hola buenos días, muchas gracias por la ayuda ya instale el programa y analice la pc y subí los archivos a one drive, y después los subí a pastebin
por si sirve de algo es esto lo que salio.
Este explorador ya no se admite.
Actualice a Microsoft Edge para aprovechar las características y actualizaciones de seguridad más recientes, y disponer de soporte técnico.
Hola! Tengo una duda, me había descargado un juego pirata el need for speed the run cuando lo instalo, recuerdo que decía que era de el amigo después ví que tiene virus esos juegos busqué en el administrador de tarea y Vi que estaba el conhost y a veces me salen 2 y cuando prendo la PC por un momento salen 3 y también el caras salen 2
Pregunta bloqueada. Esta pregunta se migró desde la Comunidad de Soporte técnico de Microsoft. Puede votar si es útil, pero no puede agregar comentarios o respuestas ni seguir la pregunta.
hola buenos días, muchas gracias por la ayuda ya instale el programa y analice la pc y subí los archivos a one drive, y después los subí a pastebin
por si sirve de algo es esto lo que salio.
Bien omar rioja esto tomara unas horas, pero de preferencia desde OneDrive usa la opcion de compartir y crea el enalce de estos archivs para que copies solo el enlace y pueda revisarlos mas ordenadamente
Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión: 05-11-2023 02
Ejecutado por omarr (14-11-2023 09:43:43)
Ejecutado desde C:\Users\omarr\Downloads
Microsoft Windows 11 Pro Versión 22H2 22621.1702 (X64) (2023-11-12 03:21:02)
Modo de Inicio: Normal
==========================================================
==================== Cuentas: =============================
(Si una entrada es incluida en el fixlist, será eliminada.)
Administrador (S-1-5-21-2309195285-1605365872-916135564-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2309195285-1605365872-916135564-503 - Limited - Disabled)
Invitado (S-1-5-21-2309195285-1605365872-916135564-501 - Limited - Disabled)
omarr (S-1-5-21-2309195285-1605365872-916135564-1001 - Administrator - Enabled) => C:\Users\omarr
WDAGUtilityAccount (S-1-5-21-2309195285-1605365872-916135564-504 - Limited - Disabled)
==================== Centro de Seguridad ========================
(Si una entrada es incluida en el fixlist, será eliminada.)
AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Disabled - Out of date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
==================== Programas instalados ======================
(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al fixlist para hacerlos visibles. Los programas adware deben ser desinstalados manualmente.)
Avast Free Antivirus (HKLM...\Avast Antivirus) (Version: 23.10.6086 - Avast Software)
Avast Secure Browser (HKLM-x32...\Avast Secure Browser) (Version: 118.0.22847.89 - AVAST Software)
Avast Update Helper (HKLM-x32...{19C3AB22-3718-4E4D-B203-242F5001565B}) (Version: 1.8.1653.5 - AVAST Software) Hidden
Battle.net (HKLM-x32...\Battle.net) (Version: - Blizzard Entertainment)
GameLoop (HKLM-x32...\MobileGamePC) (Version: 1.0.0.1 - Tencent Technology Company)
Google Chrome (HKLM-x32...\Google Chrome) (Version: 119.0.6045.124 - Google LLC)
League of Legends (HKU\S-1-5-21-2309195285-1605365872-916135564-1001...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc)
Malwarebytes version 4.6.6.294 (HKLM...{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.6.6.294 - Malwarebytes)
Microsoft Edge (HKLM-x32...\Microsoft Edge) (Version: 119.0.2151.58 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2309195285-1605365872-916135564-1001...\OneDriveSetup.exe) (Version: 23.221.1024.0002 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM...{C6FD611E-7EFE-488C-A0E0-974C09EF6473}) (Version: 5.72.0.0 - Microsoft Corporation)
Riot Client (HKU\S-1-5-21-2309195285-1605365872-916135564-1001...\Riot Game Riot_Client.) (Version: - Riot Games, Inc)
WebView2 Runtime de Microsoft Edge (HKLM-x32...\Microsoft EdgeWebView) (Version: 119.0.2151.58 - Microsoft Corporation)
Packages:
=========
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.12.3171.0_x64__8wekyb3d8bbwe [2023-11-11] (Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0 [2023-11-12] (Spotify AB) [Startup Task]
==================== Personalizado CLSID (Lista blanca): ==============
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers-x32: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => -> Ningún archivo
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast Software\Avast\ashShell.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
==================== Codecs (Lista blanca) ====================
==================== Accesos directos & WMI ========================
==================== Módulos cargados (Lista blanca) =============
==================== Alternate Data Streams (Lista blanca) ========
(Si una entrada es incluida en el fixlist, solamente los ADS serán eliminados.)
AlternateDataStreams: C:\Users\omarr\Downloads\Install League of Legends euw.exe:MBAM.Zone.Identifier [168]
==================== Modo Seguro (Lista blanca) ==================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El "AlternateShell" será restaurado.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aswSP.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Asociación (Lista blanca) =================
==================== Internet Explorer (Lista blanca) ==========
==================== Hosts contenido: =========================
(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para restablecer Hosts.)
2022-05-07 01:24 - 2022-05-07 01:22 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts
==================== Otras Áreas ===========================
(Actualmente no existe una corrección automática para esta sección.)
HKU\S-1-5-21-2309195285-1605365872-916135564-1001\Control Panel\Desktop\Wallpaper -> C:\Users\omarr\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppHost => (EnableWebContentEvaluation: 1)
Firewall de Windows está habilitado.
==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==
==================== Reglas de firewall (Lista blanca) ================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
FirewallRules: [{E6EEFE80-182C-4922-9F8C-C93E0B91E04B}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\119.0.2151.58\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{39C21856-801E-47FB-B600-D70B263F180F}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23275.702.2421.2406_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{B087DEC1-DAEF-4143-9DFA-1E38CE45A8E8}] => (Allow) C:\Program Files\WindowsApps\MicrosoftTeams_23275.702.2421.2406_x64__8wekyb3d8bbwe\msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{96B11D44-FF9D-4A34-AB28-C3A46CD0DEB2}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{0FC37293-5DD2-4C10-B5CF-0BA44F9610E4}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => Ningún archivo
FirewallRules: [{05C38830-6BD6-48E5-BC6E-77ADC0DB8CAB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe => Ningún archivo
FirewallRules: [{ECF428CE-C0D8-4EBB-929E-1E4C64B38C7D}] => (Allow) c:\program files\txgameassistant\appmarket\AppMarket.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{F6E8F05A-EFB6-4A50-99B7-C26F1416F609}] => (Allow) c:\program files\txgameassistant\appmarket\TInst.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{1744546E-6831-4EB3-B5C9-0462F9BBFD17}] => (Allow) c:\program files\txgameassistant\appmarket\bugreport.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{3B572DB0-8D64-43D9-A4C7-287D4B93B6BC}] => (Allow) c:\program files\txgameassistant\appmarket\QQExternal.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{7063921C-D3DF-4E0C-BA4A-929754AFE37D}] => (Allow) c:\program files\txgameassistant\appmarket\GameDownload.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{95006B64-08B1-46DE-86B1-88808C29D4E8}] => (Allow) c:\program files\txgameassistant\appmarket\GF186\TUpdate.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{587291CD-3D75-4686-B184-DF96A70C1783}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{DDDA8848-7A78-415F-877E-8597BD639C86}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{3A91127D-3D5D-4BEA-A041-8922011976E4}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{92475DA8-2D4D-40BF-8A29-FC1D1A07BDB1}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{04D023E7-3D5A-451A-9D38-3398A92C95A7}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{59E3DE40-9544-4634-8362-9D7ECC9A52BD}] => (Allow) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{0BA38FDC-A4EC-44B2-B948-C57CBF9FE131}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => Ningún archivo
FirewallRules: [{44E50966-BF4C-4824-A2A8-58CBB13D824A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe => Ningún archivo
FirewallRules: [{E9D925FA-A96C-42AE-AC76-EAF691428F8A}] => (Allow) c:\program files\txgameassistant\ui\AndroidEmulator.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{E7A143E0-0DB8-4673-A5AE-A74A4995E0EC}] => (Allow) c:\program files\txgameassistant\ui\AndroidEmulatorEx.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{4414CAFB-F895-42F9-8764-D29AA9177613}] => (Allow) c:\program files\txgameassistant\ui\AndroidEmulatorEn.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{F1E66A54-3F85-4B25-B488-CAEA06EE4A45}] => (Allow) c:\program files\txgameassistant\ui\adb.exe () [Archivo no firmado]
FirewallRules: [{AA8B026B-41AA-48FB-BD1B-31D50946FF77}] => (Allow) c:\program files\txgameassistant\ui\TInst.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{5E79CD76-CFEE-4F85-A410-7D2693EBF1AA}] => (Allow) c:\program files\txgameassistant\ui\bugreport.exe (Tencent Technology(Shenzhen) Company Limited -> )
FirewallRules: [{D72F552A-315F-4943-9528-737E1070383F}] => (Allow) c:\program files\txgameassistant\ui\TxGaDcc.exe (Tencent Technology(Shenzhen) Company Limited -> Tencent)
FirewallRules: [{52344F27-E3C2-4E00-A3D1-BAF00511EBE2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{836EDA1E-3DE3-4B3C-B4D7-B5341D1220E6}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F969AF74-70A1-4583-A93F-4BBDF32E580D}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{44B6F172-DA6D-4241-A7EC-49C06D94E685}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{7DC8CFF2-76FC-4787-95AA-A3A3B80BC339}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F8E87F45-5EE7-4C78-908D-B5550E900EE7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B9AC26F3-2C7B-41E2-8461-F05B6CC8987F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{D4EE543A-D0A6-46DA-8BF9-48F5C06B49FA}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{2D40BD52-79D6-4450-80D2-07E36E286BF3}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{8702A9C3-790E-4CBD-AB9C-FADD078B7E24}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.224.756.0_x64__zpdnekdrzrea0\Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{14AEE35F-4D01-4B20-8A39-CBF40396FEA1}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{C55D0554-084D-4557-94AC-E7BEC15BB0C7}] => (Allow) C:\Program Files\Avast Software\Avast\AvastUI.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{7121571C-C83F-4EEB-943A-2ECBCFD8AD8D}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software)
==================== Puntos de Restauración =========================
11-11-2023 23:24:14 Instalador de Módulos de Windows
13-11-2023 15:10:33 Instalador de Módulos de Windows
14-11-2023 09:37:12 Instalador de Módulos de Windows
14-11-2023 09:39:22 Instalador de Módulos de Windows
14-11-2023 09:39:51 Instalador de Módulos de Windows
==================== Dispositivos defectuosos en el Administrador de dispositivos ============
==================== Errores del registro de eventos: ========================
Errores de aplicación:
==================
Error: (11/14/2023 09:35:57 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (11/14/2023 09:35:54 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x80072EE7
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (11/14/2023 09:35:54 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x80072EE7
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=2
Error: (11/13/2023 05:34:43 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (11/13/2023 05:09:12 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (11/13/2023 05:09:12 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Error: (11/13/2023 04:56:18 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable
Error: (11/13/2023 04:56:17 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: Error de la activación de licencia (slui.exe) con el siguiente código:
hr=0x803F7001
Argumentos de línea de comandos:
RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
Errores del sistema:
=============
Error: (11/14/2023 09:37:57 AM) (Source: DCOM) (EventID: 10010) (User: OMAR)
Description: El servidor {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} no se registró con DCOM dentro del tiempo de espera requerido.
Error: (11/13/2023 05:44:47 PM) (Source: Schannel) (EventID: 4116) (User: NT AUTHORITY)
Description: El certificado recibido del servidor remoto no contiene el nombre esperado. Por lo tanto, no es posible determinar si estamos conectándonos al servidor correcto. El nombre del servidor esperado es outside-scanner-v6.ff.avast.com. Error en la solicitud de conexión TLS. Los datos adjuntos contienen el certificado del servidor.
el proceso del cliente SSPI es AvastSvc (PID: 4956).
Error: (11/13/2023 05:08:42 PM) (Source: DCOM) (EventID: 10005) (User: OMAR)
Description: Error de DCOM "1084" al intentar iniciar el servicio UdkUserSvc_3b28a con argumentos "No disponible" para ejecutar el servidor:
WindowsUdk.UI.Shell.ViewCoordinator
Error: (11/13/2023 05:08:42 PM) (Source: DCOM) (EventID: 10005) (User: OMAR)
Description: Error de DCOM "1084" al intentar iniciar el servicio UdkUserSvc_3b28a con argumentos "No disponible" para ejecutar el servidor:
WindowsUdk.UI.Shell.ViewCoordinator
Error: (11/13/2023 05:08:42 PM) (Source: DCOM) (EventID: 10005) (User: OMAR)
Description: Error de DCOM "1084" al intentar iniciar el servicio camsvc con argumentos "No disponible" para ejecutar el servidor:
Windows.Internal.CapabilityAccess.CapabilityAccess
Error: (11/13/2023 05:08:42 PM) (Source: DCOM) (EventID: 10005) (User: OMAR)
Description: Error de DCOM "1084" al intentar iniciar el servicio camsvc con argumentos "No disponible" para ejecutar el servidor:
Windows.Internal.CapabilityAccess.CapabilityAccess
Error: (11/13/2023 05:08:42 PM) (Source: DCOM) (EventID: 10005) (User: OMAR)
Description: Error de DCOM "1084" al intentar iniciar el servicio TokenBroker con argumentos "No disponible" para ejecutar el servidor:
Windows.Internal.Security.Authentication.Web.WamProviderRegistration
Error: (11/13/2023 05:08:42 PM) (Source: DCOM) (EventID: 10005) (User: OMAR)
Description: Error de DCOM "1084" al intentar iniciar el servicio UdkUserSvc_3b28a con argumentos "No disponible" para ejecutar el servidor:
WindowsUdk.UI.Shell.ViewCoordinator
Windows Defender:
================Event[0]
Date: 2023-11-13 17:01:20
Description:
La característica Protección en tiempo real de Antivirus de Microsoft Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
Motivo: La inteligencia de seguridad antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.
Date: 2023-11-13 16:49:58
Description:
La característica Protección en tiempo real de Antivirus de Microsoft Defender encontró un error:
Característica: Durante el acceso
Código de error: 0x8007043c
Descripción del error: El servicio no puede iniciarse en modo a prueba de errores
Motivo: La inteligencia de seguridad antimalware dejó de funcionar por motivos desconocidos. En algunos casos, reiniciar el servicio puede que resuelva el problema.
CodeIntegrity:
===============
Date: 2023-11-14 09:40:40
Description:
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements.
==================== Información de la memoria ===========================
BIOS: American Megatrends International, LLC. F64 11/07/2022
Placa base: Gigabyte Technology Co., Ltd. B450M DS3H WIFI-CF
Procesador: AMD Ryzen 5 5600G with Radeon Graphics
Porcentaje de memoria en uso: 43%
RAM física total: 15740.09 MB
RAM física disponible: 8907.77 MB
Virtual total: 18684.09 MB
Virtual disponible: 11162.64 MB
==================== Unidades ================================
Drive c: () (Fixed) (Total:236.91 GB) (Free:151.16 GB) (Model: Apacer AS2280P4 256GB) NTFS
\?\Volume{aca7c7ba-c3c5-41c0-8569-615bd2286ce4}\ () (Fixed) (Total:0.67 GB) (Free:0.08 GB) NTFS
\?\Volume{c0d56857-1fdc-4dcb-ab00-e4b2831bae89}\ () (Fixed) (Total:0.09 GB) (Free:0.06 GB) FAT32
==================== MBR & Tabla de particiones ====================
==========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: 7360DF90)
Partition: GPT.
==================== Final de Addition.txt =======================
Resultado del análisis realizado por Farbar Recovery Scan Tool (FRST) (x64) Versión: 05-11-2023 02
Ejecutado por omarr (administrador) sobre OMAR (Gigabyte Technology Co., Ltd. B450M DS3H WIFI) (14-11-2023 09:43:11)
Ejecutado desde C:\Users\omarr\Downloads\FRST64.exe
Perfiles cargados: omarr
Plataforma: Microsoft Windows 11 Pro Versión 22H2 22621.1702 (X64) Idioma: Español (México)
Navegador predeterminado: "C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe" --single-argument %1
Modo de Inicio: Normal
==================== Procesos (Lista blanca) =================
(Si una entrada es incluida en el fixlist, el proceso será cerrado. El archivo no será movido.)
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastUI.exe
(C:\Program Files\Avast Software\Avast\AvastSvc.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswEngSrv.exe
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(C:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe ->) (Tencent Technology(Shenzhen) Company Limited -> ) C:\Program Files\TxGameAssistant\AppMarket\cef_frame_render.exe <3>
(C:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe ->) (Tencent Technology(Shenzhen) Company Limited -> ) C:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe
(C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe ->) (Tencent Technology(Shenzhen) Company Limited -> Tencent) C:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe
(C:\Program Files\WindowsApps\MicrosoftTeams_23275.702.2421.2406_x64__8wekyb3d8bbwe\msteams.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\119.0.2151.58\msedgewebview2.exe <12>
(C:\Riot Games\Riot Client\RiotClientServices.exe ->) () [Archivo no firmado] C:\Riot Games\Riot Client\RiotClientCrashHandler.exe
(DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atiesrxx.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atieclxx.exe
(explorer.exe ->) (Google LLC -> Google LLC) C:\Program Files\Google\Chrome\Application\chrome.exe <30>
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <7>
(explorer.exe ->) (Riot Games, Inc. -> Riot Games, Inc.) C:\Riot Games\Riot Client\RiotClientServices.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.332\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.36.332\GoogleCrashHandler64.exe
(services.exe ->) (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.) C:\Windows\System32\amdfendrsr.exe
(services.exe ->) (Advanced Micro Devices Inc. -> AMD) C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\atiesrxx.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\aswToolsSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\AvastSvc.exe
(services.exe ->) (Avast Software s.r.o. -> AVAST Software) C:\Program Files\Avast Software\Avast\wsc_proxy.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe
(services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe
(services.exe ->) (Tencent Technology(Shenzhen) Company Limited -> Tencent) C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe
(svchost.exe ->) (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Users\omarr\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
(svchost.exe ->) (Microsoft Windows -> ) C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_423.29700.0.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\UUS\amd64\wuaucltcore.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.22621.2495_none_e94db02e42d9b0e2\TiWorker.exe
==================== Registro (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, el elemento del registro será restaurado a su valor predeterminado o será eliminado. El archivo no será movido.)
HKLM...\Run: [AvastUI.exe] => C:\Program Files\Avast Software\Avast\AvLaunch.exe [374680 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
HKU\S-1-5-21-2309195285-1605365872-916135564-1001...\Run: [MicrosoftEdgeAutoLaunch_6C2FE5781220C5F0407E97A531C42433] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5 [3894824 2023-11-09] (Microsoft Corporation -> Microsoft Corporation)
HKU\S-1-5-21-2309195285-1605365872-916135564-1001...\Run: [RiotClient] => C:\Riot Games\Riot Client\RiotClientServices.exe [70912472 2023-11-12] (Riot Games, Inc. -> Riot Games, Inc.)
HKU\S-1-5-21-2309195285-1605365872-916135564-1001...\Run: [AvastBrowserAutoLaunch_5CEEB26A43A3D6BAD04B289E70CAB606] => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3418472 2023-10-18] (Avast Software s.r.o. -> AVAST Software)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\119.0.6045.124\Installer\chrmstp.exe [2023-11-11] (Google LLC -> Google LLC)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\118.0.22847.89\Installer\chrmstp.exe [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
==================== Tareas programadas (Lista blanca) =================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
Task: {B2C914FE-17DF-40DA-95FC-BE72104EFF2C} - System32\Tasks\Avast Emergency Update => C:\Program Files\Avast Software\Avast\AvEmUpdate.exe [5153176 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
Task: {9AE36437-9780-4F79-8A52-A596B1711532} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3418472 2023-10-18] (Avast Software s.r.o. -> AVAST Software)
Task: {C839ECE6-49D4-494C-BB65-6F0E22571B5A} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [3418472 2023-10-18] (Avast Software s.r.o. -> AVAST Software)
Task: {F14AB54E-3774-47D5-B625-FADB8C798A07} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2144664 2023-11-13] (Avast Software s.r.o. -> Avast Software)
Task: {A357A03D-928B-4FF8-AA84-0B5AF68FAE03} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
Task: {AF7D9ECA-5E41-4210-80E2-62FE504C5B81} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
Task: {94C1DFD7-488F-4018-BD19-B69629125001} - System32\Tasks\GoogleUpdateTaskMachineCore{38793544-0591-4B1D-B720-A78BD6267BF7} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162080 2023-11-11] (Google LLC -> Google LLC)
Task: {357FE961-AA93-4510-B051-4E92C0A1890A} - System32\Tasks\GoogleUpdateTaskMachineUA{284FE5AF-A286-4264-9B58-77CAD636BDD3} => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [162080 2023-11-11] (Google LLC -> Google LLC)
Task: {E0F10DCF-44AD-40E8-9370-FB5DA59F93FB} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (Ningún archivo)
(Si una entrada es incluida en el fixlist, el archivo de tarea (.job) será movido. El archivo que está siendo ejecutado por la tarea no será movido.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
==================== Internet (Lista blanca) ====================
(Si un elemento es incluido en el fixlist, y éste pertenece al registro, será eliminado o restaurado a su valor predeterminado.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip..\Interfaces{431ee1e5-6db4-46fb-bdab-b6be0c725378}: [DhcpNameServer] 192.168.1.1
Edge:
=======
Edge Profile: C:\Users\omarr\AppData\Local\Microsoft\Edge\User Data\Default [2023-11-14]
Edge Extension: (Documentos de Google sin conexión) - C:\Users\omarr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-11-11]
Edge Extension: (Edge relevant text changes) - C:\Users\omarr\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2023-11-11]
FireFox:
========
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=3 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1653.5\npAvastBrowserUpdate3.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
FF Plugin-x32: @update.avastbrowser.com/Avast Browser;version=9 -> C:\Program Files (x86)\AVAST Software\Browser\Update\1.8.1653.5\npAvastBrowserUpdate3.dll [2023-11-13] (Avast Software s.r.o. -> AVAST Software)
Chrome:
=======
CHR Profile: C:\Users\omarr\AppData\Local\Google\Chrome\User Data\Default [2023-11-14]
CHR Extension: (Documentos de Google sin conexión) - C:\Users\omarr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2023-11-11]
CHR Extension: (Sistema de pagos de Chrome Web Store) - C:\Users\omarr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2023-11-11]
==================== Servicios (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
S3 aswbIDSAgent; C:\Program Files\Avast Software\Avast\aswidsagent.exe [9111960 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\Avast Software\Avast\AvastSvc.exe [806296 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Tools; C:\Program Files\Avast Software\Avast\aswToolsSvc.exe [839064 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [191120 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\118.0.22847.89\elevation_service.exe [1880304 2023-10-18] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\Avast Software\Avast\wsc_proxy.exe [56912 2023-11-13] (Avast Software s.r.o. -> AVAST Software)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9343840 2023-11-13] (Malwarebytes Inc. -> Malwarebytes)
R2 QMEmulatorService; C:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe [245640 2023-09-21] (Tencent Technology(Shenzhen) Company Limited -> Tencent)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [336144 2023-05-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\NisSrv.exe [3121120 2023-11-12] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe [133704 2023-11-12] (Microsoft Windows Publisher -> Microsoft Corporation)
===================== Controladores (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
R3 amdfendrmgr; C:\Windows\System32\drivers\amdfendrmgr.sys [54720 2022-08-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R3 amdwddmg; C:\Windows\System32\DriverStore\FileRepository\u0381941.inf_amd64_e1aaf87b06e2b6d9\B380668\amdkmdag.sys [94358424 2022-08-08] (Advanced Micro Devices Inc. -> Advanced Micro Devices, Inc.)
R2 aow_drv; C:\Program Files\TxGameAssistant\UI\3.91.4872.81\aow_drv_x64_ev.sys [1472760 2023-09-11] (Tencent Technology (Shenzhen) Company Limited -> Tencent)
S0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [31528 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [240688 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [393904 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [297984 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [96064 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S0 aswElam; C:\Windows\System32\drivers\aswElam.sys [25576 2023-11-13] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
S3 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [39752 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [275280 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R3 aswNetHub; C:\Windows\System32\drivers\aswNetHub.sys [561888 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [105352 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [80528 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [952232 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [710128 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [213296 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [319672 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> AVAST Software)
S3 atvi-randgrid; C:\ProgramData\Battle.net_components\randgridauks\randgrid.sys [2786712 2023-11-12] (Activision Publishing Inc -> Activision Blizzard, Inc.)
S3 BTHMODEM; C:\Windows\System32\drivers\bthmodem.sys [106496 2022-05-07] (Microsoft Corporation) [Archivo no firmado]
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [158640 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [222800 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [21480 2023-11-13] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt11.sys [233704 2023-11-13] (Malwarebytes Inc. -> Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\DRIVERS\mbam.sys [78400 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [239544 2023-11-13] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\DRIVERS\mwac.sys [188016 2023-11-13] (Malwarebytes Inc. -> Malwarebytes)
R3 rtcx21; C:\Windows\System32\DriverStore\FileRepository\rtcx21x64.inf_amd64_516e5c9b75c49dc2\rtcx21x64.sys [539648 2022-05-06] (Microsoft Windows -> Realtek)
S3 UniFairy_x64; C:\Windows\system32\drivers\UniFairy_x64.sys [7445944 2023-11-12] (Tencent Technology(Shenzhen) Company Limited -> )
S3 unirsdt; C:\Windows\system32\drivers\unirsdt.sys [4974960 2023-11-12] (Tencent Technology(Shenzhen) Company Limited -> )
S0 WdBoot; C:\Windows\System32\drivers\wd\WdBoot.sys [55744 2023-11-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\wd\WdFilter.sys [578856 2023-11-12] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [105768 2023-11-12] (Microsoft Windows -> Microsoft Corporation)
U3 aswbdisk; no ImagePath
==================== NetSvcs (Lista blanca) ===================
(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo no se moverá a menos que sea añadido al listado por separado.)
==================== Un mes (creado) (Lista blanca) =========
(Si una entrada es incluida en el fixlist, el archivo/carpeta será eliminado/a.)
2023-11-14 09:43 - 2023-11-14 09:43 - 000018297 _____ C:\Users\omarr\Downloads\FRST.txt
2023-11-14 09:42 - 2023-11-14 09:42 - 000000978 _____ C:\Users\omarr\Desktop\FRST64 - Acceso directo.lnk
2023-11-14 09:41 - 2023-11-14 09:43 - 000000000 ____D C:\FRST
2023-11-14 09:40 - 2023-11-14 09:40 - 002383872 _____ (Farbar) C:\Users\omarr\Downloads\FRST64.exe
2023-11-14 09:38 - 2023-11-14 09:39 - 000000000 ___HD C:$WinREAgent
2023-11-14 09:37 - 2023-11-14 09:37 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2023-11-14 09:35 - 2023-11-14 09:37 - 000000000 ____D C:\Windows\system32\MRT
2023-11-13 17:52 - 2023-11-13 17:52 - 000002568 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2023-11-13 17:52 - 2023-11-13 17:52 - 000002533 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2023-11-13 17:47 - 2023-11-13 17:47 - 000003856 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2023-11-13 17:47 - 2023-11-13 17:47 - 000003272 _____ C:\Windows\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2023-11-13 17:45 - 2023-11-13 17:45 - 000003594 _____ C:\Windows\system32\Tasks\AvastUpdateTaskMachineUA
2023-11-13 17:45 - 2023-11-13 17:45 - 000003470 _____ C:\Windows\system32\Tasks\AvastUpdateTaskMachineCore
2023-11-13 17:45 - 2023-11-13 17:45 - 000000000 ____D C:\Program Files (x86)\AVAST Software
2023-11-13 17:43 - 2023-11-13 17:47 - 000000000 ____D C:\Users\omarr\AppData\Local\Avast Software
2023-11-13 17:43 - 2023-11-13 17:43 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Avast Software
2023-11-13 17:42 - 2023-11-13 17:42 - 000002160 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2023-11-13 17:42 - 2023-11-13 17:42 - 000002148 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2023-11-13 17:40 - 2023-11-13 17:40 - 000313240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2023-11-13 17:40 - 2023-11-13 17:40 - 000003990 _____ C:\Windows\system32\Tasks\Avast Emergency Update
2023-11-13 17:40 - 2023-11-13 17:40 - 000000000 ____D C:\Windows\system32\Tasks\Avast Software
2023-11-13 17:40 - 2023-11-13 17:40 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2023-11-13 17:38 - 2023-11-13 17:38 - 000888600 _____ (Google LLC) C:\Users\Public\Documents\gcapi.dll
2023-11-13 17:38 - 2023-11-13 17:38 - 000000000 ____D C:\Program Files\Avast Software
2023-11-13 17:37 - 2023-11-13 17:41 - 000000000 ____D C:\ProgramData\Avast Software
2023-11-13 17:36 - 2023-11-13 17:36 - 000263576 _____ (AVAST Software) C:\Users\omarr\Downloads\avast_free_antivirus_setup_online.exe
2023-11-13 17:13 - 2023-11-13 17:13 - 000764574 _____ C:\Windows\system32\perfh00A.dat
2023-11-13 17:13 - 2023-11-13 17:13 - 000151736 _____ C:\Windows\system32\perfc00A.dat
2023-11-13 17:09 - 2023-11-13 17:09 - 000233704 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt11.sys
2023-11-13 17:09 - 2023-11-13 17:09 - 000188016 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2023-11-13 17:00 - 2023-11-13 17:00 - 000002033 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2023-11-13 17:00 - 2023-11-13 17:00 - 000002021 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2023-11-13 16:57 - 2023-11-13 16:57 - 000000000 ____D C:\ProgramData\Malwarebytes
2023-11-13 16:49 - 2023-11-13 17:08 - 000548524 _____ C:\Windows\ntbtlog.txt
2023-11-13 16:49 - 2023-11-13 17:01 - 000000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2023-11-13 15:09 - 2023-11-13 15:09 - 000006345 _____ C:\Windows\system32\JeaEgtbxvvqxjosc
2023-11-13 15:09 - 2023-11-13 15:09 - 000006345 _____ C:\Windows\system32\fualFieonv
2023-11-13 15:09 - 2023-11-13 15:09 - 000006345 _____ C:\Windows\system32\ddsStjrcte
2023-11-13 15:09 - 2023-11-13 15:09 - 000006345 _____ C:\Windows\system32\ddsOqays
2023-11-13 15:09 - 2023-11-13 15:09 - 000006345 _____ C:\Windows\system32\blueUbvnjxtherlz
2023-11-13 15:07 - 2023-11-13 15:07 - 000000000 ___HD C:\OneDriveTemp
2023-11-12 19:36 - 2023-11-12 19:36 - 000000000 ____D C:\Users\omarr\AppData\Local\CrashDumps
2023-11-12 13:20 - 2023-11-12 13:20 - 000000000 ____D C:\Users\omarr\Downloads\Nueva carpeta
2023-11-12 12:57 - 2023-11-12 12:57 - 000000000 ____D C:\Users\omarr\Documents\League of Legends
2023-11-12 11:46 - 2023-11-12 19:44 - 000001491 _____ C:\Users\Public\Desktop\Cliente de Riot.lnk
2023-11-12 11:45 - 2023-11-12 11:45 - 000001681 _____ C:\Users\Public\Desktop\League of Legends.lnk
2023-11-12 11:45 - 2023-11-12 11:45 - 000001567 _____ C:\Users\Public\Desktop\Riot Client.lnk
2023-11-12 11:42 - 2023-11-12 11:46 - 000000000 ____D C:\Riot Games
2023-11-12 11:42 - 2023-11-12 11:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
2023-11-12 11:42 - 2023-11-12 11:42 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Riot Games
2023-11-12 11:41 - 2023-11-13 15:24 - 000000000 ____D C:\ProgramData\Riot Games
2023-11-12 11:41 - 2023-11-12 12:57 - 000000000 ____D C:\Users\omarr\AppData\Local\Riot Games
2023-11-12 11:40 - 2023-11-12 11:41 - 071456512 _____ (Riot Games, Inc.) C:\Users\omarr\Downloads\Install League of Legends euw.exe
2023-11-12 11:25 - 2023-11-12 11:25 - 000000000 ____D C:\ProgramData\Battle.net_components
2023-11-12 11:24 - 2023-11-12 19:47 - 000000000 ____D C:\Program Files (x86)\Call of Duty
2023-11-12 11:21 - 2023-11-12 11:21 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2023-11-12 11:16 - 2023-11-14 09:36 - 000000000 ____D C:\Users\omarr\AppData\Local\Malwarebytes
2023-11-12 11:16 - 2023-11-12 11:16 - 000000000 ____D C:\Users\omarr\AppData\Local\mbam
2023-11-12 11:13 - 2023-11-13 16:57 - 000000000 ____D C:\Program Files\Malwarebytes
2023-11-12 11:13 - 2023-11-12 11:13 - 002606880 _____ (Malwarebytes) C:\Users\omarr\Downloads\MBSetup.exe
2023-11-12 10:52 - 2023-11-12 19:48 - 000000000 ____D C:\Users\omarr\AppData\Local\Battle.net
2023-11-12 10:52 - 2023-11-12 11:21 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Battle.net
2023-11-12 10:49 - 2023-11-12 10:49 - 000000950 _____ C:\Users\Public\Desktop\Battle.net.lnk
2023-11-12 10:49 - 2023-11-12 10:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2023-11-12 10:43 - 2023-11-12 11:21 - 000000000 ____D C:\Program Files (x86)\Battle.net
2023-11-12 10:43 - 2023-11-12 10:43 - 000000000 ____D C:\Users\omarr\AppData\Local\Blizzard Entertainment
2023-11-12 10:43 - 2023-11-12 10:43 - 000000000 ____D C:\ProgramData\Battle.net
2023-11-12 10:42 - 2023-11-12 10:42 - 004838352 _____ (Blizzard Entertainment) C:\Users\omarr\Downloads\Battle.net-Setup.exe
2023-11-12 02:04 - 2023-11-12 02:04 - 000000000 ____D C:\Users\omarr\AppData\Local\OneDrive
2023-11-12 01:26 - 2023-11-12 01:26 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2023-11-12 01:19 - 2023-11-12 14:16 - 004974960 _____ () C:\Windows\system32\Drivers\unirsdt.sys
2023-11-12 01:19 - 2023-11-12 10:44 - 004974960 _____ () C:\Windows\system32\Drivers\unirsdt_temp.sys
2023-11-12 01:19 - 2023-11-12 01:19 - 007445944 _____ () C:\Windows\system32\Drivers\UniFairy_x64.sys
2023-11-12 01:19 - 2023-11-12 01:19 - 000000000 ____D C:\Windows\Minidump
2023-11-12 01:19 - 2023-11-12 01:19 - 000000000 ____D C:\Users\omarr\AppData\Roaming\AndroidTbox
2023-11-12 00:14 - 2023-11-12 00:14 - 000000000 ____D C:\Users\omarr\AppData\Local\Comms
2023-11-12 00:12 - 2023-11-12 01:19 - 000000000 ____D C:\ProgramData\Tencent
2023-11-12 00:08 - 2023-11-12 00:34 - 000000000 ____D C:\Program Files\TxGameAssistant
2023-11-12 00:08 - 2023-11-12 00:12 - 000000981 _____ C:\Users\omarr\Desktop\Gameloop.lnk
2023-11-12 00:08 - 2023-11-12 00:08 - 000000000 ____D C:\Users\omarr\AppData\Local\PeerDistRepub
2023-11-12 00:08 - 2023-11-12 00:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tencent Software
2023-11-12 00:07 - 2023-11-12 00:17 - 000000000 ____D C:\Users\omarr\AppData\Local\Steam
2023-11-12 00:07 - 2023-11-12 00:07 - 000000000 ____D C:\Users\omarr\AppData\Local\CEF
2023-11-12 00:02 - 2023-11-12 00:12 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Tencent
2023-11-12 00:02 - 2023-11-12 00:02 - 000000000 ____D C:\Users\omarr\AppData\Local\Tencent
2023-11-12 00:02 - 2023-11-12 00:02 - 000000000 ____D C:\Temp
2023-11-12 00:00 - 2023-11-12 00:00 - 003809416 _____ (Tencent) C:\Users\omarr\Downloads\GLP_installer_900223150_market.exe
2023-11-11 23:58 - 2023-11-11 23:58 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Microsoft\MMC
2023-11-11 23:57 - 2023-11-11 23:57 - 000000000 ____D C:\Users\omarr\AppData\Local\Publishers
2023-11-11 23:54 - 2023-11-11 23:54 - 000002317 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2023-11-11 23:54 - 2023-11-11 23:54 - 000002276 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2023-11-11 23:54 - 2023-11-11 23:54 - 000000000 ____D C:\Users\omarr\AppData\Local\Google
2023-11-11 23:54 - 2023-11-11 23:54 - 000000000 ____D C:\Program Files\Google
2023-11-11 23:52 - 2023-11-14 09:36 - 000000000 ____D C:\Program Files (x86)\Google
2023-11-11 23:52 - 2023-11-13 15:08 - 000003936 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA{284FE5AF-A286-4264-9B58-77CAD636BDD3}
2023-11-11 23:52 - 2023-11-13 15:08 - 000003812 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore{38793544-0591-4B1D-B720-A78BD6267BF7}
2023-11-11 23:43 - 2023-11-11 23:43 - 000000000 ____D C:\Users\omarr\AppData\Local\VirtualStore
2023-11-11 23:42 - 2023-11-14 09:36 - 000000000 ___RD C:\Users\omarr\OneDrive
2023-11-11 23:42 - 2023-11-12 10:35 - 000000000 ____D C:\Users\omarr\AppData\Local\PlaceholderTileLogoFolder
2023-11-11 23:42 - 2023-11-11 23:44 - 000003588 _____ C:\Windows\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2309195285-1605365872-916135564-1001
2023-11-11 23:42 - 2023-11-11 23:44 - 000003356 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2309195285-1605365872-916135564-1001
2023-11-11 23:42 - 2023-11-11 23:44 - 000002379 _____ C:\Users\omarr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2023-11-11 23:42 - 2023-11-11 23:42 - 000000000 ____D C:\Users\omarr\AppData\LocalLow\AMD
2023-11-11 23:42 - 2023-11-11 23:42 - 000000000 ____D C:\ProgramData\Realtek
2023-11-11 23:42 - 2023-11-11 23:42 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2023-11-11 23:41 - 2023-11-13 17:49 - 000000000 ____D C:\Users\omarr\AppData\Local\D3DSCache
2023-11-11 23:41 - 2023-11-13 16:34 - 000089232 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) C:\Windows\system32\GigabyteDownloadAssistant.exe
2023-11-11 23:41 - 2023-11-12 10:35 - 000000000 ____D C:\Users\omarr\AppData\Local\ConnectedDevicesPlatform
2023-11-11 23:41 - 2023-11-12 01:42 - 000000000 ____D C:\Users\omarr\AppData\Local\Packages
2023-11-11 23:41 - 2023-11-12 00:12 - 000000000 ____D C:\Users\omarr\AppData\Local\AMD
2023-11-11 23:41 - 2023-11-11 23:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ___SD C:\Users\omarr\AppData\Roaming\Microsoft\Crypto
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ____D C:\Windows\system32\AMD
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Microsoft\Vault
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Microsoft\Network
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ____D C:\Users\omarr\AppData\Roaming\Adobe
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ____D C:\ProgramData\GIGABYTE
2023-11-11 23:41 - 2023-11-11 23:41 - 000000000 ____D C:\Program Files\AMD
2023-11-11 23:41 - 2022-08-08 06:36 - 001975192 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
2023-11-11 23:41 - 2022-08-08 06:36 - 001975192 _____ C:\Windows\system32\vulkaninfo.exe
2023-11-11 23:41 - 2022-08-08 06:36 - 001531816 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2023-11-11 23:41 - 2022-08-08 06:36 - 001531816 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2023-11-11 23:41 - 2022-08-08 06:36 - 001457064 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
2023-11-11 23:41 - 2022-08-08 06:36 - 001457064 _____ C:\Windows\system32\vulkan-1.dll
2023-11-11 23:41 - 2022-08-08 06:36 - 001168648 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
2023-11-11 23:41 - 2022-08-08 06:36 - 001168648 _____ C:\Windows\SysWOW64\vulkan-1.dll
2023-11-11 23:41 - 2022-08-08 06:36 - 000801176 _____ (Advanced Micro Devic
Saludos omar rioja seria importante realizar un informe con la herramienta farbar para que lo pueda revisar y de acuerdo a lo analisado determinar si hay infeccion, que tipo y como proceder, para esto sigue estos pasos:
Descarguen el programa Farbar Recovery Scan Tool
Farbar Recovery Scan Tool tiene dos versiones (32 bits o 64 bits). Descarguen la versión correspondiente a la arquitectura del sistema que estén utilizando. Si les aparece alguna advertencia de que este programa es peligroso/dañino, no se preocupen que es totalmente seguro. En caso de que el propio sistema no les permita utilizarlo, deberán deshabilitar temporalmente todas las características de seguridad Windows Defender.
En la ventana principal, deben marcar (si no están marcadas ya por defecto) las casillas de verificación "Registro", "Servicios", "Controladores", "Procesos" e "Internet". Además, DEBEN ASEGURARSE de marcar la casilla de verificación "Addition.txt" si no está marcada ya de manera predeterminada. Hagan clic en el botón Analizar y esperen a que concluya el análisis.