry-js\prebuilds\win32-ia32\node.napi.node
2020-12-15 03:51 - 2019-12-23 19:51 - 000093184 _____ () [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\zlibwapi.dll
2020-12-15 03:51 - 2019-06-26 17:07 - 000094208 _____ () [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\SwAgent\MacroControl.dll
2020-04-22 16:35 - 2020-04-22 16:35 - 000081920 _____ () [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\WindowID\WindowID.dll
2022-06-28 14:26 - 2022-06-28 14:26 - 005998080 _____ () [Archivo no firmado] C:\Program Files (x86)\Intel\Driver and Support Assistant\irmfuu_module_win32.dll
2020-05-26 18:08 - 2020-05-26 18:08 - 002831360 _____ (Apache Software Foundation) [Archivo no firmado] C:\Program Files (x86)\LightingService\log4cxx.dll
2022-08-18 20:42 - 2023-06-13 08:07 - 000036608 _____ (ASUSTeK Computer Inc. -> ) [Archivo no firmado] C:\Program Files (x86)\ASUS\AXSP\4.02.15\PEbiosinterface32.dll
2020-12-15 03:51 - 2019-10-24 12:15 - 002676736 _____ (ASUSTeK Computer Inc.) [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\AURAChecker.dll
2020-12-15 14:16 - 2012-08-31 09:07 - 000110592 _____ (AVerMedia Technologies, Inc.) [Archivo no firmado] C:\Program Files (x86)\Common Files\AVerMedia\dll\CardID.dll
2020-12-15 14:16 - 2011-07-21 04:40 - 000368640 _____ (AVerMedia Technologies, Inc.) [Archivo no firmado] C:\Program Files (x86)\Common Files\AVerMedia\dll\GraphMaster.dll
2022-09-26 14:46 - 2013-06-17 19:33 - 000090112 _____ (Free Time) [Archivo no firmado] C:\Users\Usuario\Downloads\Nueva carpeta\App\FormatFactory\ShellEx64_103.dll
2020-12-15 03:51 - 2019-06-26 17:07 - 003394560 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\libcrypto-1_1-x64.dll
2020-12-15 03:51 - 2019-06-26 17:07 - 000679424 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\libssl-1_1-x64.dll
2020-12-15 03:51 - 2019-07-31 15:48 - 000072704 _____ (TODO: <Company name>) [Archivo no firmado] C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ShareFromArmouryIII\Protocol\Interrupt\InterruptTransfer.dll
==================== Alternate Data Streams (Lista blanca) ========
(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)
AlternateDataStreams: C:\ProgramData\Temp:890CC2F3 [149]
==================== Modo Seguro (Lista blanca) ==================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Asociación (Lista blanca) =================
==================== Internet Explorer (Lista blanca) ==========
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2023-02-25] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_341\bin\ssv.dll [2022-09-15] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_341\bin\jp2ssv.dll [2022-09-15] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2023-03-08] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2023-05-16] (Microsoft Corporation -> Microsoft Corporation)
==================== Hosts contenido: =========================
(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)
2019-03-19 06:49 - 2022-03-19 17:16 - 000000147 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
==================== Otras Áreas ===========================
(Actualmente no existe una corrección automática para esta sección.)
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Program Files (x86)\Common Files\Acronis\FileProtector\;C:\Program Files (x86)\Common Files\Acronis\FileProtector64\;F:\PROGRAMAS INSTALADOS\POWER DIRECTOR\QUICKTIMER\QTSystem\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\;C:\Program Files\dotnet\
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Usuario\Downloads\pexels-pixabay-50594.jpg
HKU\S-1-5-21-262221257-1845490735-1762155924-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\SANDRA\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: El medio no está conectado a internet.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.
==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==
(Si una entrada es incluida en el fixlist, será eliminada.)
HKLM\...\StartupApproved\StartupFolder: => "AVerQuick.lnk"
HKLM\...\StartupApproved\StartupFolder: => "AVer HID Receiver.lnk"
HKLM\...\StartupApproved\Run: => "AdobePSE19AutoAnalyzer"
HKLM\...\StartupApproved\Run: => "CanonSolutionMenu"
HKLM\...\StartupApproved\Run: => "PWRISOVM.EXE"
HKLM\...\StartupApproved\Run: => "CanonMyPrinter"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
HKLM\...\StartupApproved\Run32: => "CanonSolutionMenu"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\StartupFolder: => "EOS Utility.lnk"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "GUDelayStartup"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "CCXProcess"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "MicrosoftEdgeAutoLaunch_D74866CC9A9FD7473DAB98067A84C526"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "ProgLauncher"
HKU\S-1-5-21-262221257-1845490735-1762155924-1001\...\StartupApproved\Run: => "NoxMultiPlayer"
HKU\S-1-5-21-262221257-1845490735-1762155924-1004\...\StartupApproved\Run: => "OneDrive"
==================== Reglas de firewall (Lista blanca) ================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
FirewallRules: [{F710C984-18D4-4D57-9314-12685C0AEA33}] => (Allow) F:\PROGRAMAS INSTALADOS\PINNACLE STUDIO 24\programs\UMI.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{CCB24A4E-A393-400F-A3D7-D3660BF69020}] => (Allow) F:\PROGRAMAS INSTALADOS\PINNACLE STUDIO 24\programs\UMI.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{2635168B-CB5F-4598-B68D-2E44ECBEDB03}] => (Allow) F:\PROGRAMAS INSTALADOS\PINNACLE STUDIO 24\programs\NGStudio.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{4EB17C85-721B-451A-AA9D-B032E649422D}] => (Allow) F:\PROGRAMAS INSTALADOS\PINNACLE STUDIO 24\programs\NGStudio.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{1DB56333-260A-4437-9D8E-799D7373A4E2}] => (Allow) F:\PROGRAMAS INSTALADOS\PINNACLE STUDIO 24\programs\RM.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{659EDF8D-8C22-4B0E-8B94-38F880A0C898}] => (Allow) F:\PROGRAMAS INSTALADOS\PINNACLE STUDIO 24\programs\RM.exe (Corel Corporation -> Pinnacle)
FirewallRules: [{C19E5E19-571F-41E8-A65F-8FC69EB81BF8}] => (Allow) F:\PROGRAMAS INSTALADOS\POWER DIRECTOR\PowerDirector\PDR9.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [UDP Query User{63B46272-455E-46C3-8E1A-6FF248A22E30}F:\partisans.1941-goldberg\partisans 1941\partisans\binaries\win64\partisans-win64-shipping.exe] => (Block) F:\partisans.1941-goldberg\partisans 1941\partisans\binaries\win64\partisans-win64-shipping.exe (Epic Games, Inc.) [Archivo no firmado]
FirewallRules: [TCP Query User{E6EA1769-11D9-4DE8-8FCC-5287AB377546}F:\partisans.1941-goldberg\partisans 1941\partisans\binaries\win64\partisans-win64-shipping.exe] => (Block) F:\partisans.1941-goldberg\partisans 1941\partisans\binaries\win64\partisans-win64-shipping.exe (Epic Games, Inc.) [Archivo no firmado]
FirewallRules: [UDP Query User{E85A3075-5B8B-4622-99D9-49C41D7F589A}F:\programas instalados\call of duty modern warfare\modernwarfare.exe] => (Block) F:\programas instalados\call of duty modern warfare\modernwarfare.exe (Activision Publishing Inc -> Activision)
FirewallRules: [TCP Query User{25B8FAD7-7C8A-435E-B1A9-816495532846}F:\programas instalados\call of duty modern warfare\modernwarfare.exe] => (Block) F:\programas instalados\call of duty modern warfare\modernwarfare.exe (Activision Publishing Inc -> Activision)
FirewallRules: [{E902955C-3824-4097-8883-65827A7BFB7D}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\ActiveProtection\anti_ransomware_service.exe (Acronis International GmbH -> Acronis International GmbH)
FirewallRules: [{4275B37F-A3B0-4C64-91B6-3AC23DDE25F1}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{86FA6444-0AAD-46FD-A5DF-7A8CBC318FEB}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmouryHtmlDebugServer.exe (ASUSTeK Computer Inc. -> ASUS)
FirewallRules: [{17C1B571-E01E-4F4C-9B97-DF349C64C417}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\asus_framework.exe (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
FirewallRules: [{FB9229BA-9F67-4269-A7BE-A007D4974BCB}] => (Allow) C:\Program Files (x86)\ASUS\ArmouryDevice\dll\ArmourySocketServer\ArmourySocketServer.exe (ASUSTeK Computer Inc. -> ASUS)
FirewallRules: [{EB9E7B03-4466-4697-80D2-ACCF294B843B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{64003896-5129-46F1-A6E0-49F30EA053A7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{E61EF444-82F0-4493-89DA-6CB65A2B4DFF}] => (Allow) F:\PROGRAMAS INSTALADOS\CANON ESCANER\SgTool.exe (CANON INC.) [Archivo no firmado]
FirewallRules: [{ADF9E688-E12E-48EF-8541-2C4951741EB4}] => (Allow) F:\PROGRAMAS INSTALADOS\CANON ESCANER\SgTool.exe (CANON INC.) [Archivo no firmado]
FirewallRules: [{B58F232D-BDB7-4988-835F-F4C434344A76}] => (Allow) F:\PROGRAMAS INSTALADOS\CANON ESCANER\SgTool.exe (CANON INC.) [Archivo no firmado]
FirewallRules: [{EBF151CB-F1EF-4FCC-81FC-A9A2B1FF4F80}] => (Allow) F:\PROGRAMAS INSTALADOS\CANON ESCANER\SgTool.exe (CANON INC.) [Archivo no firmado]
FirewallRules: [{A15D4B8B-85A5-4B39-9D1C-40DFE3101367}] => (Allow) LPort=56338
FirewallRules: [{1BBC19E0-9F31-4824-BD3F-0E2D67FC6B2D}] => (Allow) LPort=56338
FirewallRules: [{AC243D3F-B0B5-44AE-96F7-5071232E97A4}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{9FA4651E-F9E8-4CA5-9431-F31AA3477A7C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{4C659CEE-4AED-46FD-B43C-161A0810DA90}C:\users\usuario\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\usuario\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [UDP Query User{472DE324-E890-4958-ADDE-87A0F37CA970}C:\users\usuario\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\usuario\appdata\roaming\spotify\spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{35B9E693-8C27-4FFB-B144-96734980EF32}] => (Allow) F:\PROGRAMAS INSTALADOS\qBittorrent\qbittorrent.exe (The qBittorrent Project) [Archivo no firmado]
FirewallRules: [{E0246EF8-7B8F-41E4-9578-16AEAE89381A}] => (Allow) F:\PROGRAMAS INSTALADOS\qBittorrent\qbittorrent.exe (The qBittorrent Project) [Archivo no firmado]
FirewallRules: [{0492D904-8516-467A-8152-DF87E9C1F4DD}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{C0370E38-CE59-4F42-9F65-F0EFCB76D4C5}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{7B920B08-1888-4444-AD5A-C5491995107A}] => (Allow) C:\Program Files\Avast Software\Battery Saver\BatteryUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{F87F321F-4734-4FB0-96EE-615DAAF7ACD5}] => (Allow) C:\Program Files\Avast Software\Battery Saver\BatteryUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{2EB7558E-1E52-4609-8527-33F8A5E39B95}] => (Allow) C:\Program Files\Avast Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{C464F1B5-E20B-49ED-98F6-CAC595A7B711}] => (Allow) C:\Program Files\Avast Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [TCP Query User{C7CA8A52-DEA5-4983-A782-755C9F5F1F4D}F:\programas instalados\call of duty vanguard\vanguard.exe] => (Block) F:\programas instalados\call of duty vanguard\vanguard.exe (Activision Publishing Inc -> Activision)
FirewallRules: [UDP Query User{0315EEFE-3A01-4D63-AD5D-8E9E80D6032C}F:\programas instalados\call of duty vanguard\vanguard.exe] => (Block) F:\programas instalados\call of duty vanguard\vanguard.exe (Activision Publishing Inc -> Activision)
FirewallRules: [TCP Query User{991B5C44-C4DA-4AAC-A1B7-BAAACF72CC1B}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{0B65070E-E21B-41E1-9C51-EE56C75FDFB5}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{14021D74-B537-4E65-98C2-0BCFB51DB6A2}F:\programas instalados\age of empires iii definitive edition\aoe3de_s.exe] => (Block) F:\programas instalados\age
of empires iii definitive edition\aoe3de_s.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{3CEFEEDB-1A96-4FA5-A231-7687619C3534}F:\programas instalados\age of empires iii definitive edition\aoe3de_s.exe] => (Block) F:\programas instalados\age of empires iii definitive edition\aoe3de_s.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{2D7EAC9B-92BC-4BF7-8889-353966EF29A1}F:\programas instalados\age of empires iii definitive edition\battleserver.exe] => (Block) F:\programas instalados\age of empires iii definitive edition\battleserver.exe () [Archivo no firmado]
FirewallRules: [UDP Query User{92516621-ED04-4149-96C9-83306B1C902B}F:\programas instalados\age of empires iii definitive edition\battleserver.exe] => (Block) F:\programas instalados\age of empires iii definitive edition\battleserver.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{97389400-B7FA-4460-9D89-A29E974EFCF3}C:\users\usuario\appdata\local\programs\opera\opera.exe] => (Block) C:\users\usuario\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [UDP Query User{F40BAE0C-38C9-4591-91FA-24DCF149B2CA}C:\users\usuario\appdata\local\programs\opera\opera.exe] => (Block) C:\users\usuario\appdata\local\programs\opera\opera.exe (Opera Norway AS -> Opera Software)
FirewallRules: [{E7CE5B19-9C18-45B8-BF44-37CDF99E5084}] => (Allow) F:\PROGRAMAS INSTALADOS\WINAMP\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{2FB45605-9C67-4FEE-B6FA-B9E59CA5243A}] => (Allow) F:\PROGRAMAS INSTALADOS\WINAMP\winamp.exe (Winamp SA -> Winamp SA)
FirewallRules: [{3F97CC0B-5C18-4D3E-9630-EF2CD6539302}] => (Allow) LPort=57209
FirewallRules: [{855F4A7A-AF9C-4328-B411-99293C4E0401}] => (Allow) LPort=57210
FirewallRules: [{CF8B4D90-A96B-40D1-B164-8EE61F4E4EDB}] => (Allow) LPort=57211
FirewallRules: [{05041A2A-F2C9-48E0-9253-A67E30621D32}] => (Allow) LPort=57212
FirewallRules: [{1EB749BB-37D0-44DA-A7E6-50CEA365E2C6}] => (Allow) LPort=57213
FirewallRules: [{B77CE5CF-39AC-4CA5-AC42-FABE49DFA295}] => (Allow) LPort=57214
FirewallRules: [{22914CD3-AAF9-42DA-BE7B-41BA472C5831}] => (Allow) LPort=57215
FirewallRules: [{65C81DB6-DD5C-4736-AF07-E9426F80950D}] => (Allow) LPort=57216
FirewallRules: [{ECA04DDB-E900-4366-B018-010028EFAF96}] => (Allow) LPort=57217
FirewallRules: [{A95572C7-E903-4DA7-81DF-7FB954E5C1BF}] => (Allow) LPort=57218
FirewallRules: [{66ECF638-54C9-4AC3-9307-03C580F85B01}] => (Allow) LPort=57209
FirewallRules: [{E6CA6651-9BEA-481D-905C-E8E36AFAE0FC}] => (Allow) LPort=57210
FirewallRules: [{EA42806E-2AFD-4139-99A5-585F8D2C12CC}] => (Allow) LPort=57211
FirewallRules: [{CB3F70AB-35A0-47C1-AA90-B61A32102150}] => (Allow) LPort=57212
FirewallRules: [{3C93C6B3-C195-43E8-873E-825E84B5D78E}] => (Allow) LPort=57213
FirewallRules: [{A6B9231B-95BA-4C7B-9175-9D59CF03308E}] => (Allow) LPort=57214
FirewallRules: [{A0ED21B9-9583-4514-A3F6-08E66316331C}] => (Allow) LPort=57215
FirewallRules: [{A98DB8DD-379B-475C-AB83-D91ED00F6166}] => (Allow) LPort=57216
FirewallRules: [{F9D6D84D-1564-4D23-80E9-8C427F320AF8}] => (Allow) LPort=57217
FirewallRules: [{A0620C2B-20B8-4C37-BF25-FE5C6770B949}] => (Allow) LPort=57218
FirewallRules: [{8619713F-457D-4C0A-B390-A489DAE41C3D}] => (Allow) LPort=23007
FirewallRules: [{842F4F5B-B6F7-4966-910E-4FDAE8800A27}] => (Allow) LPort=23008
FirewallRules: [{976EC27B-ACA8-452F-B93A-18FD0B9992ED}] => (Allow) LPort=33009
FirewallRules: [{377580A3-AD74-4E6C-90A3-F2599EEBC6CE}] => (Allow) LPort=33010
FirewallRules: [{68924F99-D209-42A4-8226-9F9F38BB8C36}] => (Allow) LPort=33011
FirewallRules: [{9BD33CC1-7D92-48F4-94CB-E08E3A542D62}] => (Allow) LPort=43012
FirewallRules: [{BE382CDB-5B24-4853-A670-092F90B2E3FF}] => (Allow) LPort=43013
FirewallRules: [{52F7E03B-CA59-4F5D-8BB2-26E370F22795}] => (Allow) LPort=53014
FirewallRules: [{5A48EF91-9402-4437-8721-7910E912950F}] => (Allow) LPort=53015
FirewallRules: [{83BC535C-B1CB-4DDB-B5AC-5FC013B42221}] => (Allow) LPort=53016
FirewallRules: [{7151F69F-3D93-4133-ABF2-CBB0BE6480C7}] => (Allow) LPort=23007
FirewallRules: [{E4607A58-8335-4CD2-82A0-6D098C5336A4}] => (Allow) LPort=23008
FirewallRules: [{C374314C-9226-49E9-AAD6-8368F37489BE}] => (Allow) LPort=33009
FirewallRules: [{CBDFFD8B-C4B7-4BD1-A861-5CA53EA9FAC2}] => (Allow) LPort=33010
FirewallRules: [{C42421C8-DED4-414E-BCF8-9B92A3DB47FB}] => (Allow) LPort=33011
FirewallRules: [{35B34F2F-7DA2-494F-B213-5F03F70985BF}] => (Allow) LPort=43012
FirewallRules: [{5925A35E-7C99-4803-96F4-98AAA369D865}] => (Allow) LPort=43013
FirewallRules: [{3C306892-B747-4EE8-8229-152628E3E4E0}] => (Allow) LPort=53014
FirewallRules: [{4FC004B5-F3B3-47E0-B7B3-776BB7E5769F}] => (Allow) LPort=53015
FirewallRules: [{E6BB92C3-3442-436D-B631-A3FEA6AA0C33}] => (Allow) LPort=53016
FirewallRules: [{1F1A340E-A918-4AFD-815F-6801DCFBA68E}] => (Allow) LPort=50053
FirewallRules: [{C64DE5FA-F58D-4A86-9366-D3B124553653}] => (Allow) LPort=50053
FirewallRules: [{776EDF42-CF40-4310-917D-F8778D4029CE}] => (Allow) C:\Users\Usuario\Downloads\Nueva carpeta\App\FormatFactory\FormatFactory.exe (Free Time Co., Ltd. -> Free Time Co., Ltd.) [Archivo no firmado]
FirewallRules: [{C5CC18B9-613B-4852-A049-B5CF97BC033C}] => (Allow) C:\Users\Usuario\Downloads\Nueva carpeta\App\FormatFactory\FFModules\Encoder\Doc\EBookCodec.exe (Free Time Co., Ltd. -> Free Time Co., Ltd.)
FirewallRules: [{C0EDE061-DD7E-4BAF-9E3D-3A322CD618BC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{E4F630D4-06D9-4803-A3E3-99AD7A471237}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{A5B79567-8F48-41FB-8D1B-D1E73C09D39A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{95BEA51E-B2AE-4B2B-A6F1-B23FC5891965}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (Nvidia Corporation -> NVIDIA Corporation)
FirewallRules: [{4F5AB976-95FC-48B9-B398-AF39376697D6}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{478D5BE8-A228-49DC-8839-4395591CF965}] => (Allow) C:\Program Files\ASUS\ROG Live Service\ROGLiveService.exe (ASUSTeK COMPUTER INC. -> ASUSTek COMPUTER INC.)
FirewallRules: [{C1891A19-58C3-4F02-8623-11996277ECDB}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D2550911-2008-4307-892C-F5312017318F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BDE145DB-E0CE-471F-B0B5-D16B690B960F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5A8B5029-1447-4371-B97C-D0D377602673}] => (Allow) C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe (ADSL club LLC -> ADSL Club LLC)
FirewallRules: [{5E3783E5-194E-45FD-B419-744A8DA47790}] => (Allow) C:\Program Files (x86)\IP-TV Player\IpTvPlayer.exe (ADSL club LLC -> ADSL Club LLC)
FirewallRules: [{221B9440-7FC6-437D-A26E-935719195B9F}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5B6A44B4-F267-4090-8F18-DD1C32FEB9EA}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3402.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{490CD580-145E-4228-97B7-D580FFF35044}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3402.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{019C3338-71AE-4611-A505-188C93A6026A}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3402.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9258CAF3-BB87-4855-9F42-54D7AC82645C}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.98.3402.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2FDD63D3-9E3E-4EC0-A69E-6C9C0FE9B7D7}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\114.0.1823.43\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A0149795-38D3-451D-A894-E60F2BF76007}] => (Allow) C:\Users\Usuario\Downloads\4ddig-file-repair.exe => Ningún archivo
FirewallRules: [{DE7700A3-2E91-4188-A2AB-6316BC7DC11E}] => (Allow) C:\Users\Usuario\Downloads\4ddig-file-repair.exe => Ningún archivo
FirewallRules: [{5832EEE6-8845-44CD-B261-32219390559C}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\4DDiG File Repair.exe => Ningún archivo
FirewallRules: [{F9DC5B39-6BCB-4BEF-A6C1-0758AE1E3B11}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\4DDiG File Repair.exe => Ningún archivo
FirewallRules: [{37F3C0E9-3C94-498B-A1E1-E63C6144FBFA}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\NetFrameCheck.exe => Ningún archivo
FirewallRules: [{F6466E7F-EB30-4F6D-9104-AC9CB6CDBD1A}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\NetFrameCheck.exe => Ningún archivo
FirewallRules: [{76AAD099-C09E-4721-A1FB-C51724FF0AF6}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\Monitor\Monitor.exe => Ningún archivo
FirewallRules: [{30DFD091-BF12-4D59-9C03-9AE96776EA7A}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\Monitor\Monitor.exe => Ningún archivo
FirewallRules: [{DD04092F-65E3-4F28-BEE3-FCC44406C038}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\VideoRepairService.exe => Ningún archivo
FirewallRules: [{6212F9C3-3C77-4872-826B-8BCE275162DD}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\VideoRepairService.exe => Ningún archivo
FirewallRules: [{9984BCF9-48C9-49EA-B2F2-4E18B73EB97F}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\PhotosRepairService.exe => Ningún archivo
FirewallRules: [{ABB3BEFB-CB5F-44A6-980F-C4DA5D60A937}] => (Allow) C:\Program Files (x86)\Tenorshare\4DDiG File Repair\PhotosRepairService.exe => Ningún archivo
==================== Puntos de Restauración =========================
03-06-2023 20:55:38 Punto de control programado
13-06-2023 10:36:11 Punto de control programado
==================== Dispositivos defectuosos en el Administrador de dispositivos ============
==================== Errores del registro de eventos: ========================
Errores de aplicación:
==================
Error: (06/13/2023 08:08:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: ARPTray.exe, versión: 2.1.1700.0, marca de tiempo: 0x5c139943
Nombre del módulo con errores: KERNELBASE.dll, versión: 10.0.19041.2965, marca de tiempo: 0xf18c1c30
Código de excepción: 0xe0434352
Desplazamiento de errores: 0x0013d6c2
Identificador del proceso con errores: 0x4f00
Hora de inicio de la aplicación con errores: 0x01d99dbd6f820215
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\Acronis\Ransomware Protection\ARPTray.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\System32\KERNELBASE.dll
Identificador del informe: 77151522-14bb-4ccc-b2b2-6984586d197e
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (06/13/2023 08:08:13 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplicación: ARPTray.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.Xml.XmlException
en System.Xml.XmlTextReaderImpl.Throw(System.Exception)
en System.Xml.XmlTextReaderImpl.Throw(System.String, System.String[])
en System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef)
en System.Xml.XmlTextReaderImpl.ParseText()
en System.Xml.XmlTextReaderImpl.ParseElementContent()
en System.Xml.XmlTextReaderImpl.Read()
en System.Xml.XmlTextReader.Read()
en System.Configuration.XmlUtil.StrictReadToNextElement(System.Configuration.ExceptionAction)
en System.Configuration.BaseConfigurationRecord.ScanFactoriesRecursive(System.Configuration.XmlUtil, System.String, System.Collections.Hashtable)
en System.Configuration.BaseConfigurationRecord.ScanFactoriesRecursive(System.Configuration.XmlUtil, System.String, System.Collections.Hashtable)
en System.Configuration.BaseConfigurationRecord.ScanFactories(System.Configuration.XmlUtil)
en System.Configuration.BaseConfigurationRecord.InitConfigFromFile()
Información de la excepción: System.Configuration.ConfigurationErrorsException
en System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean)
en System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors)
en System.Configuration.BaseConfigurationRecord.ThrowIfInitErrors()
en System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs)
Información de la excepción: System.Configuration.ConfigurationErrorsException
en System.Configuration.ConfigurationManager.PrepareConfigSystem()
en System.Configuration.ConfigurationManager.get_AppSettings()
en NLog.Common.InternalLogger.GetSettingString(System.String, System.String)
en NLog.Common.InternalLogger.GetSetting[[System.Boolean, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String, System.String, Boolean)
en NLog.Common.InternalLogger.Reset()
en NLog.Common.InternalLogger..cctor()
Información de la excepción: System.TypeInitializationException
en NLog.Common.InternalLogger.Log(System.Exception, NLog.LogLevel, System.String)
en NLog.Internal.ExceptionHelper.MustBeRethrown(System.Exception)
en NLog.LogFactory.get_Configuration()
en NLog.LogFactory.GetLogger(LoggerCacheKey)
en NLog.LogFactory.GetLogger(System.String)
en NLog.LogManager.GetCurrentClassLogger()
en ARPTray.App..cctor()
Información de la excepción: System.TypeInitializationException
en ARPTray.App.OnStartup(System.Windows.StartupEventArgs)
en System.Windows.Application.<.ctor>b__1_0(System.Object)
en System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
en System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
en System.Windows.Threading.DispatcherOperation.InvokeImpl()
en System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
en MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object)
en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
en MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object)
en System.Windows.Threading.DispatcherOperation.Invoke()
en System.Windows.Threading.Dispatcher.ProcessQueue()
en System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
en MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
en MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
en System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
en System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
en System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
en MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
en MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
en System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
en System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
en System.Windows.Application.RunDispatcher(System.Object)
en System.Windows.Application.RunInternal(System.Windows.Window)
en System.Windows.Application.Run(System.Windows.Window)
en ARPTray.App.Main()
Error: (06/12/2023 10:01:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: dwm.exe, versión: 10.0.19041.746, marca de tiempo: 0x6be51595
Nombre del módulo con errores: KERNELBASE.dll, versión: 10.0.19041.2913, marca de tiempo: 0xa1c3e870
Código de excepción: 0xc00001ad
Desplazamiento de errores: 0x000000000012d862
Identificador del proceso con errores: 0x5a4
Hora de inicio de la aplicación con errores: 0x01d99d1bb262d57a
Ruta de acceso de la aplicación con errores: C:\WINDOWS\system32\dwm.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\System32\KERNELBASE.dll
Identificador del informe: 0ca23198-e7d7-42a0-aa54-8fc91f4e40af
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (06/12/2023 12:51:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Nombre de la aplicación con errores: ARPTray.exe, versión: 2.1.1700.0, marca de tiempo: 0x5c139943
Nombre del módulo con errores: KERNELBASE.dll, versión: 10.0.19041.2965, marca de tiempo: 0xf18c1c30
Código de excepción: 0xe0434352
Desplazamiento de errores: 0x0013d6c2
Identificador del proceso con errores: 0x1864
Hora de inicio de la aplicación con errores: 0x01d99d1bcad2b0a6
Ruta de acceso de la aplicación con errores: C:\Program Files (x86)\Acronis\Ransomware Protection\ARPTray.exe
Ruta de acceso del módulo con errores: C:\WINDOWS\System32\KERNELBASE.dll
Identificador del informe: 165a16bb-604d-42ff-8734-026849046a11
Nombre completo del paquete con errores:
Identificador de aplicación relativa del paquete con errores:
Error: (06/12/2023 12:51:08 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplicación: ARPTray.exe
Versión de Framework: v4.0.30319
Descripción: el proceso terminó debido a una excepción no controlada.
Información de la excepción: System.Xml.XmlException
en System.Xml.XmlTextReaderImpl.Throw(System.Exception)
en System.Xml.XmlTextReaderImpl.Throw(System.String, System.String[])
en System.Xml.XmlTextReaderImpl.ParseText(Int32 ByRef, Int32 ByRef, Int32 ByRef)
en System.Xml.XmlTextReaderImpl.ParseText()
en System.Xml.XmlTextReaderImpl.ParseElementContent()
en System.Xml.XmlTextReaderImpl.Read()
en System.Xml.XmlTextReader.Read()
en System.Configuration.XmlUtil.StrictReadToNextElement(System.Configuration.ExceptionAction)
en System.Configuration.BaseConfigurationRecord.ScanFactoriesRecursive(System.Configuration.XmlUtil, System.String, System.Collections.Hashtable)
en System.Configuration.BaseConfigurationRecord.ScanFactoriesRecursive(System.Configuration.XmlUtil, System.String, System.Collections.Hashtable)
en System.Configuration.BaseConfigurationRecord.ScanFactories(System.Configuration.XmlUtil)
en System.Configuration.BaseConfigurationRecord.InitConfigFromFile()
Información de la excepción: System.Configuration.ConfigurationErrorsException
en System.Configuration.ConfigurationSchemaErrors.ThrowIfErrors(Boolean)
en System.Configuration.BaseConfigurationRecord.ThrowIfParseErrors(System.Configuration.ConfigurationSchemaErrors)
en System.Configuration.BaseConfigurationRecord.ThrowIfInitErrors()
en System.Configuration.ClientConfigurationSystem.OnConfigRemoved(System.Object, System.Configuration.Internal.InternalConfigEventArgs)
Información de la excepción: System.Configuration.ConfigurationErrorsException
en System.Configuration.ConfigurationManager.PrepareConfigSystem()
en System.Configuration.ConfigurationManager.get_AppSettings()
en NLog.Common.InternalLogger.GetSettingString(System.String, System.String)
en NLog.Common.InternalLogger.GetSetting[[System.Boolean, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.String, System.String, Boolean)
en NLog.Common.InternalLogger.Reset()
en NLog.Common.InternalLogger..cctor()
Información de la excepción: System.TypeInitializationException
en NLog.Common.InternalLogger.Log(System.Exception, NLog.LogLevel, System.String)
en NLog.Internal.ExceptionHelper.MustBeRethrown(System.Exception)
en NLog.LogFactory.get_Configuration()
en NLog.LogFactory.GetLogger(LoggerCacheKey)
en NLog.LogFactory.GetLogger(System.String)
en NLog.LogManager.GetCurrentClassLogger()
en ARPTray.App..cctor()
Información de la excepción: System.TypeInitializationException
en ARPTray.App.OnStartup(System.Windows.StartupEventArgs)
en System.Windows.Application.<.ctor>b__1_0(System.Object)
en System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
en System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
en System.Windows.Threading.DispatcherOperation.InvokeImpl()
en System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object)
en MS.Internal.CulturePreservingExecutionContext.CallbackWrapper(System.Object)
en System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
en System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
en MS.Internal.CulturePreservingExecutionContext.Run(MS.Internal.CulturePreservingExecutionContext, System.Threading.ContextCallback, System.Object)
en System.Windows.Threading.DispatcherOperation.Invoke()
en System.Windows.Threading.Dispatcher.ProcessQueue()
en System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
en MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
en MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
en System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
en System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
en System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
en MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
en MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
en System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
en System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
en System.Windows.Application.RunDispatcher(System.Object)
en System.Windows.Application.RunInternal(System.Windows.Window)
en System.Windows.Application.Run(System.Windows.Window)
en ARPTray.App.Main()
Error: (06/11/2023 06:02:45 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: El optimizador de almacenamiento no pudo completar volver a optimizar en Nuevo vol (H:) debido a: El hardware del volumen no admite la operación solicitada. (0x8900002A)
Error: (06/11/2023 06:02:44 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: El optimizador de almacenamiento no pudo completar volver a optimizar en (G:) debido a: El hardware del volumen no admite la operación solicitada. (0x8900002A)
Error: (06/11/2023 06:02:41 PM) (Source: Microsoft-Windows-Defrag) (EventID: 264) (User: )
Description: El optimizador de almacenamiento no pudo completar volver a optimizar en Nuevo vol (F:) debido a: El hardware del volumen no admite la operación solicitada. (0x8900002A)
Errores del sistema:
=============
Error: (06/13/2023 08:09:52 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: El servicio Enrutamiento y acceso remoto se cerró con el error específico de servicio
Una sesión de inicio especificada no existe. Es posible que haya finalizado.
Error: (06/13/2023 08:09:50 AM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: Error irrecuperable al intentar tener acceso a la clave privada de la credencial TLS servidor. El código de error devuelto del módulo criptográfico es 0x8009030d. El estado de error interno es 10001.
Error: (06/13/2023 08:09:50 AM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: Error irrecuperable al intentar tener acceso a la clave privada de la credencial TLS servidor. El código de error devuelto del módulo criptográfico es 0x8009030d. El estado de error interno es 10001.
Error: (06/13/2023 08:09:50 AM) (Source: RasSstp) (EventID: 13) (User: )
Description: El servicio del protocolo de túnel de sockets seguros no pudo configurar el siguiente certificado para su uso con el protocolo de Internet versión 6 (IPv6). Esto podría impedir que se estableciesen conexiones SSTP. Solucione el problema e inténtelo de nuevo.
Nombre del certificado: CN=NVIDIA GameStream Server
Una sesión de inicio especificada no existe. Es posible que haya finalizado.
Error: (06/13/2023 08:09:50 AM) (Source: RasSstp) (EventID: 12) (User: )
Description: El servicio del protocolo de túnel de sockets seguros no pudo configurar el siguiente certificado para su uso con el protocolo de Internet versión 4 (IPv4). Esto podría impedir que se establezcan conexiones SSTP correctamente. Solucione el problema e inténtelo de nuevo.
Nombre del certificado: CN=NVIDIA GameStream Server
Una sesión de inicio especificada no existe. Es posible que haya finalizado.
Error: (06/12/2023 12:52:40 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: El servicio Enrutamiento y acceso remoto se cerró con el error específico de servicio
Una sesión de inicio especificada no existe. Es posible que haya finalizado.
Error: (06/12/2023 12:52:38 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: Error irrecuperable al intentar tener acceso a la clave privada de la credencial TLS servidor. El código de error devuelto del módulo criptográfico es 0x8009030d. El estado de error interno es 10001.
Error: (06/12/2023 12:52:38 PM) (Source: Schannel) (EventID: 4102) (User: NT AUTHORITY)
Description: Error irrecuperable al intentar tener acceso a la clave privada de la credencial TLS servidor. El código de error devuelto del módulo criptográfico es 0x8009030d. El estado de error interno es 10001.
Windows Defender:
================Event[0]:
Date: 2022-01-30 20:15:08
Description:
Antivirus de Microsoft Defender encontró un error al intentar cargar la inteligencia de seguridad e intentará revertir a una versión que sepa que es correcta.
Inteligencia de seguridad intentada: Actual
Código de error: 0x80070002
Descripción del error: El sistema no puede encontrar el archivo especificado.
Versión de inteligencia de seguridad: 0.0.0.0;0.0.0.0
Versión del motor: 0.0.0.0
CodeIntegrity:
===============
Date: 2023-06-13 10:37:49
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.
Date: 2023-06-13 09:08:43
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Avast Software\Avast\AvastSvc.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2023-06-13 08:08:45
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\Avast Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.
==================== Información de la memoria ===========================
BIOS: American Megatrends Inc. 0601 04/03/2020
Placa base: ASUSTeK COMPUTER INC. PRIME H410M-A
Procesador: Intel(R) Core(TM) i5-10400F CPU @ 2.90GHz
Porcentaje de memoria en uso: 35%
RAM física total: 16291.54 MB
RAM física disponible: 10486.47 MB
Virtual total: 26531.54 MB
Virtual disponible: 18218.34 MB
==================== Unidades ================================
Drive c: (OS) (Fixed) (Total:222.94 GB) (Free:3.77 GB) (Model: KINGSTON SA400S37240G) NTFS
Drive d: (Reservado para el sistema) (Fixed) (Total:0.34 GB) (Free:0.07 GB) (Model: WDC WD10EZEX-08M2NA0) NTFS ==>[sistema con componentes de arranque (obtenido de unidad)]
Drive e: () (Fixed) (Total:0 GB) (Free:0 GB) (Model: WDC WD20EARX-008FB0)
Drive f: (Nuevo vol) (Fixed) (Total:930.61 GB) (Free:113.49 GB) (Model: WDC WD10EZEX-08M2NA0) NTFS
Drive g: () (Fixed) (Total:934.07 GB) (Free:133.44 GB) (Model: WDC WD20EARX-008FB0) NTFS
Drive h: (Nuevo vol) (Fixed) (Total:928.85 GB) (Free:339.59 GB) (Model: WDC WD20EARX-008FB0) NTFS
Drive j: () (Removable) (Total:117.18 GB) (Free:103.82 GB) exFAT
\\?\Volume{2e34956b-1240-43a5-8c0c-42ce5b212da8}\ (Recuperación) (Fixed) (Total:0.52 GB) (Free:0.08 GB) NTFS
\\?\Volume{9954b94f-0000-0000-0000-20bde8000000}\ () (Fixed) (Total:0.56 GB) (Free:0.12 GB) NTFS
\\?\Volume{a4922406-6e67-4f37-80ba-03806705ca4d}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32
==================== MBR & Tabla de particiones ====================
==========================================================
Disk: 3 (Size: 117.2 GB) (Disk ID: FA2CB833)
Partition 1: (Active) - (Size=117.2 GB) - (Type=07 NTFS)
==================== Final de Addition.txt =======================
Muchas gracias.