0% found this document useful (0 votes)
58 views

Addition

Uploaded by

Ulises- Sa-V.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
58 views

Addition

Uploaded by

Ulises- Sa-V.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 12

Resultados del Análisis Adicional de Farbar Recovery Scan Tool (x64) Versión:

11.01.2024
Ejecutado por Estudiante (13-01-2024 11:41:06)
Ejecutado desde C:\Users\Estudiante\Downloads
Microsoft Windows 11 Pro Education Versión 23H2 22631.2861 (X64) (2023-11-17
01:03:35)
Modo de Inicio: Normal
==========================================================

==================== Cuentas: =============================

(Si una entrada es incluida en el fixlist, será eliminada.)

Administrador (S-1-5-21-3063857521-964734792-2487657082-500 - Administrator -


Disabled)
DefaultAccount (S-1-5-21-3063857521-964734792-2487657082-503 - Limited - Disabled)
Estudiante (S-1-5-21-3063857521-964734792-2487657082-1000 - Administrator -
Enabled) => C:\Users\Estudiante
Invitado (S-1-5-21-3063857521-964734792-2487657082-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-3063857521-964734792-2487657082-504 - Limited -
Disabled)

==================== Centro de Seguridad ========================

(Si una entrada es incluida en el fixlist, será eliminada.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Programas instalados ======================

(Solo los programas de adware con indicador "Oculto", pueden ser añadidos al
fixlist para hacerlos visibles. Los programas adware deben ser desinstalados
manualmente.)

Adobe Acrobat (64-bit) (HKLM\...\{AC76BA86-1033-FF00-7760-BC15014EA700}) (Version:


23.008.20458 - Adobe)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 6.1.0.587 -
Adobe Inc.)
Adobe Refresh Manager (HKLM-x32\...\{AC76BA86-0804-1033-1959-018244601053})
(Version: 1.8.0 - Adobe Systems Incorporated) Hidden
Arduino IDE 2.2.1 (HKU\S-1-5-21-3063857521-964734792-2487657082-1000\...\459fc68c-
eb53-59f8-8957-9913bc627af3) (Version: 2.2.1 - Arduino SA)
Counter-Strike 1.6 version 8949 (HKLM-x32\...\{23C6896F-3BCC-4038-9D4F-
2D63973D6E45}_is1) (Version: 8949 - download-cs16.ro Team)
Disk Drill 5.3.826.0 (HKLM-x32\...\{49b90425-d03c-4b56-b8ba-0ccd425f5863})
(Version: 5.3.826.0 - CleverFiles)
Disk Drill 5.3.826.0 (x64) (HKLM\...\{219D8DEC-A93F-4A90-866B-20B5B37DAE94})
(Version: 5.3.826.0 - CleverFiles) Hidden
Dokan Library 1.5.1.1000 (x64) (HKLM\...\{65A3A964-3DC3-0105-0001-211126123627})
(Version: 1.5.1.1000 - Dokany Project) Hidden
Dokan Library 1.5.1.1000 Bundle (HKLM-x32\...\{05c046de-f751-48c8-b8d3-
77259ea88eb7}) (Version: 1.5.1.1000 - Dokany Project)
Logitech Options (HKLM\...\LogiOptions) (Version: 10.10.58 - Logitech)
Microsoft .NET Host - 7.0.8 (x64) (HKLM\...\{19FCE07F-2A75-44AC-9EA5-8E29FE2F8DBE})
(Version: 56.35.63143 - Microsoft Corporation) Hidden
Microsoft .NET Host FX Resolver - 7.0.8 (x64) (HKLM\...\{174E0D7C-F2C9-49A2-83FB-
95A0FE6FA023}) (Version: 56.35.63143 - Microsoft Corporation) Hidden
Microsoft .NET Runtime - 7.0.8 (x64) (HKLM\...\{B45C77BA-0B4E-4FBB-99B9-
9774ECBE20AA}) (Version: 56.35.63143 - Microsoft Corporation) Hidden
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 120.0.2210.133 - Microsoft
Corporation)
Microsoft Office Profesional 2021 - es-mx (HKLM\...\Professional2021Retail - es-mx)
(Version: 16.0.17126.20132 - Microsoft Corporation)
Microsoft OneDrive (HKLM\...\OneDriveSetup.exe) (Version: 23.246.1127.0002 -
Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{C6FD611E-7EFE-488C-A0E0-974C09EF6473})
(Version: 5.72.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40664 (HKLM-x32\...\
{042d26ef-3dbe-4c25-95d3-4c1b11b235a7}) (Version: 12.0.40664.0 - Microsoft
Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40664 (HKLM-x32\...\
{9dff3540-fc85-4ed5-ac84-9e3c7fd8bece}) (Version: 12.0.40664.0 - Microsoft
Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40664 (HKLM\...\{010792BA-
551A-3AC0-A7EF-0FAB4156C382}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40664 (HKLM\...\{53CF6934-
A98D-3D84-9146-FC4EDF3D5641}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40664 (HKLM-x32\...\
{D401961D-3A20-3AC7-943B-6139D5BD490A}) (Version: 12.0.40664 - Microsoft
Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40664 (HKLM-x32\...\{8122DAB1-
ED4D-3676-BB0A-CA368196543E}) (Version: 12.0.40664 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.34.31938 (HKLM-x32\...\
{d92971ab-f030-43c8-8545-c66c818d0e05}) (Version: 14.34.31938.0 - Microsoft
Corporation)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.32.31326 (HKLM-x32\...\
{817e21c1-6b3a-4bc1-8c49-67e4e1887b3a}) (Version: 14.32.31326.0 - Microsoft
Corporation)
Microsoft Visual C++ 2022 X64 Additional Runtime - 14.34.31938 (HKLM\...\{7DA37AE3-
D8AE-49B1-9BDC-23CA0AB9FF22}) (Version: 14.34.31938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.34.31938 (HKLM\...\{0AE39060-
F209-4D05-ABC7-54B8F9CFA32E}) (Version: 14.34.31938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.32.31326 (HKLM-x32\...\
{A250E750-DB3F-40C1-8460-8EF77C7582DA}) (Version: 14.32.31326 - Microsoft
Corporation) Hidden
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.32.31326 (HKLM-x32\...\
{46E11E7F-01E1-44D0-BB86-C67342D253DD}) (Version: 14.32.31326 - Microsoft
Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.8 (x64) (HKLM\...\{3133BC55-90BD-4B87-82A2-
6670B3CAFB81}) (Version: 56.35.63153 - Microsoft Corporation) Hidden
Microsoft Windows Desktop Runtime - 7.0.8 (x64) (HKLM-x32\...\{d260fcb6-95b8-4c81-
8e07-ce75876ffca2}) (Version: 7.0.8.32619 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM\...\{90160000-008C-0000-1000-
0000000FF1CE}) (Version: 16.0.17126.20132 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-007E-0000-1000-
0000000FF1CE}) (Version: 16.0.17126.20132 - Microsoft Corporation) Hidden
PCB Wizard 3 Demonstration (HKLM-x32\...\{4D52F957-1316-4A12-86D7-3CDC04081970})
(Version: - )
Software Logitech Unifying 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 -
Logitech)
Theft Deterrent Plus client (HKLM-x32\...\{391856DF-9B97-4381-9361-34D227CBEDF5})
(Version: 6.0.10000.3 - JP-IK)
Theft Deterrent Plus guardian (HKLM-x32\...\{783CE66B-15CF-4F58-B0CE-7101486A43C0})
(Version: 6.0.10000.3 - ECS)
Update for Windows 10 for x64-based Systems (KB5001716) (HKLM\...\{C270D21B-2327-
49B8-85F7-395133A93C75}) (Version: 8.92.0.0 - Microsoft Corporation)
WebView2 Runtime de Microsoft Edge (HKLM-x32\...\Microsoft EdgeWebView) (Version:
120.0.2210.121 - Microsoft Corporation)
WinRAR 6.24 (64-bit) (HKLM\...\WinRAR archiver) (Version: 6.24.0 - win.rar GmbH)

Packages:
=========
Adobe Acrobat Reader -> C:\Program Files\Adobe\Acrobat DC [2024-01-12] ()
AppUp.IntelGraphicsExperience -> C:\Program Files\WindowsApps\
AppUp.IntelGraphicsExperience_1.100.5287.0_x64__8j3eq9eme6ctt [2023-12-22] (INTEL
CORP) [Startup Task]
Asphalt 8: Airborne -> C:\Program Files\WindowsApps\
GAMELOFTSA.Asphalt8Airborne_7.5.12.0_x64__0pp20fcewvvtj [2023-12-26] (GAMELOFT SA)
Dev Home -> C:\Program Files\WindowsApps\
Microsoft.Windows.DevHome_0.0.0.0_x64__8wekyb3d8bbwe [2023-11-16] (Microsoft
Corporation)
Instagram -> C:\Program Files\WindowsApps\
Facebook.InstagramBeta_42.0.21.0_neutral__8xx8rvfyw5nnt [2023-12-26] (Instagram)
Light and Dark by Nick Boyer -> C:\Program Files\WindowsApps\
Microsoft.LightandDarkbyNickBoyer_1.0.0.0_neutral__8wekyb3d8bbwe [2023-11-16]
(Microsoft Corporation)
Microsoft.WindowsAppRuntime.CBS -> C:\Windows\SystemApps\
Microsoft.WindowsAppRuntime.CBS_8wekyb3d8bbwe [2023-12-22] (Microsoft Corporation)
Roblox -> C:\Program Files\WindowsApps\
ROBLOXCORPORATION.ROBLOX_2.605.660.0_x64__55nm5eh3cm0pr [2023-12-20] (Roblox
Corporation)
Samsung Printer Experience -> C:\Program Files\WindowsApps\
SAMSUNGELECTRONICSCO.LTD.SamsungPrinterExperience_1.3.15.0_x64__3c1yjt4zspk6g
[2023-11-09] (Samsung Electronics Co. Ltd.)
Solitaire & Casual Games -> C:\Program Files\WindowsApps\
Microsoft.MicrosoftSolitaireCollection_4.18.11020.0_x64__8wekyb3d8bbwe [2023-11-14]
(Microsoft Studios) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\
SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0 [2023-12-20] (Spotify AB)
[Startup Task]
WhatsApp -> C:\Program Files\WindowsApps\
5319275A.WhatsAppDesktop_2.2349.2.0_x64__cv1g1gvanyjgm [2023-12-22] (WhatsApp Inc.)
[Startup Task]
Windows Feature Experience Pack -> C:\Windows\SystemApps\
MicrosoftWindows.Client.FileExp_cw5n1h2txyewy [2023-12-22] (Microsoft Corporation)

==================== Personalizado CLSID (Lista blanca): ==============

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo
no se moverá a menos que sea añadido al listado por separado.)

CustomCLSID: HKU\S-1-5-21-3063857521-964734792-2487657082-1000_Classes\CLSID\
{2F81B25E-7507-4844-BFF2-77D2CC24CED4}\localserver32 -> C:\Program Files\Adobe\
Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Inc. -> Adobe Inc.)
CustomCLSID: HKU\S-1-5-21-3063857521-964734792-2487657082-1000_Classes\CLSID\
{38142727-3008-9161-1521-349515000000}\localserver32 -> C:\Program Files\Adobe\
Acrobat DC\Acrobat\ADNotificationManager.exe (Adobe Inc. -> Adobe)
CustomCLSID: HKU\S-1-5-21-3063857521-964734792-2487657082-1000_Classes\CLSID\
{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\
Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Inc. -> Adobe
Systems)
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}
=> C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-
12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-
C78F2274A524} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-
AF20F3606282} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-
2A5D9D2F7F30} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-
7085BA96DA5A} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-
95FFCCAEF20E} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-
24A483E2CCC3} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-
2DFDD5449D9C} => C:\Program Files\Microsoft OneDrive\23.246.1127.0002\
FileSyncShell64.dll [2023-12-20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>
C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-12-
20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander
Roshal)
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>
C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-12-
20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers5: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} =>
C:\Program Files\Microsoft OneDrive\23.246.1127.0002\FileSyncShell64.dll [2023-12-
20] (Microsoft Corporation -> Microsoft Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\
Program Files\WinRAR\rarext.dll [2023-10-03] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>
C:\Program Files\WinRAR\rarext32.dll [2023-10-03] (win.rar GmbH -> Alexander
Roshal)

==================== Codecs (Lista blanca) ====================


==================== Accesos directos & WMI ========================

==================== Módulos cargados (Lista blanca) =============

2012-10-10 21:59 - 2012-10-10 21:59 - 000023552 _____ () [Archivo no firmado] C:\


Program Files (x86)\Intel Education Software\Theft Deterrent client\TDHelpDLL.dll
2018-01-31 10:58 - 2018-01-31 10:58 - 001209856 _____ (Intel Corporation) [Archivo
no firmado] [El archivo está en uso] C:\Program Files (x86)\Intel Education
Software\Theft Deterrent client\theme.dll
2018-01-30 11:43 - 2018-01-30 11:43 - 000812032 _____ (Intel Corporation) [Archivo
no firmado] C:\Program Files (x86)\Intel Education Software\Theft Deterrent client\
liblog.dll
2023-07-29 14:01 - 2023-07-29 14:01 - 000000000 ____L (Microsoft Corporation)
[symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\
AppvIsvSubsystems64.dll] C:\Program Files\Microsoft Office\Root\Office16\
AppVIsvSubsystems64.dll
2023-07-29 14:01 - 2023-07-29 14:01 - 000000000 ____L (Microsoft Corporation)
[symlink -> C:\Program Files\Common Files\Microsoft Shared\ClickToRun\C2R64.dll]
C:\Program Files\Microsoft Office\Root\Office16\c2r64.dll
2012-10-29 11:49 - 2012-10-29 11:49 - 000042496 _____ (The Apache Software
Foundation) [Archivo no firmado] [El archivo está en uso] C:\Program Files (x86)\
Intel Education Software\Theft Deterrent client\Thrift.dll
2018-01-30 11:57 - 2018-01-30 11:57 - 001234432 _____ (TODO: <Company name>)
[Archivo no firmado] C:\Program Files (x86)\Intel Education Software\Theft
Deterrent protect\LockTime.dll

==================== Alternate Data Streams (Lista blanca) ========

==================== Modo Seguro (Lista blanca) ==================

==================== Asociación (Lista blanca) =================

==================== Internet Explorer (Lista blanca) ==========

BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-


2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\
Microsoft Office\Office16\OCHelper.dll [2024-01-12] (Microsoft Corporation ->
Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program
Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-01-12] (Microsoft Corporation
-> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\
Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\
MSOSB.DLL [2024-01-12] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\
Microsoft Office\root\Office16\MSOSB.DLL [2024-01-12] (Microsoft Corporation ->
Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program
Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
[2024-01-12] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program
Files\Microsoft Office\root\Office16\MSOSB.DLL [2024-01-12] (Microsoft Corporation
-> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program
Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
[2024-01-12] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\
Microsoft Office\root\Office16\MSOSB.DLL [2024-01-12] (Microsoft Corporation ->
Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\
Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
[2024-01-12] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts contenido: =========================

(Si es necesario, la directiva Hosts: puede ser incluida en el fixlist para


restablecer Hosts.)

2019-12-07 06:14 - 2019-12-07 06:12 - 000000824 _____ C:\WINDOWS\system32\drivers\


etc\hosts

==================== Otras Áreas ===========================

(Actualmente no existe una corrección automática para esta sección.)

HKU\S-1-5-21-3063857521-964734792-2487657082-1000\Control Panel\Desktop\\Wallpaper
-> c:\users\estudiante\downloads\windows-11-dark-black-tp-2560x1440.jpg
DNS Servers: 192.168.100.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System =>
(ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Firewall de Windows está habilitado.

==================== MSCONFIG/TASK MANAGER elementos deshabilitados ==

==================== Reglas de firewall (Lista blanca) ================

(Si una entrada es incluida en el fixlist, será eliminada del registro. El archivo
no se moverá a menos que sea añadido al listado por separado.)

FirewallRules: [UDP Query User{AF672DD2-E0F9-486E-856A-BAB59912118A}C:\users\


estudiante\appdata\local\programs\arduino ide\arduino ide.exe] => (Allow) C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe (Arduino SA ->
Arduino SA)
FirewallRules: [TCP Query User{7BD3F501-B999-4CAE-8A02-18278DF51FF8}C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe] => (Allow) C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe (Arduino SA ->
Arduino SA)
FirewallRules: [UDP Query User{698FE660-53F3-4A51-99CB-0527F7AECF51}C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe] => (Allow) C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe (Arduino SA ->
Arduino SA)
FirewallRules: [TCP Query User{2A82CDC0-5D60-47A1-8416-ADB8E22D27F0}C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe] => (Allow) C:\users\
estudiante\appdata\local\programs\arduino ide\arduino ide.exe (Arduino SA ->
Arduino SA)
FirewallRules: [UDP Query User{B231EB78-81AA-4DFE-AA23-5105AC7036E9}C:\users\
estudiante\appdata\local\arduino15\packages\builtin\tools\mdns-discovery\1.0.9\
mdns-discovery.exe] => (Allow) C:\users\estudiante\appdata\local\arduino15\
packages\builtin\tools\mdns-discovery\1.0.9\mdns-discovery.exe () [Archivo no
firmado]
FirewallRules: [TCP Query User{ABCBC81B-61F1-447E-BAFB-B8A4A8DEC3FB}C:\users\
estudiante\appdata\local\arduino15\packages\builtin\tools\mdns-discovery\1.0.9\
mdns-discovery.exe] => (Allow) C:\users\estudiante\appdata\local\arduino15\
packages\builtin\tools\mdns-discovery\1.0.9\mdns-discovery.exe () [Archivo no
firmado]
FirewallRules: [{416B16AB-AE90-4579-BFD7-ACBB768CCF58}] => (Allow) C:\Program
Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation ->
Microsoft Corporation)
FirewallRules: [{981A58C3-EA67-439D-BC24-2A2E48E6D557}] => (Allow) LPort=10911
FirewallRules: [UDP Query User{87FFC77F-25A5-4B92-98CF-2CB900C958C8}C:\program
files (x86)\intel education software\theft deterrent protect\locktimeapp.exe] =>
(Allow) C:\program files (x86)\intel education software\theft deterrent protect\
locktimeapp.exe () [Archivo no firmado]
FirewallRules: [TCP Query User{37CBCF6D-6B05-482E-A049-E56632A9BD38}C:\program
files (x86)\intel education software\theft deterrent protect\locktimeapp.exe] =>
(Allow) C:\program files (x86)\intel education software\theft deterrent protect\
locktimeapp.exe () [Archivo no firmado]
FirewallRules: [{659A898A-FD35-4AE4-A96E-00316CEF31FD}] => (Allow) LPort=5000
FirewallRules: [{FE1C5599-F798-4FB0-8EE0-853679D23946}] => (Allow) LPort=8911
FirewallRules: [{BF45D977-D3A2-4029-B346-99303852B579}] => (Allow) LPort=7911
FirewallRules: [{15DAFC55-AA19-4641-8D8D-72F625427CA6}] => (Allow) LPort=9911
FirewallRules: [{091BA823-8A0C-4E31-986B-C7F94CEC8353}] => (Allow) C:\Program
Files\WindowsApps\MicrosoftTeams_23285.3703.2471.4627_x64__8wekyb3d8bbwe\
msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{BF793A76-DC8D-43BA-9A17-D821D155C32F}] => (Allow) C:\Program
Files\WindowsApps\MicrosoftTeams_23285.3703.2471.4627_x64__8wekyb3d8bbwe\
msteams.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A7F5DF2F-F4B8-4D5A-8EF9-D773468C47FB}] => (Allow) C:\Games\
Counter-Strike 1.6\hl.exe (Valve -> Valve)
FirewallRules: [{5945193A-F970-4BE4-B598-FA8E8349F309}] => (Allow) C:\Games\
Counter-Strike 1.6\hl.exe (Valve -> Valve)
FirewallRules: [{7EE1CB85-CE8B-47E1-96C7-05837150A8AE}] => (Allow) C:\Games\
Counter-Strike 1.6\hl.exe (Valve -> Valve)
FirewallRules: [{29F44969-79B5-41E1-831F-A1FF2AD79423}] => (Allow) C:\Games\
Counter-Strike 1.6\hl.exe (Valve -> Valve)
FirewallRules: [{5EF10A5D-F69F-47CF-ACB8-0F87FC455500}] => (Allow) C:\ProgramData\
Logishrd\LogiOptions\Software\Current\LogiOptionsMgr.EXE (Logitech Inc -> Logitech,
Inc.)
FirewallRules: [{53192716-D481-4027-8554-D5C463FAB4B4}] => (Allow) C:\Program
Files\Fortect\MainService.exe => Ningún archivo
FirewallRules: [{FF7820BA-C202-4190-9859-A68394C6E636}] => (Allow) C:\Program
Files\Fortect\MainService.exe => Ningún archivo
FirewallRules: [{B8FF69A8-8DD1-4602-937D-8DE90A61694E}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{B9F3E75D-03CA-467F-A2DA-BFFC296D8ED1}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{E5B02D46-50BD-4F93-87BD-E2F938DE2FB2}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{50AADCAC-0B03-4065-A26E-3888D7533C4B}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{08785357-B425-438D-BA6C-59E4CE955973}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{432DC23C-0726-421D-94AB-6657B9E942DB}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{F903A4D4-A293-46C7-82BC-61C7E796B2C6}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{FD80CBC4-2AB9-4B9C-80F0-551CC902A6FC}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{CEAA7BD1-4420-4292-B940-DFD67B9060DA}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BEF27C0E-7A88-458D-AA2A-660584234AA1}] => (Allow) C:\Program
Files\WindowsApps\SpotifyAB.SpotifyMusic_1.226.1187.0_x64__zpdnekdrzrea0\
Spotify.exe (453637B3-4E12-4CDF-B0D3-2A3C863BF6EF -> Spotify Ltd)
FirewallRules: [{BD00ECF2-3FA5-43E1-9FDC-9017C5E83C81}] => (Allow) C:\Program Files
(x86)\Microsoft\EdgeWebView\Application\120.0.2210.121\msedgewebview2.exe
(Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{FE61158F-6B78-4EE0-A1A4-C1A5C294BF5E}] => (Allow) C:\Program
Files\WindowsApps\Microsoft.SkypeApp_15.110.3218.0_x64__kzf8qxf38zg5c\Skype\
Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{65FDD92D-D101-4499-A764-2B8B9E8488CB}] => (Allow) C:\Program
Files\WindowsApps\Microsoft.SkypeApp_15.110.3218.0_x64__kzf8qxf38zg5c\Skype\
Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{DF3079DD-651F-4047-B722-F695551E3A72}] => (Allow) C:\Program
Files\WindowsApps\Microsoft.SkypeApp_15.110.3218.0_x64__kzf8qxf38zg5c\Skype\
Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{CA5919D2-AB87-4CF5-B19E-5F3CEC9E6C62}] => (Allow) C:\Program
Files\WindowsApps\Microsoft.SkypeApp_15.110.3218.0_x64__kzf8qxf38zg5c\Skype\
Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)

==================== Puntos de Restauración =========================

==================== Dispositivos defectuosos en el Administrador de dispositivos


============

==================== Errores del registro de eventos: ========================

Errores de aplicación:
==================
Error: (01/12/2024 02:01:52 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1017)
(User: NT AUTHORITY)
Description: Se deshabilitó la recopilación de datos de los contadores de
rendimiento del servicio "Lsa" debido a uno o más errores generados por la
biblioteca de contadores de rendimiento de este servicio. Los errores que exigieron
esta acción se escribieron en el registro de eventos de la aplicación. Corrija
estos errores antes de habilitar los contadores de rendimiento para este servicio.

Error: (01/12/2024 02:01:52 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1005)


(User: NT AUTHORITY)
Description: El intento de localizar el procedimiento Open "OpenLsaPerformanceData"
en el archivo DLL "C:\Windows\System32\Secur32.dll" del servicio "Lsa" produjo un
error con el código Win32 127. Los datos de rendimiento de este servicio no estarán
disponibles.

Error: (01/12/2024 01:27:30 PM) (Source: Microsoft-Windows-RestartManager)


(EventID: 10006) (User: ULYSSES-DESK)
Description: Application or service 'Microsoft Office SDX Helper' could not be shut
down.

Error: (12/22/2023 10:13:35 PM) (Source: Application Hang) (EventID: 1002) (User:
NT AUTHORITY)
Description: El programa GameBar.exe versión 6.123.11012.0 dejó de interactuar con
Windows y se cerró. Para ver si hay más información disponible sobre este problema,
comprueba el historial de problemas en el panel de control de Seguridad y
mantenimiento.
Error: (12/21/2023 09:31:42 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Error del Servicio de instantáneas de volumen: error inesperado al
llamar a la rutina QueryFullProcessImageNameW. HR = 0x80070006, Controlador no
válido..

Operación:
Ejecutando operación asincrónica

Contexto:
Estado actual: DoSnapshotSet

Error: (12/21/2023 09:30:53 PM) (Source: VSS) (EventID: 8193) (User: )


Description: Error del Servicio de instantáneas de volumen: error inesperado al
llamar a la rutina QueryFullProcessImageNameW. HR = 0x80070006, Controlador no
válido..

Operación:
Ejecutando operación asincrónica

Contexto:
Estado actual: DoSnapshotSet

Error: (12/20/2023 11:42:58 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: No se pudo crear el punto de restauración (proceso = C:\WINDOWS\
system32\svchost.exe -k netsvcs -p -s wuauserv; descripción = Windows Update; error
= 0x80042319).

Error: (12/20/2023 11:42:57 AM) (Source: SPP) (EventID: 16387) (User: )


Description: Error en la creación de instantáneas debido a un error notificado por
el
escritor MSSearch Service Writer.

Más información: .

Errores del sistema:


=============
Error: (01/13/2024 11:30:08 AM) (Source: DCOM) (EventID: 10010) (User: ULYSSES-
DESK)
Description: El servidor {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} no se registró con
DCOM dentro del tiempo de espera requerido.

Error: (01/12/2024 09:59:10 PM) (Source: Microsoft-Windows-WindowsUpdateClient)


(EventID: 20) (User: NT AUTHORITY)
Description: Error de instalación: error de Windows al instalar la siguiente
actualización, error 0x80073d02: 9MSSGKG348SP-
MicrosoftWindows.Client.WebExperience.

Error: (01/12/2024 09:56:48 PM) (Source: Microsoft-Windows-WindowsUpdateClient)


(EventID: 20) (User: NT AUTHORITY)
Description: Error de instalación: error de Windows al instalar la siguiente
actualización, error 0x80073d02: 9NKSQGP7F2NH-5319275A.WhatsAppDesktop.

Error: (12/22/2023 11:30:13 PM) (Source: DCOM) (EventID: 10010) (User: ULYSSES-
DESK)
Description: El servidor {8CFC164F-4BE5-4FDD-94E9-E2AF73ED4A19} no se registró con
DCOM dentro del tiempo de espera requerido.
Error: (12/22/2023 10:35:42 PM) (Source: DCOM) (EventID: 10010) (User: ULYSSES-
DESK)
Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con
DCOM dentro del tiempo de espera requerido.

Error: (12/22/2023 10:35:42 PM) (Source: DCOM) (EventID: 10010) (User: ULYSSES-
DESK)
Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con
DCOM dentro del tiempo de espera requerido.

Error: (12/22/2023 10:35:42 PM) (Source: DCOM) (EventID: 10010) (User: ULYSSES-
DESK)
Description: El servidor {021E4F06-9DCC-49AD-88CF-ECC2DA314C8A} no se registró con
DCOM dentro del tiempo de espera requerido.

Error: (12/22/2023 10:35:42 PM) (Source: DCOM) (EventID: 10010) (User: ULYSSES-
DESK)
Description: El servidor {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} no se registró con
DCOM dentro del tiempo de espera requerido.

Windows Defender:
================
Date: 2024-01-13 11:31:32
Description:
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {0E9A2D0F-D495-40D5-9D74-0A270DE582DB}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: ULYSSES-DESK\Estudiante#

Date: 2024-01-13 11:28:49


Description:
Antivirus de Microsoft Defender detectó malware u otro software potencialmente no
deseado.
Para más información, consulta lo siguiente:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Script/Wacatac.H!
ml&threatid=2147814524&enterprise=0
Nombre: Trojan:Script/Wacatac.H!ml
Id.: 2147814524
Gravedad: Grave
Categoría: Caballo de Troya
Ruta de acceso: file:_C:\Users\Estudiante\AppData\Local\Microsoft\Edge\User Data\
Profile 1\Cache\Cache_Data\f_00120d
Origen de detección: Equipo local
Tipo de detección: FastPath
Origen de detección: Protección en tiempo real
Usuario: NT AUTHORITY\SYSTEM
Nombre de proceso: C:\Program Files\CleverFiles\Disk Drill\cfbackd.w32.exe
Versión de inteligencia de seguridad: AV: 1.403.2065.0, AS: 1.403.2065.0, NIS:
1.403.2065.0
Versión de motor: AM: 1.1.23110.2, NIS: 1.1.23110.2#

Date: 2023-11-29 11:35:38


Description:
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {2743987C-52F8-4C65-8035-86895DFAE980}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM#

Date: 2023-11-27 09:03:02


Description:
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {170781DB-D205-4EEE-89B9-389B766B8A02}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM#

Date: 2023-11-23 21:25:33


Description:
El examen de Antivirus de Microsoft Defender se detuvo antes de completarse.
Id. de examen: {D200C084-8DFF-431C-A2CF-8E5D7A257268}
Tipo de examen: Antimalware
Parámetros de examen: Examen rápido
Usuario: NT AUTHORITY\SYSTEM#
Event[0]

Date: 2023-12-21 21:32:10


Description:
Antivirus de Microsoft Defender detectó un error al intentar actualizar la
inteligencia de seguridad.
Nueva versión de inteligencia de seguridad:
Versión anterior de inteligencia de seguridad: 1.403.810.0
Origen de actualización: Servidor de Microsoft Update
Tipo de inteligencia de seguridad: AntiVirus
Tipo de actualización: Completa
Usuario: NT AUTHORITY\SYSTEM
Versión actual del motor:
Versión anterior del motor: 1.1.23110.2
Código de error: 0x80240016
Descripción del error: Se produjo un problema inesperado mientras se buscaban
actualizaciones. Para obtener más información sobre cómo instalar o solucionar
problemas en las actualizaciones, consulta Ayuda y soporte técnico. #

CodeIntegrity:
===============
Date: 2023-11-23 21:07:54
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\ProgramData\
Microsoft\Windows Defender\Platform\4.18.23100.2009-0\MsMpEng.exe) attempted to
load \Device\HarddiskVolume6\Program Files\Microsoft Office\root\vfs\
ProgramFilesCommonX64\Microsoft Shared\OFFICE16\MSOXMLMF.DLL that did not meet the
Custom 3 / Antimalware signing level requirements.#

==================== Información de la memoria ===========================

BIOS: American Megatrends Inc. 2.03.00.CI22 08/26/2022


Placa base: Conectar Igualdad SF20GM7
Procesador: Intel(R) Celeron(R) N4020 CPU @ 1.10GHz
Porcentaje de memoria en uso: 61%
RAM física total: 8015.79 MB
RAM física disponible: 3097.89 MB
Virtual total: 8527.79 MB
Virtual disponible: 3288.93 MB

==================== Unidades ================================


Drive c: (Windows) (Fixed) (Total:187.11 GB) (Free:124.57 GB) (Model: kimtigo SSD
480GB) NTFS

\\?\Volume{a1cde6a5-d1e6-4138-af0a-963b9871867d}\ () (Fixed) (Total:0.65 GB)


(Free:0.08 GB) NTFS
\\?\Volume{76883b72-f9b5-467b-99bb-219586c24926}\ () (Fixed) (Total:0.5 GB)
(Free:0.47 GB) FAT32

==================== MBR & Tabla de particiones ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 447.1 GB) (Disk ID: 00000000)

Partition: GPT.

==================== Final de Addition.txt =======================

You might also like