Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 21-08-2025 Ejecutado por Ricardo (administrador) sobre DESKTOP-5VKPPIP (Gigabyte Technology Co., Ltd. Z390 AORUS MASTER) (31-08-2025 20:12:05) Ejecutado desde C:\Users\Ricardo\Desktop\FRST64 (1).exe Perfiles cargados: Ricardo Plataforma: Microsoft Windows 11 Education Versión 24H2 26100.5074 (X64) Idioma: Español (España, internacional) Navegador predeterminado: Chrome Modo de Inicio: Normal ==================== Procesos (Lista blanca) ================= (Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.) () [Archivo no firmado] C:\Program Files (x86)\Labtec\Keyboard\V5.1\KBDAP32A.EXE (5BD5593D-A41B-4F89-884E-B4F3E0FBAA75 -> Apple Inc.) C:\Program Files\WindowsApps\AppleInc.AppleDevices_1.1284.24577.0_x64__nzyj5cx40ttqa\AppleMobileDeviceProcess.exe (C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSATray.exe (C:\Program Files (x86)\Windows MV\ScreenConnect.ClientService.exe ->) (Connectwise, LLC -> ScreenConnect Software) C:\Program Files (x86)\Windows MV\ScreenConnect.WindowsClient.exe (C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\LAClient\laclient.exe (C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_appbroker.exe (C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe ->) (Logitech Inc -> Sentry and Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logi_crashpad_handler.exe <2> (C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe (C:\Program Files\Logitech\SetPointP\SetPoint.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (explorer.exe ->) () [Archivo no firmado] C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe (explorer.exe ->) () [Archivo no firmado] C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe (explorer.exe ->) (AVerMedia TECHNOLOGIES, Inc.) [Archivo no firmado] C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe (explorer.exe ->) (Cloudflare, Inc. -> Cloudflare) C:\Program Files\Cloudflare\Cloudflare WARP\Cloudflare WARP.exe (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <14> (explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <11> (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\x64\esrv.exe (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (services.exe ->) () [Archivo no firmado] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe (services.exe ->) (AOMEI International Network Limited -> AOMEI International Network Limited) C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.2\ABService.exe (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (services.exe ->) (AVerMedia TECHNOLOGIES, Inc.) [Archivo no firmado] C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe (services.exe ->) (AVerMedia) [Archivo no firmado] C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe (services.exe ->) (Cloudflare, Inc. -> ) C:\Program Files\Cloudflare\Cloudflare WARP\warp-svc.exe (services.exe ->) (Connectwise, LLC -> ) C:\Program Files (x86)\Windows MV\ScreenConnect.ClientService.exe (services.exe ->) (Hewlett-Packard Company -> HP) [Archivo no firmado] C:\Windows\System32\HPSIsvc.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Intel Corporation -> ) C:\Program Files\Intel\SUR\QUEENCREEK\SurSvc.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe (services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe (services.exe ->) (Intel Corporation -> Intel) C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation) [Archivo no firmado] C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MsMpEng.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe <2> (svchost.exe ->) (24803D75-212C-471A-BC57-9EF86AB91435 -> ) C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2534.2.0_x64__cv1g1gvanyjgm\WhatsApp.exe (svchost.exe ->) (Dolby Laboratories, Inc. -> Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (svchost.exe ->) (Intel Corporation -> Intel Corporation) C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SecHealthUI_1000.27840.1000.0_x64__8wekyb3d8bbwe\SecHealthUI.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.92.1.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe <3> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SecurityHealth\10.0.27840.1000-0\SecurityHealthHost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe Error al acceder al proceso -> AVerRemote.exe ==================== Registro (Lista blanca) =================== (Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-10] (Adobe Systems Incorporated -> Adobe Systems Incorporated) HKLM\...\Run: [GamecomSound] => C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe [2453504 2024-03-21] () [Archivo no firmado] HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3138560 2023-01-11] (Logitech Inc -> Logitech, Inc.) HKLM\...\Run: [] => [X] HKLM\...\Run: [Acrobat Assistant 8.0] => C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrotray.exe [10723232 2025-06-05] (Adobe Inc. -> Adobe Systems Inc.) [Archivo no firmado] HKLM\...\Run: [AdobeGCInvoker-1.0] => "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe" (Ningún archivo) HKLM-x32\...\Run: [OFFICEKB] => C:\Program Files (x86)\Labtec\Keyboard\V5.1\kbdap32a.exe [387584 2024-03-20] () [Archivo no firmado] HKU\S-1-5-19\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4978576 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [OneDrive] => C:\Program Files\Microsoft OneDrive\OneDrive.exe [4978576 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-231195856-3100956415-3167264710-1000\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" (Ningún archivo) HKU\S-1-5-21-231195856-3100956415-3167264710-1000\...\Run: [MicrosoftEdgeAutoLaunch_8C464BBCD19C16ED3CCFC960C2CD5F90] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [4117544 2025-08-28] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-231195856-3100956415-3167264710-1000\...\MountPoints2: {ae5d3027-e6e6-11ee-ace8-d43b04e7fe36} - "F:\setup.exe" HKU\S-1-5-21-231195856-3100956415-3167264710-1000\...\MountPoints2: {dc124bd5-5d77-11f0-ada9-d43b04e7fe36} - "E:\AutoRun.exe" HKLM\...\Windows x64\Print Processors\HPCP1020PP: C:\Windows\System32\spool\prtprocs\x64\HPCP1020PP.DLL [65024 2012-11-28] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.) HKLM\...\Windows x64\Print Processors\hpcpp270: C:\Windows\System32\spool\prtprocs\x64\hpcpp270.dll [873168 2023-05-30] (HP Inc. -> HP Inc.) HKLM\...\Windows x64\Print Processors\hpcpp300: C:\Windows\System32\spool\prtprocs\x64\hpcpp300.dll [879520 2024-04-08] (HP Inc. -> HP Inc.) HKLM\...\Windows x64\Print Processors\hpcpp330: C:\Windows\System32\spool\prtprocs\x64\hpcpp330.dll [881056 2025-04-03] (HP Inc. -> HP Inc.) HKLM\...\Windows x64\Print Processors\hpcpp340: C:\Windows\System32\spool\prtprocs\x64\hpcpp340.dll [881032 2025-06-30] (HP Inc. -> HP Inc.) HKLM\...\Print\Monitors\Adobe PDF Port Monitor: C:\WINDOWS\system32\AdobePDF.dll [203936 2025-05-30] (Adobe Inc. -> Adobe Systems Inc) HKLM\...\Print\Monitors\HP CP1020 LM: C:\WINDOWS\system32\HPCP1020LM.DLL [129024 2012-11-28] (Microsoft Windows Hardware Compatibility Publisher -> ) HKLM\...\Print\Monitors\HP Standard TCP/IP Port: C:\WINDOWS\system32\HpTcpMon.dll [331264 2009-09-16] (Hewlett Packard) [Archivo no firmado] HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\WINDOWS\system32\HPMPW082.DLL [130984 2025-06-30] (HP Inc. -> HP Inc.) HKLM\...\Print\Monitors\HPMLM225: C:\WINDOWS\system32\hpmlm225.dll [318160 2023-05-30] (HP Inc. -> HP Inc.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\139.0.7258.128\Installer\chrmstp.exe [2025-08-19] (Google LLC -> Google LLC) HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{73FA19D0-2D75-11D2-995D-00C04F98BBC9}] -> HKLM\Software\...\Authentication\Credential Providers: [{6FF59A85-BC37-4CD4-BD8E-5AE965B838AB}] -> C:\Program Files (x86)\Windows MV\ScreenConnect.WindowsCredentialProvider.dll [2024-12-18] (Connectwise, LLC -> ) Lsa: [Authentication Packages] msv1_0 C:\Program Files (x86)\Windows MV\ScreenConnect.WindowsAuthenticationPackage.dll Startup: C:\Users\Ricardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE XTREME GAMING ENGINE.lnk [2024-07-04] ShortcutTarget: GIGABYTE XTREME GAMING ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\autorun.exe () [Archivo no firmado] Startup: C:\Users\Ricardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\taskmgr.lnk [2024-11-06] ShortcutTarget: taskmgr.lnk -> C:\Users\Ricardo\AppData\Local\Packages\wlogon.exe (Ningún archivo) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVer HID Receiver.lnk [2024-03-21] ShortcutTarget: AVer HID Receiver.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe () [Archivo no firmado] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AVerQuick.lnk [2024-03-21] ShortcutTarget: AVerQuick.lnk -> C:\Program Files (x86)\Common Files\AVerMedia\AVerQuick\AVerQuick.exe (AVerMedia TECHNOLOGIES, Inc.) [Archivo no firmado] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Cloudflare WARP.lnk [2025-08-22] ShortcutTarget: Cloudflare WARP.lnk -> C:\Program Files\Cloudflare\Cloudflare WARP\Cloudflare WARP.exe (Cloudflare, Inc. -> Cloudflare) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2024-03-23] ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation -> Microsoft Corporation) GroupPolicy: Restricción ? <==== ATENCIÓN Policies: C:\ProgramData\NTUSER.pol: Restricción <==== ATENCIÓN ==================== Tareas programadas (Lista blanca) ================= (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.) Task: {3CE3FE85-DADD-4F8A-BCA4-B40941DC634E} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-08-31] (Dolby Laboratories, Inc. -> Dolby Laboratories Inc.) Task: {26EDDB26-F428-4879-9D05-2E63BA969B71} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem141.0.7340.0{84F1AA39-05EA-4398-AE1C-74BEDA9CAAD7} => C:\Program Files (x86)\Google\GoogleUpdater\141.0.7340.0\updater.exe [6813336 2025-08-06] (Google LLC -> Google LLC) Task: {4DC36642-5468-4FC4-AD23-26B26C0F43C6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send (Ningún archivo) Task: {F01753EA-136D-49B6-894D-6A672290BFDA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe -> C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\/f Task: {EB8126F3-82BA-409C-BCE0-3A141303FE6C} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-15] (Intel Corporation -> Intel Corporation) Task: {57C8568B-910D-49E9-AD50-8D54B2E3E9C1} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4916640 2024-04-15] (Intel Corporation -> Intel Corporation) Task: {58447756-6508-449D-B35C-52F5EDCF4A66} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe --automatic (Ningún archivo) Task: {CBBC6AC5-E97B-4D7A-BE6F-7FDC204E23DC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2401792 2025-06-09] () [Archivo no firmado] Task: {8715759E-31BD-4166-9E0B-FCCEB2E1466B} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491744 2024-03-07] (Microsoft Corporation -> Microsoft Corporation) Task: {B356FB44-84EA-4F22-9799-CAD4842D24B3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28491744 2024-03-07] (Microsoft Corporation -> Microsoft Corporation) Task: {D34DB340-E5AE-48C8-B31B-ACFA22E95441} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309184 2024-03-23] (Microsoft Corporation -> Microsoft Corporation) Task: {9AF4E7B2-90A4-46EC-B05B-80ABDE3DE53E} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [309184 2024-03-23] (Microsoft Corporation -> Microsoft Corporation) Task: {DC9F9F3B-8323-4995-A671-BF4B12B0C9FE} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [170136 2024-03-23] (Microsoft Corporation -> Microsoft Corporation) Task: {077BA067-7C15-40F0-B22E-C9DC2A54B4A2} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (Ningún archivo) Task: {85DABA04-83AF-4E9C-B346-8C2D865972E4} - System32\Tasks\Microsoft\Windows\Shell\UndockedFlightingUpdate => C:\WINDOWS\system32\UndockedFlightingUpdateTask.exe [81920 2025-08-30] (Microsoft Windows -> Microsoft Corporation) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Ningún archivo) Task: {B468EE6A-B575-459A-A3C1-6BFB94EE0EA4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {90B7BDB2-CB5C-444E-8689-E58EDD51204F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {0DC2625C-C257-45B4-9727-949C56D9B907} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {97BE88D5-010E-4215-B7E1-83A4CB1A173D} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpCmdRun.exe [1778240 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {6B68D74B-ADB3-46F6-91BB-D02CA00E7C23} - System32\Tasks\OneDrive Per-Machine Standalone Update Task => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4232592 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) Task: {5CD7A8E6-2589-4DAA-83A2-DE8D81251F3A} - System32\Tasks\OneDrive Reporting Task-S-1-5-21-231195856-3100956415-3167264710-1000 => C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe [4232592 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) Task: {373922F3-419A-4145-892C-501FB6802B2E} - System32\Tasks\OneDrive Startup Task-S-1-5-21-231195856-3100956415-3167264710-1000 => C:\Program Files\Microsoft OneDrive\25.140.0720.0001\OneDriveLauncher.exe [723816 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) Task: {38117423-861B-4799-9A15-F99DAC98B91B} - System32\Tasks\Opera scheduled Autoupdate 1710967547 => C:\Users\Ricardo\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe [6239704 2025-08-19] (Opera Norway AS -> Opera Software) Task: {DB417F3D-C51C-4D66-A278-1C0A3E30AAA1} - System32\Tasks\Remove AdwCleaner Application => C:\WINDOWS\system32\CMD.EXE [344064 2025-08-30] (Microsoft Windows -> Microsoft Corporation) -> /C DEL /F /Q "C:\Users\Ricardo\Downloads\adwcleaner.exe" Task: {B74687A0-9134-4324-B742-B3A338BD739C} - System32\Tasks\Uninstall AdwCleaner Application => C:\Users\Ricardo\Downloads\adwcleaner.exe [9616736 2025-08-31] (Malwarebytes Inc -> Malwarebytes) Task: {EB0E8FED-19DD-4E10-818D-233B91D1279B} - System32\Tasks\Updater => C:\Users\Public\Updater.vbs [370 2025-08-31] () [Archivo no firmado] <==== ATENCIÓN Task: {C780B985-C4F7-4530-80E4-A69ACA18E9C5} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\Windows\System32\Wscript.exe [204800 2025-08-30] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" (Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe ==================== Internet (Lista blanca) ==================== (Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.) Hosts: Hay más de una entrada en Hosts. Consulte la sección Hosts de Addition.txt Tcpip\Parameters: [DhcpNameServer] 100.100.1.1 100.90.1.1 Tcpip\..\Interfaces\{29d989e8-df71-4ed8-a703-b213ee67b51e}: [DhcpNameServer] 100.100.1.1 100.90.1.1 Tcpip\..\Interfaces\{b97a2716-1e16-4f34-9f69-2d2e58f3cecb}: [DhcpNameServer] 8.8.8.8 Edge: ======= Edge Profile: C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default [2025-08-31] Edge HomePage: Default -> hxxps://www.google.es/ Edge StartupUrls: Default -> "hxxp://www.google.es/" Edge Extension: (MEGA) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2025-08-31] [UpdateUrl:hxxps://mega.nz/firefox-web-extension-updates.json] <==== ATENCIÓN Edge Extension: (Llamadas de Skype) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2024-03-20] Edge Extension: (Avast Passwords) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2025-04-12] Edge Extension: (Avast Online Security & Privacy) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fdgpikaaheckgdijjmepmdjjkbceakif [2025-03-19] Edge Extension: (Marcadores en iCloud) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2024-03-20] Edge Extension: (Complemento inhabilitación Google Analytics) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2024-05-09] Edge Extension: (Documentos de Google sin conexión) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-08-31] Edge Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\gmgoamodcdcjnbaobigkjelfplakmdhh [2025-08-31] Edge Extension: (MyJDownloader Browser Extension) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ieapabanbplofifeaapjocpaogdhncdd [2024-03-20] Edge Extension: (Online Security) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jcpgbnbdnakoblgfkbgggankeidkfcdl [2025-08-19] Edge Extension: (MEGA) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jemjknhgpjaacbghpdhgchbgccbpkkgf [2025-08-31] Edge Extension: (Edge relevant text changes) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-03-20] Edge Extension: (Cookie-Editor) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\neaplmfkghagebokkhpjpoebhdledlfi [2025-06-03] Edge Extension: (PrintFriendly - Imprimir, PDF y captura de pantalla de páginas web) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\nhiebejbpolmpkikgbijamagibifhjib [2025-08-19] Edge Extension: (Contraseñas en iCloud) - C:\Users\Ricardo\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pejdijmoenmkgeppbflobdenhhabjlaj [2025-08-31] Edge HKU\S-1-5-21-231195856-3100956415-3167264710-1000\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl] Edge HKLM-x32\...\Edge\Extension: [jcpgbnbdnakoblgfkbgggankeidkfcdl] FireFox: ======== FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Extension: (Adobe Acrobat) - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2021-02-01] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2024-05-01] [no firmado] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2024-03-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2025-05-30] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2024-03-23] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2024-03-23] (Microsoft Corporation -> Microsoft Corporation) Chrome: ======= CHR Profile: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default [2025-08-31] CHR Notifications: Default -> hxxps://digital.comunidad.madrid; hxxps://www.iberia.com; hxxps://www.netflix.com; hxxps://www.passfab.es; hxxps://www.xmaduras.com CHR HomePage: Default -> hxxps://www.google.es/ CHR StartupUrls: Default -> "hxxp://www.google.es/" CHR DefaultSearchKeyword: Default -> google.es______________________________________________________________ CHR Extension: (MEGA) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2025-08-29] [UpdateUrl:hxxps://mega.nz/firefox-web-extension-updates.json] <==== ATENCIÓN CHR Extension: (Llamadas de Skype) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2024-03-20] CHR Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2025-08-29] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2025-08-27] CHR Extension: (MyJDownloader Browser Extension) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbcohnmimjicjdomonkcbcpbpnhggkip [2024-03-20] CHR Extension: (Marcadores en iCloud) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2024-03-20] CHR Extension: (Complemento inhabilitación Google Analytics) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2024-05-09] CHR Extension: (Documentos de Google sin conexión) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2025-08-27] CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2024-03-20] CHR Extension: (PrintFriendly - Imprimir, PDF y captura de pantalla de páginas web) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2025-08-14] CHR Extension: (Cookie Editor) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ookdjilphngeeeghgngjabigmpepanpl [2025-07-18] CHR Extension: (Contraseñas en iCloud) - C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pejdijmoenmkgeppbflobdenhhabjlaj [2025-08-23] CHR Profile: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\System Profile [2025-02-17] CHR HKU\S-1-5-21-231195856-3100956415-3167264710-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKU\S-1-5-21-231195856-3100956415-3167264710-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKLM-x32\...\Chrome\Extension: [llbcnfanfmjhpedaedhbcnpgeepdnnok] Opera: ======= OPR DefaultProfile: Default ==================== Servicios (Lista blanca) =================== (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.) S4 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [174520 2025-03-21] (Adobe Inc. -> Adobe Inc.) R2 AVerRemote; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRemote.exe [360448 2024-03-21] (AVerMedia) [Archivo no firmado] R2 AVerScheduleService; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerScheduleService.exe [403456 2024-03-21] () [Archivo no firmado] R2 AVerUpdateServer; C:\Program Files (x86)\AVerMedia\AVerUpdate\AVerUpdateServer.exe [167936 2011-10-31] (AVerMedia TECHNOLOGIES, Inc.) [Archivo no firmado] R2 Backupper Service; C:\Program Files (x86)\AOMEI\AOMEI Backupper\7.4.2\ABService.exe [1109232 2024-09-19] (AOMEI International Network Limited -> AOMEI International Network Limited) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [14097992 2024-03-07] (Microsoft Corporation -> Microsoft Corporation) R2 CloudflareWARP; C:\Program Files\Cloudflare\Cloudflare WARP\warp-svc.exe [48867448 2025-08-21] (Cloudflare, Inc. -> ) R2 DSAService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAService.exe [124008 2025-06-03] (Intel Corporation -> Intel) R2 DSAUpdateService; C:\Program Files (x86)\Intel\Driver and Support Assistant\x86\DSAUpdateService.exe [123496 2025-06-03] (Intel Corporation -> Intel) S3 FileSyncHelper; C:\Program Files\Microsoft OneDrive\25.140.0720.0001\FileSyncHelper.exe [3639184 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243720 2025-08-26] (HP Inc. -> HP Inc.) R2 HPSIService; C:\Windows\system32\HPSIsvc.exe [124536 2012-12-25] (Hewlett-Packard Company -> HP) [Archivo no firmado] R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MpDefenderCoreService.exe [2050952 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7Debug\mdm.exe [270336 2001-02-23] (Microsoft Corporation) [Archivo no firmado] R2 Microsoft; C:\Program Files (x86)\Windows MV\ScreenConnect.ClientService.exe [95512 2024-12-18] (Connectwise, LLC -> ) R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2019-02-01] (HP Inc.) [Archivo no firmado] R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_0afec3f2050014a0\Display.NvContainer\NVDisplay.Container.exe [1275000 2024-09-15] (NVIDIA Corporation -> NVIDIA Corporation) S3 OneDrive Updater Service; C:\Program Files\Microsoft OneDrive\25.140.0720.0001\OneDriveUpdaterService.exe [3922304 2025-08-19] (Microsoft Corporation -> Microsoft Corporation) R2 OptionsPlusUpdaterService; C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe [21271888 2025-08-20] (Logitech Inc -> Logitech, Inc.) R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2019-02-01] (HP Inc.) [Archivo no firmado] S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [918456 2025-07-23] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\NisSrv.exe [4517784 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25070.5-0\MsMpEng.exe [282464 2025-08-07] (Microsoft Windows Publisher -> Microsoft Corporation) S2 HPSupportSolutionsFrameworkService; "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe" [X] ===================== Controladores (Lista blanca) =================== (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.) S3 AcpiAudioCompositorInbox; C:\WINDOWS\System32\DriverStore\FileRepository\acpiaudiocompositor.inf_amd64_047f553a6f70b169\AcpiAudioCompositor.sys [102400 2025-08-30] (Microsoft Windows -> Microsoft Corporation) R0 ambakdrv; C:\WINDOWS\System32\ambakdrv.sys [51120 2024-04-29] (CHENGDU AOMEI Tech Co., Ltd. -> ) R3 AmdTools64; C:\WINDOWS\System32\drivers\AmdTools64.sys [63392 2020-06-16] (Microsoft Windows Hardware Compatibility Publisher -> ) R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [172928 2025-03-30] (AOMEI International Network Limited -> ) S3 ampa; C:\Windows\system32\ampa.sys [38320 2017-02-28] (CHENGDU AOMEI Tech Co., Ltd. -> ) R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [32176 2025-03-30] (AOMEI International Network Limited -> ) S3 ASUSU7; C:\WINDOWS\system32\DRIVERS\ASUSU7.SYS [406016 2024-03-21] (C-MEDIA ELECTRONICS INC. -> C-Media Inc.) R3 AVerHybrid; C:\WINDOWS\system32\drivers\averhbtv.sys [337280 2009-08-20] (Microsoft Windows Hardware Compatibility Publisher -> AVerMedia TECHNOLOGIES, Inc.) S3 ddmdrv; C:\Windows\system32\ddmdrv.sys [35760 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> ) R3 e1dexpress; C:\WINDOWS\System32\DriverStore\FileRepository\e1d.inf_amd64_09270b2481e30fca\e1d.sys [613072 2024-03-13] (Intel Corporation -> Intel Corporation) S3 gdrv3; C:\WINDOWS\gdrv3.sys [36352 2024-07-02] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.) S3 GVCIDrv; C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\GVCIDrv64.sys [16712 2019-01-15] (GIGA-BYTE TECHNOLOGY CO., LTD. -> ) R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [332184 2025-08-07] (Microsoft Windows -> Microsoft Corporation) S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.) S3 SdcaHidInbox; C:\WINDOWS\System32\DriverStore\FileRepository\sdcahid.inf_amd64_9b043c5c82568ed0\SdcaHid.sys [159744 2025-08-30] (Microsoft Windows -> Microsoft Corporation) S3 SdcaMfdInbox; C:\WINDOWS\System32\DriverStore\FileRepository\sdcamfd.inf_amd64_7616b07de0d13d6f\SdcaMfd.sys [176128 2025-08-30] (Microsoft Windows -> Microsoft Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [20888 2025-08-07] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [627120 2025-08-07] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [101792 2025-08-07] (Microsoft Windows -> Microsoft Corporation) S3 wintun; C:\WINDOWS\System32\drivers\wintun.sys [29592 2025-03-28] (Microsoft Windows Hardware Compatibility Publisher -> WireGuard LLC) R3 WSDPrintDevice; C:\WINDOWS\System32\DriverStore\FileRepository\wsdprint.inf_amd64_1f9e32519098c0b6\WSDPrint.sys [57344 2024-09-06] (Microsoft Windows -> Microsoft Corporation) S3 usbscan; \SystemRoot\System32\DriverStore\FileRepository\sti.inf_amd64_971c769b103df369\usbscan.sys [X] ==================== NetSvcs (Lista blanca) =================== (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.) ==================== Un mes (creado) (Lista blanca) ========= (Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.) 2025-08-31 20:12 - 2025-08-31 20:12 - 000036376 _____ C:\Users\Ricardo\Desktop\FRST.txt 2025-08-31 19:55 - 2025-08-31 18:46 - 002409472 _____ (Farbar) C:\Users\Ricardo\Desktop\FRST64 (1).exe 2025-08-31 19:47 - 2025-08-31 19:47 - 000000000 ___HD C:\$SysReset 2025-08-31 19:16 - 2025-08-31 19:16 - 000753716 _____ C:\WINDOWS\system32\perfh00A.dat 2025-08-31 19:16 - 2025-08-31 19:16 - 000156488 _____ C:\WINDOWS\system32\perfc00A.dat 2025-08-31 19:13 - 2025-08-31 19:13 - 000425747 _____ C:\Users\Ricardo\Downloads\DTKill.zip 2025-08-31 19:09 - 2025-08-31 19:09 - 000000000 ____D C:\Users\Ricardo\Downloads\DT-Kill 2025-08-31 18:48 - 2025-08-31 18:48 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Ricardo\Downloads\rkill.exe 2025-08-31 18:46 - 2025-08-31 18:46 - 002409472 _____ (Farbar) C:\Users\Ricardo\Downloads\FRST64 (1).exe 2025-08-31 18:32 - 2025-08-31 18:32 - 000003310 _____ C:\WINDOWS\system32\Tasks\Remove AdwCleaner Application 2025-08-31 18:32 - 2025-08-31 18:32 - 000003292 _____ C:\WINDOWS\system32\Tasks\Uninstall AdwCleaner Application 2025-08-31 17:43 - 2025-08-31 17:43 - 002844576 _____ (Malwarebytes) C:\Users\Ricardo\Downloads\MBSetup.exe 2025-08-31 17:11 - 2025-08-31 17:57 - 000865928 _____ C:\WINDOWS\ntbtlog.txt 2025-08-31 10:51 - 2025-08-31 11:37 - 000000000 ___HD C:\$WINDOWS.~BT 2025-08-31 10:51 - 2025-08-31 11:18 - 000001908 _____ C:\WINDOWS\diagwrn.xml 2025-08-31 10:51 - 2025-08-31 11:18 - 000001908 _____ C:\WINDOWS\diagerr.xml 2025-08-31 09:02 - 2025-08-31 09:02 - 009616736 _____ (Malwarebytes) C:\Users\Ricardo\Downloads\adwcleaner.exe 2025-08-31 08:37 - 2025-08-31 12:44 - 000000000 ____D C:\WINDOWS\CbsTemp 2025-08-30 23:53 - 2025-08-30 23:53 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware 2025-08-30 23:16 - 2025-08-30 23:18 - 000175386 _____ C:\Users\Ricardo\Downloads\Addition.txt 2025-08-30 23:15 - 2025-08-30 23:16 - 000059588 _____ C:\Users\Ricardo\Downloads\FRST.txt 2025-08-30 23:14 - 2025-08-31 20:12 - 000000000 ____D C:\FRST 2025-08-30 23:13 - 2025-08-30 23:13 - 002409472 _____ (Farbar) C:\Users\Ricardo\Downloads\FRST64.exe 2025-08-30 23:11 - 2025-08-30 23:23 - 1528410112 _____ C:\Users\Ricardo\Downloads\Win11_24H2_Spanish_x64 (2).iso 2025-08-30 21:24 - 2025-08-30 21:24 - 000077233 _____ C:\WINDOWS\SysWOW64\ctac.json 2025-08-30 21:24 - 2025-08-30 21:24 - 000077233 _____ C:\WINDOWS\system32\ctac.json 2025-08-30 21:24 - 2025-08-30 21:24 - 000001681 _____ C:\WINDOWS\system32\DeviceFeatureDDF.json 2025-08-30 18:54 - 2025-08-31 19:15 - 000000073 _____ C:\Bug_TKill.txt 2025-08-30 18:54 - 2025-08-31 19:15 - 000000000 ____D C:\DTRToll 2025-08-30 18:53 - 2025-08-30 18:53 - 000655848 _____ C:\Users\Ricardo\Downloads\DT-Kill.zip 2025-08-30 17:10 - 2025-08-30 17:10 - 000119014 _____ C:\Users\Ricardo\Downloads\el-club-del-crimen-de-los-jueves--2025---4KUHDrip_24_4056.torrent 2025-08-30 15:46 - 2025-08-30 16:12 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\Avast Software 2025-08-30 15:44 - 2025-08-30 16:12 - 000000000 ____D C:\Users\Ricardo\AppData\Local\AVAST Software 2025-08-30 15:42 - 2025-08-30 16:14 - 000000000 ____D C:\ProgramData\Avast Software 2025-08-29 08:28 - 2025-08-31 20:12 - 000003702 _____ C:\WINDOWS\system32\Tasks\Updater 2025-08-29 08:28 - 2025-08-31 20:12 - 000000370 _____ C:\Users\Public\Updater.vbs 2025-08-29 07:21 - 2025-08-29 07:21 - 000392535 _____ C:\Users\Ricardo\Downloads\this_month_in_anesthesiology.3.pdf 2025-08-27 11:21 - 2025-08-27 11:21 - 000144823 _____ C:\Users\Ricardo\Downloads\f1-la-pelicula--2025---BluRay-720p_23_3059.torrent 2025-08-22 13:25 - 2025-08-22 13:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cloudflare 2025-08-22 13:08 - 2025-08-22 13:08 - 067421328 _____ (KLCP ) C:\Users\Ricardo\Downloads\K-Lite_Codec_Pack_1915_Mega.exe 2025-08-22 13:00 - 2025-08-22 13:00 - 000668495 _____ C:\Users\Ricardo\Downloads\La ciudad sin luz. Mil ojos esconde la noche - Juan Manuel de Prada.epub 2025-08-22 12:56 - 2025-08-22 12:56 - 000905183 _____ C:\Users\Ricardo\Downloads\La ciudad sin luz. Cárcel de tinieblas - Juan Manuel de Prada .epub 2025-08-20 18:28 - 2025-08-30 22:16 - 000000000 ____D C:\Program Files\LogiOptionsPlus 2025-08-20 18:28 - 2025-08-20 18:28 - 000000859 _____ C:\Users\Public\Desktop\Logi Options+.lnk 2025-08-20 18:28 - 2025-08-20 18:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 2025-08-19 12:41 - 2025-06-30 13:24 - 000881032 _____ (HP Inc.) C:\WINDOWS\system32\spool\prtprocs\x64\hpcpp340.dll 2025-08-19 12:40 - 2025-06-30 13:31 - 000206728 _____ (HP Inc.) C:\WINDOWS\system32\hpmtp340.dll 2025-08-19 12:40 - 2025-06-30 13:29 - 000267656 _____ (HP Inc.) C:\WINDOWS\system32\hpmml340.dll 2025-08-19 12:40 - 2025-06-30 13:29 - 000233384 _____ (HP Inc.) C:\WINDOWS\system32\hpmpm082.dll 2025-08-19 12:40 - 2025-06-30 13:29 - 000130984 _____ (HP Inc.) C:\WINDOWS\system32\hpmpw082.dll 2025-08-19 12:40 - 2025-06-30 13:28 - 000245672 _____ (HP Inc.) C:\WINDOWS\system32\hpmja340.dll 2025-08-19 12:40 - 2025-06-30 13:24 - 000601992 _____ (HP Inc.) C:\WINDOWS\system32\hpcpn340.dll 2025-08-19 12:40 - 2025-06-30 13:04 - 000564616 _____ (HP Inc.) C:\WINDOWS\SysWOW64\hpcc3340.dll 2025-08-19 12:40 - 2023-05-30 10:17 - 000180944 _____ (HP Inc.) C:\WINDOWS\system32\hpcjpm.dll 2025-08-19 12:39 - 2025-08-19 12:39 - 000000000 ____D C:\Users\Ricardo\Downloads\upd-pcl6-x64-7.8.0.26261 2025-08-19 12:37 - 2025-08-19 12:37 - 022212658 _____ C:\Users\Ricardo\Downloads\upd-pcl6-x64-7.8.0.26261.zip 2025-08-19 10:40 - 2025-08-19 10:40 - 016308096 _____ C:\Users\Ricardo\Downloads\lj2420_fw_util_08_120_4 (4).exe 2025-08-19 10:39 - 2025-08-19 10:39 - 016308096 _____ C:\Users\Ricardo\Downloads\lj2420_fw_util_08_120_4 (3).exe 2025-08-19 10:39 - 2025-08-19 10:39 - 000000000 ____D C:\HP LaserJet lj2420 Firmware v08.120.4 2025-08-19 10:37 - 2025-08-19 10:37 - 016045104 _____ C:\Users\Ricardo\Downloads\lj2420_fw_08_120_4 (4).zip 2025-08-19 10:36 - 2025-08-19 10:36 - 016045104 _____ C:\Users\Ricardo\Downloads\lj2420_fw_08_120_4 (3).zip 2025-08-18 12:53 - 2025-08-18 12:53 - 000165242 _____ C:\Users\Ricardo\Downloads\maria-callas--2024---BluRay-1080p_28_1029.torrent 2025-08-18 12:50 - 2025-08-18 12:50 - 000022745 _____ C:\Users\Ricardo\Downloads\148453_-1616583653-Traffic-Criterion-Edition--BluRay-1080p.torrent 2025-08-17 11:21 - 2025-08-17 11:21 - 000099007 _____ C:\Users\Ricardo\Downloads\mail.google.com-Reserva confirmada en el Complejo San Juan no de reserva 0079786 - rmlarraurigmailcom.pdf 2025-08-17 09:22 - 2025-08-30 22:16 - 000000000 ____D C:\vDos 2025-08-17 09:22 - 2025-08-17 09:22 - 002601488 _____ ( ) C:\Users\Ricardo\Downloads\vDosSetup.exe 2025-08-17 09:22 - 2025-08-17 09:22 - 000000587 _____ C:\Users\Public\Desktop\vDos - Initial test.lnk 2025-08-16 12:55 - 2025-08-16 13:00 - 129724416 _____ C:\Users\Ricardo\Downloads\Cloudflare_WARP_2025.5.943.0.msi 2025-08-16 09:35 - 2025-08-16 09:35 - 000074080 _____ C:\Users\Ricardo\Downloads\el-escuadron-del-crimen--2024---BluRay-720p_23_3059.torrent 2025-08-16 09:33 - 2025-08-16 09:33 - 000079308 _____ C:\Users\Ricardo\Downloads\amateur--2025---BluRay-720p_15_3059.torrent 2025-08-15 09:20 - 2025-08-15 09:20 - 000000000 ____D C:\Users\Ricardo\AppData\Local\Microsoft_Corporation 2025-08-15 09:17 - 2025-08-15 09:17 - 000000424 __RSH C:\ProgramData\ntuser.pol 2025-08-15 09:15 - 2025-08-15 09:15 - 002102632 _____ (Akeo Consulting) C:\Users\Ricardo\Downloads\rufus-4.9.exe 2025-08-14 18:32 - 2025-08-14 18:32 - 067768992 _____ (Intel Corporation) C:\Users\Ricardo\Downloads\BT-23.160.0-64UWD-Win10-Win11.exe 2025-08-14 18:32 - 2025-08-14 18:32 - 067768992 _____ (Intel Corporation) C:\Users\Ricardo\Downloads\BT-23.160.0-64UWD-Win10-Win11 (1).exe 2025-08-09 16:57 - 2025-08-09 16:57 - 000003713 _____ C:\Users\Ricardo\Downloads\Beogram4002_Cableado.pdf 2025-08-01 20:06 - 2025-08-01 20:06 - 000480211 _____ C:\Users\Ricardo\Downloads\manual FE FY900.pdf ==================== Un mes (modificado) ================== (Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.) 2025-08-31 19:58 - 2024-04-01 09:26 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2025-08-31 19:29 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\AppReadiness 2025-08-31 19:22 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemTemp 2025-08-31 19:16 - 2024-10-13 20:40 - 001689282 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2025-08-31 19:16 - 2024-04-01 09:24 - 000000000 ____D C:\WINDOWS\INF 2025-08-31 19:12 - 2025-03-30 09:01 - 000000432 _____ C:\WINDOWS\SysWOW64\winsevr.dat 2025-08-31 19:12 - 2025-03-30 09:01 - 000000208 _____ C:\WINDOWS\SysWOW64\AbBakConfig.dat 2025-08-31 19:12 - 2024-10-13 20:38 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2025-08-31 19:12 - 2024-10-13 20:36 - 000012556 _____ C:\WINDOWS\system32\5E37410B-D6F1-471D-AE27-563CEAC0D6B2 2025-08-31 19:12 - 2024-06-28 21:25 - 000000000 ____D C:\Intel 2025-08-31 19:12 - 2024-05-01 14:02 - 000000000 ____D C:\Users\Ricardo\AppData\Local\LogiOptionsPlus 2025-08-31 19:12 - 2024-03-20 19:51 - 000000000 ____D C:\ProgramData\NVIDIA 2025-08-31 19:12 - 2024-03-20 17:34 - 000012288 ___SH C:\DumpStack.log.tmp 2025-08-31 19:11 - 2024-04-01 09:21 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2025-08-31 18:55 - 2024-03-20 21:12 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\Microsoft\Word 2025-08-31 18:15 - 2024-05-01 13:46 - 000018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys 2025-08-31 18:10 - 2025-04-24 17:07 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\Zoom 2025-08-31 18:05 - 2024-04-01 09:26 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2025-08-31 18:05 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps 2025-08-31 17:54 - 2024-03-24 15:33 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\mf 2025-08-31 17:49 - 2024-07-02 13:54 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2025-08-31 17:21 - 2024-03-20 19:42 - 000000000 ____D C:\Users\Ricardo\AppData\Local\Packages 2025-08-31 17:08 - 2025-06-09 09:35 - 000004222 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{73F4E095-A67E-4AB8-AE75-2EECF582723C} 2025-08-31 17:01 - 2024-03-22 11:32 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\utorrent 2025-08-31 16:43 - 2024-03-20 22:56 - 000001156 _____ C:\Users\Ricardo\advanced_ip_scanner_MAC.bin 2025-08-31 16:43 - 2024-03-20 22:56 - 000000015 _____ C:\Users\Ricardo\advanced_ip_scanner_Comments.bin 2025-08-31 16:43 - 2024-03-20 22:56 - 000000015 _____ C:\Users\Ricardo\advanced_ip_scanner_Aliases.bin 2025-08-31 12:39 - 2024-03-23 12:33 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\Microsoft\Excel 2025-08-31 12:26 - 2024-03-22 11:32 - 000000000 ____D C:\Users\Ricardo\AppData\Local\CrashDumps 2025-08-31 11:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\oobe 2025-08-31 11:00 - 2024-10-13 14:52 - 000000000 ___DC C:\WINDOWS\Panther 2025-08-31 10:49 - 2025-03-28 19:11 - 000000000 ____D C:\Users\Ricardo\AppData\Local\Cloudflare 2025-08-31 09:04 - 2024-03-21 23:45 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\Hewlett-Packard 2025-08-31 09:04 - 2024-03-21 23:37 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard 2025-08-31 09:04 - 2024-03-21 21:54 - 000000000 ____D C:\ProgramData\Hewlett-Packard 2025-08-31 08:49 - 2025-06-10 18:05 - 000000000 ____D C:\WINDOWS\Minidump 2025-08-31 08:49 - 2024-06-30 09:59 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\MPC-HC 2025-08-31 08:49 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2025-08-31 02:00 - 2025-03-28 19:11 - 000000000 ____D C:\ProgramData\Cloudflare 2025-08-30 23:00 - 2024-10-13 20:36 - 000500232 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2025-08-30 22:51 - 2024-04-01 18:30 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2025-08-30 22:51 - 2024-04-01 18:29 - 000000000 ____D C:\WINDOWS\system32\OpenSSH 2025-08-30 22:51 - 2024-04-01 09:26 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2025-08-30 22:51 - 2024-04-01 09:26 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\F12 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ___RD C:\Program Files\Windows Defender 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\UUS 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SystemResources 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\setup 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\migwiz 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\HealthAttestationClient 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Dism 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\appraiser 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellExperiences 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ShellComponents 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Provisioning 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\bcastdvr 2025-08-30 22:51 - 2024-04-01 09:26 - 000000000 ____D C:\Program Files\Common Files\System 2025-08-30 22:51 - 2024-04-01 09:21 - 000000000 ____D C:\WINDOWS\servicing 2025-08-30 22:20 - 2024-03-20 19:29 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2025-08-30 22:20 - 2024-03-20 19:29 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2025-08-30 22:19 - 2024-10-13 20:29 - 000000000 ____D C:\Users\Ricardo 2025-08-30 22:19 - 2024-03-20 19:42 - 000000000 ___SD C:\Users\Ricardo\AppData\Roaming\Microsoft\Credentials 2025-08-30 22:18 - 2025-05-29 11:13 - 000000000 ____D C:\Program Files (x86)\Windows MV 2025-08-30 22:17 - 2025-06-27 20:37 - 000000000 ____D C:\WINDOWS\system32\ruxim 2025-08-30 22:17 - 2025-03-28 14:55 - 000000000 ____D C:\WINDOWS\system32\AccountHealthAssets 2025-08-30 22:17 - 2024-04-01 18:30 - 000000000 ___SD C:\WINDOWS\system32\AppV 2025-08-30 22:17 - 2024-04-01 18:30 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2025-08-30 22:17 - 2024-04-01 18:30 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2025-08-30 22:17 - 2024-04-01 18:29 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2025-08-30 22:17 - 2024-04-01 18:29 - 000000000 ____D C:\WINDOWS\system32\Microsoft-Edge-WebView 2025-08-30 22:17 - 2024-04-01 18:29 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2025-08-30 22:17 - 2024-04-01 18:27 - 000000000 ____D C:\WINDOWS\SysWOW64\es 2025-08-30 22:17 - 2024-04-01 18:27 - 000000000 ____D C:\WINDOWS\system32\es 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 __RSD C:\WINDOWS\Media 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\SysWOW64\lxss 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\Nui 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\lxss 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ___SD C:\WINDOWS\system32\dsc 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\ras 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\DDFs 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Com 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Sysprep 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ras 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Keywords 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\icsxml 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\ias 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\downlevel 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\DDFs 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Com 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Bthprops 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\L2Schemas 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\IME 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\IdentityCRL 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\DiagTrack 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\Cursors 2025-08-30 22:17 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\BrowserCore 2025-08-30 22:16 - 2025-06-08 08:56 - 000000000 ____D C:\Program Files (x86)\TagScanner 2025-08-30 22:16 - 2024-07-07 09:39 - 000000000 ____D C:\Program Files (x86)\WinPcap 2025-08-30 22:16 - 2024-06-02 12:57 - 000000000 ____D C:\Program Files\HPPrintScanDoctor 2025-08-30 22:16 - 2024-05-29 17:14 - 000000000 ____D C:\Program Files\Bonjour 2025-08-30 22:16 - 2024-04-10 09:28 - 000000000 ____D C:\Program Files\Monkey's Audio x64 2025-08-30 22:16 - 2024-04-06 09:25 - 000000000 ____D C:\Users\Ricardo\AppData\Local\JDownloader 2.0 2025-08-30 22:16 - 2024-04-03 20:13 - 000000000 ____D C:\Program Files\Audacity 2025-08-30 22:16 - 2024-04-02 09:04 - 000000000 ____D C:\Program Files\MegaDownloader 2025-08-30 22:16 - 2024-04-01 13:33 - 000000000 ____D C:\Program Files (x86)\eMule 2025-08-30 22:16 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\system32\Pbr 2025-08-30 22:16 - 2024-03-24 15:45 - 000000000 ____D C:\Program Files\freac 2025-08-30 22:16 - 2024-03-24 10:27 - 000000000 ____D C:\Program Files\Microsoft OneDrive 2025-08-30 22:16 - 2024-03-22 10:24 - 000000000 ____D C:\Program Files (x86)\WinSCP 2025-08-30 22:16 - 2024-03-21 19:21 - 000000000 ____D C:\Program Files (x86)\Dolby Home Theater v4 2025-08-30 22:16 - 2024-03-21 18:19 - 000000000 ____D C:\Program Files (x86)\GPU-Z 2025-08-30 22:16 - 2024-03-21 10:18 - 000000000 ____D C:\ProgramData\XonarU7 2025-08-30 22:16 - 2024-03-21 10:02 - 000000000 ____D C:\Program Files\Calibre2 2025-08-30 22:16 - 2024-03-21 09:30 - 000000000 ____D C:\Users\Ricardo\Downloads\WinPrint-1.5.0.53-beta-bin 2025-08-30 22:16 - 2024-03-21 09:26 - 000000000 ____D C:\Users\Ricardo\Downloads\lide500fvst6411222a_64es 2025-08-30 22:16 - 2024-03-20 22:55 - 000000000 ____D C:\Program Files (x86)\Advanced IP Scanner 2025-08-30 22:16 - 2024-03-20 21:46 - 000000000 ____D C:\Program Files\WinRAR 2025-08-30 22:16 - 2024-03-20 21:37 - 000000000 ____D C:\Program Files\totalcmd 2025-08-30 22:16 - 2024-03-20 21:17 - 000000000 ____D C:\Program Files (x86)\AOMEI Partition Assistant 2025-08-30 22:16 - 2024-03-20 19:44 - 000000000 ____D C:\ProgramData\Package Cache 2025-08-30 22:00 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\registration 2025-08-30 21:57 - 2024-03-20 23:39 - 000000000 ____D C:\Program Files\Intel 2025-08-30 21:45 - 2024-04-01 09:26 - 000000000 ___HD C:\Program Files\WindowsApps.tmp 2025-08-30 21:24 - 2024-10-13 20:36 - 003270656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2025-08-30 19:12 - 2024-03-22 11:32 - 000000000 ____D C:\Users\Ricardo\AppData\Local\BitTorrentHelper 2025-08-30 18:30 - 2024-03-20 19:44 - 000000000 ____D C:\Users\Ricardo\AppData\Local\D3DSCache 2025-08-30 18:04 - 2024-03-20 19:31 - 000000000 ____D C:\ProgramData\Packages 2025-08-30 17:41 - 2024-03-21 11:56 - 000000000 ____D C:\Users\Ricardo\AppData\Local\ElevatedDiagnostics 2025-08-30 13:27 - 2024-10-13 20:36 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2025-08-26 09:49 - 2024-10-13 20:38 - 000000000 ____D C:\WINDOWS\system32\Tasks\HP 2025-08-22 13:10 - 2024-10-13 20:38 - 000003296 _____ C:\WINDOWS\system32\Tasks\klcp_update 2025-08-22 13:10 - 2024-06-30 09:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 2025-08-22 13:10 - 2024-06-30 09:55 - 000000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2025-08-22 12:58 - 2024-03-21 10:01 - 000000000 ____D C:\Users\Ricardo\Biblioteca de calibre 2025-08-22 12:58 - 2024-03-21 10:01 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\calibre 2025-08-21 00:48 - 2024-04-01 13:05 - 000000000 ____D C:\Users\Ricardo\Documents\AVerTV 2025-08-20 18:29 - 2025-03-02 19:49 - 000000000 ____D C:\Program Files\Logi 2025-08-20 12:07 - 2024-10-13 20:38 - 000004290 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1710967547 2025-08-20 12:07 - 2024-03-20 22:45 - 000001437 _____ C:\Users\Ricardo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Navegador Opera.lnk 2025-08-19 17:55 - 2025-02-13 18:53 - 000003546 _____ C:\WINDOWS\system32\Tasks\OneDrive Startup Task-S-1-5-21-231195856-3100956415-3167264710-1000 2025-08-19 17:55 - 2024-10-13 20:38 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-231195856-3100956415-3167264710-1000 2025-08-19 17:55 - 2024-10-13 20:38 - 000003194 _____ C:\WINDOWS\system32\Tasks\OneDrive Per-Machine Standalone Update Task 2025-08-19 17:55 - 2024-03-23 09:57 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2025-08-19 10:38 - 2024-03-23 13:22 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\Microsoft\Plantillas 2025-08-19 10:21 - 2024-03-20 20:23 - 000000000 ____D C:\Users\Ricardo\AppData\Local\PlaceholderTileLogoFolder 2025-08-19 09:47 - 2024-04-01 09:26 - 000000000 ____D C:\WINDOWS\ServiceState 2025-08-19 07:29 - 2024-03-20 21:51 - 000002245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2025-08-19 07:29 - 2024-03-20 21:51 - 000002204 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2025-08-15 09:15 - 2024-03-21 09:36 - 000000205 _____ C:\Users\Ricardo\Downloads\rufus.ini 2025-08-14 18:09 - 2024-03-20 23:39 - 000000000 ____D C:\Program Files (x86)\Intel 2025-08-14 14:40 - 2024-03-20 20:08 - 000000000 ____D C:\WINDOWS\system32\MRT 2025-08-14 14:37 - 2024-03-20 20:08 - 223939376 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2025-08-08 19:06 - 2024-05-01 14:02 - 000000000 ____D C:\Users\Ricardo\AppData\Roaming\logioptionsplus 2025-08-07 09:26 - 2024-03-20 19:28 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2025-08-02 05:15 - 2024-10-13 20:38 - 000003708 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2025-08-02 05:15 - 2024-10-13 20:38 - 000003582 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore ==================== Archivos en la raíz de algunos directorios ======== 2025-08-29 08:28 - 2025-08-31 20:13 - 000000370 _____ () C:\Users\Public\Updater.vbs 2024-03-22 10:24 - 2024-10-13 21:10 - 000000128 _____ () C:\Users\Ricardo\AppData\Roaming\winscp.rnd 2024-05-31 12:37 - 2024-05-31 12:37 - 000000000 ____H () C:\Users\Ricardo\AppData\Local\dimp.sts 2024-03-21 17:57 - 2025-06-01 08:53 - 000000820 _____ () C:\Users\Ricardo\AppData\Local\oobelibMkey.log 2024-11-06 13:51 - 2024-11-06 13:52 - 000006459 _____ () C:\Users\Ricardo\AppData\Local\unins000.dat 2024-11-06 13:51 - 2024-11-06 13:51 - 003302461 _____ (Adobe Systems ) C:\Users\Ricardo\AppData\Local\unins000.exe 2025-03-30 08:59 - 2025-03-30 08:59 - 000006145 _____ () C:\Users\Ricardo\AppData\Local\unins001.dat 2025-03-30 08:59 - 2025-03-30 08:59 - 003308093 _____ (AOMEI Technology Co., Ltd ) C:\Users\Ricardo\AppData\Local\unins001.exe ==================== SigCheck ============================ (No existe una corrección automática para los archivos que no pasan la verificación.) ==================== Final de FRST.txt ========================