Buenas tardes! He acabado por aqui porque he caido en el famoso virus de la doble tilde. Recuerdo hace muchos años que lo tuve en un PC antiguo, pero en aquel entonces se eliminaba muy facil. En este caso he intentado todo lo que se me ha ocurrido y no ha habido manera (pasar el defender de Microsoft y el Malwarebytes, que si que ha encontrado alguna cosa, pero no ha dado resultado). El problema ha venido porque he descargado una ROM de Nintendo DS que vendria contaminada (mal por mi parte que suelo ser bastante precavido…). Como ya he visto lo que se suele solicitar me he adelantado y he realizado el Farbar. Adjunto por aqui los resultados. Muchisimas gracias de antemano, haceis un trabajo espectacular por aqui.
FRST
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 01-04-2025
Ejecutado por asier (administrador) sobre DESKTOP-LV6HL6C (Micro-Star International Co., Ltd. MS-7C75) (03-04-2025 18:12:56)
Ejecutado desde C:\Users\asier\Desktop\FRST64.exe
Perfiles cargados: asier
Plataforma: Microsoft Windows 10 Pro Versión 22H2 19045.5608 (X64) Idioma: Español (España, internacional)
Navegador predeterminado: Chrome
Modo de Inicio: Normal
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzAppManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzBTLEManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaConnectManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaConnectServer
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzDeviceManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzDiagnostic
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzIoTDeviceManager
(C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSmartlightingDeviceManager
(C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe ->) (Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(explorer.exe ->) (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering, Ltd.) C:\Program Files\Focusrite\Drivers\Focusrite Notifier.exe
(explorer.exe ->) (Microsoft Corporation -> ) C:\Program Files\WindowsApps\Microsoft.SurfaceWirelessDisplayAdapter_4.232.137.0_x64__8wekyb3d8bbwe\Desktop\WDADesktopService.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
(services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_a55aa2cd52a3429d\LMS.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WSL\wslservice.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpDefenderCoreService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MsMpEng.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (Plex, Inc. -> Plex, Inc.) C:\Program Files\Plex\Plex Media Server\Plex Update Service.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(services.exe ->) (Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_550508a90a3c9a47\RtkAudUService64.exe <2>
(services.exe ->) (Skutta Software GmbH -> ) C:\Windows\SysWOW64\wallpaperservice32.exe
(sihost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_11.2502.2.0_x64__8wekyb3d8bbwe\CalculatorApp.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft) C:\Program Files\WindowsApps\Microsoft.ZuneMusic_11.2502.4.0_x64__8wekyb3d8bbwe\Microsoft.Media.Player.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_550508a90a3c9a47\RtkAudUService64.exe [1618320 2022-11-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Focusrite Notifier] => C:\Program Files\Focusrite\Drivers\Focusrite Notifier.exe [906840 2023-10-13] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering, Ltd.)
HKLM\...\Run: [Riot Vanguard] => C:\Program Files\Riot Vanguard\vgtray.exe [4143376 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3599496 2025-03-11] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [RiotClient] => E:\Riot Games\Riot Client\RiotClientServices.exe [74683360 2025-04-01] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [Steam] => E:\Program Files (x86)\Steam\steam.exe [4694624 2025-04-02] (Valve Corp. -> Valve Corporation)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [com.blitz.app] => C:\Users\asier\AppData\Local\Programs\Blitz\Blitz.exe [180674464 2025-04-01] (Swift Media Entertainment, Inc. -> Blitz, Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [EpicGamesLauncher] => E:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [37352464 2025-03-28] (Epic Games Inc. -> Epic Games, Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [Docker Desktop] => C:\Program Files\Docker\Docker\Docker Desktop.exe [2348104 2023-12-13] (Docker Inc -> Docker Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [AF_uuid_2139460] => da5435ee-067b-45b3-ae6d-cb0844de48bd (Ningún archivo)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [AF_counter_2139460] => 2 (Ningún archivo)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [AceStream] => C:\Users\asier\AppData\Roaming\ACEStream\engine\ace_engine.exe [96192 2024-07-09] (Innovative Digital Technologies, LLC -> Innovative Digital Technologies, LLC)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [Plex Media Server] => C:\Program Files\Plex\Plex Media Server\Plex Media Server.exe [29753608 2024-08-23] (Plex, Inc. -> Plex, Inc.)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [GalaxyClient] => [X]
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [GogGalaxy] => E:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [14359888 2024-11-12] (GOG sp. z o.o -> GOG.com)
HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Run: [MicrosoftEdgeAutoLaunch_65D608756315D3D26C4944115B9602E9] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4291144 2025-03-26] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3599496 2025-03-11] (Razer USA Ltd. -> Razer Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\134.0.6998.179\Installer\chrmstp.exe [2025-04-02] (Google LLC -> Google LLC)
Startup: C:\Users\asier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\metallizations.vbs [2025-04-03] () [Archivo no firmado]
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ableton Push Control Panel Autostart.lnk [2024-02-26]
ShortcutTarget: Ableton Push Control Panel Autostart.lnk -> C:\Program Files\Ableton\Push Driver\x64\AbletonPushCpl.exe (Thesycon Software Solutions GmbH & Co. KG -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Valeton USB Audio Device Control Panel Autostart.lnk [2023-12-01]
ShortcutTarget: Valeton USB Audio Device Control Panel Autostart.lnk -> C:\Program Files\Valeton\USB Audio Device Driver\x64\ValetonUsbAudioCpl.exe (Changsha Hotone Audio Co,. LTD -> )
GroupPolicy: Restricción ? <==== ATENCIÓN
Policies: C:\ProgramData\NTUSER.pol: Restricción <==== ATENCIÓN
==================== Tareas programadas (Lista blanca) =================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {BC2D68A7-4089-4719-82F7-1C7F7C13B182} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem136.0.7079.0{5284BEE0-4E6A-4415-A822-095F648C532E} => C:\Program Files (x86)\Google\GoogleUpdater\136.0.7079.0\updater.exe [7017568 2025-03-20] (Google LLC -> Google LLC)
Task: {FB27A4ED-7F26-4119-9536-B5D9E699AE10} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpCmdRun.exe [1745192 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9F7372E7-0CAE-4510-907D-A558873F3D8B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpCmdRun.exe [1745192 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {6896DBF8-FE84-48D7-8013-4D42AECFD96A} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpCmdRun.exe [1745192 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {40B38AE6-AF74-4911-8751-1D1A645836B1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpCmdRun.exe [1745192 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {94F3102B-68BD-4D1A-8176-FDFD932FD406} - System32\Tasks\OneDrive Startup Task-S-1-5-21-3457603053-2513319760-2250614245-1001 => C:\Users\asier\AppData\Local\Microsoft\OneDrive\25.041.0303.0002\OneDriveLauncher.exe [673064 2025-04-01] (Microsoft Corporation -> Microsoft Corporation)
Task: {162E8036-CF96-4247-A5FE-6C8494D51BDF} - System32\Tasks\UpdateTask => C:\Users\asier\AppData\Roaming\IPEvcon\AvastBrowserUpdate.exe [180240 2025-04-03] (Avast Software s.r.o. -> AVAST Software)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
Hosts: Hay más de una entrada en Hosts. Consulte la sección Hosts de Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2ce20538-a5e7-4539-8107-11191be6e8f0}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2ce20538-a5e7-4539-8107-11191be6e8f0}: [DhcpDomain] home
Tcpip\..\Interfaces\{74f75eee-f8ca-4d73-9db8-5b0a3ac25a6f}: [DhcpNameServer] 212.142.173.65 77.26.11.233
Edge:
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\asier\AppData\Local\Microsoft\Edge\User Data\Default [2025-04-03]
Edge Extension: (Documentos de Google sin conexión) - C:\Users\asier\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-31]hxxps://clients2.google.com/service/update2/crx
Edge Extension: (Edge relevant text changes) - C:\Users\asier\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-05-24]hxxps://edge.microsoft.com/extensionwebstorebase/v1/crx
Edge Extension: (Google Docs) - C:\Users\asier\AppData\Local\reisa\llg [2025-04-03] [UpdateUrl:0] <==== ATENCIÓN
FireFox:
========
FF HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\asier\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi
FF Extension: (Ace Script) - C:\Users\asier\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi [2018-11-26]
FF Plugin HKU\S-1-5-21-3457603053-2513319760-2250614245-1001: @acestream.net/acestreamplugin,version=3.2.8 -> C:\Users\asier\AppData\Roaming\ACEStream\player\npace_plugin.dll [2017-01-13] (Innovative Digital Technologies -> Innovative Digital Technologies)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default [2025-04-03]
CHR DownloadDir: E:\Descargas
CHR Notifications: Default -> hxxps://aternos.org; hxxps://web.telegram.org
CHR HomePage: Default -> hxxp://www.google.es/
CHR StartupUrls: Default -> "hxxp://www.google.es/"
CHR Extension: (uBlock Origin) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2025-03-22]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Documentos de Google sin conexión) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-03-26]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (AdBlock — block ads across the web) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2025-04-03]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (TweetDeck by Twitter) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2023-11-28]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Google Keep - Notes and Lists) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2025-03-28]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Rastreador de precios de Booking.com) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\kddajedgmmccjldkcbafjlmcpcgkaodp [2024-10-28]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Notion Web Clipper) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\knheggckgoiihginacbkhaalnibhilkk [2023-11-28]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Extensión de Google Keep para Chrome) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2025-04-03]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Ace Script) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjbepbhonbojpoaenhckjocchgfiaofo [2024-08-27]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Keepa - Amazon Price Tracker) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\neebplgakaahbhdphmkckjjcegoiijjo [2025-02-10]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\asier\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-28]hxxps://clients2.google.com/service/update2/crx
CHR Extension: (Google Docs) - C:\Users\asier\AppData\Local\reisa\llg [2025-04-03] [UpdateUrl:0] <==== ATENCIÓN
CHR HKU\S-1-5-21-3457603053-2513319760-2250614245-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo]
==================== Servicios (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3318400 2025-02-24] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
S3 com.docker.service; C:\Program Files\Docker\Docker\com.docker.service [20072 2023-12-13] (Docker Inc -> Docker Inc.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [1134624 2023-09-23] (EasyAntiCheat Oy -> Epic Games, Inc)
S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [954704 2024-06-23] (EasyAntiCheat Oy -> Epic Games, Inc.)
S3 EpicGamesUpdater; E:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3064848 2025-03-28] (Epic Games Inc. -> Epic Games, Inc.)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934352 2023-08-02] (Epic Games Inc. -> Epic Games, Inc.)
S3 GalaxyClientService; \\?\E:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [2368848 2024-11-12] (GOG sp. z o.o -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7627600 2024-11-12] (GOG sp. z o.o -> GOG.com)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9484384 2025-04-03] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-04-03] (Malwarebytes Inc. -> Malwarebytes)
R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpDefenderCoreService.exe [1968320 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe [1275000 2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation)
R2 PlexUpdateService; C:\Program Files\Plex\Plex Media Server\Plex Update Service.exe [903944 2024-08-23] (Plex, Inc. -> Plex, Inc.)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [1882024 2024-10-18] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [232360 2024-10-18] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma Stream Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzChromaStreamServer.exe [1268176 2024-07-18] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [256256 2024-10-15] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [300168 2025-03-11] (Razer USA Ltd. -> Razer Inc.)
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [513672 2025-03-06] (Razer USA Ltd. -> Razer Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [559328 2025-03-13] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 vgc; C:\Program Files\Riot Vanguard\vgc.exe [40071784 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
R2 Wallpaper Engine Service; E:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe [3647928 2025-02-23] (Skutta Software GmbH -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\NisSrv.exe [4464024 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MsMpEng.exe [270040 2025-04-01] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Controladores (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R3 FocusritePCIeSwRoot; C:\Windows\System32\drivers\FocusritePCIeSwRoot.sys [106824 2023-10-13] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsb; C:\Windows\System32\drivers\FocusriteUsb.sys [169800 2023-10-13] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsbAudio; C:\Windows\System32\drivers\FocusriteUsbAudio.sys [110408 2023-10-13] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 FocusriteUsbSwRoot; C:\Windows\System32\drivers\FocusriteUsbSwRoot.sys [112968 2023-10-13] (Focusrite Audio Engineering Ltd -> Focusrite Audio Engineering Ltd.)
R3 KslD; C:\Windows\System32\drivers\wd\KslD.sys [278960 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
R2 mbamchameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [234072 2025-04-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [22120 2025-04-03] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239568 2025-04-03] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 RzCommon; C:\Windows\System32\drivers\RzCommon.sys [64168 2022-08-18] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0064; C:\Windows\System32\drivers\RzDev_0064.sys [54152 2020-08-24] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_021e; C:\Windows\System32\drivers\RzDev_021e.sys [54168 2020-08-24] (Razer USA Ltd. -> Razer Inc)
S3 ValetonUsbAudio; C:\Windows\System32\drivers\ValetonUsbAudio.sys [413728 2022-08-17] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 ValetonUsbAudioks; C:\Windows\System32\drivers\ValetonUsbAudioks.sys [54808 2022-08-17] (Microsoft Windows Hardware Compatibility Publisher -> )
S1 vgk; C:\Program Files\Riot Vanguard\vgk.sys [27067392 2025-03-19] (Riot Games, Inc. -> Riot Games, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [20016 2025-04-01] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [601520 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [100744 2025-04-01] (Microsoft Windows -> Microsoft Corporation)
S3 NEProtect; \??\E:\Program Files (x86)\Steam\steamapps\common\Once Human\NEProtect.sys [X]
==================== NetSvcs (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
==================== Un mes (creado) (Lista blanca) =========
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2025-04-03 18:12 - 2025-04-03 18:13 - 000024058 _____ C:\Users\asier\Desktop\FRST.txt
2025-04-03 18:11 - 2025-04-03 18:13 - 000000000 ____D C:\FRST
2025-04-03 16:28 - 2025-04-03 16:28 - 002404864 _____ (Farbar) C:\Users\asier\Desktop\FRST64.exe
2025-04-03 15:56 - 2025-04-03 18:12 - 000000000 ____D C:\Users\asier\AppData\Local\Malwarebytes
2025-04-03 15:56 - 2025-04-03 15:56 - 000002093 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-04-03 15:56 - 2025-04-03 15:56 - 000002081 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2025-04-03 15:56 - 2025-04-03 15:56 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-04-03 15:56 - 2025-04-03 15:56 - 000000000 ____D C:\Program Files\Malwarebytes
2025-04-03 15:42 - 2025-04-03 15:42 - 000000000 ____D C:\Users\asier\AppData\Local\reisa
2025-04-03 15:41 - 2025-04-03 16:00 - 000000000 ____D C:\Users\asier\AppData\Roaming\IPEvcon
2025-04-03 15:41 - 2025-04-03 15:41 - 000003324 _____ C:\Windows\system32\Tasks\UpdateTask
2025-04-03 15:41 - 2025-04-03 15:41 - 000000000 ____D C:\Users\asier\AppData\Local\Yandex
2025-04-01 11:29 - 2025-04-01 11:29 - 000280625 _____ C:\Users\asier\Documents\entradas_21529446.pdf
2025-03-13 09:44 - 2025-03-13 09:44 - 000000000 ___HD C:\$WinREAgent
==================== Un mes (modificado) ==================
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2025-04-03 18:10 - 2024-05-01 16:04 - 000000001 _____ C:\Windows\vgkbootstatus.dat
2025-04-03 18:10 - 2019-12-07 11:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-04-03 18:02 - 2023-11-28 21:08 - 000000000 ____D C:\Windows\system32\SleepStudy
2025-04-03 16:08 - 2023-11-28 21:21 - 001773382 _____ C:\Windows\system32\PerfStringBackup.INI
2025-04-03 16:08 - 2019-12-07 16:55 - 000788510 _____ C:\Windows\system32\perfh00A.dat
2025-04-03 16:08 - 2019-12-07 16:55 - 000155898 _____ C:\Windows\system32\perfc00A.dat
2025-04-03 16:08 - 2019-12-07 11:13 - 000000000 ____D C:\Windows\INF
2025-04-03 16:02 - 2023-12-23 19:08 - 000000000 ____D C:\Users\asier\AppData\Local\CrashDumps
2025-04-03 16:01 - 2023-12-13 20:49 - 000001607 _____ C:\Windows\system32\config\VSMIDK
2025-04-03 16:01 - 2023-11-28 21:21 - 000000000 ____D C:\ProgramData\NVIDIA
2025-04-03 16:01 - 2023-11-28 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2025-04-03 16:01 - 2021-04-28 02:11 - 000008192 ___SH C:\DumpStack.log.tmp
2025-04-03 16:01 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ServiceState
2025-04-03 16:01 - 2019-12-07 11:03 - 000524288 _____ C:\Windows\system32\config\BBI
2025-04-03 15:56 - 2019-12-07 11:14 - 000000000 ___HD C:\Windows\ELAMBKUP
2025-04-03 09:15 - 2019-12-07 11:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-04-03 09:15 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\AppReadiness
2025-04-02 18:05 - 2023-11-29 18:48 - 000000000 ____D C:\Users\asier\AppData\Roaming\Blitz
2025-04-02 17:08 - 2024-02-23 17:30 - 000000000 ____D C:\Users\asier\AppData\Roaming\riot-client-ux
2025-04-02 17:08 - 2023-11-29 18:48 - 000000032 _____ C:\Users\asier\AppData\Roaming\.machineId
2025-04-02 17:08 - 2023-11-28 22:08 - 000000000 ____D C:\ProgramData\Riot Games
2025-04-02 08:19 - 2023-11-28 21:31 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2025-04-02 08:19 - 2023-05-05 14:24 - 000000000 ____D C:\Windows\SystemTemp
2025-04-01 18:44 - 2024-09-13 11:33 - 134222904 _____ C:\Windows\392667600.dat
2025-04-01 13:21 - 2025-02-06 10:06 - 000003576 _____ C:\Windows\system32\Tasks\OneDrive Startup Task-S-1-5-21-3457603053-2513319760-2250614245-1001
2025-04-01 13:21 - 2023-11-28 21:22 - 000003592 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-3457603053-2513319760-2250614245-1001
2025-04-01 13:21 - 2023-11-28 21:22 - 000003380 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3457603053-2513319760-2250614245-1001
2025-04-01 13:21 - 2023-11-28 21:18 - 000002417 _____ C:\Users\asier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-04-01 07:59 - 2023-11-28 21:08 - 000000000 ____D C:\Windows\system32\Drivers\wd
2025-03-31 18:11 - 2024-04-06 16:56 - 000000000 ____D C:\Users\asier\Desktop\Miyoo
2025-03-31 13:28 - 2023-11-28 21:20 - 000000000 ____D C:\Users\asier\AppData\Local\D3DSCache
2025-03-31 07:50 - 2023-11-28 21:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2025-03-31 07:48 - 2024-05-01 16:00 - 000000000 ____D C:\Program Files\Riot Vanguard
2025-03-28 18:35 - 2023-11-28 21:20 - 000000000 ____D C:\Users\asier\AppData\Local\Packages
2025-03-28 09:21 - 2023-11-28 21:08 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-03-20 09:13 - 2023-12-26 10:55 - 002897472 _____ (Microsoft Corporation) C:\Windows\system32\xgameruntime.dll
2025-03-20 09:13 - 2023-12-26 10:55 - 000788008 _____ (Microsoft Corporation) C:\Windows\system32\gameplatformservices.dll
2025-03-20 09:13 - 2023-12-26 10:55 - 000267816 _____ (Microsoft Corporation) C:\Windows\system32\gamelaunchhelper.dll
2025-03-20 09:13 - 2023-12-26 10:55 - 000243264 _____ (Microsoft Corporation) C:\Windows\system32\gameconfighelper.dll
2025-03-20 09:13 - 2023-12-26 10:55 - 000153152 _____ (Microsoft Corporation) C:\Windows\system32\gamingtcuihelpers.dll
2025-03-20 09:13 - 2023-12-26 10:55 - 000124480 _____ (Microsoft Corporation) C:\Windows\system32\xgamehelper.exe
2025-03-20 09:13 - 2023-12-26 10:55 - 000075304 _____ (Microsoft Corporation) C:\Windows\system32\xgamecontrol.exe
2025-03-13 18:42 - 2023-11-28 21:08 - 000269576 _____ C:\Windows\system32\FNTCACHE.DAT
2025-03-13 18:41 - 2023-11-28 21:21 - 000000000 ___SD C:\Windows\system32\lxss
2025-03-13 18:41 - 2019-12-07 16:58 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2025-03-13 18:41 - 2019-12-07 16:56 - 000000000 ____D C:\Windows\system32\OpenSSH
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SysWOW64\Dism
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\SystemResources
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\oobe
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\system32\Dism
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\ShellExperiences
2025-03-13 18:41 - 2019-12-07 11:14 - 000000000 ____D C:\Windows\bcastdvr
2025-03-13 18:41 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\servicing
2025-03-13 09:51 - 2019-12-07 11:03 - 000000000 ____D C:\Windows\CbsTemp
2025-03-13 09:48 - 2023-11-28 21:10 - 003016192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2025-03-10 09:18 - 2023-11-28 21:08 - 000003708 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-03-10 09:18 - 2023-11-28 21:08 - 000003584 _____ C:\Windows\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
==================== Archivos en la raíz de algunos directorios ========
2023-11-29 18:48 - 2025-04-02 17:08 - 000000032 _____ () C:\Users\asier\AppData\Roaming\.machineId
2024-12-30 21:36 - 2024-12-30 21:36 - 000000218 _____ () C:\Users\asier\AppData\Local\recently-used.xbel
2023-12-01 22:56 - 2023-12-01 22:56 - 000026564 _____ () C:\Users\asier\AppData\Local\TempTemporary.wav
==================== SigCheck ============================
(No existe una corrección automática para los archivos que no pasan la verificación.)
==================== Final de FRST.txt ========================