Copio primera parte de reporte FRST. (Debo hacerlo así por las restricciones del foro).
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 01-04-2025
Ejecutado por Diego Canales (administrador) sobre DESKTOP-8PNNOV5 (LENOVO 20JVA05KCL) (17-04-2025 23:11:15)
Ejecutado desde C:\Users\Diego Canales\Downloads\FRST64.exe
Perfiles cargados: Diego Canales
Plataforma: Microsoft Windows 10 Enterprise Versión 22H2 19045.5737 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: "C:\Users\Diego Canales\AppData\Local\Programs\Opera\opera.exe" -noautoupdate -- "%1"
Modo de Inicio: Normal
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
(AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGUI.exe <4>
(C:\Program Files (x86)\EaseUS\ENS\ensserver.exe ->) (CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\ENS\AliyunWrapExe.exe
(C:\Program Files\AVG\Antivirus\AVGSvc.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\aswEngSrv.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.AlwaysOnTop.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.Awake.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.ColorPickerUI.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.CropAndLock.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.FancyZones.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.MouseWithoutBorders.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.PowerAccent.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.PowerLauncher.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.PowerOCR.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\WinUI3Apps\PowerToys.Peek.UI.exe
(C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.MouseWithoutBorders.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.MouseWithoutBordersHelper.exe
(C:\Users\Diego Canales\AppData\Roaming\uTorrent Web\utweb.exe ->) (BitTorrent Inc -> BitTorrent Inc.) C:\Users\Diego Canales\AppData\Roaming\uTorrent Web\helper\helper.exe
(cmd.exe ->) (Lenovo (Beijing) Limited -> Lenovo Group Limited) C:\Users\Diego Canales\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSB.exe
(explorer.exe ->) (Autodesk, Inc. -> Autodesk, Inc.) C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessService.exe
(explorer.exe ->) (AVB Disc Soft, SIA -> Disc Soft Limited) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(explorer.exe ->) (BitTorrent Inc -> BitTorrent Limited) C:\Users\Diego Canales\AppData\Roaming\uTorrent Web\utweb.exe
(explorer.exe ->) (FxSound, LLC -> FxSound LLC) C:\Program Files\FxSound LLC\FxSound\FxSound.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <39>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.051.0317.0003\Microsoft.SharePoint.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\OneDrive.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.CommandPalette_0.1.1.0_x64__8wekyb3d8bbwe\Microsoft.CmdPal.UI.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <10>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(services.exe ->) (AnyDesk Software GmbH -> AnyDesk Software GmbH) C:\Program Files (x86)\AnyDesk\AnyDesk.exe <2>
(services.exe ->) (Autodesk, Inc. -> ) C:\Program Files\Autodesk\Autodesk CER\service\cer_service.exe
(services.exe ->) (Autodesk, Inc. -> Autodesk) C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\14.4.0.11537\AdskLicensingService\AdskLicensingService.exe
(services.exe ->) (AVB Disc Soft, SIA -> Disc Soft Limited) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\wsc_proxy.exe
(services.exe ->) (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\afwServ.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(services.exe ->) (AVG Technologies USA, LLC -> Gen Digital Inc.) C:\Program Files\AVG\Antivirus\avgToolsSvc.exe
(services.exe ->) (Broadcom Inc -> VMware, Inc.) C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
(services.exe ->) (Broadcom Inc -> VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(services.exe ->) (CHENGDU YIWO Tech Development Co., Ltd. -> ) C:\Program Files (x86)\EaseUS\ENS\ensserver.exe
(services.exe ->) (Firebird Project) [Archivo no firmado] C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
(services.exe ->) (Firebird Project) [Archivo no firmado] C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
(services.exe ->) (Glarysoft Ltd -> Glarysoft Ltd) C:\Program Files (x86)\Common Files\Glarysoft\StartupManager\1.0\GUBootService.exe
(services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_4a8c83f7e646bfcf\IntelCpHeciSvc.exe
(services.exe ->) (Lespeed Technology Co., Ltd -> WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe
(services.exe ->) (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(svchost.exe ->) () [Archivo no firmado] C:\Program Files (x86)\EaseUS\EaseUS CleanGenius\bin\CleanGenius.exe
(svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2514.4.0_x64__cv1g1gvanyjgm\WhatsApp.exe
(svchost.exe ->) (Lenovo -> Lenovo) C:\Windows\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe
(svchost.exe ->) (Lespeed Technology Co., Ltd -> WiseCleaner.com) C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
(svchost.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.25.340.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft OneDrive\25.051.0317.0003\FileCoAuth.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\prevhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Diego Canales\AppData\Local\Kingsoft\WPS Office\12.2.0.20795\office6\wpscenter.exe
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM\...\Run: [PrintDisp] => C:\WINDOWS\system32\PrintDisp.exe [610080 2024-10-28] (ActMask Group Co., Ltd -> ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [VCVS07EN] => C:\Program Files\ACD Systems\LUXEA Pro\7.0\acdIDInTouch2.exe [3501616 2023-08-07] (ACD Systems International Inc. -> ACD Systems International Inc.)
HKLM\...\Run: [MMReminderService] => C:\Program Files\MindManager 23\MMReminderService.exe [464912 2023-10-11] (Corel Corporation -> MindManager)
HKLM\...\Run: [TechSmithSnagit] => C:\Program Files\TechSmith\Snagit 2024\SnagitCapture.exe [9368416 2025-02-04] (TechSmith Corporation -> TechSmith Corporation)
HKLM\...\Run: [CDSBupd.exe] => C:\Program Files\ConceptDraw Office\ConceptDraw STORE\CDSBupd.exe [6201816 2023-10-23] (CS ODESSA DISTI CORP -> CS Odessa Corp.)
HKLM\...\Run: [TuneupUI.exe] => C:\Program Files\AVG\TuneUp\TuneupUI.exe [6945608 2025-04-01] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Autodesk Access Service] => C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessService.exe [13673248 2025-01-08] (Autodesk, Inc. -> Autodesk, Inc.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [492872 2025-04-09] (AVG Technologies USA, LLC -> Gen Digital Inc.)
HKLM-x32\...\Run: [SO5 Integrator Pass Two] => C:\WINDOWS\SOINTGR.EXE [20480 2000-05-08] () [Archivo no firmado]
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-12-15] (CyberLink -> CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-02] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [75048 2011-05-25] (CyberLink -> cyberlink)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [LGODDFU] => C:\Program Files (x86)\lg_fwupdate\fwupdate.exe [548864 2008-09-19] (BL) [Archivo no firmado]
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2075480 2013-06-24] (Flexera Software LLC -> Flexera Software LLC.)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT Pro 9\Common\RoxWatchTray15.exe [303672 2022-09-28] (Corel Corporation -> Corel Corporation)
HKLM-x32\...\Run: [Adobe CCXProcess] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe [133128 2025-02-05] (Adobe Inc. -> Adobe Inc.)
HKLM-x32\...\Run: [QuickFinder Scheduler] => c:\Program Files (x86)\Corel\WordPerfect Office 2021\Programs\QFSCHD210.EXE [247032 2022-06-23] (Corel Corporation -> Corel Corporation)
HKLM-x32\...\Run: [Ultralingua 7 Hotkey] => C:\Program Files (x86)\Ultralingua\Ultralingua 7\ULHotkey.exe [1483264 2009-11-04] () [Archivo no firmado]
HKLM-x32\...\Run: [Lingvo Launcher] => C:\Program Files (x86)\ABBYY Lingvo x6\LvAgent.exe [772088 2019-12-19] (ABBYY Production LLC -> ABBYY)
HKLM-x32\...\Run: [OmniPage Preload] => C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe [3021528 2014-11-25] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
HKLM-x32\...\Run: [PowerPDF Registry Controller] => C:\Program Files (x86)\Nuance\Nuance Power PDF\RegistryController.exe [274216 2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
HKLM-x32\...\Run: [PowerPDFInboxMonitor] => C:\Program Files (x86)\Nuance\Nuance Power PDF\InboxMonitor.exe [255544 2017-05-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort14\pptd40nt.exe [35624 2016-08-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort14\IndexSearch.exe [17576 2016-08-16] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
HKLM-x32\...\Run: [YouCam Service10] => C:\Program Files (x86)\CyberLink\YouCam365\YouCamService10.exe [418312 2024-11-06] (CyberLink Corp. -> CyberLink Corp.)
HKLM-x32\...\Run: [YouCam10] => C:\Program Files (x86)\CyberLink\YouCam365\YouCam10.exe [587272 2024-11-06] (CyberLink Corp. -> CyberLink Corp.)
HKLM-x32\...\Run: [FileFort] => C:\Program Files (x86)\NCH Software\FileFort\filefort.exe [1102880 2018-10-18] (NCH Software Pty Ltd -> NCH Software)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [2138272 2016-10-08] (Shenzhen Jia Xing Investment Co., Ltd. -> AimerSoft)
HKLM-x32\...\Run: [ReminderApp_EEAC3053-7055-4143-B8A0-306758055099] => C:\Program Files (x86)\Nova Development\Office Printing Essentials 3\ReminderApp.exe [139776 2015-12-18] () [Archivo no firmado]
HKLM-x32\...\Run: [DoroServer] => C:\Program Files (x86)\DoroPDFWriter\DoroServer.exe [217088 2025-01-06] (the sz development) [Archivo no firmado]
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [114040 2024-11-28] (Broadcom Inc -> VMware, Inc.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restricción <==== ATENCIÓN
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restricción <==== ATENCIÓN
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [5012288 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [483888 2025-01-31] (AVB Disc Soft, SIA -> Disc Soft Limited)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft -> Alcohol Soft Development Team)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\Update Notifier\QMxNetworkSync.exe [1027088 2024-04-23] (MAGIX Software GmbH -> MAGIX)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [movavi_suite_22.4.1_screenrecorder] => C:\Users\Diego Canales\AppData\Roaming\Movavi Video Suite 22\ScreenRecorder.exe [10885248 2025-02-07] (Movavi Software Limited -> Movavi)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [movavi_suite_agent] => C:\Users\Diego Canales\AppData\Roaming\Movavi Video Suite 22\AgentInformer.exe [1118848 2025-02-07] (Movavi Software Limited -> Movavi)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [EdrawMaxTray] => C:\Program Files (x86)\EdrawSoft\EdrawMax\EdrawMaxTray.exe [218168 2025-01-10] (SHENZHEN EDRAW SOFTWARE CO.,LTD -> )
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [VideoDownloadCapture] => C:\Program Files (x86)\Apowersoft\Video Download Capture 6\Video Download Capture 6.exe [9051200 2024-09-28] (Apowersoft Ltd -> Apowersoft) [Archivo no firmado]
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [ApowersoftScreenCapture] => C:\Program Files (x86)\Apowersoft\Apowersoft Screen Capture Pro\Apowersoft Screen Capture Pro.exe [11944464 2024-10-18] (Apowersoft Ltd -> Apowersoft)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [ApowerManager] => C:\Program Files (x86)\Apowersoft\ApowerManager\ApowerManager.exe [56449584 2020-09-29] (Apowersoft Ltd -> Apowersoft Ltd.)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 2022\AudialsNotifier.exe [2204352 2022-10-05] (Audials AG -> )
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [DVDFab VDrive] => C:\Program Files\DVDFab\ExplorerFab\vdrive.exe [15596360 2023-06-05] (DVDFab Software Inc. -> DVDFab Software Inc.)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [iMusicService] => C:\Program Files (x86)\iMusic\iMusic\iMusicService.exe [16384 2019-08-22] (Aimersoft) [Archivo no firmado]
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [Automatic PDF Processor] => C:\Program Files\Automatic PDF Processor\AutomaticPDFProcessor.exe [4819728 2025-02-11] (René Gillmeister -> Gillmeister Software)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [Windows File Locker Helper] => C:\Program Files (x86)\GiliSoft\Privacy Protector\WinFLockerHelp.exe [33040 2019-02-15] (SiChuan HengYiDa XinXiJiShu YouXianGongSi -> GiliSoft International LLC)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [iMindQ Notifier] => C:\Program Files (x86)\iMindQ\iMindQReminder.exe [217600 2021-11-17] (Synami DOOEL) [Archivo no firmado]
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [ALLUpdate] => C:\Program Files\ALLPlayer\ALLUpdate.exe [4230016 2023-11-17] (ALLPlayer Group sp. z o.o. -> ALLPlayer.org)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [Messenger Plus] => C:\Program Files\Messenger Plus\MessengerPlus.exe [120400 2025-02-04] (Sara AI sp. z o.o. -> )
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [ScreenHunter 7 Pro] => C:\Program Files (x86)\ScreenHunter 7 Pro\ScreenHunter7Pro64.exe [20535296 2024-04-10] (Wisdom Software Inc.) [Archivo no firmado]
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [HyperCam 6 Business Edition Recovery] => C:\Program Files (x86)\HyperCam 6 Business Edition\SMM_HyperCam_Recovery.exe [2030800 2022-09-13] (Solveig Multimedia Germany GmbH -> Solveig Multimedia)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [utweb] => C:\Users\Diego Canales\AppData\Roaming\uTorrent Web\utweb.exe [6426632 2024-11-25] (BitTorrent Inc -> BitTorrent Limited)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [GoogleChromeAutoLaunch_1517AF06D1A8047CAB91D06F0216BB3E] => "C:\Program Files\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5 [3533920 2025-04-08] (Google LLC -> Google LLC)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [MicrosoftEdgeAutoLaunch_470E91CE4317DE782D92CB7656680E45] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4418112 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [Opera Stable] => C:\Users\Diego Canales\AppData\Local\Programs\Opera\opera.exe [1606552 2025-04-02] (Opera Norway AS -> Opera Software)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [45882672 2025-04-09] (Gen Digital Inc. -> Gen Digital Inc.)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Run: [Microsoft.Lists] => C:\Program Files\Microsoft OneDrive\25.051.0317.0003\Microsoft.SharePoint.exe [1030440 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Policies\system: [shell] explorer.exe <==== ATENCIÓN
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Policies\Explorer: []
HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\...\Policies\Explorer: [DisallowCPL] 1
HKU\S-1-5-18\...\Run: [OpAgent] => "OpAgent.exe" /agent (Ningún archivo)
HKLM\...\Windows x64\Print Processors\ActMaskR: C:\Windows\System32\spool\prtprocs\x64\ActPrint.dll [51848 2018-09-15] (ActMask Group Co., Ltd -> ActMask Co.,Ltd)
HKLM\...\Windows x64\Print Processors\ActMaskR1: C:\Windows\System32\spool\prtprocs\x64\ActPrint1.dll [55584 2024-10-27] (ActMask Group Co., Ltd -> ActMask Co.,Ltd hxxp://ALL2PDF.COM)
HKLM\...\Windows x64\Print Processors\Perfect PDF 11 Premium Print Processor: C:\Windows\System32\spool\prtprocs\x64\sx_p11_p.dll [263088 2025-02-17] (soft Xpansion GmbH & Co.KG -> soft Xpansion)
HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [203936 2024-10-01] (Adobe Inc. -> Adobe Systems Inc)
HKLM\...\Print\Monitors\Doro PDF Writer Port: C:\Program Files (x86)\DoroPDFWriter\Doro.dll [677888 2020-11-28] () [Archivo no firmado]
HKLM\...\Print\Monitors\FPP9:: C:\WINDOWS\system32\fppmon9-x64.dll [150264 2024-11-16] (FinePrint Software, LLC -> FinePrint Software)
HKLM\...\Print\Monitors\MPE3 Port: C:\WINDOWS\system32\mpelocalmon.dll [27136 2023-11-16] (Copyright (c) Code Industry Ltd) [Archivo no firmado]
HKLM\...\Print\Monitors\PDF Architect 9 Monitor: C:\WINDOWS\system32\spool\DRIVERS\x64\architect_pdfpmon_v.6.23.0.2.dll [974120 2025-02-07] (PDF Tools AG -> PDF Tools AG (hxxp://www.pdf-tools.com))
HKLM\...\Print\Monitors\PDF Suite 2021 Monitor: C:\WINDOWS\system32\spool\DRIVERS\x64\suite_pdfpmon_v.4.12.26.3.dll [932984 2025-03-09] (PDF Tools AG -> PDF Tools AG (hxxp://www.pdf-tools.com))
HKLM\...\Print\Monitors\PDF-XChange Lite Port Monitor: C:\WINDOWS\system32\pxcpmL.dll [912208 2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
HKLM\...\Print\Monitors\PDF-XChange4: C:\WINDOWS\system32\pxc40pm.dll [57408 2014-02-17] (Tracker Software Products (Canada) Ltd -> Tracker Software Products Ltd.)
HKLM\...\Print\Monitors\PDFTron PDFNet Port Monitor: C:\WINDOWS\system32\pdfnetmon.dll [33792 2025-02-14] (Windows (R) Win 7 DDK provider) [Archivo no firmado]
HKLM\...\Print\Monitors\Soda PDF Desktop 14 Monitor: C:\WINDOWS\system32\spool\DRIVERS\x64\soda_pdfpmon_v.6.23.0.2.dll [974120 2025-02-07] (PDF Tools AG -> PDF Tools AG (hxxp://www.pdf-tools.com))
HKLM\...\Print\Monitors\Solid PDF Port Monitor: C:\WINDOWS\system32\solidlocalmon.dll [30608 2020-04-28] (Solid Documents Ltd -> Solid Documents Limited)
HKLM\...\Print\Monitors\Wondershare PDF Converter Monitor: C:\WINDOWS\system32\WSPDFConverterMonitor.dll [271360 2020-06-28] (Wondershare Software) [Archivo no firmado]
HKLM\...\Print\Monitors\Wondershare PDFelement Monitor: C:\WINDOWS\system32\PEPrinterMonitor.dll [408304 2025-01-14] (Wondershare Technology Group Co.,Ltd -> Wondershare Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{28B89EEF-8107-0000-8103-CF3F3A09B77D}] -> msiexec /fus {28B89EEF-8107-0000-8103-CF3F3A09B77D}
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\135.0.7049.86\Installer\chrmstp.exe [2025-04-15] (Google LLC -> Google LLC)
Startup: C:\Users\Diego Canales\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Enviar a OneNote.lnk [2025-03-29]
ShortcutTarget: Enviar a OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation -> Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2025-03-26]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (AnyDesk Software GmbH -> AnyDesk Software GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Clock.lnk [2025-02-05]
ShortcutTarget: Desktop Clock.lnk -> C:\Program Files (x86)\SSuiteExcaliburOffice\SideClock.exe (Van Loo Software (TM}) [Archivo no firmado]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Efofex MultiDocs.lnk [2025-02-06]
ShortcutTarget: Efofex MultiDocs.lnk -> C:\Program Files (x86)\Efofex\bin\FXMultiDocs.exe (Efofex Pty Ltd -> Efofex Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FxSound.lnk [2025-03-22]
ShortcutTarget: FxSound.lnk -> C:\Program Files\FxSound LLC\FxSound\FxSound.exe (FxSound, LLC -> FxSound LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PC Mac Dock.lnk [2025-02-05]
ShortcutTarget: PC Mac Dock.lnk -> C:\Program Files (x86)\SSuiteExcaliburOffice\Desktop.exe (Van Loo Software(TM)) [Archivo no firmado]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\System Monitor.lnk [2025-02-05]
ShortcutTarget: System Monitor.lnk -> C:\Program Files (x86)\SSuiteExcaliburOffice\SysMon.exe (Van Loo Software (TM)) [Archivo no firmado]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\The Journal 8.lnk [2025-02-10]
ShortcutTarget: The Journal 8.lnk -> C:\Program Files (x86)\DavidRM Software\The Journal 8\Journal8.exe (DavidRM Software) [Archivo no firmado]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2025-02-06]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (COREL CORPORATION -> WinZip Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEScreenshot.lnk [2025-02-07]
ShortcutTarget: Wondershare PEScreenshot.lnk -> C:\Program Files\Wondershare\PDFelement11\PENotify.exe (Wondershare) [Archivo no firmado]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wondershare PEToolbox.lnk [2025-02-07]
ShortcutTarget: Wondershare PEToolbox.lnk -> C:\Program Files\Wondershare\PDFelement11\PENotify.exe (Wondershare) [Archivo no firmado]
BootExecute: autocheck autochk *
GroupPolicy\User: Restricción ? <==== ATENCIÓN
==================== Tareas programadas (Lista blanca) =================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {2E818D1C-84DE-4310-BB35-0CC8DFE5D06E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1580992 2025-03-21] (Adobe Inc. -> Adobe Inc.)
Task: {C89C5A1E-2393-4EFA-A5CF-A8493E635AC4} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [617096 2022-02-25] (Apple Inc. -> Apple Inc.)
Task: {882AC98C-0AFB-45F1-9930-67606625F9AC} - System32\Tasks\Avanquest pdfforge GmbH\PDF Architect 9\App Notification => C:\Program Files\PDF Architect 9\architect-launcher.exe [2350528 2024-11-29] (pdfforge GmbH -> Avanquest pdfforge GmbH)
Task: {D3C41613-2FD7-44E5-B6F5-6AA935DA94F4} - System32\Tasks\Avanquest pdfforge GmbH\PDF Architect 9\App Notification Logon => C:\Program Files\PDF Architect 9\architect-launcher.exe [2350528 2024-11-29] (pdfforge GmbH -> Avanquest pdfforge GmbH)
Task: {6F1173A4-9D57-40B7-8675-2D61F5C1655E} - System32\Tasks\Avanquest pdfforge GmbH\PDF Architect 9\Update => C:\Program Files\PDF Architect 9\architect.exe [3640768 2024-11-29] (pdfforge GmbH -> Avanquest pdfforge GmbH)
Task: {5D21B1C1-0981-402A-A296-4CE1BDCFBADD} - System32\Tasks\Avanquest Software\Soda PDF Desktop 14\Update => C:\Program Files\Soda PDF Desktop 14\soda.exe [3681752 2024-12-10] (Avanquest Software (7270356 Canada Inc) -> Avanquest Software)
Task: {2D46F1C7-4704-4CBD-88F2-057B265DCB90} - System32\Tasks\AVG\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [5330760 2025-04-09] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {A3D506EE-8092-4C15-A236-FEDA119E6FEF} - System32\Tasks\AVG\AVG Antivirus Patcher => C:\Program Files\Common Files\AVG\Icarus\avg-av\icarus.exe [8618824 2025-03-27] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {F0F5824F-F465-472E-9BAD-86C07BEABE61} - System32\Tasks\AVG\AVG TuneUp BugReport => C:\Program Files\AVG\TuneUp\AvBugReport.exe [6079304 2025-04-01] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) -> --send "dumps|report" --silent --product 74 --programpath "C:\Program Files\AVG\TuneUp" --configpath "C:\ProgramData\AVG\TuneUp" --path "C:\ProgramData\AVG\TuneUp\log" --path "C:\ProgramData\AVG\Icarus\Logs" --logpath "C:\ProgramData\AVG\TuneUp\log" --guid 73b8ec24-dd8f-467d-a5d9-15adfc619ac9
Task: {0C326950-D625-4BB8-991E-879522C174B6} - System32\Tasks\AVG\AVG TuneUp Update => C:\Program Files\Common Files\AVG\Icarus\avg-tu\icarus.exe [8618824 2025-03-31] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {2A12E363-9133-4304-A9AB-08B77EA093A2} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2601800 2025-03-04] (AVG Technologies USA, LLC -> Gen Digital Inc.)
Task: {9D4C64EB-B73D-4520-87EB-E71DAE5EC796} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [3480504 2025-04-09] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {4A754D61-8AFA-4D7C-B07B-E5E85649A891} - System32\Tasks\CCleanerCrashReporting => C:\Program Files\CCleaner\CCleanerBugReport.exe [6139696 2025-04-09] (Gen Digital Inc. -> Gen Digital Inc.) -> --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "ffb0f100-00b3-420f-b3b7-38b1f909257f" --version "6.35.0.11488" --silent
Task: {A7208C9A-F397-4DFC-AFB1-FB7BE88A4BA0} - System32\Tasks\CCleanerSkipUAC - Diego Canales => C:\Program Files\CCleaner\CCleaner.exe [39622960 2025-04-09] (Gen Digital Inc. -> Gen Digital Inc.)
Task: {58511F76-E0B6-441E-A138-AF8A7D4BCFFB} - System32\Tasks\CleanGenius => C:\Program Files (x86)\EaseUS\EaseUS CleanGenius\bin\CleanGenius.exe [656384 2024-07-12] () [Archivo no firmado]
Task: {FE961769-9BFB-4FF2-81EF-7ACF62E26AB0} - System32\Tasks\FxSound\Update => C:\Program Files\FxSound LLC\FxSound\updater.exe [1675152 2025-03-08] (FxSound, LLC -> FxSound LLC)
Task: {47906EC9-73D1-4A25-B830-9C5C2702D607} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem137.0.7115.0{993FE926-C9BD-4AED-9467-607640C0ECEE} => C:\Program Files (x86)\Google\GoogleUpdater\137.0.7115.0\updater.exe [7360096 2025-04-08] (Google LLC -> Google LLC)
Task: {712C8838-351F-40D1-A739-245724B103A3} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2118144 2025-03-22] () [Archivo no firmado]
Task: {7B875D03-A058-4248-94AD-EC881E9A27A0} - System32\Tasks\Lenovo\Lenovo Service Bridge\S-1-5-21-1296002004-1646576553-2792702146-1001 => C:\Users\Diego Canales\AppData\Local\Programs\Lenovo\Lenovo Service Bridge\LSBUpdater.exe [88584 2024-05-17] (Lenovo (Beijing) Limited -> Lenovo Group Limited)
Task: {3901A9C0-2BCC-43C2-8018-BF1AAEF2486C} - System32\Tasks\Lenovo\Power Manager\Background monitor => C:\WINDOWS\SysWOW64\Lenovo\PowerMgr\PowerMgr.exe [129368 2024-06-27] (Lenovo -> Lenovo)
Task: {1744799E-3264-47F2-B7F7-122B9172C847} - System32\Tasks\Lenovo\Power Manager\Uninstall task => C:\WINDOWS\SysWOW64\PowerMgrInst.exe [67424 2024-06-27] (Lenovo -> )
Task: {509FCDA4-A6C8-40C3-A392-1168A9773B26} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28609776 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {364F19A1-6589-44F8-A289-A754D92B87DE} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28609776 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {A1C1F631-0785-44E3-B79B-CEF63C8121BB} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312496 2025-04-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {BD6AC14C-596B-42B4-B95E-5EA07F09C9BA} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [312496 2025-04-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {CE277189-4BF6-4473-B579-6E451B91540A} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe [187024 2025-03-28] (Microsoft Corporation -> Microsoft Corporation)
Task: {4CB572FA-8B8A-4117-9DD1-75A0205B05FE} - System32\Tasks\Microsoft\Office\Office Serviceability Manager => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\officesvcmgr.exe [4464552 2025-03-30] (Microsoft Corporation -> Microsoft Corporation)
Task: {3F4ADF69-B023-487D-A0E5-D5A92C97136E} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\OS Edition Upgrade event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {DD61BAEC-30F3-4B7B-9726-D21FBB7C935A} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Passport for Work alert created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {3145EC10-82DD-4E7C-B8ED-BEFDFC678501} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Provisioning initiated session => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {075815F8-2FB1-40C7-BF1D-D10207E113AE} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\PushLaunch => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {84C0AABF-406B-4205-80DC-1936D3F1E56F} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\PushRenewal => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {B5E9B94F-B3A8-41E2-BB26-838B94E7004C} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Refresh schedule created by Declared Configuration to refresh any settings changed on the device => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {368D1880-E186-4BF4-A625-2ABA50E3E363} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Retry Schedule created for incomplete session => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {33223CB7-B565-4488-9523-FF76331DFBA2} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Schedule #1 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {5C92C64D-E9AD-4CE0-B7AB-CE1AADFAD174} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Schedule #2 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {129AD475-E2CD-425C-938E-C54C3C0B418B} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Schedule #3 created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {37126BD9-00B0-440A-AE98-3EC01B90FACB} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Schedule created by enrollment client for renewal of certificate warning => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {02FDF7B6-87C1-4957-92B0-24FA70DCDFA9} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Schedule to run OMADMClient by client => C:\WINDOWS\system32\omadmclient.exe [515584 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {0AE8463A-6513-4748-85FF-0DBF7917C5D1} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Schedule to run OMADMClient by server => C:\WINDOWS\system32\omadmclient.exe [515584 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {BF981CD1-D4EB-4C2C-8147-F548D55A0FA5} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Win10 S Mode event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {DDCF3F92-8FEB-495D-92D3-A57A8409C945} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Wsc Startup event listener created by enrollment client => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {0C975C89-99D0-437A-AD67-4A8626DF1359} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\SessionRetry\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Retry Schedule created for incomplete session {862BBF62-A6E3-3A2A-9CE7-63CE2EB9D65E} => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {0DA63693-1162-407B-AFDF-9FF9021862D4} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\SessionRetry\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Retry Schedule created for incomplete session {938A1A92-FE73-4997-B645-C09573D57D3B} => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {22800945-7093-47A7-A66B-DAB93A5DFCBC} - System32\Tasks\Microsoft\Windows\EnterpriseMgmt\SessionRetry\D7CD089E-4736-440C-BBC4-580FCE3B48A5\Retry Schedule created for incomplete session {DC8C94D2-6AA1-4171-8F19-1A61A34C1962} => C:\WINDOWS\system32\deviceenroller.exe [504320 2025-03-26] (Microsoft Windows -> Microsoft Corporation)
Task: {3B60FC9E-B7C1-433E-88F4-A57DE23D8914} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1296002004-1646576553-2792702146-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [695360 2025-04-07] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (la entrada de datos tiene 6 más caracteres).
Task: {6211B3EF-1E6C-4CBE-AFF6-5DABC97D256B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [34880 2025-04-07] (Mozilla Corporation -> Mozilla Foundation)
Task: {1871C125-FA0F-4510-ABE7-ABD9E07AF72A} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223808 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {C8F3B6CC-A85B-46EA-9E7A-B1B4D18E1488} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1296002004-1646576553-2792702146-1001 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223808 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF0B4EB1-3F5A-4822-BB1F-03774E05038B} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1296002004-1646576553-2792702146-1003 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223808 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {B76CA12B-AF28-4CEC-B975-E9995DCAFE17} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-1296002004-1646576553-2792702146-1005 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4223808 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {05C1B40B-C21D-4653-BA71-29259088F437} - System32\Tasks\OneDrive Startup Task-S-1-5-21-1296002004-1646576553-2792702146-1001 => C:\Program Files\Microsoft OneDrive\25.051.0317.0003\OneDriveLauncher.exe [674624 2025-04-11] (Microsoft Corporation -> Microsoft Corporation)
Task: {C03815EF-F39D-48CF-B57A-57C1F2275CED} - System32\Tasks\Opera scheduled assistant Autoupdate 1738713073 => C:\Users\Diego Canales\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5647768 2025-04-02] (Opera Norway AS -> Opera Software) -> --scheduledtask --productiscomponent --bypasslauncher --installdir="C:\Users\Diego Canales\AppData\Local\Programs\Opera\assistant" --producttype=assistant $(Arg0)
Task: {28DD27A3-500E-4962-972C-CDB887CFBC1C} - System32\Tasks\Opera scheduled Autoupdate 1738713065 => C:\Users\Diego Canales\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [5647768 2025-04-02] (Opera Norway AS -> Opera Software)
Task: {4C4A4EFF-FD0F-42A0-BAF4-8B486EE24E8A} - System32\Tasks\PowerToys\Autorun for Diego Canales => C:\Users\Diego Canales\AppData\Local\PowerToys\PowerToys.exe [1249864 2025-04-09] (Microsoft Corporation -> Microsoft Corporation)
Task: {630F532C-521A-4233-ABD7-390D2F0EA175} - System32\Tasks\Wise Care 365.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe [8397208 2024-12-11] (Lespeed Technology Co., Ltd -> WiseCleaner.com) -> C:\Program Files (x86)\Wise\Wise Care 365\-StartTray
Task: {C62CAFA0-82D9-4970-8335-5773105AC082} - System32\Tasks\Wise Turbo Checker.job => C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe [9164184 2024-08-28] (Lespeed Technology Co., Ltd -> wisecleaner.com)
Task: {BD26FDF8-482C-4B48-BF74-E68B1A3B08CF} - System32\Tasks\WpsExternal_Diego Canales_20250415183154 => C:\Users\Diego Canales\AppData\Local\Kingsoft\WPS Office\12.2.0.20795\office6\wpscloudsvr.exe [945536 2025-04-15] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd) -> /wpscloudlaunch /run_plugin /plugin_name=ktaskschdtool /plugin_entry=ktaskschdtool.dll /task=wpsexternal /launchtask /ver=1.0 /start_from=task_external
Task: {3530D221-A9FB-4EE2-8E40-7F799FC8DAD7} - System32\Tasks\WpsUpdateTask_Diego Canales => C:\Users\Diego Canales\AppData\Local\Kingsoft\WPS Office\12.2.0.20795\office6\wpsupdate.exe [1709440 2025-04-15] (Zhuhai Kingsoft Office Software Co., Ltd. -> Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {ED834C25-5BD0-49CA-BB47-23BD05405CA0} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1296002004-1646576553-2792702146-1001 => C:\Users\Diego Canales\AppData\Roaming\Zoom\bin\Zoom.exe [436024 2025-04-10] (Zoom Video Communications, Inc. -> Zoom Communications, Inc.)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
Hosts: Hay más de una entrada en Hosts. Consulte la sección Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 200.28.4.130 200.28.4.129
Tcpip\..\Interfaces\{2300e2fc-b488-40ae-9c8c-64b6091664cd}: [DhcpNameServer] 200.28.4.130 200.28.4.129
Tcpip\..\Interfaces\{32fd6fa6-adb5-413d-90b4-2bf55f7b6e87}: [DhcpNameServer] 200.28.4.130 200.28.4.129
Tcpip\..\Interfaces\{32fd6fa6-adb5-413d-90b4-2bf55f7b6e87}\6456E696875303: [DhcpNameServer] 200.28.4.130 200.28.4.129
Tcpip\..\Interfaces\{32fd6fa6-adb5-413d-90b4-2bf55f7b6e87}\7596649602553454E4: [DhcpNameServer] 172.20.60.212 172.20.8.80
Tcpip\..\Interfaces\{32fd6fa6-adb5-413d-90b4-2bf55f7b6e87}\7596649602553454E4: [DhcpDomain] ucentral.cl
Tcpip\..\Interfaces\{32fd6fa6-adb5-413d-90b4-2bf55f7b6e87}\75966696F5553656E6472716C6: [DhcpNameServer] 172.20.60.212 172.20.8.80
Tcpip\..\Interfaces\{32fd6fa6-adb5-413d-90b4-2bf55f7b6e87}\75966696F5553656E6472716C6: [DhcpDomain] ucentral.cl
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-18]
Edge Extension: (YouTube™ Enhancer Plus) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojcplklhdbhcndefcidaipkccnnagod [2025-03-16]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Random User-Agent (Switcher)) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\einpaelgookohagofgnnkcfjbkkgepnp [2025-03-16]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Documentos de Google sin conexión) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-04-03]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2025-04-16]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Cisco Webex Extension) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ikdddppdhmjcdfgilpnbkdeggoiicjgo [2025-03-16]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (MEGA) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jemjknhgpjaacbghpdhgchbgccbpkkgf [2025-04-12]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (HP Network Check Launcher) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2025-03-16]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2025-03-15]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Ace Script) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2025-03-16]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (AdBlock — block ads across the web) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ndcileolkflehcjpmjnfbnaibdcgglog [2025-04-16]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Reverso - Traducción, diccionario) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\onhiacboedfinnofagfgoaanfedhmfab [2025-04-10]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Avast SafePrice) - C:\Users\Diego Canales\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\phhhmbgggfifgikoihlakngnngdehhfe [2025-03-16]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
FireFox:
========
FF DefaultProfile: nthv27pq.default
FF ProfilePath: C:\Users\Diego Canales\AppData\Roaming\SWP\Profiles\tgqf8t9w.default [2025-02-06]
FF Extension: (DOM Inspector) - C:\Program Files (x86)\MacKichan\SWP\extensions\[email protected] [2025-02-06] [Heredado] [no firmado]
FF Extension: (JavaScript Debugger) - C:\Program Files (x86)\MacKichan\SWP\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8} [2025-02-06] [Heredado] [no firmado]
FF ProfilePath: C:\Users\Diego Canales\AppData\Roaming\SW\Profiles\1offh7wt.default [2025-02-06]
FF Extension: (DOM Inspector) - C:\Program Files (x86)\MacKichan\SW\extensions\[email protected] [2025-02-06] [Heredado] [no firmado]
FF Extension: (JavaScript Debugger) - C:\Program Files (x86)\MacKichan\SW\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8} [2025-02-06] [Heredado] [no firmado]
FF ProfilePath: C:\Users\Diego Canales\AppData\Roaming\SNB\Profiles\3avcyk1l.default [2025-02-06]
FF Extension: (DOM Inspector) - C:\Program Files (x86)\MacKichan\SNB\extensions\[email protected] [2025-02-06] [Heredado] [no firmado]
FF Extension: (JavaScript Debugger) - C:\Program Files (x86)\MacKichan\SNB\extensions\{f13b157f-b174-47e7-a34d-4815ddfdfeb8} [2025-02-06] [Heredado] [no firmado]
FF ProfilePath: C:\Users\Diego Canales\AppData\Roaming\Mozilla\Firefox\Profiles\nthv27pq.default [2025-02-14]
FF ProfilePath: C:\Users\Diego Canales\AppData\Roaming\Mozilla\Firefox\Profiles\y98za4w3.default-release [2025-04-17]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-02-02]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF Extension: (Foxit PDF Creator) - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2024-11-21] [Heredado]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\[email protected]
FF Extension: (Foxit PDF Creator) - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\[email protected] [2024-11-21]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\PDF Architect 9\creator\plugins\FirefoxAddin\[email protected]
FF Extension: (PDF Architect 8 Creator) - C:\Program Files\PDF Architect 9\creator\plugins\FirefoxAddin\[email protected] [2024-11-29]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Soda PDF Desktop 14\creator\plugins\FirefoxAddin\[email protected]
FF Extension: (Soda PDF Desktop 12 Creator) - C:\Program Files\Soda PDF Desktop 14\creator\plugins\FirefoxAddin\[email protected] [2024-12-10]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Nuance\Nuance Power PDF\bin\SFirefoxExtn
FF Extension: (Nuance PDF Create) - C:\Program Files (x86)\Nuance\Nuance Power PDF\bin\SFirefoxExtn [2025-02-07] [Heredado]
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\PDF Suite 2021\creator\plugins\FirefoxAddin\[email protected]
FF Extension: (PDF Suite 2020 Creator) - C:\Program Files\PDF Suite 2021\creator\plugins\FirefoxAddin\[email protected] [2023-02-22]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\FirefoxAddin\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\PDF Architect 9\creator\plugins\FirefoxAddin\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Soda PDF Desktop 14\creator\plugins\FirefoxAddin\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Nuance\Nuance Power PDF\bin\SFirefoxExtn
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\PDF Suite 2021\creator\plugins\FirefoxAddin\[email protected]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2025-03-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2024-06-08] (VideoLAN -> VideoLAN)
FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-03-13] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin: PDF Suite 2021 -> C:\Program Files\PDF Suite 2021\np-previewer.dll [2023-02-22] (Avanquest Software (7270356 Canada Inc) -> Interactive Brands Malta Limited)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2025-01-09] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2025-01-09] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2025-01-09] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\npFoxitPDFEditorPlugin.dll [2025-01-09] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-12-05] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-12-05] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-12-05] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\plugins\npFoxitPDFReaderPlugin.dll [2024-12-05] (FOXIT SOFTWARE INC. -> Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.441.2 -> C:\Program Files (x86)\Java\jre1.8.0_441\bin\dtplugin\npDeployJava1.dll [2024-12-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.441.2 -> C:\Program Files (x86)\Java\jre1.8.0_441\bin\plugin2\npjp2.dll [2024-12-04] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2025-03-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2025-03-28] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-10] (Nero AG -> Nero AG)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin-x32: PDF Suite 2021 -> C:\Program Files (x86)\PDF Suite 2021\np-previewer.dll [2023-02-22] (Avanquest Software (7270356 Canada Inc) -> Interactive Brands Malta Limited)
FF Plugin HKU\S-1-5-21-1296002004-1646576553-2792702146-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin HKU\S-1-5-21-1296002004-1646576553-2792702146-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.adobe.xfdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
FF Plugin HKU\S-1-5-21-1296002004-1646576553-2792702146-1001: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll [2025-02-12] (TRACKER SOFTWARE PRODUCTS (CANADA) LIMITED -> PDF-XChange Co Ltd.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default [2025-04-18]
CHR Extension: (MEGA) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2025-04-15] [UpdateUrl:hxxps://mega.nz/firefox-web-extension-updates.json] <==== ATENCIÓN
CHR Extension: (YouTube™ Enhancer Plus) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\bojcplklhdbhcndefcidaipkccnnagod [2025-02-04]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2025-04-10]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Foxit PDF Creator) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\cifnddnffldieaamihfkhkdgnbhfmaci [2025-02-05]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-04-18]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Random User-Agent (Switcher)) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\einpaelgookohagofgnnkcfjbkkgepnp [2025-02-04]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-20]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (AdBlock — block ads across the web) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-04-18]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Sin Nombre) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpaiobkfhnonedkhhfjpmhdalgeoebfa [2025-02-04]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Picture-in-Picture Extension (by Google)) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgfoiooedgoejojocmhlaklaeopbecg [2025-02-13]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Cisco Webex Extension) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2025-02-04]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2025-02-04]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Reverso - Traducción, diccionario) - C:\Users\Diego Canales\AppData\Local\Google\Chrome\User Data\Default\Extensions\onhiacboedfinnofagfgoaanfedhmfab [2025-04-10]hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\ChromeAddin\ChromeAddin.crx [2024-11-21]
CHR HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo]
CHR HKU\S-1-5-21-1296002004-1646576553-2792702146-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\Program Files (x86)\Foxit Software\Foxit PDF Editor\plugins\Creator\ChromeAddin\ChromeAddin.crx [2024-11-21]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
Opera:
=======
OPR DefaultProfile: Default