Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 15-08-2022
- Ejecutado por Jack (administrador) sobre SNAKE (ASUSTeK COMPUTER INC. S551LB) (21-08-2022 09:33:50)
- Ejecutado desde C:\Users\Jack\Desktop
- Perfiles cargados: UpdatusUser & Jack
- Plataforma: Microsoft Windows 8.1 (Update) (X64) Idioma: Español (España, internacional)
- Navegador predeterminado: FF
- Modo de Inicio: Normal
- ==================== Procesos (Lista blanca) =================
- (Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
- (ASUS Cloud Corporation -> ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe
- (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
- (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
- (C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
- (C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
- (C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe ->) (Qualcomm Atheros -> ) [Archivo no firmado] C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
- (C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ->) (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
- (C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe ->) (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe <2>
- (C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
- (C:\Program Files\ASUS\P4G\InsOnSrv.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
- (C:\Program Files\LibreOffice\program\soffice.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.bin
- (C:\Program Files\McAfee\WebAdvisor\servicehost.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
- (C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
- (cmd.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
- (CyberLink Corp. -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
- (Epic Games Inc. -> Epic Games, Inc.) C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
- (explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <22>
- (explorer.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\hkcmd.exe
- (explorer.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxpers.exe
- (explorer.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxtray.exe
- (explorer.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
- (explorer.exe ->) (Lavasoft Software Canada Inc. -> Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
- (explorer.exe ->) (Qualcomm Atheros -> Atheros Communications) [Archivo no firmado] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
- (explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
- (explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
- (explorer.exe ->) (The Document Foundation -> The Document Foundation) C:\Program Files\LibreOffice\program\soffice.exe
- (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
- (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
- (Mixbyte Inc -> ) C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
- (nvvsvc.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
- (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- (Pulse Secure, LLC -> ) C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\Pulse.exe
- (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
- (services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- (services.exe ->) (Arcai.com) [Archivo no firmado] C:\Program Files (x86)\netcut\services\aips.exe
- (services.exe ->) (ASUS Cloud Corporation) [Archivo no firmado] C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe
- (services.exe ->) (ASUSTeK Computer Inc. -> ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
- (services.exe ->) (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
- (services.exe ->) (Atheros) [Archivo no firmado] C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
- (services.exe ->) (CONDUSIV TECHNOLOGIES -> Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
- (services.exe ->) (Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
- (services.exe ->) (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
- (services.exe ->) (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
- (services.exe ->) (Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- (services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
- (services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
- (services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
- (services.exe ->) (Intel(R) Software -> Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
- (services.exe ->) (Lavasoft Software Canada Inc. -> ) C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe
- (services.exe ->) (McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
- (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
- (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
- (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
- (services.exe ->) (Mixbyte Inc -> Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
- (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
- (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe <2>
- (services.exe ->) (Pulse Secure, LLC -> Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Pulse Secure\JUNS\PulseSecureService.exe <2>
- (services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [Archivo no firmado] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
- (services.exe ->) (TODO: <Company name>) [Archivo no firmado] C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
- (svchost.exe ->) (AutoIt Consulting Ltd -> AutoIt Team) C:\Users\Jack\AppData\Roaming\ServiceMod\hodumev.exe
- (svchost.exe ->) (Intel Corporation - pGFX -> Intel Corporation) C:\Windows\System32\igfxsrvc.exe
- (svchost.exe ->) (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.4.9926.19918_x64__8wekyb3d8bbwe\glcnd.exe
- (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
- ==================== Registro (Lista blanca) ===================
- (Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
- HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [111976 2013-09-11] (Intel(R) Software -> Intel Corporation)
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s**RtHDVCpl****C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s**kernel32.dll* (Ningún archivo)
- HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-30] (Realtek Semiconductor Corp -> Realtek Semiconductor)
- HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2013-09-06] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.) [Archivo no firmado]
- HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe [63296 2013-08-16] (ASUS Cloud Corporation -> )
- HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp. -> CyberLink Corp.)
- HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [76600 2019-07-19] (Apple Inc. -> Apple Inc.)
- HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
- HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Ningún archivo)
- HKLM-x32\...\Run: [WSVCUUpdateHelper.exe] => C:\Program Files (x86)\Wondershare\Wondershare Video Converter Free\WSVCUUpdateHelper.exe (Ningún archivo)
- HKLM-x32\...\Run: [] => [X]
- HKLM-x32\...\Run: [PulseSecure] => C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\Pulse.exe [3237840 2019-04-12] (Pulse Secure, LLC -> )
- HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [183080 2021-01-14] (Mixbyte Inc -> )
- HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] (Qualcomm Atheros -> Atheros Communications) [Archivo no firmado]
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-30] (Disc Soft Ltd -> Disc Soft Ltd)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [Xpadder] => C:\Users\Jack\Documents\TRADUCCIONES Y MANDO STEAM\Xpadder by juanhito_Ralda\Xpadder [5.7].exe [1713152 2010-03-20] () [Archivo no firmado]
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [Google Update 12.3] => "C:\Users\Jack\AppData\Roaming\Macromedia\svchost.exe" (Ningún archivo) <==== ATENCIÓN
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [9677640 2022-06-23] (Lavasoft Software Canada Inc. -> Lavasoft)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [32845670] => C:\ProgramData\Intel\Wireless\49373c3\hgaadgf.exe C:\ProgramData\Intel\Wireless\49373c3\755c746.au3 (Ningún archivo)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [BitTorrent] => C:\Users\Jack\AppData\Roaming\BitTorrent\BitTorrent.exe [2106408 2022-03-18] (BitTorrent Inc -> BitTorrent Inc.)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [] => AutoIt3.exe qamqysoe.au3 (Ningún archivo)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [bt] => C:\Users\Jack\AppData\Roaming\BitTorrent\BitTorrent.exe [2106408 2022-03-18] (BitTorrent Inc -> BitTorrent Inc.)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [EpicGamesLauncher] => C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe [32706512 2022-08-17] (Epic Games Inc. -> Epic Games, Inc.)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\Run: [0f6ea6fd] => C:\ProgramData\9d81619\AutoIt3.exe [893608 2022-08-17] (AutoIt Consulting Ltd -> AutoIt Team)
- HKU\S-1-5-21-2177426780-1625849119-3246566683-1002\...\MountPoints2: {8514895c-7c4d-11e7-82a3-54271e18183a} - "G:\setup\rsrc\Autorun.exe"
- HKU\S-1-5-18\...\Run: [GarminExpress] => "C:\Program Files (x86)\Garmin\Express\express.exe" /minimized (Ningún archivo)
- HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\103.0.5060.114\Installer\chrmstp.exe [2022-07-12] (Google LLC -> Google LLC)
- HKLM\Software\...\Authentication\Credential Providers: [{4B9CAC01-6732-40d0-8B8F-B5B340F9D44F}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2019-04-12] (Pulse Secure, LLC -> )
- HKLM\Software\...\Authentication\Credential Providers: [{4EFD0F35-BFBA-44eb-8F25-2B3530203C1D}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2019-04-12] (Pulse Secure, LLC -> )
- HKLM\Software\...\Authentication\Credential Providers: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2013-09-07] (Qualcomm Atheros -> Qualcomm®Atheros®) [Archivo no firmado]
- HKLM\Software\...\Authentication\Credential Providers: [{b84ca702-35a8-4e67-8d2a-6c2807b297d3}] -> C:\Windows\system32\FaceCredentialProvider.dll [2013-11-14] (Hanwang Technology Co., LTD -> Hanwang Technology Co.,Ltd.)
- HKLM\Software\...\Authentication\Credential Providers: [{C1258FBC-F04F-4862-B78A-DDAAEF4A9707}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2019-04-12] (Pulse Secure, LLC -> )
- HKLM\Software\...\Authentication\Credential Providers: [{EAB1A79F-DFAA-4faf-A7B9-A6652E97EE16}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2019-04-12] (Pulse Secure, LLC -> )
- HKLM\Software\...\Authentication\Credential Provider Filters: [{3884BCAA-C611-4e2d-9105-E11B1203294E}] -> C:\Program Files (x86)\Common Files\Pulse Secure\JamUI\jamSSOCredProv64.dll [2019-04-12] (Pulse Secure, LLC -> )
- HKLM\Software\...\Authentication\Credential Provider Filters: [{ACFC407B-266C-8504-8DAE-F3E276336E4B}] -> C:\Windows\system32\AthCredentialProvider.dll [2013-09-07] (Qualcomm Atheros -> Qualcomm®Atheros®) [Archivo no firmado]
- AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-10-04] (NVIDIA CORPORATION -> NVIDIA Corporation)
- AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156256 2013-10-04] (NVIDIA CORPORATION -> NVIDIA Corporation)
- GroupPolicy: Restricción - Chrome <==== ATENCIÓN
- Policies: C:\ProgramData\NTUSER.pol: Restricción <==== ATENCIÓN
- ==================== Tareas programadas (Lista blanca) ============
- (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
- Task: {00756B4D-81E6-42E5-88DD-79719DB3C3EA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [570240 2017-02-14] (Apple Inc. -> Apple Inc.)
- Task: {0BD4A95E-D0BE-4FCA-A5FA-16722592A23F} - no ruta de acceso de archivo
- Task: {1B0CB81E-A8AF-4E05-85C4-26C57B88C3B9} - no ruta de acceso de archivo
- Task: {284A619A-BB4C-46D8-AFF1-F9BA035683B8} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
- Task: {284A619A-BB4C-46D8-AFF1-F9BA035683B8} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent
- Task: {284A619A-BB4C-46D8-AFF1-F9BA035683B8} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [360960 [360960 2015-09-24]] (Microsoft Windows -> Microsoft Corporation)
- Task: {3FAE9951-7069-43AA-8F9F-D661CDACC498} - System32\Tasks\GoogleUpdateTaskMachineCore1d11a0f35ee4e7c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-11-08] (Google Inc -> Google Inc.)
- Task: {472AF3E3-460C-4BCA-8C2F-E0473F85CA89} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
- Task: {472AF3E3-460C-4BCA-8C2F-E0473F85CA89} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [360960 [360960 2015-09-24]] (Microsoft Windows -> Microsoft Corporation)
- Task: {4D9364B1-4414-457A-B9A8-8171D95B3970} - no ruta de acceso de archivo
- Task: {5DFBD8A3-F29A-4750-B262-81264DC2C3F8} - System32\Tasks\ASUS Vivokey => C:\Program Files\ASUS\ASUS VivoBook\vivokey.exe [2278168 2013-08-23] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
- Task: {6272371F-956C-4902-9F60-2EEF2FDD6FD4} - System32\Tasks\Mozilla\Firefox Background Update E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\E7CF176E110C211B\backgroundupdate.moz_log --backgroundtask backgroundupdate
- Task: {69DF8F81-461E-4FAB-89BD-43BD99009F03} - System32\Tasks\GoogleUpdateTaskMachineUA1d11a0f36088863 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-11-08] (Google Inc -> Google Inc.)
- Task: {76420A70-4889-4309-845F-A89F6207FF9D} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [18232 2013-11-08] (ASUSTeK Computer Inc. -> AsusTek)
- Task: {7890759A-9F63-44E2-A0BC-B73364DA2A50} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2998552 2015-03-23] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
- Task: {7D4E471C-5B8D-40DC-A9CF-7BA536F1EAC0} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [55880 2013-10-07] (ASUSTeK Computer Inc. -> ASUS)
- Task: {8702B759-B94E-4CC8-B1A7-6054AD264039} - no ruta de acceso de archivo
- Task: {8C09916A-E6AB-46FD-9C35-EDDCF8F581EE} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2998552 2015-03-23] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
- Task: {8D211A1C-D167-45C7-AB68-6A7BF21512C5} - no ruta de acceso de archivo
- Task: {96CB7588-31B3-49B4-B7E2-FB3E43EC8E63} - System32\Tasks\Service\Diagnostic => C:\Users\Jack\AppData\Roaming\ServiceMod\hodumev.exe [893608 2022-08-20] (AutoIt Consulting Ltd -> AutoIt Team) -> "C:\Users\Jack\AppData\Roaming\ServiceMod\hodumev.dat"
- Task: {AB3EE1BA-3440-4639-839A-297EF72C80A5} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
- Task: {AB3EE1BA-3440-4639-839A-297EF72C80A5} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [360960 [360960 2015-09-24]] (Microsoft Windows -> Microsoft Corporation)
- Task: {AB6F18D8-DC1F-4FE5-A60E-9E90F2E22994} - no ruta de acceso de archivo
- Task: {AD6F8F2F-24D7-4059-82CC-FE43DCFEE991} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [19646544 2013-08-29] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
- Task: {B05A1376-317B-4674-8F54-7DFFA56B7F5F} - no ruta de acceso de archivo
- Task: {B20651F0-F01F-47C9-9697-B865AAF966DA} - no ruta de acceso de archivo
- Task: {B2E76952-D6A7-4819-91CA-1595FAFDFB15} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-12-11] (Adobe Inc. -> Adobe)
- Task: {BC81B98E-A834-4B5E-9897-C5EEB14DA784} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [1957040 2013-11-04] (ASUSTeK Computer Inc. -> ) [Archivo no firmado]
- Task: {C00E1503-5F8E-490F-8B7C-AFBE41347557} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_303_Plugin.exe [1457720 2019-12-11] (Adobe Inc. -> Adobe)
- Task: {C8B5DA38-4A49-4882-9704-8DA3CA570A32} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [181360 2013-10-07] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
- Task: {D49363CB-DD1A-4879-989D-D7B1177C5687} - no ruta de acceso de archivo
- Task: {DE7061EF-2F30-470C-AF35-5F77E30435FD} - no ruta de acceso de archivo
- Task: {E442CC2A-CD29-4306-BC33-CEBEC81A6E68} - no ruta de acceso de archivo
- Task: {E97232A9-D3B3-4CD7-854B-40798BE306FC} - no ruta de acceso de archivo
- Task: {ECA3331C-E846-41BD-9699-D048F437EFE9} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [1038648 2013-08-29] (ASUSTeK Computer Inc. -> ASUS)
- Task: {EF4EA5C5-B1EE-4CB8-BAB5-98F703F2CC4F} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe do-task "E7CF176E110C211B"
- Task: {F52419BD-2B9C-4080-8B57-2105A651AF85} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1341008 2020-09-06] (Adobe Inc. -> Adobe Inc.)
- (Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- ==================== Internet (Lista blanca) ====================
- (Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
- AutoConfigURL: [{1D066406-AE3F-4496-830C-A64E08270CA5}] => hxxp://127.0.0.1:58981/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{266AFA01-4242-406F-A259-4AC795EB6541}] => hxxp://127.0.0.1:50874/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{46D215A0-9178-4738-822F-9ABD6E88913A}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{5D66713D-16F5-4335-B015-361141C5FC47}] => hxxp://127.0.0.1:62253/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{5FDFDD81-B0CD-41CB-941D-9525C0127BD4}] => hxxp://127.0.0.1:62467/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{633F8BFB-6771-49A9-ADA3-785BB15656BF}] => hxxp://127.0.0.1:63004/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{63CF78DA-3B70-4671-AA25-5DFA04C17B26}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{691768FC-9251-4378-906B-9FD74814CB49}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{6E7F4D2D-D549-48B4-8E3B-B03BEB6A11F1}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{72413C91-FA89-44BE-987E-F218EB9CC01C}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{7AA06DE4-31C6-487E-BF77-1CDAC2F51A15}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{7D23F0D9-B413-4909-866D-536BF67E689C}] => hxxp://127.0.0.1:58833/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{80842047-4F01-4790-ACE1-476AD268E088}] => hxxp://127.0.0.1:63475/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{87FD3270-FBD2-4D62-97B0-E3756A602ACA}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{9C6C791F-B4E3-4CB3-8E91-508C98A537E6}] => hxxp://127.0.0.1:54851/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{9FA9F6BE-C49F-49A6-930E-6770D761F614}] => hxxp://127.0.0.1:59895/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{A15B974E-B336-4610-B45C-3920CAF880AC}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{A50114B0-AFDC-46F1-AD9E-D08FB15783C5}] => hxxp://127.0.0.1:54177/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{AA0F2B64-35B0-4E86-BCB6-8E1B6211F992}] => hxxp://127.0.0.1:63548/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{D641AC73-83CB-481E-9A7C-9D87320DEA26}] => hxxp://127.0.0.1:49425/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{D6B2589B-A6E0-4E9C-9994-AFB97C311ABB}] => hxxp://127.0.0.1:64844/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{E24C9B2F-7471-46EF-B3E8-B19B98D6F244}] => hxxp://127.0.0.1:53957/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{EC088FC7-3767-4B53-95DE-80B2DC1B24AC}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{F35FA210-5C2B-4235-99A6-07302CCD656E}] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [{F8B0A260-0E5E-4663-B986-6DD8D77B1D5F}] => hxxp://127.0.0.1:58252/proxy.pac <==== ATENCIÓN
- AutoConfigURL: [S-1-5-21-2177426780-1625849119-3246566683-1002] => hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
- Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
- Tcpip\Parameters: [DhcpNameServer] 212.166.210.80 212.166.132.104
- Tcpip\..\Interfaces\{91761E9C-F98F-466A-85C1-32EE4819E84C}: [DhcpNameServer] 40.53.1.201 40.53.1.203
- Tcpip\..\Interfaces\{A21C31CD-29A5-4D5A-9A1F-E4E00EFAF0A1}: [NameServer] 172.26.12.113,172.26.12.113
- Tcpip\..\Interfaces\{C1F2DB30-DE17-4ED6-9FAC-AC0EC5E18242}: [DhcpNameServer] 212.166.210.80 212.166.132.104
- Tcpip\..\Interfaces\{CB356103-BFFA-4649-ACAA-0317226EB562}: [NameServer] 172.26.12.113,172.26.12.113
- ManualProxies: 0hxxp://127.0.0.1:57176/proxy.pac <==== ATENCIÓN
- FireFox:
- ========
- FF DefaultProfile: y43y7q9e.default
- FF ProfilePath: C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default [2022-08-20]
- FF NewTab: Mozilla\Firefox\Profiles\y43y7q9e.default -> hxxps://defaultsearch.co/homepage?hp=1&pId=BT170901&iDate=2018-08-07 05:32:10&bName=&bitmask=0450
- FF Notifications: Mozilla\Firefox\Profiles\y43y7q9e.default -> hxxps://www2a.lucienmann.pro; hxxps://www2a.debrahinton.pro
- FF Extension: (YouTube™ Flash® Player) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\[email protected] [2017-08-11]
- FF Extension: (youtube-flash-html) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\[email protected] [2020-04-15]
- FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\[email protected] [2022-07-18]
- FF Extension: (uBlock Origin) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\[email protected] [2022-08-18]
- FF Extension: (Avast Online Security & Privacy) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\[email protected] [2022-08-02]
- FF Extension: (Descargador de MP3 gratis ) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\{6f2446a6-0a8d-4a1c-86f6-ad6fa27ae55f}.xpi [2022-08-20]
- FF Extension: (Video DownloadHelper) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2022-08-13]
- FF Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2022-07-18]
- FF Extension: (YouTube mp3 Downloader) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\y43y7q9e.default\Extensions\{defe5404-0b6f-4cce-a119-ee0df858e5f9}.xpi [2022-08-20]
- FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_303.dll [2019-12-11] (Adobe Inc. -> )
- FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_303.dll [2019-12-11] (Adobe Inc. -> )
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-10-23] (Intel® Identity Protection Technology Software -> Intel Corporation)
- FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-10-23] (Intel® Identity Protection Technology Software -> Intel Corporation)
- FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-03-31] (Oracle America, Inc. -> Oracle Corporation)
- FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-03-31] (Oracle America, Inc. -> Oracle Corporation)
- FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-07-13] (WildTangent Inc -> )
- FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2020-10-23] (Adobe Inc. -> Adobe Systems Inc.)
- Chrome:
- =======
- CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default [2022-08-21]
- CHR Notifications: Default -> hxxps://apsolutamente.org; hxxps://artepigr.com; hxxps://exey.io; hxxps://success-news.net; hxxps://techgeek.digital; hxxps://www2a.moshemartin.pro; hxxps://www32.todhamilton.pro; hxxps://www3a.michellehardin.pro
- CHR HomePage: Default -> hxxps://www.google.es/
- CHR StartupUrls: Default -> "hxxps://www.google.es/"
- CHR Extension: (Adblock Plus - bloqueador de anuncios gratis) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2022-07-10]
- CHR Extension: (Búsqueda de Google) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
- CHR Extension: (Adobe Acrobat: herramientas para convertir, editar y firmar PDFs) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2022-07-29]
- CHR Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2022-07-08]
- CHR Extension: (McAfee® WebAdvisor) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2022-08-20]
- CHR Extension: (AdBlock: el mejor bloqueador de anuncios) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2022-08-18]
- CHR Extension: (Avast Online Security & Privacy) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2022-07-29]
- CHR Extension: (Adaware Secure) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\nladljmabboanhihfkjacnnkgjhnokhj [2019-04-15]
- CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2021-01-30]
- CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
- CHR HKLM\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj]
- CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj]
- CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
- CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
- CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
- CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj]
- ==================== Servicios (Lista blanca) ===================
- (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
- R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [169544 2020-09-06] (Adobe Inc. -> Adobe Inc.)
- S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-12-11] (Adobe Inc. -> Adobe)
- R2 AIPS; C:\Program Files (x86)\netcut\services\AIPS.exe [262144 2011-07-28] (Arcai.com) [Archivo no firmado]
- R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2019-04-29] (Apple Inc. -> Apple Inc.)
- R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-08-29] (ASUSTeK Computer Inc. -> ASUS)
- R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [Archivo no firmado]
- R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) [Archivo no firmado]
- R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd -> Disc Soft Ltd)
- R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [115632 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116656 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148688 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [124880 2013-09-11] (Intel(R) Software -> Intel Corporation)
- S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2021-10-01] (Epic Games Inc. -> Epic Games, Inc.)
- R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [828656 2013-10-07] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
- R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [82216 2021-01-14] (Mixbyte Inc -> Freemake)
- R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [Archivo no firmado]
- S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel(R) Corporation) [Archivo no firmado]
- R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [808728 2022-08-05] (McAfee, LLC -> McAfee, LLC)
- R2 PulseSecureService; C:\Program Files (x86)\Common Files\Pulse Secure\JUNS\PulseSecureService.exe [182224 2019-04-12] (Pulse Secure, LLC -> Pulse Secure, LLC)
- R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [26440 2022-06-23] (Lavasoft Software Canada Inc. -> )
- R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation -> Microsoft Corporation)
- R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation -> Microsoft Corporation)
- R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) [Archivo no firmado]
- S2 McAPExe; "C:\Program Files\McAfee\MSC\McAPExe.exe" [X]
- S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\Wondershare Video Converter Free\Transfer\DriverInstall.exe" [X]
- ===================== Controladores (Lista blanca) ===================
- (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
- R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Microsoft Windows Hardware Compatibility Publisher -> Qualcomm Atheros Communications, Inc.)
- R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [70928 2013-11-08] (ASUSTeK Computer Inc. -> ASUS Corporation)
- R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [143568 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [114680 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [287160 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494272 2013-09-11] (Intel(R) Software -> Intel Corporation)
- R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-12-19] (Disc Soft Ltd -> Disc Soft Ltd)
- R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [46392 2015-12-19] (Disc Soft Ltd -> Disc Soft Ltd)
- R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [25840 2013-10-07] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
- R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [117488 2013-10-07] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
- R1 FNETURPX; C:\Windows\SysWOW64\drivers\FNETURPX.SYS [16648 2019-08-20] (FNet Co., Ltd. -> FNet Co., Ltd.)
- R1 jnprns; C:\Windows\system32\DRIVERS\jnprns.sys [507192 2019-04-12] (Juniper Networks, Inc. -> Juniper Networks)
- S4 jnprTdi_824_597; C:\Windows\system32\Drivers\jnprTdi_824_597.sys [106176 2016-06-01] (Pulse Secure, LLC -> Pulse Secure, LLC)
- S3 jnprva; C:\Windows\system32\DRIVERS\jnprva.sys [30072 2019-04-12] (Juniper Networks, Inc. -> Juniper Networks, Inc.)
- R3 JnprVaMgr; C:\Windows\system32\DRIVERS\jnprvamgr.sys [45352 2019-04-12] (Juniper Networks, Inc. -> Juniper Networks, Inc.)
- R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-06] (ASUSTeK Computer Inc. -> )
- S3 libusbK; C:\Windows\System32\drivers\libusbK.sys [47200 2016-06-07] (Travis Lee Robinson -> hxxp://libusb-win32.sourceforge.net)
- R3 MpKsl650ec603; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A241BFBA-3AEF-447F-BD0C-511D319B0B01}\MpKslDrv.sys [50448 2022-08-20] (Microsoft Windows -> Microsoft Corporation)
- R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [14136 2013-08-29] (ASUSTeK Computer Inc. -> Windows (R) Win 7 DDK provider)
- R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
- S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [28400 2016-07-08] () [Archivo no firmado]
- S3 SzCCID; C:\Windows\system32\DRIVERS\SzCCID.sys [48408 2014-08-26] (AlcorMicro, Corp. -> Generic)
- S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2015-06-17] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
- S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [34760 2013-08-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
- R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [265056 2013-08-22] (Microsoft Windows -> Microsoft Corporation)
- R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Windows -> Microsoft Corporation)
- U0 msahci; system32\drivers\msahci.sys [X]
- ==================== NetSvcs (Lista blanca) ===================
- (Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
- ==================== Un mes (creado) (Lista blanca) =========
- (Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
- 2022-08-21 09:33 - 2022-08-21 09:35 - 000039788 _____ C:\Users\Jack\Desktop\FRST.txt
- 2022-08-20 17:49 - 2022-08-21 09:34 - 000000000 ____D C:\FRST
- 2022-08-20 17:47 - 2022-08-20 17:48 - 002371072 _____ (Farbar) C:\Users\Jack\Desktop\FRST64.exe
- 2022-08-20 17:09 - 2022-08-20 17:09 - 000000000 ____D C:\Windows\system32\Tasks\Service
- 2022-08-20 17:09 - 2022-08-20 17:09 - 000000000 ____D C:\Users\Jack\AppData\Roaming\ServiceMod
- 2022-08-20 17:09 - 2022-08-20 17:09 - 000000000 ____D C:\Users\Jack\AppData\Roaming\3C29D9764978DA64
- 2022-08-20 16:44 - 2022-08-20 16:47 - 044612640 _____ (DownloadHelper ) C:\Users\Jack\Downloads\VdhCoAppSetup-1.6.3.exe
- 2022-08-19 10:37 - 2022-08-19 10:37 - 000000000 ___SH C:\DkHyperbootSync
- 2022-08-13 09:38 - 2022-08-13 09:38 - 004815223 _____ C:\Users\Jack\Downloads\クラクション・ラヴ ~ONIISAN MOTTO GANBATTE~ - YouTube.mp4
- 2022-08-13 09:36 - 2022-08-13 09:36 - 004606779 _____ C:\Users\Jack\Downloads\Junk (feat. Smike, Пойманные Муравьеды) - YouTube.mp4
- 2022-08-13 09:35 - 2022-08-13 09:36 - 010669335 _____ C:\Users\Jack\Downloads\Home Free - Sea Shanty Medley - YouTube.mp4
- 2022-08-13 09:33 - 2022-08-13 09:33 - 005926099 _____ C:\Users\Jack\Downloads\Emily Jane White - Hole in the Middle [OFFICIAL VIDEO] - You.mp4
- 2022-08-13 09:30 - 2022-08-13 09:30 - 006032194 _____ C:\Users\Jack\Downloads\This Life (Sons of Anarchy Theme Song) Full - YouTube.mp4
- 2022-08-13 09:29 - 2022-08-13 09:30 - 021447251 _____ C:\Users\Jack\Downloads\Fiddledum, Fiddledee (Nevermore) - The Yordles (Original Son.mp4
- 2022-08-13 09:29 - 2022-08-13 09:29 - 005339659 _____ C:\Users\Jack\Downloads\God Will Cut You Down - YouTube.mp4
- 2022-08-13 09:29 - 2022-08-13 09:29 - 004504476 _____ C:\Users\Jack\Downloads\Gangstagrass - Nobody Gonna Miss Me (ft. T.O.N.E-z) - YouTub.mp4
- 2022-08-13 09:28 - 2022-08-13 09:28 - 008746344 _____ C:\Users\Jack\Downloads\The Heavy Horses - 8. Hell Awaits - YouTube.mp4
- 2022-08-13 09:28 - 2022-08-13 09:28 - 006241140 _____ C:\Users\Jack\Downloads\Gangstagrass- I'm Gonna Put You Down - YouTube.mp4
- 2022-08-13 09:28 - 2022-08-13 09:28 - 003541890 _____ C:\Users\Jack\Downloads\Uncle Sinner - When Jesus Comes - YouTube.mp4
- 2022-08-13 09:27 - 2022-08-13 09:28 - 013693499 _____ C:\Users\Jack\Downloads\Drink the Water - Justin Cross - YouTube.mp4
- 2022-08-13 09:27 - 2022-08-13 09:28 - 004300187 _____ C:\Users\Jack\Downloads\The Brothers Bright - Awake O Sleeper - YouTube.mp4
- 2022-08-13 09:26 - 2022-08-13 09:27 - 003448246 _____ C:\Users\Jack\Downloads\Urban Country-Knife and Stone - YouTube.mp4
- 2022-08-13 09:26 - 2022-08-13 09:26 - 004019903 _____ C:\Users\Jack\Downloads\Urban Country - Gonna Need a Grave - YouTube.mp4
- 2022-08-13 09:25 - 2022-08-13 09:25 - 006083195 _____ C:\Users\Jack\Downloads\Blues Saraceno - Heroes Dress in Black - YouTube.mp4
- 2022-08-13 09:25 - 2022-08-13 09:25 - 003446846 _____ C:\Users\Jack\Downloads\Blues Saraceno - Blood To Spill - YouTube.mp4
- 2022-08-13 09:24 - 2022-08-13 09:24 - 004126692 _____ C:\Users\Jack\Downloads\Nick Nolan - Life of Sin (Dark Country 3) - YouTube.mp4
- 2022-08-13 09:24 - 2022-08-13 09:24 - 003705862 _____ C:\Users\Jack\Downloads\Robin Loxley - Rain Down - YouTube.mp4
- 2022-08-13 09:24 - 2022-08-13 09:24 - 003600536 _____ C:\Users\Jack\Downloads\Robin Loxley & Jay Hawke - crop won't ever come.wmv - YouTub.mp4
- 2022-08-13 09:23 - 2022-08-13 09:23 - 004349186 _____ C:\Users\Jack\Downloads\Blues Saraceno - Strident Missile - YouTube.mp4
- 2022-08-13 09:22 - 2022-08-13 09:22 - 017142633 _____ C:\Users\Jack\Downloads\Blues Saraceno - The Bible Or The Gun. - YouTube.mp4
- 2022-08-13 09:22 - 2022-08-13 09:22 - 009702469 _____ C:\Users\Jack\Downloads\Blues Saraceno - The River (Dark Country 4) - YouTube.mp4
- 2022-08-13 09:22 - 2022-08-13 09:22 - 004203115 _____ C:\Users\Jack\Downloads\Blues Saraceno – Dogs of War - YouTube.mp4
- 2022-08-13 09:15 - 2022-08-13 09:16 - 052558637 _____ C:\Users\Jack\Downloads\Dark Country 2 [Compilation] .mp4
- 2022-08-13 09:07 - 2022-08-13 09:37 - 091463469 _____ C:\Users\Jack\Downloads\Dark Country 972678382 mp3.zip
- 2022-08-12 17:19 - 2022-08-12 17:22 - 406263055 _____ C:\Users\Jack\Downloads\T0d0V3zT0d4sP4rt3sHD1080pX265 ESP.mkv
- 2022-08-10 16:50 - 2022-08-10 16:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
- 2022-08-10 16:45 - 2022-08-10 16:45 - 000177807 _____ C:\Users\Jack\Downloads\08-JURIDICAS-ACTO-ADMINISTRATIVO.pdf
- 2022-08-09 17:40 - 2022-08-09 17:43 - 3145401632 _____ C:\Users\Jack\Downloads\Pr3y.2022.1080p.Castilian.mkv
- 2022-08-01 11:01 - 2022-08-01 11:01 - 000000000 ____D C:\Users\Jack\Desktop\Pamplona
- 2022-07-31 18:31 - 2022-07-31 18:32 - 005375938 _____ C:\Users\Jack\Downloads\eTicket.pdf
- ==================== Un mes (modificado) ==================
- (Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
- 2022-08-20 17:04 - 2016-11-29 21:32 - 000000000 ____D C:\Users\Jack\AppData\LocalLow\Mozilla
- 2022-08-18 14:27 - 2020-10-15 23:41 - 000000000 ____D C:\Users\Jack\AppData\Roaming\vlc
- 2022-08-18 08:46 - 2013-09-06 21:59 - 000818580 _____ C:\Windows\system32\perfh00A.dat
- 2022-08-18 08:46 - 2013-09-06 21:59 - 000169858 _____ C:\Windows\system32\perfc00A.dat
- 2022-08-18 08:46 - 2013-09-06 13:53 - 001829802 _____ C:\Windows\system32\PerfStringBackup.INI
- 2022-08-18 08:46 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf
- 2022-08-17 11:50 - 2015-12-29 22:59 - 000000000 ____D C:\Users\Jack\Documents\CNP
- 2022-08-17 11:19 - 2021-02-18 15:43 - 000000000 ____D C:\Users\Jack\AppData\Local\BitTorrentHelper
- 2022-08-17 11:19 - 2020-07-13 11:18 - 000000000 ____D C:\Users\Jack\AppData\Roaming\BitTorrent
- 2022-08-17 11:18 - 2020-07-23 22:05 - 000000000 ____D C:\ProgramData\9d81619
- 2022-08-17 07:14 - 2019-12-31 11:32 - 002039808 ___SH C:\Users\Jack\Downloads\Thumbs.db
- 2022-08-13 09:20 - 2019-03-31 14:29 - 000003600 _____ C:\Windows\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2177426780-1625849119-3246566683-1002
- 2022-08-13 07:53 - 2022-03-13 16:46 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
- 2022-08-13 07:53 - 2016-11-10 14:06 - 000001177 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
- 2022-08-12 17:05 - 2015-11-08 13:33 - 000000000 ____D C:\Users\Jack\Documents\Cocina
- 2022-07-30 13:54 - 2020-01-06 00:03 - 000162304 ___SH C:\Users\Jack\Documents\Thumbs.db
- 2022-07-30 12:10 - 2020-03-05 21:41 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Pulse Secure
- 2022-07-30 10:49 - 2020-03-05 21:39 - 000563200 _____ (Dirección General de la Policía) C:\Users\Jack\AppData\Local\TIFService.exe
- 2022-07-29 19:11 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\LiveKernelReports
- ==================== Archivos en la raíz de algunos directorios ========
- 2018-09-04 10:26 - 2018-09-04 10:26 - 000000172 _____ () C:\Users\Jack\AppData\Roaming\encKey.cryptolocker
- 2018-09-04 10:26 - 2018-09-04 10:26 - 000000069 _____ () C:\Users\Jack\AppData\Roaming\jokingwithyou.cryptolocker
- 2015-11-08 03:31 - 2019-03-31 12:25 - 000000074 _____ () C:\Users\Jack\AppData\Roaming\sp_data.sys
- 2016-02-19 00:48 - 2016-04-18 14:47 - 000000096 _____ () C:\Users\Jack\AppData\Roaming\WB.CFG
- 2021-09-30 17:10 - 2022-04-10 17:05 - 000535040 _____ (Dirección General de la Policía) C:\Users\Jack\AppData\Local\DNIeService.exe
- 2021-06-19 09:48 - 2021-06-19 09:48 - 000016438 _____ () C:\Users\Jack\AppData\Local\partner.bmp
- 2020-03-05 21:39 - 2022-07-30 10:49 - 000563200 _____ (Dirección General de la Policía) C:\Users\Jack\AppData\Local\TIFService.exe
- ==================== SigCheck ============================
- (No existe una corrección automática para los archivos que no pasan la verificación.)
- LastRegBack: 2019-03-31 10:30
- ==================== Final de FRST.txt ========================
Add Comment
Please, Sign In to add comment