Hola espero se encuentren muy bien
Resulta que infect´´e mi computador intentando descargar algún juego hace unos días y estuve investigando en los distintos foros, pero no pude encontrar solución, el malwarebytes elimino aproximadamente 58 archivos infestados y el ESET otros 20, pero como podr´´an notar el problema persiste.
Revise en otras conversaciones, la posible soluci´´on, seguí los pasos y aquí traigo mis reportes de FARBAR para ver si me pueden ayudar a componer mi PC.
De ante mano muchas gracias.
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 24.01.2024
Ejecutado por User (administrador) sobre DESKTOP-BC0EK2J (ECS H81H3-M4) (24-01-2024 22:19:38)
Ejecutado desde C:\Users\User\OneDrive\Escritorio\FRST64.exe
Perfiles cargados: User
Plataforma: Microsoft Windows 10 Pro Versión 22H2 19045.3930 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: Edge
Modo de Inicio: Normal
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
(Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
(C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cncmd.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\WindowsApps\MSTeams_23335.232.2637.4844_x64__8wekyb3d8bbwe\ms-teams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\120.0.2210.144\msedgewebview2.exe <7>
(C:\Riot Games\Riot Client\RiotClientServices.exe ->) () [Archivo no firmado] C:\Riot Games\Riot Client\RiotClientCrashHandler.exe
(D:\Games\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) D:\Games\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
(DriverStore\FileRepository\u0380462.inf_amd64_98be862657f36791\B378995\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0380462.inf_amd64_98be862657f36791\B378995\atieclxx.exe
(explorer.exe ->) (Cleversort FZ-LLC -> ) C:\Users\User\AppData\Local\Programs\TaskbarSystem\TaskbarSystem.exe
(explorer.exe ->) (Epic Games Inc. -> Epic Games, Inc.) D:\Games\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe <2>
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\RiotClientServices.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\MSTeams_23335.232.2637.4844_x64__8wekyb3d8bbwe\ms-teams.exe
(rundll32.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe <2>
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0380462.inf_amd64_98be862657f36791\B378995\atiesrxx.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(services.exe ->) (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe
(services.exe ->) (TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\SDXHelper.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileCoAuth.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe <3>
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc. -> Apple Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restricción <==== ATENCIÓN
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restricción <==== ATENCIÓN
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center: Restricción <==== ATENCIÓN
HKLM\Software\Policies\...\system: [EnableSmartScreen] 0
HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\85.0.37.0\GoogleDriveFS.exe [58857760 2024-01-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\85.0.37.0\GoogleDriveFS.exe [58857760 2024-01-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [2595344 2023-12-13] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [EpicGamesLauncher] => D:\Games\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37188048 2024-01-11] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [144008 2019-11-26] (Adobe Inc. -> Adobe Systems Incorporated)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [utweb] => "C:\Users\User\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (Ningún archivo)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\85.0.37.0\GoogleDriveFS.exe [58857760 2024-01-24] (Google LLC -> Google, Inc.)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [MicrosoftEdgeAutoLaunch_C46CFC0629905CC775E70B50EA8A519C] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [3854376 2024-01-17] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [44540320 2024-01-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [Spotify] => C:\Users\User\AppData\Roaming\Spotify\Spotify.exe [30487880 2024-01-20] (Spotify AB -> Spotify Ltd)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [TaskbarSystem] => C:\Users\User\AppData\Local\Programs\TaskbarSystem\TaskbarSystem.exe [911360 2022-12-08] (Cleversort FZ-LLC -> ) <==== ATENCIÓN
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize (Ningún archivo) <==== ATENCIÓN
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [70920704 2024-01-24] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\Run: [com.squirrel.Teams.Teams] => C:\Users\User\AppData\Local\Microsoft\Teams\Update.exe [2591296 2024-01-04] (Microsoft 3rd Party Application Component -> Microsoft Corporation)
HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\...\MountPoints2: {1fdd738f-a082-11ec-b8da-b8aeed316b41} - "H:\Setup.exe"
HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\85.0.37.0\GoogleDriveFS.exe [58857760 2024-01-24] (Google LLC -> Google, Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\120.0.6099.225\Installer\chrmstp.exe [2024-01-19] (Google LLC -> Google LLC)
GroupPolicy: Restricción - Windows Defender <==== ATENCIÓN
Policies: C:\ProgramData\NTUSER.pol: Restricción <==== ATENCIÓN
==================== Tareas programadas (Lista blanca) =================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {787B5CB3-4B3C-4F2F-BAB6-2094B3AF67C4} - System32\Tasks\AMDLinkUpdate => C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe [1707056 2022-04-28] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {804349CE-FC32-4A1D-BFFC-A520FD0CD561} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [561984 2011-06-01] (Apple Inc. -> Apple Inc.)
Task: {566556CC-0978-49AC-A0F7-B2D70CFA451D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [714256 2024-01-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {F33742D0-3874-4483-9ABA-61B3CAC6C4C4} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [4703648 2024-01-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "ae185ab3-422e-441b-ba51-ce46bffacfa1" --version "6.20.10897" --silent
Task: {4F2253BE-D04F-42E0-9BA2-10768915E1E9} - System32\Tasks\CCleanerSkipUAC - User => C:\Program Files\CCleaner\CCleaner.exe [38319520 2024-01-11] (PIRIFORM SOFTWARE LIMITED -> Piriform Software Ltd)
Task: {9FC3EDD8-5E96-42A5-A6DB-E1576FAB332E} - System32\Tasks\CLToast => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2322472 2022-12-01] (CyberLink Corp. -> )
Task: {8CEDF641-137A-4AB6-8202-3134DF0E030A} - System32\Tasks\CLToastRun => C:\Program Files (x86)\CyberLink\Shared files\CLToast.exe [2322472 2022-12-01] (CyberLink Corp. -> )
Task: {542E3734-D79A-4C40-81B9-46C1A7DE3FC3} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\User\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [21737944 2024-01-24] (ESET, spol. s r.o. -> ESET)
Task: {60352E6D-A0AC-4FCD-9F90-6F8CE36EA2D1} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\User\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe [21737944 2024-01-24] (ESET, spol. s r.o. -> ESET)
Task: {01D7DE65-3C1F-4458-8D35-147AC0E0E931} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2021-01-27] (Google LLC -> Google LLC)
Task: {F17C6C02-A0C3-4A49-B6B2-0D0B8B7DC622} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [155592 2021-01-27] (Google LLC -> Google LLC)
Task: {9BCCACEB-6665-41B1-928D-F5174380B336} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28425192 2024-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {AB4EE7B5-99B6-4CC1-B483-E9A1D058697F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28425192 2024-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {3662C54B-1C50-4BBB-BE45-8D543ECD9972} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [305744 2024-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {792CD04E-9825-44CE-B788-0124EF21A7BE} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [305744 2024-01-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BAC6A874-6D47-44EA-BE6B-F98510E07AD3} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [170048 2024-01-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {CB9496C5-DA47-41F3-8564-639BADA10D9D} - System32\Tasks\Microsoft\OneCore\ipsecunch => C:\WINDOWS\system32\RUNDLL32.EXE [71680 2023-11-15] (Microsoft Windows -> Microsoft Corporation) -> "C:\Program Files (x86)\Common Files\WorkImage\CojmandGreseptation\Sqvtxm3WebzAbrestr.dll" rtwrptyDCredefck
Task: {37F21C2A-E53C-4999-ABBE-C8FB2B7F4CE0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {B7D5D7CF-33E1-4197-8A27-5331EEE54205} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4CF53563-970D-42DA-95AA-091BEDEFBB54} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpCmdRun.exe [1608808 2023-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {16670A37-C2FB-43D1-AC96-F42EFDF5B143} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [662432 2023-05-09] (Mozilla Corporation -> Mozilla Corporation) -> --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {F5D51F10-DC72-45A5-9CF2-D794B311E9C6} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [713120 2023-05-09] (Mozilla Corporation -> Mozilla Foundation)
Task: {56D9A966-EB89-49D0-A2FC-D73520018928} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4130736 2023-12-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {79E4E449-7126-45F8-B11E-2D6EE20D3C87} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1889977516-2818661329-1748021256-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4130736 2023-12-13] (Microsoft Corporation -> Microsoft Corporation)
Task: {86FBE693-BE63-4A02-ACB6-180F4D173F92} - System32\Tasks\Opera scheduled Autoupdate 1638252513 => C:\Users\User\AppData\Local\Programs\Opera\launcher.exe [2350496 2024-01-18] (Opera Norway AS -> Opera Software)
Task: {2B5B0355-3D87-469D-9240-82FEEF711804} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [55856 2022-04-28] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
Task: {E0004E4A-947D-40C4-A9CE-44DF295DC326} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\RSServCmd.exe [261680 2022-04-28] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c06a78d7-9339-4710-abd8-9447d3e1ad4f}: [DhcpNameServer] 192.168.0.1
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default [2024-01-24]
Edge Extension: (ColorZilla) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2023-09-13]
Edge Extension: (Meta Pixel Helper) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2024-01-09]
Edge Extension: (Documentos de Google sin conexión) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-20]
Edge Extension: (Corrector ortográfico y gramatical y parafraseador de textos — LanguageTool) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\hfjadhjooeceemgojogkhlppanjkbobc [2024-01-09]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
Edge Extension: ([DEPRECATED] Tag Assistant Legacy) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2023-10-16]
Edge Profile: C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Profile 1 [2024-01-24]
Edge Extension: (Documentos de Google sin conexión) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-24]
Edge Extension: (The Elder Scrolls V: Skyrim 10th Anniversary) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\icahgcdchandbkbhminlkmeljdoflpoi [2023-01-30]
Edge Extension: (Edge relevant text changes) - C:\Users\User\AppData\Local\Microsoft\Edge\User Data\Profile 1\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-01-24]
FireFox:
========
FF DefaultProfile: q0x8zfph.default
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\q0x8zfph.default [2024-01-19]
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\7hnuoy5i.default-release [2024-01-24]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2023-12-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll [2021-01-27] (Adobe Systems Incorporated -> )
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2023-12-05] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Profile 1
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2024-01-21]
CHR Notifications: Default -> hxxps://n19.biz; hxxps://onevenadvnow.com; hxxps://regadsacademy.com; hxxps://richhackers.club.hotmart.com; hxxps://se05.biz; hxxps://shotvideoair.ru; hxxps://totalcoolblog.com; hxxps://totalrecaptcha.top; hxxps://typiccor.com; hxxps://www4.elbaestes.pro; hxxps://www55.richardwashington.pro
CHR Extension: (ColorZilla) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2023-11-17]
CHR Extension: (Meta Pixel Helper) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdgfkebogiimcoedlicjlajpkdmockpc [2023-11-17]
CHR Extension: (Tag Assistant Legacy (by Google)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejbdjndbnbjgmefkgdddjlbokphdefk [2023-11-17]
CHR Extension: (Menú de aplicaciones de Drive (de Google)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-11-17]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28]
CHR Extension: (Corrector ortográfico y gramatical — LanguageTool) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\oldceeleldhonbafppcapldpdifcinji [2023-03-31]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Guest Profile [2024-01-21]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1 [2024-01-21]
CHR Extension: (Color Picker for Chrome™) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\clldacgmdnnanihiibdgemajcfkmfhia [2023-05-07]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-17]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2024-01-17]
CHR Extension: (Google Meet Grid View) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kklailfgofogmmdlhgmjgenehkjoioip [2021-01-28]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-08-28]
CHR Extension: (Microsoft 365) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ndjpnladcallmjemlbaebfadecfhkepb [2024-01-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-28]
CHR Extension: (Grammar Checker & Paraphraser – LanguageTool) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\oldceeleldhonbafppcapldpdifcinji [2024-01-17]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4 [2024-01-21]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2023-11-20]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-10-08]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2023-11-20]
CHR Extension: (Google Scholar Button) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ldipcbpaocekfooobnbcddclnhejkcpn [2022-08-14]
CHR Extension: (Application Launcher For Drive (by Google)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2023-10-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2022-06-17]
CHR Extension: (Grammar Checker & Paraphraser – LanguageTool) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\oldceeleldhonbafppcapldpdifcinji [2023-11-20]
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\System Profile [2024-01-21]
CHR HKU\S-1-5-21-1889977516-2818661329-1748021256-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
Opera:
=======
OPR Profile: C:\Users\User\AppData\Roaming\Opera Software\Opera Stable [2024-01-21]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2023-02-19]
OPR Extension: (Opera Wallet) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\gojhcdgcpbpfigcaejpfhfegekdgiblk [2023-02-19]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\User\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-11-30]
==================== Servicios (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [81088 2015-09-24] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [9880840 2023-01-14] (BattlEye Innovations e.K. -> )
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13777080 2024-01-14] (Microsoft Corporation -> Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1137576 2023-10-22] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [954704 2023-12-15] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [375248 2023-10-22] (Epic Games Inc. -> Epic Games, Inc.)
S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncHelper.exe [3514384 2023-12-13] (Microsoft Corporation -> Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9410296 2024-01-24] (Malwarebytes Inc. -> Malwarebytes)
S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\23.246.1127.0002\OneDriveUpdaterService.exe [3851280 2023-12-13] (Microsoft Corporation -> Microsoft Corporation)
S3 Rockstar Service; D:\Games\Launcher\RockstarService.exe [1631360 2021-01-28] (Rockstar Games, Inc. -> Rockstar Games)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [534472 2023-12-13] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [16360768 2022-08-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S3 ucldr_battlegrounds_gl; C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe [5963304 2022-12-23] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\NisSrv.exe [3174840 2023-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MsMpEng.exe [133592 2023-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [176624 2018-05-14] (Microsoft Corporation -> Microsoft Corporation)
S3 zksvc; C:\Program Files\Common Files\PUBG\zksvc.exe [10533960 2022-12-23] (PUBG CORPORATION -> KRAFTON, Inc)
===================== Controladores (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R3 AMDSAFD; C:\WINDOWS\System32\DriverStore\FileRepository\amdsafd.inf_amd64_8e2568524f674315\amdsafd.sys [100768 2021-03-29] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R3 AMDXE; C:\WINDOWS\System32\drivers\amdxe.sys [63096 2022-02-22] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 AmUStor; C:\WINDOWS\system32\drivers\AmUStorU.sys [136760 2019-05-07] (Alcorlink Corp. -> )
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [279040 2019-12-07] (Microsoft Corporation) [Archivo no firmado]
S3 BthHFEnum; C:\WINDOWS\System32\drivers\bthhfenum.sys [144896 2019-12-07] (Microsoft Corporation) [Archivo no firmado]
R3 dc3d; C:\WINDOWS\System32\drivers\dc3d.sys [47616 2011-05-18] (Hardware Group Test Cert -> Microsoft Corporation)
R1 googledrivefs31357; C:\WINDOWS\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys [384712 2023-11-01] (Microsoft Windows Hardware Compatibility Publisher -> Google, Inc.)
S3 HoYoProtect; C:\WINDOWS\system32\HoYoKProtect.sys [3669520 2022-12-30] (Microsoft Windows Hardware Compatibility Publisher -> miHoYo)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [223296 2024-01-24] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2024-01-24] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239576 2024-01-24] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 NewTek_AudioPortClass; C:\WINDOWS\System32\drivers\NewTek_AudioPortClass.sys [33336 2020-10-18] (Microsoft Windows Hardware Compatibility Publisher -> NewTek)
R3 NewTek_WDM_KS; C:\WINDOWS\System32\drivers\NewTek_WDM_KS.sys [27832 2020-10-18] (Microsoft Windows Hardware Compatibility Publisher -> NewTek)
S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2014-08-08] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [24064 2021-04-10] (Microsoft Corporation) [Archivo no firmado]
R3 VBAudioVACMME; C:\WINDOWS\System32\drivers\vbaudio_cable64_win7.sys [41192 2014-09-02] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2021-03-25] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [55856 2023-12-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [594304 2023-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [105856 2023-12-07] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [49336 2018-03-11] (Microsoft Corporation -> Microsoft Corporation)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [1432232 2022-12-23] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X]
==================== NetSvcs (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
==================== Un mes (creado) (Lista blanca) =========
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2024-01-24 22:01 - 2024-01-24 22:04 - 000080150 _____ C:\Users\User\OneDrive\Escritorio\Addition.txt
2024-01-24 21:59 - 2024-01-24 22:20 - 000031093 _____ C:\Users\User\OneDrive\Escritorio\FRST.txt
2024-01-24 21:57 - 2024-01-24 22:20 - 000000000 ____D C:\FRST
2024-01-24 21:56 - 2024-01-24 21:56 - 002389504 _____ (Farbar) C:\Users\User\OneDrive\Escritorio\FRST64.exe
2024-01-24 21:19 - 2024-01-24 21:19 - 000000000 ___HD C:\OneDriveTemp
2024-01-24 21:13 - 2024-01-24 21:13 - 000003854 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onLogOn
2024-01-24 21:13 - 2024-01-24 21:13 - 000003412 _____ C:\WINDOWS\system32\Tasks\EOSv3 Scheduler onTime
2024-01-24 13:41 - 2024-01-24 21:54 - 000001381 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2024-01-24 13:41 - 2024-01-24 21:54 - 000001281 _____ C:\Users\User\OneDrive\Escritorio\ESET Online Scanner.lnk
2024-01-24 13:41 - 2024-01-24 13:41 - 000000000 ____D C:\Users\User\AppData\Local\ESET
2024-01-24 11:44 - 2024-01-24 11:44 - 000000000 ____D C:\Users\User\AppData\Local\mbam
2024-01-24 11:43 - 2024-01-24 21:50 - 000000000 ____D C:\Users\User\AppData\Local\Malwarebytes
2024-01-24 11:43 - 2024-01-24 11:43 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2024-01-24 11:42 - 2024-01-24 11:42 - 000000000 ____D C:\ProgramData\Malwarebytes
2024-01-24 11:42 - 2024-01-24 11:42 - 000000000 ____D C:\Program Files\Malwarebytes
2024-01-22 12:21 - 2024-01-22 12:21 - 000028273 _____ C:\Users\User\Downloads\Pago Fb Ads 22 enero.jpeg
2024-01-20 17:17 - 2024-01-21 12:01 - 000000000 ___HD C:\ProgramData\Ptnfd
2024-01-20 17:17 - 2024-01-20 17:17 - 000001205 _____ C:\Users\User\OneDrive\Escritorio\Google Chrome.lnk
2024-01-20 17:17 - 2024-01-20 17:17 - 000001066 _____ C:\Users\User\OneDrive\Escritorio\Epic Games Launcher.lnk
2024-01-20 17:17 - 2024-01-20 17:17 - 000000000 ____D C:\Users\User\AppData\Local\DesktopCleanup
2024-01-20 17:17 - 2024-01-20 17:17 - 000000000 ____D C:\Users\User\AppData\Local\Default
2024-01-20 17:16 - 2024-01-21 12:08 - 000000000 ____D C:\Users\User\AppData\Roaming\UbPublic
2024-01-20 17:12 - 2024-01-20 17:12 - 000002200 __RSH C:\ProgramData\ntuser.pol
2024-01-19 13:02 - 2024-01-24 12:03 - 000000000 ____D C:\Users\User\AppData\Local\LegalHelper2
2024-01-19 13:02 - 2024-01-24 12:02 - 000000000 ____D C:\ProgramData\IEUpdater2
2024-01-19 13:01 - 2024-01-24 15:08 - 000000000 ____D C:\Users\User\OneDrive\Documents\GuardFox
2024-01-14 20:37 - 2024-01-14 20:37 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2024-01-10 08:54 - 2024-01-10 09:07 - 000000000 ___HD C:\$WinREAgent
2023-12-30 17:21 - 2023-12-30 17:21 - 000000323 _____ C:\Users\User\OneDrive\Escritorio\Saints Row.url
2023-12-28 18:47 - 2023-12-28 18:47 - 000093228 _____ C:\Users\User\Downloads\recibo pico y placa.pdf
2023-12-28 00:58 - 2023-12-28 00:58 - 000000000 ____D C:\WINDOWS\InboxApps
==================== Un mes (modificado) ==================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2024-01-24 21:57 - 2023-01-19 10:46 - 000000000 ____D C:\Users\User\AppData\Local\Spotify
2024-01-24 21:49 - 2022-08-24 19:40 - 000000000 ____D C:\Program Files\CCleaner
2024-01-24 21:47 - 2021-12-19 17:32 - 000000000 ____D C:\WINDOWS\SystemTemp
2024-01-24 21:47 - 2021-01-27 15:31 - 000000000 ____D C:\Program Files (x86)\Google
2024-01-24 21:45 - 2023-02-06 10:57 - 000004218 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{CF2E06EB-E955-46CA-8582-3DEF51669B8B}
2024-01-24 21:22 - 2023-01-19 13:56 - 000000000 ____D C:\Users\User\AppData\Roaming\Spotify
2024-01-24 21:20 - 2023-10-17 12:03 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Teams
2024-01-24 21:19 - 2021-01-27 14:28 - 000000000 ___RD C:\Users\User\OneDrive
2024-01-24 21:16 - 2022-10-01 19:06 - 000000666 _____ C:\WINDOWS\Tasks\CCleanerCrashReporting.job
2024-01-24 21:16 - 2022-08-24 18:21 - 000000000 ____D C:\Program Files\TeamViewer
2024-01-24 21:16 - 2021-04-11 03:04 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2024-01-24 21:16 - 2019-12-07 04:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2024-01-24 21:15 - 2021-04-11 02:39 - 000008192 ___SH C:\DumpStack.log.tmp
2024-01-24 21:15 - 2021-01-27 15:34 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2024-01-24 21:15 - 2019-12-07 04:03 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2024-01-24 21:11 - 2021-04-11 02:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2024-01-24 18:29 - 2021-10-03 23:04 - 000000000 ____D C:\Users\User\AppData\LocalLow\Mozilla
2024-01-24 12:10 - 2023-03-06 21:39 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2024-01-24 12:09 - 2022-10-01 19:06 - 000003382 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
2024-01-24 12:09 - 2022-08-24 19:40 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2024-01-24 11:43 - 2019-12-07 04:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2024-01-24 10:07 - 2019-12-07 04:14 - 000000000 ___HD C:\Program Files\WindowsApps
2024-01-24 10:07 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2024-01-24 09:48 - 2023-01-15 15:38 - 000000000 ____D C:\Users\User\AppData\Local\AMD_Common
2024-01-24 09:45 - 2021-05-24 11:31 - 000002173 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive.lnk
2024-01-22 11:50 - 2021-11-30 01:08 - 000004206 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1638252513
2024-01-22 11:50 - 2021-11-30 01:08 - 000001406 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
2024-01-22 11:45 - 2021-01-27 14:25 - 000000000 ____D C:\Users\User\AppData\Local\Packages
2024-01-21 21:00 - 2022-01-09 14:13 - 000000000 ____D C:\ProgramData\Riot Games
2024-01-21 12:33 - 2022-02-10 14:41 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2024-01-21 12:33 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2024-01-21 12:06 - 2023-01-15 14:47 - 000000000 ____D C:\Users\User\AppData\Local\D3DSCache
2024-01-21 12:02 - 2021-01-27 14:25 - 000000000 __RHD C:\Users\Public\AccountPictures
2024-01-20 22:42 - 2021-01-27 14:25 - 000000000 ___SD C:\Users\User\AppData\Roaming\Microsoft\Protect
2024-01-19 13:02 - 2023-04-15 17:53 - 000000000 ____D C:\Users\User\AppData\Local\Steam
2024-01-19 13:02 - 2021-06-01 17:49 - 000000000 ____D C:\Users\User\AppData\Local\Battle.net
2024-01-19 13:01 - 2023-01-06 17:15 - 000000000 ____D C:\Users\User\AppData\Roaming\discord
2024-01-19 13:01 - 2021-11-30 01:08 - 000000000 ____D C:\Users\User\AppData\Roaming\Opera Software
2024-01-19 13:01 - 2018-09-15 02:33 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2024-01-19 12:55 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2024-01-19 12:54 - 2021-10-06 09:47 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2024-01-19 12:49 - 2021-01-27 15:32 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2024-01-19 12:48 - 2021-02-09 09:30 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2024-01-19 12:45 - 2019-12-07 04:13 - 000000000 ____D C:\WINDOWS\INF
2024-01-19 12:42 - 2021-04-11 03:04 - 000003852 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2024-01-19 12:42 - 2021-04-11 03:04 - 000003728 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2024-01-17 10:59 - 2022-01-09 14:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2024-01-16 23:22 - 2021-01-28 17:58 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Word
2024-01-16 23:22 - 2021-01-28 17:58 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Office
2024-01-16 20:14 - 2021-04-11 02:55 - 001773686 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2024-01-16 20:14 - 2019-12-07 09:55 - 000788582 _____ C:\WINDOWS\system32\perfh00A.dat
2024-01-16 20:14 - 2019-12-07 09:55 - 000155970 _____ C:\WINDOWS\system32\perfc00A.dat
2024-01-16 20:07 - 2021-04-11 02:39 - 000450336 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2024-01-16 20:04 - 2019-12-07 04:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2024-01-16 20:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2024-01-16 20:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SystemResources
2024-01-16 20:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\setup
2024-01-16 20:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2024-01-16 20:04 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2024-01-14 20:35 - 2021-01-27 15:23 - 000000000 ____D C:\Program Files\Microsoft Office
2024-01-14 20:27 - 2021-01-27 16:29 - 000918944 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2024-01-10 09:51 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2024-01-10 09:05 - 2021-01-27 18:44 - 000000000 ____H C:\$WINRE_BACKUP_PARTITION.MARKER
2024-01-10 08:36 - 2021-01-27 18:15 - 000000000 ____D C:\WINDOWS\system32\MRT
2024-01-10 00:11 - 2021-01-27 18:15 - 189718008 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2024-01-09 13:57 - 2021-01-27 14:43 - 000000000 ____D C:\ProgramData\Packages
2024-01-04 00:55 - 2023-10-17 12:03 - 000002363 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Teams classic.lnk
2023-12-31 20:31 - 2023-01-06 17:14 - 000000000 ____D C:\Users\User\AppData\Local\Discord
2023-12-31 20:25 - 2021-01-28 20:56 - 000000000 ____D C:\Program Files\Rockstar Games
2023-12-31 20:25 - 2021-01-28 20:56 - 000000000 ____D C:\Program Files (x86)\Rockstar Games
2023-12-31 20:23 - 2023-05-10 11:20 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2023-12-31 09:53 - 2021-02-12 18:18 - 000000000 ____D C:\Users\User\AppData\Local\BitTorrentHelper
2023-12-28 01:01 - 2023-03-17 15:05 - 000000000 ____D C:\Program Files\Microsoft OneDrive
2023-12-28 00:58 - 2019-12-07 09:58 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\Provisioning
2023-12-28 00:58 - 2019-12-07 04:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2023-12-28 00:58 - 2019-12-07 04:03 - 000000000 ____D C:\WINDOWS\servicing
==================== Archivos en la raíz de algunos directorios ========
2022-08-24 18:20 - 2022-08-24 18:20 - 043404592 _____ (TeamViewer Germany GmbH) C:\Users\User\TeamViewer_Setup_x64.exe
2023-01-15 14:50 - 2023-01-15 14:50 - 383999808 _____ (AMD Inc.) C:\Users\User\win10-64Bit-Radeon-Software-Adrenalin-2019-Edition-19.6.3-June27.exe
2021-03-24 17:09 - 2021-11-30 21:16 - 000000015 _____ () C:\Users\User\AppData\Roaming\obs-virtualcam.txt
2021-03-25 17:54 - 2021-03-25 22:38 - 000037925 _____ () C:\Users\User\AppData\Roaming\VoiceMeeterBananaDefault.xml
2021-03-25 22:18 - 2021-03-25 22:18 - 000006096 _____ () C:\Users\User\AppData\Roaming\VoiceMeeterDefault.xml
2023-02-04 13:50 - 2023-02-04 13:50 - 000016438 _____ () C:\Users\User\AppData\Local\partner.bmp
2022-08-24 19:32 - 2023-04-22 19:57 - 000007603 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ============================
(No existe una corrección automática para los archivos que no pasan la verificación.)
==================== Final de FRST.txt ========================