Saludos, realicé todas las pruebas. Antes de pegar los reportes deseo comentar algo que pasó. Casi nunca reinicio el sistema, siempre lo prendo y lo apago sin ningún problema, al seguir estos pasos, después de que al adwcleaner me pidiera reiniciar y darle que si, el sistema estaba prendiendo y salió la pantalla azul de error. Pensé que era por el mismo programa, pero en el paso 4 de las instrucciones, que también pide reiniciar volvió a pasar lo mismo, el mensaje azul de error, no alcancé a anotar el código del error que sale.
Reporte Adwcleaner
# -------------------------------
# Malwarebytes AdwCleaner 8.0.6.0
# -------------------------------
# Build: 06-24-2020
# Database: 2020-06-15.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 07-14-2020
# Duration: 00:00:23
# OS: Windows 10 Home Single Language
# Scanned: 31836
# Detected: 7
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
No malicious registry entries found.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
Preinstalled.ASUSSmartGesture Folder C:\Program Files (x86)\ASUS\ASUS SMART GESTURE
Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F88C153-C11E-404B-8135-24639199A4F4}
Preinstalled.ASUSSmartGesture Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ASUS Smart Gesture Launcher
Preinstalled.ASUSSmartGesture Registry HKLM\Software\Classes\CLSID\{F31B5912-07D6-4895-B4BA-5486CF3B18B1}
Preinstalled.ASUSSmartGesture Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}
Preinstalled.ASUSSmartGesture Task C:\Windows\System32\Tasks\ASUS SMART GESTURE LAUNCHER
Preinstalled.ASUSSplendid Folder C:\Program Files (x86)\ASUS\SPLENDID
AdwCleaner[S00].txt - [1343 octets] - [15/07/2018 13:05:59]
AdwCleaner[C00].txt - [1509 octets] - [15/07/2018 13:06:47]
AdwCleaner[S01].txt - [1380 octets] - [15/07/2018 13:35:00]
AdwCleaner[S02].txt - [1864 octets] - [27/03/2019 09:47:14]
AdwCleaner[C02].txt - [2033 octets] - [27/03/2019 09:49:07]
AdwCleaner_Debug.log - [21711 octets] - [24/11/2019 08:03:45]
AdwCleaner[S03].txt - [3889 octets] - [24/11/2019 08:04:51]
AdwCleaner[C03].txt - [2699 octets] - [24/11/2019 08:06:42]
AdwCleaner[S04].txt - [3355 octets] - [03/04/2020 13:10:15]
AdwCleaner[C04].txt - [2794 octets] - [03/04/2020 13:48:04]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S05].txt ##########
Reporte ZHPCleaner
~ ZHPCleaner v2020.7.13.212 by Nicolas Coolman (2020/07/13)
~ Run by Henry Percy (Administrator) (14/07/2020 09:16:48)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scanner
~ Report : C:\Users\Henry Percy\Desktop\ZHPCleaner (S).txt
~ Quarantine : C:\Users\Henry Percy\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point :
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home Single Language, 64-bit (Build 18362)
---\\ Alternate Data Stream (ADS). (0)
~ No malintencionados o innecesarios artículos encontrados.
---\\ Servicios (0)
~ No malintencionados o innecesarios artículos encontrados.
---\\ Navegadores de Internet (0)
~ No malintencionados o innecesarios artículos encontrados.
---\\ Hosts carpeta (1)
~ El archivo hosts es legítimo (119)
---\\ Tareas automáticas programadas. (0)
~ No malintencionados o innecesarios artículos encontrados.
---\\ Explorador ( Archivos, Carpetas ) (0)
~ No malintencionados o innecesarios artículos encontrados.
---\\ Registro ( Claves, Valores, Datos) (0)
~ No malintencionados o innecesarios artículos encontrados.
---\\ Resultado de la reparación.
~ ninguna reparación hecha
~ Google Chrome OK
~ Mozilla Firefox OK
~ Internet Explorer OK
~ Opera OK
---\\ STATISTIQUES
~ Items escaneado : 118541
~ Items encontrado : 0
~ artículos cancelados : 0
~ Ahorro de espacio (bytes) : 0
~ Items opciones : 8/15
---\\ OPCIONES NO ACTIVAS
~ Análisis temporal de archivos
~ Análisis temporal de carpetas
~ Análisis de CLSID de carpetas vacías
~ Vaciar otro análisis de carpetas
~ Análisis de carpetas locales vacías
~ Análisis de carpetas locales vacías
~ Análisis de archivos de instalación obsoleto
~ End of search in 00h11mn53s
---\\ Reporte (0)
ZHPCleaner-[S]-14072020-09_28_41.txt
Reporte Malwarebytes
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 14/7/20
Hora del análisis: 9:34
Archivo de registro: 258988b4-c5df-11ea-9db1-ac220baf99a4.json
-Información del software-
Versión: 4.1.0.56
Versión de los componentes: 1.0.859
Versión del paquete de actualización: 1.0.26817
Licencia: Gratis
-Información del sistema-
SO: Windows 10 (Build 18362.900)
CPU: x64
Sistema de archivos: NTFS
Usuario: HENRYPERCY\Henry Percy
-Resumen del análisis-
Tipo de análisis: Análisis personalizado
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 1022287
Amenazas detectadas: 6
Amenazas en cuarentena: 0
Tiempo transcurrido: 1 hr, 7 min, 27 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 0
(No hay elementos maliciosos detectados)
Valor del registro: 0
(No hay elementos maliciosos detectados)
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 0
(No hay elementos maliciosos detectados)
Archivo: 6
MachineLearning/Anomalous.100%, C:\PROGRAM FILES (X86)\TIPARD STUDIO\TIPARD IPHONE TRANSFER ULTIMATE\PATCH.EXE, Sin acciones por parte del usuario, 0, 392687, 1.0.26817, , shuriken,
Generic.Malware/Suspicious, E:\DOWNLOADS CUALQUIERAS\WHOS.ON.MY.WIFI.2.1.7\WHOS.ON.MY.WIFI.KEYGEN.REPT\WHOS.ON.MY.WIFI.KEYGEN.2013.REPT.EXE, Sin acciones por parte del usuario, 0, 392686, 1.0.26817, , shuriken,
Generic.Malware/Suspicious, E:\DOWNLOADS CUALQUIERAS\WHOS.ON.MY.WIFI.2.1.7\WHOS.ON.MY.WIFI.KEYGEN.REPT.RAR, Sin acciones por parte del usuario, 0, 392686, 1.0.26817, , shuriken,
Malware.Generic.923849912, E:\VR\BASE 9.5\MYDISKFIX FORMAT UTILITY\MYDISKFIX.EXE, Sin acciones por parte del usuario, 1000000, 0, 1.0.26817, EB42739E102DDFDB3710D4B8, dds, 00807087
MachineLearning/Anomalous.100%, E:\VR\BASE 9.5\TIPARD.IPHONE.TRANSFER.ULTIMATE.8.2.30\TIPARD.IPHONE.TRANSFER.ULTIMATE.8.2.30\UMP1.2.RAR, Sin acciones por parte del usuario, 0, 392687, 1.0.26817, , shuriken,
Malware.Generic.923849912, E:\VR\BASE 9.5\MYDISKFIX FORMAT UTILITY.RAR, Sin acciones por parte del usuario, 1000000, 0, 1.0.26817, EB42739E102DDFDB3710D4B8, dds, 00807087
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
Reporte FRST
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 08-07-2020 01
Ejecutado por Henry Percy (administrador) sobre HENRYPERCY (ASUSTeK COMPUTER INC. N550JV) (14-07-2020 11:02:52)
Ejecutado desde C:\Users\Henry Percy\Desktop
Perfiles cargados: Henry Percy
Platform: Windows 10 Home Single Language Versión 1903 18362.900 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: FF
Modo de Inicio: Normal
Tutorial para Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
(Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
(Adobe Inc. -> Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(ASUSTeK Computer Inc. -> ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files\ASUS\ASUS Console\ASUS Console Starter.exe
(Atheros) [Archivo no firmado] C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\eguiProxy.exe
(ESET, spol. s r.o. -> ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Google LLC -> ) C:\Program Files\Google\Drive\googledrivesync.exe <2>
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation -> Intel(R) Corporation) C:\Windows\SysWOW64\XtuService.exe
(Intel(R) Corporation) [Archivo no firmado] C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel(R) Driver & Support Assistant -> Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealthHost.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe <2>
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(StagWare) [Archivo no firmado] [El archivo está en uso] C:\Program Files (x86)\NoteBook FanControl\NbfcService.exe
(StagWare) [Archivo no firmado] [El archivo está en uso] C:\Program Files (x86)\NoteBook FanControl\NoteBookFanControl.exe
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [185648 2020-07-10] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3325520 2020-06-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM-x32\...\Run: [ASUS InstantKey] => C:\Program Files (x86)\ASUS\ASUS Instant Key\Ikey_start.exe [13936 2013-06-04] (ASUSTeK Computer Inc. -> ASUS)
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [126712 2018-09-26] (Intel(R) Driver & Support Assistant -> Intel)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [646776 2020-03-12] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-970227938-1326680726-1648082153-1002\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [48594832 2020-06-15] (Google LLC -> )
HKU\S-1-5-21-970227938-1326680726-1648082153-1002\...\Run: [PTOneClick] => C:\Users\Henry Percy\AppData\Local\Webex\Webex\Applications\ptoneclk.exe [7184120 2020-03-28] (Cisco WebEx LLC -> Cisco Webex LLC)
HKU\S-1-5-21-970227938-1326680726-1648082153-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [28990136 2020-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-970227938-1326680726-1648082153-1002\...\Run: [NBFC-ClientApplication] => C:\Program Files (x86)\NoteBook FanControl\NoteBookFanControl.exe [427008 2019-04-14] (StagWare) [Archivo no firmado] [El archivo está en uso]
HKU\S-1-5-21-970227938-1326680726-1648082153-1002\...\Run: [Opera Browser Assistant] => C:\Users\Henry Percy\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3105304 2020-07-07] (Opera Software AS -> Opera Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.116\Installer\chrmstp.exe [2020-06-24] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{4B95ACA9-75CD-4442-AFC2-7D508B03711B}] -> Msiexec.exe /fu {4B95ACA9-75CD-4442-AFC2-7D508B03711B} /qn
HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2013-06-28] (Qualcomm Atheros -> Qualcomm®Atheros®) [Archivo no firmado]
HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\WINDOWS\system32\AthCredentialProvider.dll [2013-06-28] (Qualcomm Atheros -> Qualcomm®Atheros®) [Archivo no firmado]
GroupPolicy: Restricción ? <==== ATENCIÓN
==================== Tareas programadas (Lista blanca) ============
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {006BE61E-A9C6-4750-923F-304908EDC6A9} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407736 2015-11-16] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {04553AB6-D8B1-4C47-BD35-15798EBC32D5} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Ningún archivo <==== ATENCIÓN
Task: {0600FDE5-90FC-44D2-B90C-6BE49AFB7E2B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [24584376 2020-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {094CD275-5C71-4753-B57E-5566CA859498} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {0CBA421A-DBA6-4973-B0F5-555C88321DB4} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {0DBB37E3-54F9-4E14-BD25-6C9D7196C06F} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [1850776 2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {147EF152-C592-431F-9DF4-EE588894047D} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {153C2201-AE79-4492-9493-D9ED5B89F0BE} - System32\Tasks\{8CF2B0BF-D9B1-4D95-A5A9-EA00C548822D} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.21.0.100&LastError=404
Task: {17CE098D-85D7-4990-BA10-6815B140CF07} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1A2C33CF-452B-4AE9-90DF-302DB1CEAE2D} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-06-17] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {1C828256-374B-4BFE-8F74-1AE1A13E3347} - System32\Tasks\AdwCleaner_onReboot => E:\DOWNLOADS CUALQUIERAS\forospyware julio 2020\adwcleaner_8.0.6.exe [8420016 2020-07-14] (Malwarebytes Inc -> Malwarebytes)
Task: {26670623-61ED-445B-8D1B-84EC7F6119D7} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2A12821C-42A8-4989-95DF-F854521197BD} - System32\Tasks\ASUS Console => C:\Program Files\ASUS\ASUS Console\ASUS Console Starter.exe [2278168 2013-07-09] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {2C05F02E-1752-4639-AFA8-A188A788CDFD} - System32\Tasks\Opera scheduled assistant Autoupdate 1584381389 => C:\Users\Henry Percy\AppData\Local\Programs\Opera\launcher.exe [1517592 2020-06-18] (Opera Software AS -> Opera Software)
Task: {328092B3-101B-4560-950A-BE68199E7983} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [1036088 2013-06-19] (ASUSTeK Computer Inc. -> ASUS)
Task: {329D0294-59F4-4F95-88DB-EA5FEA7547F2} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {3695FA15-3CCF-415D-BC5B-F7484F0096D3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Ningún archivo <==== ATENCIÓN
Task: {3F8C98C8-033E-4F97-9BF7-13BCDEE26985} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1331792 2020-05-07] (Adobe Inc. -> Adobe Inc.)
Task: {4BCF9256-D5C8-4AC8-9FC2-A0F1112A5241} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {52D9F939-2C31-4AFC-9BB4-9BD0ED33FFA4} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5A3FB241-0B11-4EA5-BC66-0D9F1B406040} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM => {C8367320-6F85-11E0-A1F0-0800200C9A66} C:\WINDOWS\System32\BthTelemetry.dll [32256 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
Task: {5CB60D51-793B-4074-8B49-2AEC9A9DED61} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {5E35571A-C523-4038-9031-B42934385480} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-28] (Google Inc -> Google Inc.)
Task: {6225C13A-6DF4-4DD4-A987-5F8AB33FCB09} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Ningún archivo <==== ATENCIÓN
Task: {6499AD08-5B5A-4113-9991-6F8EF60FD761} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1724928 2019-12-17] () [Archivo no firmado]
Task: {6C290EEE-9E96-4884-BD33-6000DB7806DD} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Ningún archivo <==== ATENCIÓN
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {78C840A3-1B9C-4B01-BD8C-F94512DB4BD7} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {7AB89C6B-6041-4392-BCEB-27B396A2AD64} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Ningún archivo <==== ATENCIÓN
Task: {7CB0F760-1523-4CF1-B07A-5C21F57CE3D7} - System32\Tasks\GoogleUpdateTaskMachineUA1cfeb5cc3f0626e => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-28] (Google Inc -> Google Inc.)
Task: {7D0E0FF6-13B6-4342-A2FD-510351F53098} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3787304 2019-05-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {7E825CF5-E187-4890-93C7-C20171109A8B} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {817293CC-0C6A-4BEC-8904-64482094D3B6} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {82B5EFB0-8161-4A66-80BA-0DC852DB64AF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6063024 2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {874139B0-C616-4856-8849-E95D2FAE4368} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-06-13] (Adobe Inc. -> Adobe)
Task: {896A013D-65B8-4789-88DF-363D017F7ECD} - System32\Tasks\Intel\Intel Telemetry 2 (x86) => C:\Program Files (x86)\Intel\Telemetry 2.0\lrio.exe [1652536 2018-11-05] (Intel(R) Software -> Intel Corporation)
Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {93B11ABD-D1E4-40D4-9E92-51C31D4DD72E} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [170848 2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {990170E9-66E6-4320-8C47-978DDAFA72E6} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [5146192 2013-06-05] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {9DE4FF05-E597-4856-8CDB-E59339C74A56} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [124112 2020-07-09] (Mozilla Corporation -> Mozilla Foundation)
Task: {A30A467F-A17F-4185-829F-1AB8CF2F08FE} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23810952 2020-06-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {A33E6DB6-BB3E-4EAF-BDEB-C2377078DD5B} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16409496 2015-11-16] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {A8A958E6-C8CE-4C3A-A0BC-D262CFA2C01A} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_387_Plugin.exe [1459256 2020-06-13] (Adobe Inc. -> Adobe)
Task: {A90A963E-8A19-486C-8954-A94C720F0E7A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [170848 2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Task: {AA9F500F-6015-420E-88CC-89AD33C2B6FB} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [23810952 2020-06-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {AEFE5A30-B41C-44EC-A554-1000E035D052} - System32\Tasks\ASUS InstantOn Config => C:\Program Files\ASUS\P4G\InsOnCfg.exe
Task: {B6D50BBA-AA32-44AD-ADAA-C61912128B6F} - System32\Tasks\{952A8D83-D67D-4085-9807-B1323EC94F15} => "c:\program files\mozilla firefox\firefox.exe" hxxps://www.skype.com/go/downloading?source=lightinstaller&ver=7.39.0.102&LastError=12029
Task: {B70AB5AB-6B94-40A8-AD7A-6E6765087DEB} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C5AF0CCF-BFAE-427B-AC4D-63C9C1B3CE38} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Ningún archivo <==== ATENCIÓN
Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {CA894ABF-18C7-4A2E-A03F-2330B177F703} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
Task: {CA8DCD13-2934-4991-8B44-E7FFCF37FE5A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [899056 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CBEB2CB5-99D3-4254-943C-9671EE9BCC71} - \Microsoft\Windows\UNP\RunCampaignManager -> Ningún archivo <==== ATENCIÓN
Task: {CC03F4F3-95DE-49EA-83D1-F84D236E6FA4} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407736 2015-11-16] (Realtek Semiconductor Corp -> Realtek Semiconductor)
Task: {CC2B2115-67E1-490D-89E1-EDC85005FB3A} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130296 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {D5783697-6601-4A61-8419-9D033440C78B} - System32\Tasks\AdobeGCInvoker-1.0 => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [3325520 2020-06-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {D5A56737-ED96-4281-A94F-6E5530367E55} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Ningún archivo <==== ATENCIÓN
Task: {DA26F807-D62A-48B0-814E-E3DA1B0AEE4D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Ningún archivo <==== ATENCIÓN
Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {DDF01A16-DA13-4AEC-BE6C-87D9AE458D02} - System32\Tasks\Opera scheduled Autoupdate 1584381384 => C:\Users\Henry Percy\AppData\Local\Programs\Opera\launcher.exe [1517592 2020-06-18] (Opera Software AS -> Opera Software)
Task: {E7F3C426-6649-4EA3-B5CA-376978C6691D} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Ningún archivo <==== ATENCIÓN
Task: {E91D202D-70DF-4D70-96E7-7A58000D8692} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Ningún archivo <==== ATENCIÓN
Task: {E93AF17C-AEF4-4709-A24E-66DE486E06FF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Ningún archivo <==== ATENCIÓN
Task: {EC1A27D0-94D2-48DC-872A-A4EEAD5A09CA} - System32\Tasks\Pantalla => "C:\Users\Henry Percy\pantalla.cmd"
Task: {EC61C5BB-AAAB-4A6C-A782-F477A4584B29} - System32\Tasks\{204DF228-A169-4DCF-B533-3AD3FE059620} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxp://ui.skype.com/ui/0/7.0.0.102/es/abandoninstall?page=tsPlugin
Task: {F125CCC4-5443-4256-AD5F-73852CE60AFC} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [122168 2015-03-10] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {F204B1E9-693B-4BCA-8EBA-0D6515291EA5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6063024 2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
Hosts: Hay más de una entrada en Hosts. Consulte la sección Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 181.70.124.110 200.13.249.101
Tcpip\..\Interfaces\{657d5e98-4628-46fb-b686-9a7d2c997257}: [DhcpNameServer] 181.70.124.110 200.13.249.101
Tcpip\..\Interfaces\{83255062-b1de-4745-bc4f-d5d79a1f9638}: [DhcpNameServer] 181.70.124.110 200.13.249.101
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restricción <==== ATENCIÓN
HKU\S-1-5-21-970227938-1326680726-1648082153-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com/
SearchScopes: HKU\S-1-5-21-970227938-1326680726-1648082153-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll [2020-01-10] (Microsoft Corporation -> Microsoft Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2013-06-28] (Qualcomm Atheros -> Qualcomm®Atheros®) [Archivo no firmado]
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-01-10] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\ssv.dll [2020-05-10] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\jp2ssv.dll [2020-05-10] (Oracle America, Inc. -> Oracle Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-07-10] (Microsoft Corporation -> Microsoft Corporation)
FireFox:
========
FF DefaultProfile: jcfnbium.default-1511215343475
FF ProfilePath: C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475 [2020-07-14]
FF Extension: (Facebook Container) - C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475\Extensions\@contain-facebook.xpi [2020-04-14]
FF Extension: (Dark Background and Light Text) - C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475\Extensions\[email protected] [2019-11-25]
FF Extension: (uBlock Origin) - C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475\Extensions\[email protected] [2020-07-14]
FF Extension: (uMatrix) - C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475\Extensions\[email protected] [2019-09-06]
FF Extension: (Mendeley Web Importer) - C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475\Extensions\[email protected] [2020-06-30]
FF Extension: (YouTube NonStop) - C:\Users\Henry Percy\AppData\Roaming\Mozilla\Firefox\Profiles\jcfnbium.default-1511215343475\Extensions\{0d7cafdd-501c-49ca-8ebb-e3341caaa55e}.xpi [2020-05-29]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\[email protected] [2017-03-29] [Heredado] [no firmado]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt => no encontrado
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK => no encontrado
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_387.dll [2020-06-13] (Adobe Inc. -> )
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-01-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_387.dll [2020-06-13] (Adobe Inc. -> )
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-15] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-15] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\dtplugin\npDeployJava1.dll [2020-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.251.2 -> C:\Program Files (x86)\Java\jre1.8.0_251\bin\plugin2\npjp2.dll [2020-05-10] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-12-06] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-01-10] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-05-03] (Adobe Inc. -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-970227938-1326680726-1648082153-1002: @radvision.com/ConfClient -> C:\Users\Henry Percy\AppData\Local\Radvision\Installer\1.5.5.3\npclientinstmgr.dll [2019-02-27] (Avaya Inc. -> Avaya, Inc.)
FF Plugin HKU\S-1-5-21-970227938-1326680726-1648082153-1002: @zoom.us/ZoomVideoPlugin -> C:\Users\Henry Percy\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2020-05-17] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-07-14]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\eset_security_config_overlay.js [2020-07-14]
Chrome:
=======
CHR DefaultProfile: Profile 2
CHR Profile: C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default [2020-07-14]
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-04]
CHR Extension: (YouTube) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-04]
CHR Extension: (Google Search) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-30]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-05-16]
CHR Extension: (Bookmark Manager) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-09]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-17]
CHR Extension: (Google Wallet) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-15]
CHR Extension: (Gmail) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30]
CHR Profile: C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2 [2020-07-14]
CHR Extension: (Presentaciones) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Documentos) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-16]
CHR Extension: (YouTube) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-29]
CHR Extension: (uBlock Origin) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-05-30]
CHR Extension: (Búsqueda de Google) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Archive Downloader) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\elhoagejfapekjaefenmngphliikoace [2020-01-12]
CHR Extension: (Hojas de cálculo) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Escritorio Remoto de Chrome) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2019-07-17]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-05-27]
CHR Extension: (PDF Mergy - Merge PDF files) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hgecghmkcdefnknohcimkoemhaofpoha [2017-10-11]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2019-03-25]
CHR Extension: (Morpheon Dark) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mafbdhjdkjnoafhfelkjpchpaepjknad [2018-09-13]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Gmail) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-24]
CHR Extension: (Chrome Media Router) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-05-28]
CHR Extension: (Privacy Badger) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2020-07-01]
CHR Profile: C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile [2020-07-14]
CHR Extension: (Google Slides) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-16]
CHR Extension: (Google Docs) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-16]
CHR Extension: (Google Drive) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-16]
CHR Extension: (YouTube) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-16]
CHR Extension: (Google Search) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-16]
CHR Extension: (Google Sheets) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-16]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-16]
CHR Extension: (Google Wallet) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-16]
CHR Extension: (Gmail) - C:\Users\Henry Percy\AppData\Local\Google\Chrome\User Data\System Profile\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-16]
CHR HKU\S-1-5-21-970227938-1326680726-1648082153-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
Opera:
=======
OPR DownloadDir: E:\DOWNLOADS CUALQUIERAS
OPR Extension: (uMatrix) - C:\Users\Henry Percy\AppData\Roaming\Opera Software\Opera Stable\Extensions\clblbeknmgobkgonndomehcjpckopfeh [2020-06-10]
OPR Extension: (Dark Mode) - C:\Users\Henry Percy\AppData\Roaming\Opera Software\Opera Stable\Extensions\jabpfojepndedlelamfloejfoopkogcf [2020-06-09]
OPR Extension: (uBlock Origin) - C:\Users\Henry Percy\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2020-06-10]
==================== Servicios (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-04-10] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
S4 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-06-13] (Adobe Inc. -> Adobe)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [3673680 2020-06-04] (Adobe Inc. -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [3406416 2020-06-04] (Adobe Inc. -> Adobe Systems, Incorporated)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc. -> Apple Inc.)
R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUSTeK Computer Inc. -> ASUS)
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\84.0.4147.39\remoting_host.exe [73200 2020-06-08] (Google LLC -> Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [10574728 2020-06-23] (Microsoft Corporation -> Microsoft Corporation)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23800 2018-09-26] (Intel(R) Driver & Support Assistant -> Intel)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [395024 2016-12-07] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2371248 2020-07-10] (ESET, spol. s r.o. -> ESET)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-11-30] (Intel(R) pGFX -> Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [Archivo no firmado]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-15] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6933272 2020-03-28] (Malwarebytes Inc -> Malwarebytes)
R2 NbfcService; C:\Program Files (x86)\NoteBook FanControl\NbfcService.exe [8704 2019-04-14] (StagWare) [Archivo no firmado] [El archivo está en uso]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-02-27] (NVIDIA Corporation -> NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [767472 2019-04-09] (NVIDIA Corporation -> NVIDIA Corporation)
S4 NvTelemetryContainer; C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [782136 2019-05-22] (NVIDIA Corporation -> NVIDIA Corporation)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2124296 2017-04-14] (Electronic Arts, Inc. -> Electronic Arts)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-18] (Microsoft Corporation -> Microsoft Corporation)
R2 XTU3SERVICE; C:\WINDOWS\SysWOW64\XtuService.exe [82200 2019-09-25] (Intel Corporation -> Intel(R) Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-06-28] (Atheros) [Archivo no firmado]
===================== Controladores (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R3 AiCharger; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [17280 2012-04-18] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) [Archivo no firmado]
R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUSTeK Computer Inc. -> ASUS Corporation)
S3 BthA2dp; C:\WINDOWS\System32\drivers\BthA2dp.sys [231936 2019-09-11] (Microsoft Corporation) [Archivo no firmado]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [159528 2020-07-10] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [106640 2020-07-10] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15800 2019-05-30] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [195456 2020-07-10] (ESET, spol. s r.o. -> ESET)
R2 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [53064 2020-07-10] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [79536 2020-07-10] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [116488 2020-07-10] (ESET, spol. s r.o. -> ESET)
R3 HIDSwitch; C:\WINDOWS\System32\drivers\AsRadioControl.sys [32680 2019-08-07] (ASUSTek Computer Inc. -> ASUS)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [14992 2012-08-01] (ASUSTeK Computer Inc. -> )
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2020-03-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
S3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-05-20] (Malwarebytes Inc -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_a3d5bcc37ff12fed\nvlddmkm.sys [20747736 2019-04-10] (NVIDIA Corporation -> NVIDIA Corporation)
R0 nvpciflt; C:\WINDOWS\System32\DriverStore\FileRepository\nvami.inf_amd64_a3d5bcc37ff12fed\nvpciflt.sys [57216 2019-04-10] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-05-10] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [66792 2019-04-09] (NVIDIA Corporation -> NVIDIA Corporation)
R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [18232 2013-06-19] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project) [Archivo no firmado]
R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2019-05-29] (MiniTool Solution Ltd -> )
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2019-05-29] (MiniTool Solution Ltd -> )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-18] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
R1 WinRing0_1_2_0; C:\Program Files (x86)\NoteBook FanControl\WinRing0x64.sys [14544 2020-06-02] (Noriyuki MIYAZAKI -> OpenLibSys.org)
R3 XTUComponent; C:\WINDOWS\System32\drivers\iocbios2.sys [48632 2019-09-25] (Intel Corporation -> Intel Corporation)
R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [310536 2019-04-14] (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation)
==================== NetSvcs (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
==================== Un mes (creado) ===================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2020-07-14 11:02 - 2020-07-14 11:03 - 000046681 _____ C:\Users\Henry Percy\Desktop\FRST.txt
2020-07-14 11:02 - 2020-07-14 10:59 - 002292736 _____ (Farbar) C:\Users\Henry Percy\Desktop\FRST64.exe
2020-07-14 10:55 - 2020-07-14 10:56 - 000588244 _____ C:\WINDOWS\Minidump\071420-10390-01.dmp
2020-07-14 09:28 - 2020-07-14 09:28 - 000008309 _____ C:\Users\Henry Percy\Desktop\ZHPCleaner (S).html
2020-07-14 09:28 - 2020-07-14 09:28 - 000001984 _____ C:\Users\Henry Percy\Desktop\ZHPCleaner (S).txt
2020-07-14 09:16 - 2020-07-14 09:28 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\ZHP
2020-07-14 09:16 - 2020-07-14 09:16 - 000000883 _____ C:\Users\Henry Percy\Desktop\ZHPCleaner.lnk
2020-07-14 09:12 - 2020-07-14 10:55 - 404725631 _____ C:\WINDOWS\MEMORY.DMP
2020-07-14 09:12 - 2020-07-14 09:12 - 000593628 _____ C:\WINDOWS\Minidump\071420-9515-01.dmp
2020-07-14 09:09 - 2020-07-14 09:09 - 000003222 _____ C:\WINDOWS\system32\Tasks\AdwCleaner_onReboot
2020-07-09 18:35 - 2020-07-09 18:35 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-07-09 17:35 - 2020-07-09 17:35 - 000001230 _____ C:\Users\Public\Desktop\FlexSim 2020 Update 1.lnk
2020-07-09 17:35 - 2020-07-09 17:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlexSim
2020-07-09 10:12 - 2020-07-09 10:12 - 000000000 ____D C:\Program Files\Mozilla Firefox
2020-07-06 18:52 - 2020-07-06 18:52 - 000000000 ____D C:\Users\Henry Percy\Documents\IPEVO_Annotator
2020-07-06 18:52 - 2020-07-06 18:52 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\IPEVO
2020-07-06 18:52 - 2020-07-06 18:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IPEVO
2020-07-06 18:52 - 2020-07-06 18:52 - 000000000 ____D C:\Program Files (x86)\IPEVO
2020-07-01 16:27 - 2020-07-13 09:49 - 000000128 _____ C:\Users\Henry Percy\AppData\Roaming\winscp.rnd
2020-07-01 16:27 - 2020-07-01 16:27 - 000001142 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2020-07-01 16:27 - 2020-07-01 16:27 - 000001130 _____ C:\Users\Public\Desktop\WinSCP.lnk
2020-07-01 16:27 - 2020-07-01 16:27 - 000000000 ____D C:\Program Files (x86)\WinSCP
2020-07-01 16:25 - 2020-07-01 16:25 - 000000128 _____ C:\Users\Henry Percy\AppData\Local\PUTTY.RND
2020-07-01 11:32 - 2020-07-01 11:58 - 000000000 ____D C:\Program Files (x86)\Kernel Outlook PST Viewer
2020-07-01 11:32 - 2020-07-01 11:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kernel Outlook PST Viewer
2020-07-01 11:32 - 2004-03-09 00:00 - 000212240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RICHTX32.OCX
2020-07-01 11:29 - 2020-07-01 11:31 - 000000000 ____D C:\Program Files (x86)\SysTools MailPro+
2020-07-01 11:29 - 2020-07-01 11:29 - 000000000 ____D C:\ProgramData\CDTPL
2020-07-01 10:48 - 2020-07-01 12:51 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\AnyDesk
2020-07-01 04:24 - 2020-07-01 04:24 - 035988764 _____ C:\WINDOWS\SysWOW64\debug.txt
2020-06-30 21:46 - 2020-06-30 21:46 - 000000000 ____D C:\Users\Henry Percy\AppData\Local\Raspberry Pi
2020-06-30 21:45 - 2020-06-30 21:45 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Raspberry Pi
2020-06-30 21:45 - 2020-06-30 21:45 - 000000000 ____D C:\Program Files (x86)\Raspberry Pi Imager
2020-06-23 17:52 - 2020-06-23 17:52 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2020-06-22 17:01 - 2020-06-22 17:02 - 000000000 ____D C:\Users\Henry Percy\AppData\Local\Alt.Binz
==================== Un mes (modificado) ==================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2020-07-14 11:03 - 2019-11-24 08:35 - 000000000 ____D C:\FRST
2020-07-14 11:01 - 2020-03-17 06:29 - 000000000 ____D C:\Users\Henry Percy\Downloads\opera autoupdate
2020-07-14 11:00 - 2019-08-03 14:01 - 002384384 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-07-14 11:00 - 2019-08-03 12:29 - 000478180 _____ C:\WINDOWS\system32\perfh011.dat
2020-07-14 11:00 - 2019-08-03 12:29 - 000132960 _____ C:\WINDOWS\system32\perfc011.dat
2020-07-14 11:00 - 2019-03-19 06:59 - 000789814 _____ C:\WINDOWS\system32\perfh00A.dat
2020-07-14 11:00 - 2019-03-19 06:59 - 000156068 _____ C:\WINDOWS\system32\perfc00A.dat
2020-07-14 11:00 - 2019-03-18 23:50 - 000000000 ____D C:\WINDOWS\INF
2020-07-14 11:00 - 2016-11-15 21:56 - 000000000 ____D C:\Users\Henry Percy\AppData\LocalLow\Mozilla
2020-07-14 10:58 - 2017-04-12 20:12 - 000000000 ____D C:\ProgramData\NVIDIA
2020-07-14 10:56 - 2019-03-18 23:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-07-14 10:56 - 2018-10-08 09:20 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-07-14 10:56 - 2014-05-23 10:08 - 000000000 __SHD C:\Users\Henry Percy\IntelGraphicsProfiles
2020-07-14 10:55 - 2020-01-12 09:51 - 000000000 ____D C:\WINDOWS\Minidump
2020-07-14 10:55 - 2019-08-03 14:02 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-07-14 10:55 - 2019-08-03 13:50 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-07-14 10:54 - 2019-03-18 23:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-07-14 09:30 - 2020-04-10 14:49 - 000214496 ____N (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-07-14 09:09 - 2015-12-13 21:56 - 000000000 ____D C:\Program Files (x86)\ASUS
2020-07-14 09:00 - 2019-06-23 23:26 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\MPC-HC
2020-07-14 09:00 - 2014-06-23 18:28 - 000000000 ____D C:\Program Files (x86)\Steam
2020-07-14 08:37 - 2017-04-11 23:50 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2020-07-13 20:04 - 2020-03-21 19:38 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\obs-studio
2020-07-13 19:43 - 2019-10-04 02:22 - 000000000 ___HD C:\Users\Public\Documents\AdobeGCData
2020-07-13 14:20 - 2019-08-03 14:02 - 000004220 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{0A8213DB-ECEA-42D3-A753-E2C6EDADE0EA}
2020-07-13 08:23 - 2020-06-02 21:24 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\NoteBookFanControl
2020-07-13 08:22 - 2020-06-02 21:24 - 000000000 ____D C:\ProgramData\NbfcService
2020-07-12 19:07 - 2019-08-03 13:50 - 000587368 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-07-12 18:18 - 2017-12-10 07:13 - 000000000 ____D C:\Users\Henry Percy\AppData\Local\Packages
2020-07-10 15:53 - 2018-05-18 07:22 - 000195456 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2020-07-10 15:53 - 2018-05-18 07:22 - 000159528 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2020-07-10 15:53 - 2018-05-18 07:22 - 000116488 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2020-07-10 15:53 - 2018-05-18 07:22 - 000106640 _____ (ESET) C:\WINDOWS\system32\Drivers\edevmon.sys
2020-07-10 15:53 - 2018-05-18 07:22 - 000079536 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2020-07-10 15:53 - 2018-05-18 07:22 - 000053064 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2020-07-10 12:16 - 2019-03-18 23:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-07-10 12:14 - 2014-06-23 19:07 - 000000000 ____D C:\Program Files\Microsoft Office
2020-07-09 23:38 - 2019-03-18 23:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-07-09 23:38 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-07-09 18:35 - 2014-06-23 17:11 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-07-09 17:36 - 2015-01-10 13:18 - 000000000 ____D C:\ProgramData\Package Cache
2020-07-09 17:35 - 2020-04-29 07:22 - 000000000 ____D C:\Users\Henry Percy\Documents\FlexSim 2020 Projects
2020-07-09 17:35 - 2020-04-29 07:22 - 000000000 ____D C:\Program Files\FlexSim 2020 Update 1
2020-07-08 17:10 - 2019-08-03 14:02 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-07-08 17:09 - 2015-11-09 21:07 - 000002138 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2020-07-08 09:26 - 2020-03-16 12:56 - 000004490 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1584381389
2020-07-04 13:27 - 2019-03-18 23:52 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-07-04 10:50 - 2020-05-21 09:38 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-07-02 07:00 - 2014-06-23 17:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-06-30 21:46 - 2020-03-28 18:56 - 000000000 ____D C:\Users\Henry Percy\AppData\Local\cache
2020-06-29 21:05 - 2019-06-13 13:35 - 000002075 _____ C:\Users\Public\Desktop\Google Slides.lnk
2020-06-29 21:05 - 2019-06-13 13:35 - 000002073 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2020-06-29 21:05 - 2019-06-13 13:35 - 000002063 _____ C:\Users\Public\Desktop\Google Docs.lnk
2020-06-29 21:05 - 2019-06-13 13:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2020-06-24 16:04 - 2015-08-07 07:35 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-06-23 12:20 - 2015-10-31 18:48 - 000000000 ____D C:\Users\Henry Percy\AppData\Roaming\MusicBee
2020-06-22 09:45 - 2020-03-16 12:56 - 000004232 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1584381384
2020-06-22 09:45 - 2020-03-16 12:56 - 000001489 _____ C:\Users\Henry Percy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk
==================== Archivos en la raíz de algunos directorios ========
2014-07-01 16:02 - 2014-07-01 16:23 - 000000179 _____ () C:\Users\Henry Percy\pantalla.cmd
2020-07-01 16:27 - 2020-07-13 09:49 - 000000128 _____ () C:\Users\Henry Percy\AppData\Roaming\winscp.rnd
2018-02-05 14:29 - 2018-02-06 16:30 - 000000027 _____ () C:\Users\Henry Percy\AppData\Local\.sdpl-system-config4
2018-09-29 09:03 - 2018-09-29 09:03 - 000000000 _____ () C:\Users\Henry Percy\AppData\Local\oobelibMkey.log
2020-07-01 16:25 - 2020-07-01 16:25 - 000000128 _____ () C:\Users\Henry Percy\AppData\Local\PUTTY.RND
2014-10-14 15:42 - 2018-08-28 19:10 - 000007612 _____ () C:\Users\Henry Percy\AppData\Local\Resmon.ResmonCfg
2020-03-28 11:04 - 2020-03-28 11:06 - 000000075 _____ () C:\Users\Henry Percy\AppData\Local\update_progress.txt
==================== SigCheck ============================
(No existe una corrección automática para los archivos que no pasan la verificación.)
==================== Final de FRST.txt ========================