Sospecha de estar hackeado


2020-05-11 07:40 - 2020-05-11 07:40 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.UserService.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRClient.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000485376 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_WorkAccess.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2020-05-11 07:40 - 2020-05-11 07:40 - 000420448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MitigationClient.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000399872 _____ (Microsoft Corporation) C:\WINDOWS\system32\secproc_isv.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvctpSvc.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000383224 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000353840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExecModelClient.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthAvrcp.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000339000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcApi.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000287232 _____ C:\WINDOWS\system32\CoreMas.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Accessibility.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposerFramework.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000261432 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataExchange.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApproveChildRequest.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatializerApo.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000217600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Radios.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\EapTeapAuth.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Haptics.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcui.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.System.UserProfile.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoipRT.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000146944 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000127288 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Credentials.UI.UserConsentVerifier.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRBroker.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Printers.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000090400 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ffbroker.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000047616 _____ (Microsoft Corporation) C:\WINDOWS\system32\printfilterpipelineprxy.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveTask.exe
2020-05-11 07:40 - 2020-05-11 07:40 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-05-11 07:40 - 2020-05-11 07:40 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\localui.dll
2020-05-11 07:40 - 2020-05-11 07:40 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dstokenclean.exe

==================== Tres meses (modificado) ==================

(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)

2020-07-18 00:24 - 2019-12-07 11:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-07-18 00:03 - 2019-12-07 16:55 - 000752148 _____ C:\WINDOWS\system32\perfh00A.dat
2020-07-18 00:03 - 2019-12-07 16:55 - 000147826 _____ C:\WINDOWS\system32\perfc00A.dat
2020-07-18 00:03 - 2019-12-07 11:13 - 000000000 ____D C:\WINDOWS\INF
2020-07-17 23:58 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-07-17 23:56 - 2019-12-07 11:03 - 000262144 _____ C:\WINDOWS\system32\config\BBI
2020-07-17 23:49 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-07-17 18:11 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-07-17 18:05 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2020-07-17 16:54 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-07-17 05:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\appcompat
2020-07-17 05:20 - 2019-12-07 11:18 - 000000000 ____D C:\WINDOWS\Setup
2020-07-17 05:20 - 2019-12-07 11:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2020-07-17 05:16 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows Defender
2020-07-17 05:11 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\NDF
2020-07-17 04:52 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ServiceState
2020-07-17 04:49 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2020-07-17 04:49 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-07-17 04:48 - 2019-12-07 16:57 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2020-07-17 04:48 - 2019-12-07 16:57 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SystemResources
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\Com
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-07-17 04:48 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Common Files\System
2020-07-17 04:48 - 2019-12-07 11:03 - 000000000 ____D C:\WINDOWS\servicing
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2020-07-17 04:40 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2020-07-17 04:35 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\USOPrivate
2020-07-17 04:28 - 2019-12-07 16:56 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2020-07-17 04:28 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\spool
2020-07-17 04:24 - 2019-12-07 11:14 - 000000000 ____D C:\Program Files\Windows NT
2020-07-17 04:22 - 2019-12-07 11:14 - 000000000 ___RD C:\WINDOWS\PrintDialog

==================== SigCheckExt =========================

2020-07-18 00:19 - 2020-07-18 00:19 - 002292736 _____ (Farbar) C:\Users\HAL 9000\Downloads\FRST64.exe

==================== SigCheck ============================

(No existe una corrección automática para los archivos que no pasan la verificación.)


==================== BCD ================================

Administrador de arranque de firmware
-----------------------------------
Identificador           {fwbootmgr}
displayorder            {bootmgr}
                        {c7b0502b-c739-11ea-824f-806e6f6e6963}
timeout                 1

Administrador de arranque de Windows
----------------------------------
Identificador           {bootmgr}
device                  partition=\Device\HarddiskVolume2
path                    \EFI\Microsoft\Boot\bootmgfw.efi
description             Windows Boot Manager
locale                  es-ES
inherit                 {globalsettings}
default                 {current}
resumeobject            {716a090f-c7dc-11ea-a713-a562fba6fd2e}
displayorder            {current}
toolsdisplayorder       {memdiag}
timeout                 30

Aplicaci�n de firmware (101fffff)
---------------------------------
Identificador           {c7b0502b-c739-11ea-824f-806e6f6e6963}
device                  partition=\Device\HarddiskVolume2
path                    \EFI\BOOT\BOOTX64.EFI
description             UEFI: KINGSTON SV300S37A240G

Cargador de arranque de Windows
-----------------------------
Identificador           {current}
device                  partition=C:
path                    \WINDOWS\system32\winload.efi
description             Windows 10
locale                  es-ES
inherit                 {bootloadersettings}
recoverysequence        {716a0911-c7dc-11ea-a713-a562fba6fd2e}
displaymessageoverride  Recovery
recoveryenabled         Yes
isolatedcontext         Yes
allowedinmemorysettings 0x15000075
osdevice                partition=C:
systemroot              \WINDOWS
resumeobject            {716a090f-c7dc-11ea-a713-a562fba6fd2e}
nx                      OptIn
bootmenupolicy          Standard

Cargador de arranque de Windows
-----------------------------
Identificador           {716a0911-c7dc-11ea-a713-a562fba6fd2e}
device                  ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{716a0912-c7dc-11ea-a713-a562fba6fd2e}
path                    \windows\system32\winload.efi
description             Windows Recovery Environment
locale                  es-ES
inherit                 {bootloadersettings}
displaymessage          Recovery
osdevice                ramdisk=[\Device\HarddiskVolume5]\Recovery\WindowsRE\Winre.wim,{716a0912-c7dc-11ea-a713-a562fba6fd2e}
systemroot              \windows
nx                      OptIn
bootmenupolicy          Standard
winpe                   Yes

Reanudar tras hibernaci�n
-------------------------
Identificador           {716a090f-c7dc-11ea-a713-a562fba6fd2e}
device                  partition=C:
path                    \WINDOWS\system32\winresume.efi
description             Windows Resume Application
locale                  es-ES
inherit                 {resumeloadersettings}
recoverysequence        {716a0911-c7dc-11ea-a713-a562fba6fd2e}
recoveryenabled         Yes
isolatedcontext         Yes
allowedinmemorysettings 0x15000075
filedevice              partition=C:
filepath                \hiberfil.sys
bootmenupolicy          Standard
debugoptionenabled      No

Herramienta de comprobaci�n de memoria de Windows
-------------------------------------------------
Identificador           {memdiag}
device                  partition=\Device\HarddiskVolume2
path                    \EFI\Microsoft\Boot\memtest.efi
description             Herramienta de diagn�stico de memoria de Windows
locale                  es-ES
inherit                 {globalsettings}
badmemoryaccess         Yes

Configuraci�n de EMS
--------------------
Identificador           {emssettings}
bootems                 No

Configuraci�n del depurador
---------------------------
Identificador           {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200

Defectos de RAM
---------------
Identificador           {badmemory}

Configuraci�n global
--------------------
Identificador           {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Configuraci�n del cargador de arranque
------------------------------------
Identificador           {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Configuraci�n de hipervisor
-------------------
Identificador           {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Reanudar la configuraci�n del cargador
--------------------------------------
Identificador           {resumeloadersettings}
inherit                 {globalsettings}

Opciones de dispositivo
-----------------------
Identificador           {716a0912-c7dc-11ea-a713-a562fba6fd2e}
description             Windows Recovery
ramdisksdidevice        partition=\Device\HarddiskVolume5
ramdisksdipath          \Recovery\WindowsRE\boot.sdi

==================== Final de FRST.txt ========================