FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2021
Ran by Carlos Luna (administrator) on 1989AH (ASUS All Series) (03-11-2021 20:11:42)
Running from C:\Users\Carlos Luna\Desktop
Loaded Profiles: Carlos Luna
: Microsoft Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Default browser: Opera
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Borislav Surbat -> MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) [File not signed] C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Windows Hardware Compatibility Publisher -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(Opera Software AS -> Opera Software) C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\80.0.4170.61\opera_crashreporter.exe
(Opera Software AS -> Opera Software) C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\opera.exe <12>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9068040 2016-11-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [ProxyCap] => C:\Program Files\Proxy Labs\ProxyCap\pcapui.exe
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8294680 2014-02-27] (Logitech -> Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Genshin Impact_Launcher] => [X]
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [ADSKAppManager] => "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\Run: [Opera GX Browser Assistant] => C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (Borislav Surbat -> MyCity)
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\Run: [Google Update] => "C:\Users\Carlos Luna\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: E - E:\setup.exe
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: {7776be3f-f783-11e4-b3bf-ab6770d31304} - E:\Startme.exe
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: {c02e2f6e-805e-11e6-9b0c-d850e63c46b2} - E:\setup\rsrc\Autorun.exe
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: {c2d0008f-546d-11e8-b0dd-0014d1237121} - F:\startme.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-03-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\Users\Carlos Luna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameVox.lnk [2016-03-17]
ShortcutTarget: GameVox.lnk -> C:\Program Files (x86)\GameVox\GameVox.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0C9A5565-C85D-4309-810F-9B2EF6D93455} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Carlos Luna\Downloads\esetonlinescanner_esn.exe
Task: {1156D15A-AAE6-4EE4-A768-C21AF23191D3} - System32\Tasks\{9F4A8BFD-E17F-4A42-B4EE-55FD2C147405} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\AppData\Roaming\Nox\bin\Nox_unload.exe"
Task: {1ADD0762-CC79-45E7-B15D-17E123E1BE18} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2206488 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {427624A0-6125-446F-84D9-BC6C71027E47} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2225952 2016-08-15] (Microsoft Corporation -> Microsoft)
Task: {4580E52B-91EE-42B5-9363-56BABDA2AFFC} - System32\Tasks\CorelUpdateHelperTask-F299A6B575097899476390FCD7D79BE3 => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe
Task: {45A4D6E9-3EB8-4039-87C0-8EDD5A1CDC23} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1634663272 => C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\launcher.exe [3963600 2021-10-19] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {4D109734-C672-4DAB-8E1C-0848709181B8} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2305226654-651215044-733858041-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {52482CF5-BDD9-49A4-94A9-43C7A412C125} - System32\Tasks\{CB3E5831-270F-443A-894C-A54F005941DE} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\Downloads\setup-gtarcade-601b27db75125.exe" -d "C:\Users\Carlos Luna\Downloads"
Task: {5918D14A-68E3-4CFE-B21E-E1748D153440} - System32\Tasks\AdobeAAMUpdater-1.0-CarlosLuna-PC-Carlos Luna => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {61AA0E70-25B1-4153-A33F-B19B7AC78098} - System32\Tasks\{0C2E49FB-E0FA-4939-849F-2F5A476D0F82} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\Downloads\coreaacSetup.exe" -d "C:\Users\Carlos Luna\Downloads"
Task: {62A6C492-DB90-48A0-8729-0E9EE4C6AA60} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104 2015-07-07] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {671E9D4A-C29E-4F2E-B2B6-E844B48D0215} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {6D10DDD6-E35A-4909-8989-1D5F095840CE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [4624152 2014-06-24] (Piriform Ltd -> Piriform Ltd)
Task: {6FC4D6E7-AEFA-40A9-9BB7-93CA381DA6F7} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2021-09-21] (Bluestack Systems, Inc -> BlueStack Systems, Inc.)
Task: {8F95A2D6-F062-4745-A5AF-962DB9825FAA} - System32\Tasks\Opera GX scheduled Autoupdate 1634241479 => C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\launcher.exe [3963600 2021-10-19] (Opera Software AS -> Opera Software)
Task: {93D89636-DEDB-4163-B18A-E7AA18E71A78} - System32\Tasks\CorelUpdateHelperTaskCore => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe
Task: {A3B005D3-E9D2-481C-8F83-C314EFE5F8A2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1665312 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B07B46E1-E12B-40BE-98B3-19CE5A3F4679} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-2305226654-651215044-733858041-1000 => C:\Users\Carlos Luna\AppData\Local\MEGAsync\MEGAupdater.exe
Task: {BD5159BA-C4CA-4CEC-A03A-8757F4788891} - System32\Tasks\{9AC3D973-ABA9-417C-BFEC-58F9A2E0316A} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{7F7E4FA7-6F32-4DE2-917E-361E034AED7A}\setup.exe" -c -runfromtemp -l0x0409
Task: {CFE7C1EB-6D01-4C36-9CBB-4299E628064A} - System32\Tasks\{FB630E37-2B8D-498A-AF0C-D1E8035CCC9A} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\Downloads\remix-os-player-1-0-108.exe" -d "C:\Users\Carlos Luna\Downloads"
Task: {D0087371-BA7B-40D8-B082-1AA679E01EE7} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2206488 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D0C532E0-D1C5-4939-9A5D-20C1E65CEBAA} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1665312 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D685ED40-7570-4DD0-8D05-E36B8F49EF67} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [754472 2021-04-05] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {DD67DAB7-77D5-429A-A54E-4723DD7E316D} - System32\Tasks\{8BA74D91-FA29-419D-858B-36DC14E276AD} => C:\Windows\system32\pcalua.exe -a "F:\AutoPlay\Docs\Extras\Game Tools\DOSBox 0.63\DOSBox0.63-win32-installer.exe" -d "F:\AutoPlay\Docs\Extras\Game Tools\DOSBox 0.63"
Task: {E7C96D1D-73AE-4ED4-ACCB-72AAE2A699BB} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Carlos Luna\Downloads\esetonlinescanner_esn.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
IPSecPolicy: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{54a8fc58-9b91-49c0-9f77-0893a0c1aae3} <==== ATTENTION (Restriction - IP)
Tcpip\Parameters: [DhcpNameServer] 200.48.225.146 200.48.225.130
Tcpip\..\Interfaces\{4F611090-1E2A-4C0B-B218-CB68014871BD}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{577DA66F-E0C5-4726-8D88-1A73332085A9}: [DhcpNameServer] 200.48.225.146 200.48.225.130
Tcpip\..\Interfaces\{8D58557D-1DB6-4DD8-B77E-9A6F9972990A}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A27F8B15-26C0-4909-9700-9719E16C3A24}: [DhcpNameServer] 200.48.225.130 200.48.225.146
Tcpip\..\Interfaces\{B67BBEAF-70C7-4ED9-ADCE-DAC65DF532A9}: [DhcpNameServer] 200.48.225.146 200.48.225.130
HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,26.0.0.1,9256]
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin HKU\S-1-5-21-2305226654-651215044-733858041-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Carlos Luna\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-05] (Unity Technologies SF -> Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2305226654-651215044-733858041-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
CHR HKLM-x32\...\Chrome\Extension: [looohgelibjoplmkhecmalapkgadkfcc]
CHR HKLM-x32\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo]
Opera:
=======
OPR Profile: C:\Users\Carlos Luna\AppData\Roaming\Opera Software\Opera Stable [2021-10-14]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Carlos Luna\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-09-29]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Carlos Luna\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-09-28]
StartMenuInternet: (HKU\S-1-5-21-2305226654-651215044-733858041-1000) Opera GXStable - "C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\Launcher.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128 2015-07-07] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [927232 2012-10-29] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2019-03-11] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-23] (Epic Games Inc. -> Epic Games, Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [9473408 2021-01-18] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S4 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-21] (ASUSTeK Computer Inc. -> )
R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [320728 2021-09-20] (Bluestack Systems, Inc -> Bluestack System Inc.)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-09-22] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-09-22] (Disc Soft Ltd -> Disc Soft Ltd)
R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [246952 2021-10-19] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [284408 2021-10-19] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech -> Logitech Inc.)
R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech -> Logitech Inc.)
R3 rtl819xpn64; C:\Windows\System32\DRIVERS\rtl819xp.sys [622624 2010-02-01] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam620.sys [58512 2012-07-03] (Realtek Semiconductor Corp -> Realtek Corporation)
S3 RvNetMP60; C:\Windows\System32\DRIVERS\RvNetMP60.sys [69048 2018-12-25] (Famatech Corp. -> Famatech Corp.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2017-08-30] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R1 VBoxUSBMon; C:\Windows\System32\DRIVERS\VBoxUSBMon.sys [127432 2016-12-03] (Duodian Online Technology Co. Ltd. -> BigNox Corporation)
R3 wovad_micarray; C:\Windows\System32\drivers\womic.sys [35696 2017-11-25] (Beijing Wolicheng Technology Co., Ltd. -> Windows (R) Win 7 DDK provider)
S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X]
S2 BlueStacksDrv; \??\C:\Program Files\BlueStacks\BstkDrv_bgp.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WacHidRouter; system32\DRIVERS\wachidrouter.sys [X]
S3 wacomrouterfilter; system32\DRIVERS\wacomrouterfilter.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Carlos Luna\AppData\Local\Temp\tmpE675.tmp [X] <==== ATTENTION
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
S1 YSDrv; \??\C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three months (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-11-03 20:11 - 2021-11-03 20:13 - 000021478 _____ C:\Users\Carlos Luna\Desktop\FRST.txt
2021-11-03 20:02 - 2021-11-03 20:03 - 000001970 _____ C:\Users\Carlos Luna\Desktop\netcfg_2021-11-03_20-02-55.dat
2021-11-03 10:11 - 2021-11-03 10:11 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\CrashDumps
2021-11-03 01:03 - 2021-11-03 01:03 - 000000031 _____ C:\Users\Carlos Luna\Documents\recover network settings.txt
2021-11-02 19:01 - 2021-11-02 19:01 - 000005478 _____ C:\NetworkSettings.txt
2021-11-02 18:59 - 2021-11-02 19:00 - 000005478 _____ C:\Windows\system32\NetworkSettings.txt
2021-11-02 18:58 - 2021-11-02 18:58 - 001053600 _____ (ESET) C:\Users\Carlos Luna\Desktop\esetuninstaller.exe
2021-11-01 15:33 - 2021-11-03 20:11 - 000000000 ____D C:\Users\Carlos Luna\Desktop\FRST-OlderVersion
2021-10-31 20:20 - 2021-10-31 20:20 - 000000186 _____ C:\Users\Carlos Luna\Documents\fixlist.txt
2021-10-30 19:13 - 2021-10-30 19:10 - 000038441 _____ C:\Users\Carlos Luna\Documents\FRST.txt
2021-10-28 17:52 - 2021-11-03 20:04 - 000000000 ____D C:\ProgramData\MCShield
2021-10-28 17:52 - 2021-10-28 17:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MCShield
2021-10-28 17:52 - 2021-10-28 17:52 - 000000000 ____D C:\Program Files (x86)\MCShield
2021-10-28 17:44 - 2021-10-28 17:45 - 002856736 _____ (MyCity) C:\Users\Carlos Luna\Desktop\MCShield-Setup.exe
2021-10-26 22:53 - 2021-10-26 22:53 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Carlos Luna\Downloads\iExplore.exe
2021-10-25 20:29 - 2021-11-03 20:12 - 000000000 ____D C:\FRST
2021-10-25 19:16 - 2021-11-03 20:11 - 002311168 _____ (Farbar) C:\Users\Carlos Luna\Desktop\FRST64.exe
2021-10-24 19:45 - 2021-10-24 19:48 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\niemiro
2021-10-24 01:54 - 2021-10-24 01:54 - 002316112 _____ (niemiro) C:\Users\Carlos Luna\Desktop\SFCFix.exe
2021-10-24 01:20 - 2021-10-24 01:20 - 010228313 _____ (Macrovision Corporation) C:\Users\Carlos Luna\Downloads\asmwsoftpcoptimizersetup.exe
2021-10-24 01:04 - 2021-10-24 01:05 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Windupdate
2021-10-24 00:28 - 2021-10-28 22:08 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\ElevatedDiagnostics
2021-10-24 00:11 - 2021-10-24 00:11 - 003298367 _____ C:\Users\Carlos Luna\Downloads\Windows6.1-KB3050265-x64.msu
2021-10-23 23:01 - 2021-10-23 23:02 - 000000000 ____D C:\Program Files\TEST
2021-10-23 21:43 - 2021-10-23 21:43 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\EOSUserHelper
2021-10-23 21:42 - 2021-10-23 21:42 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Epic Games
2021-10-23 21:30 - 2021-10-23 21:30 - 000000000 ____D C:\Users\Default\AppData\Local\Epic Games
2021-10-21 20:11 - 2021-10-21 20:19 - 000000000 ____D C:\Users\Carlos Luna\Downloads\backups
2021-10-21 18:01 - 2021-10-21 18:01 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\CEF
2021-10-20 22:52 - 2021-10-20 22:53 - 000388608 _____ (Trend Micro Inc.) C:\Users\Carlos Luna\Downloads\HijackThis.exe
2021-10-19 12:08 - 2021-10-19 12:08 - 000004352 _____ C:\Windows\system32\Tasks\Opera GX scheduled assistant Autoupdate 1634663272
2021-10-19 05:27 - 2021-10-19 05:27 - 000284408 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys
2021-10-19 05:25 - 2021-10-19 05:25 - 000246952 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys
2021-10-19 02:18 - 2021-10-19 02:18 - 000057449 _____ C:\Windows\system32\NOTICE_mod
2021-10-18 22:48 - 2021-10-18 22:48 - 000909824 _____ (Farbar) C:\Users\Carlos Luna\Downloads\FSS.exe
2021-10-18 22:47 - 2021-10-18 22:48 - 201686784 _____ (SUPERAntiSpyware) C:\Users\Carlos Luna\Downloads\SUPERAntiSpyware.exe
2021-10-17 02:19 - 2021-10-17 02:19 - 000000000 ____D C:\ProgramData\Emsisoft
2021-10-17 00:57 - 2021-10-17 00:57 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Carlos Luna\Downloads\rkill.exe
2021-10-14 14:58 - 2021-10-26 12:39 - 000004100 _____ C:\Windows\system32\Tasks\Opera GX scheduled Autoupdate 1634241479
2021-10-14 14:58 - 2021-10-14 14:58 - 000001437 _____ C:\Users\Carlos Luna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera GX Browser.lnk
2021-10-13 21:05 - 2021-10-13 21:06 - 000000083 _____ C:\Users\Carlos Luna\Documents\lista cosas.txt
2021-10-12 02:37 - 2021-10-12 02:37 - 000001085 _____ C:\Users\Carlos Luna\Desktop\Windows Media Player.lnk
2021-10-11 02:36 - 2021-10-11 02:36 - 000001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2021-10-11 02:35 - 2021-10-11 02:35 - 000000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2021-10-08 16:24 - 2021-10-08 16:24 - 000000000 ____D C:\.android
2021-10-08 04:10 - 2021-10-08 04:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project64 2.3
2021-10-08 04:10 - 2021-10-08 04:10 - 000000000 ____D C:\Program Files (x86)\Project64 3.0
2021-09-27 15:15 - 2021-09-27 20:37 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\GUI
2021-09-26 13:30 - 2021-11-03 10:12 - 000000000 ____D C:\ProgramData\BlueStacks_nxt
2021-09-26 13:30 - 2021-09-27 18:10 - 000000000 ____D C:\Program Files\BlueStacks_nxt
2021-09-26 13:26 - 2021-09-26 13:26 - 001168608 _____ (BlueStack Systems Inc.) C:\Users\Carlos Luna\Downloads\BlueStacksMicroInstaller_5.3.70.1004_native.exe
2021-08-30 00:49 - 2021-10-10 23:03 - 000000995 _____ C:\Users\Carlos Luna\Desktop\Genshin Impact.lnk
2021-08-06 18:53 - 2021-09-26 13:32 - 000001987 _____ C:\Users\Public\Desktop\BlueStacks 5.lnk
==================== Three months (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-11-03 20:11 - 2009-07-13 23:45 - 000023936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-11-03 20:11 - 2009-07-13 23:45 - 000023936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-11-03 20:05 - 2020-07-17 23:22 - 000000000 ____D C:\ProgramData\NVIDIA
2021-11-03 20:04 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-11-03 20:03 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2021-11-03 19:59 - 2016-04-14 00:33 - 000000000 ____D C:\Windows\pss
2021-11-03 17:31 - 2020-10-21 01:14 - 000000000 ____D C:\Program Files\Genshin Impact
2021-11-03 10:11 - 2015-04-19 18:58 - 000007630 _____ C:\Users\Carlos Luna\AppData\Local\Resmon.ResmonCfg
2021-11-03 08:57 - 2014-07-04 16:56 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Adobe
2021-11-03 01:02 - 2014-06-22 19:37 - 000000000 ____D C:\Program Files (x86)\Steam
2021-11-02 21:38 - 2017-05-05 20:31 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\discord
2021-11-02 21:10 - 2017-05-05 20:30 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Discord
2021-11-02 18:52 - 2020-03-13 03:31 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\Sun
2021-11-02 18:52 - 2014-05-10 22:18 - 000000000 ____D C:\Program Files\Java
2021-11-02 18:47 - 2014-03-12 19:31 - 000000000 ____D C:\Windows\system32\Macromed
2021-11-02 18:47 - 2014-03-12 19:26 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2021-11-01 20:53 - 2016-06-08 15:05 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\.minecraft
2021-10-30 17:55 - 2014-08-07 03:52 - 000000132 _____ C:\Users\Carlos Luna\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2021-10-28 18:29 - 2020-03-22 18:03 - 000689126 _____ C:\Windows\system32\perfh007.dat
2021-10-28 18:29 - 2020-03-22 18:03 - 000149098 _____ C:\Windows\system32\perfc007.dat
2021-10-28 18:29 - 2014-03-12 20:39 - 000745504 _____ C:\Windows\system32\perfh00A.dat
2021-10-28 18:29 - 2014-03-12 20:39 - 000158582 _____ C:\Windows\system32\perfc00A.dat
2021-10-28 18:29 - 2009-07-14 00:13 - 002514704 _____ C:\Windows\system32\PerfStringBackup.INI
2021-10-28 18:28 - 2018-08-09 13:46 - 000000000 ____D C:\Users\Carlos Luna\Documents\Hermanos
2021-10-25 20:23 - 2018-08-09 13:33 - 000000000 ____D C:\Users\Carlos Luna\Documents\Carlos
2021-10-25 19:58 - 2014-04-11 01:54 - 000000000 ____D C:\Users\Carlos Luna\Documents\My Games
2021-10-24 00:28 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2021-10-23 02:22 - 2021-08-02 01:56 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\vlc
2021-10-21 02:15 - 2014-03-12 19:32 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\Adobe
2021-10-21 02:04 - 2021-03-11 21:40 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Opera Software
2021-10-21 01:46 - 2015-10-24 19:03 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Series
2021-10-20 23:09 - 2014-04-19 03:42 - 000000000 ____D C:\Program Files (x86)\Adobe
2021-10-20 16:10 - 2009-01-01 01:05 - 000000000 ___RD C:\Program Files (x86)\ASUS
2021-10-19 05:17 - 2009-01-01 00:26 - 000154328 _____ C:\Users\Carlos Luna\AppData\Local\GDIPFONTCACHEV1.DAT
2021-10-19 02:57 - 2009-07-13 23:45 - 005165616 _____ C:\Windows\system32\FNTCACHE.DAT
2021-10-19 02:07 - 2016-06-08 15:04 - 000000000 ____D C:\Program Files (x86)\Minecraft
2021-10-19 02:06 - 2014-04-19 03:17 - 000000000 ____D C:\ProgramData\Adobe
2021-10-19 02:03 - 2015-02-16 14:11 - 000000000 ____D C:\Program Files (x86)\Java
2021-10-18 22:24 - 2019-02-06 20:46 - 000000000 ____D C:\Windows\system32\DAX2
2021-10-18 22:23 - 2021-05-01 02:22 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2021-10-18 22:05 - 2015-10-24 19:03 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Archives
2021-10-18 22:02 - 2014-03-12 20:50 - 000000000 ____D C:\Windows\system32\Tasks\Games
2021-10-18 14:41 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2021-10-14 14:56 - 2016-01-14 23:46 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\Opera Software
2021-10-12 00:06 - 2009-01-01 03:16 - 000000000 ____D C:\Windows\Panther
2021-10-11 02:35 - 2009-07-14 02:45 - 000000000 ___RD C:\Users\Public\Recorded TV
2021-10-11 02:14 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-10-10 23:03 - 2020-10-21 01:14 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\miHoYo
2021-10-10 23:03 - 2020-10-21 01:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genshin Impact
2021-10-10 13:31 - 2014-03-12 20:50 - 000018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2021-10-10 01:13 - 2009-07-14 00:08 - 000032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2021-10-08 16:24 - 2014-07-08 15:40 - 000000000 ____D C:\ProgramData\Apple
2021-10-08 03:55 - 2015-01-14 14:34 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Zips
==================== Files in the root of some directories ========
2014-10-07 03:30 - 2016-03-28 23:20 - 000000132 _____ () C:\Users\Carlos Luna\AppData\Roaming\Prefs. de formato OpenEXR de Adobe CS6
2014-08-07 03:52 - 2021-10-30 17:55 - 000000132 _____ () C:\Users\Carlos Luna\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2016-02-15 18:17 - 2017-09-18 11:15 - 002447075 _____ () C:\Users\Carlos Luna\AppData\Roaming\PS13_panel.log
2020-06-26 00:10 - 2020-06-26 00:10 - 000000045 _____ () C:\Users\Carlos Luna\AppData\Roaming\WB.CFG
2016-08-03 21:50 - 2017-09-17 09:56 - 000001456 _____ () C:\Users\Carlos Luna\AppData\Local\Adobe Guardar para Web 13.0 Prefs
2021-01-10 12:03 - 2021-01-10 12:04 - 000000774 _____ () C:\Users\Carlos Luna\AppData\Local\install_info.txt
2015-08-07 11:17 - 2015-08-07 11:17 - 013545694 _____ () C:\Users\Carlos Luna\AppData\Local\package.nw.new
2018-08-31 01:09 - 2018-12-29 02:20 - 000000600 _____ () C:\Users\Carlos Luna\AppData\Local\PUTTY.RND
2015-04-19 18:58 - 2021-11-03 10:11 - 000007630 _____ () C:\Users\Carlos Luna\AppData\Local\Resmon.ResmonCfg
2019-10-18 02:55 - 2020-07-25 01:51 - 000000077 _____ () C:\Users\Carlos Luna\AppData\Local\update_progress.txt
2019-12-06 23:13 - 2019-12-06 23:13 - 000017408 _____ () C:\Users\Carlos Luna\AppData\Local\WebpageIcons.db
2018-06-21 16:19 - 2018-06-21 16:19 - 000000000 _____ () C:\Users\Carlos Luna\AppData\Local\{A194310A-E09D-4DA5-9E3E-1171E9EEAB3E}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2021
Ran by Carlos Luna (administrator) on 1989AH (ASUS All Series) (03-11-2021 20:11:42)
Running from C:\Users\Carlos Luna\Desktop
Loaded Profiles: Carlos Luna
: Microsoft Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Default browser: Opera
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Arvato Digital Services Canada Inc -> arvato digital services llc) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Borislav Surbat -> MyCity) C:\Program Files (x86)\MCShield\MCShieldRTM.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) [File not signed] C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Logitech -> Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Windows Hardware Compatibility Publisher -> ) C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(Opera Software AS -> Opera Software) C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\80.0.4170.61\opera_crashreporter.exe
(Opera Software AS -> Opera Software) C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\opera.exe <12>
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
==================== Registry (Whitelisted) ===================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9068040 2016-11-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [ProxyCap] => C:\Program Files\Proxy Labs\ProxyCap\pcapui.exe
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8294680 2014-02-27] (Logitech -> Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [Genshin Impact_Launcher] => [X]
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [ADSKAppManager] => "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun
HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\Run: [Opera GX Browser Assistant] => C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe [3291288 2021-02-01] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (Borislav Surbat -> MyCity)
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\Run: [Google Update] => "C:\Users\Carlos Luna\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: E - E:\setup.exe
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: {7776be3f-f783-11e4-b3bf-ab6770d31304} - E:\Startme.exe
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: {c02e2f6e-805e-11e6-9b0c-d850e63c46b2} - E:\setup\rsrc\Autorun.exe
HKU\S-1-5-21-2305226654-651215044-733858041-1000\...\MountPoints2: {c2d0008f-546d-11e8-b0dd-0014d1237121} - F:\startme.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-03-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
Startup: C:\Users\Carlos Luna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameVox.lnk [2016-03-17]
ShortcutTarget: GameVox.lnk -> C:\Program Files (x86)\GameVox\GameVox.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) ============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0C9A5565-C85D-4309-810F-9B2EF6D93455} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Carlos Luna\Downloads\esetonlinescanner_esn.exe
Task: {1156D15A-AAE6-4EE4-A768-C21AF23191D3} - System32\Tasks\{9F4A8BFD-E17F-4A42-B4EE-55FD2C147405} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\AppData\Roaming\Nox\bin\Nox_unload.exe"
Task: {1ADD0762-CC79-45E7-B15D-17E123E1BE18} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2206488 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {427624A0-6125-446F-84D9-BC6C71027E47} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2225952 2016-08-15] (Microsoft Corporation -> Microsoft)
Task: {4580E52B-91EE-42B5-9363-56BABDA2AFFC} - System32\Tasks\CorelUpdateHelperTask-F299A6B575097899476390FCD7D79BE3 => C:\Program Files (x86)\Corel\CUH\v2\CUH.exe
Task: {45A4D6E9-3EB8-4039-87C0-8EDD5A1CDC23} - System32\Tasks\Opera GX scheduled assistant Autoupdate 1634663272 => C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\launcher.exe [3963600 2021-10-19] (Opera Software AS -> Opera Software) -> --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
Task: {4D109734-C672-4DAB-8E1C-0848709181B8} - System32\Tasks\Games\UpdateCheck_S-1-5-21-2305226654-651215044-733858041-1000 => {CA22F5B1-E06F-4A2B-94FC-21E87FE53781} C:\Windows\System32\gameux.dll [2746368 2012-12-07] (Microsoft Windows -> Microsoft Corporation)
Task: {52482CF5-BDD9-49A4-94A9-43C7A412C125} - System32\Tasks\{CB3E5831-270F-443A-894C-A54F005941DE} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\Downloads\setup-gtarcade-601b27db75125.exe" -d "C:\Users\Carlos Luna\Downloads"
Task: {5918D14A-68E3-4CFE-B21E-E1748D153440} - System32\Tasks\AdobeAAMUpdater-1.0-CarlosLuna-PC-Carlos Luna => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {61AA0E70-25B1-4153-A33F-B19B7AC78098} - System32\Tasks\{0C2E49FB-E0FA-4939-849F-2F5A476D0F82} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\Downloads\coreaacSetup.exe" -d "C:\Users\Carlos Luna\Downloads"
Task: {62A6C492-DB90-48A0-8729-0E9EE4C6AA60} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [998104 2015-07-07] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {671E9D4A-C29E-4F2E-B2B6-E844B48D0215} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {6D10DDD6-E35A-4909-8989-1D5F095840CE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [4624152 2014-06-24] (Piriform Ltd -> Piriform Ltd)
Task: {6FC4D6E7-AEFA-40A9-9BB7-93CA381DA6F7} - System32\Tasks\BlueStacksHelper_nxt => C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe [275136 2021-09-21] (Bluestack Systems, Inc -> BlueStack Systems, Inc.)
Task: {8F95A2D6-F062-4745-A5AF-962DB9825FAA} - System32\Tasks\Opera GX scheduled Autoupdate 1634241479 => C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\launcher.exe [3963600 2021-10-19] (Opera Software AS -> Opera Software)
Task: {93D89636-DEDB-4163-B18A-E7AA18E71A78} - System32\Tasks\CorelUpdateHelperTaskCore => c:\Program Files (x86)\Corel\CUH\v2\CUH.exe
Task: {A3B005D3-E9D2-481C-8F83-C314EFE5F8A2} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1665312 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {B07B46E1-E12B-40BE-98B3-19CE5A3F4679} - System32\Tasks\MEGA\MEGAsync Update Task S-1-5-21-2305226654-651215044-733858041-1000 => C:\Users\Carlos Luna\AppData\Local\MEGAsync\MEGAupdater.exe
Task: {BD5159BA-C4CA-4CEC-A03A-8757F4788891} - System32\Tasks\{9AC3D973-ABA9-417C-BFEC-58F9A2E0316A} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{7F7E4FA7-6F32-4DE2-917E-361E034AED7A}\setup.exe" -c -runfromtemp -l0x0409
Task: {CFE7C1EB-6D01-4C36-9CBB-4299E628064A} - System32\Tasks\{FB630E37-2B8D-498A-AF0C-D1E8035CCC9A} => C:\Windows\system32\pcalua.exe -a "C:\Users\Carlos Luna\Downloads\remix-os-player-1-0-108.exe" -d "C:\Users\Carlos Luna\Downloads"
Task: {D0087371-BA7B-40D8-B082-1AA679E01EE7} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2206488 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D0C532E0-D1C5-4939-9A5D-20C1E65CEBAA} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1665312 2016-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {D685ED40-7570-4DD0-8D05-E36B8F49EF67} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [754472 2021-04-05] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {DD67DAB7-77D5-429A-A54E-4723DD7E316D} - System32\Tasks\{8BA74D91-FA29-419D-858B-36DC14E276AD} => C:\Windows\system32\pcalua.exe -a "F:\AutoPlay\Docs\Extras\Game Tools\DOSBox 0.63\DOSBox0.63-win32-installer.exe" -d "F:\AutoPlay\Docs\Extras\Game Tools\DOSBox 0.63"
Task: {E7C96D1D-73AE-4ED4-ACCB-72AAE2A699BB} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Carlos Luna\Downloads\esetonlinescanner_esn.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
IPSecPolicy: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{54a8fc58-9b91-49c0-9f77-0893a0c1aae3} <==== ATTENTION (Restriction - IP)
Tcpip\Parameters: [DhcpNameServer] 200.48.225.146 200.48.225.130
Tcpip\..\Interfaces\{4F611090-1E2A-4C0B-B218-CB68014871BD}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{577DA66F-E0C5-4726-8D88-1A73332085A9}: [DhcpNameServer] 200.48.225.146 200.48.225.130
Tcpip\..\Interfaces\{8D58557D-1DB6-4DD8-B77E-9A6F9972990A}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{A27F8B15-26C0-4909-9700-9719E16C3A24}: [DhcpNameServer] 200.48.225.130 200.48.225.146
Tcpip\..\Interfaces\{B67BBEAF-70C7-4ED9-ADCE-DAC65DF532A9}: [DhcpNameServer] 200.48.225.146 200.48.225.130
HKLM\System\...\Parameters\PersistentRoutes: [0.0.0.0,0.0.0.0,26.0.0.1,9256]
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No File]
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin HKU\S-1-5-21-2305226654-651215044-733858041-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Carlos Luna\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-05] (Unity Technologies SF -> Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2305226654-651215044-733858041-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [bnbbhgcfmdnamgfgjfgjdkcjbofkjihb]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl]
CHR HKLM-x32\...\Chrome\Extension: [looohgelibjoplmkhecmalapkgadkfcc]
CHR HKLM-x32\...\Chrome\Extension: [mcegpkkjabjeiddmpmgbmjlmiebfiofd]
CHR HKLM-x32\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo]
Opera:
=======
OPR Profile: C:\Users\Carlos Luna\AppData\Roaming\Opera Software\Opera Stable [2021-10-14]
OPR DefaultSuggestURL: Opera Stable -> hxxps://www.google.com/complete/search?client=opera&q={searchTerms}&ie={inputEncoding}&oe={outputEncoding}
OPR Extension: (Rich Hints Agent) - C:\Users\Carlos Luna\AppData\Roaming\Opera Software\Opera Stable\Extensions\enegjkbbakeegngfapepobipndnebkdk [2021-09-29]
OPR Extension: (Amazon Assistant Promotion) - C:\Users\Carlos Luna\AppData\Roaming\Opera Software\Opera Stable\Extensions\kbmoiomgmchbpihhdpabemajcbjpcijk [2021-09-28]
StartMenuInternet: (HKU\S-1-5-21-2305226654-651215044-733858041-1000) Opera GXStable - "C:\Users\Carlos Luna\AppData\Local\Programs\Opera GX\Launcher.exe"
==================== Services (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [82128 2015-07-07] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [927232 2012-10-29] (Microsoft Windows Hardware Compatibility Publisher -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [781440 2019-03-11] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [16029472 2021-10-23] (Epic Games Inc. -> Epic Games, Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [9473408 2021-01-18] (INCA Internet Co.,Ltd. -> INCA Internet Co., Ltd.)
R2 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2014-04-30] (Arvato Digital Services Canada Inc -> arvato digital services llc)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
S4 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X]
===================== Drivers (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-21] (ASUSTeK Computer Inc. -> )
R2 BlueStacksDrv_nxt; C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys [320728 2021-09-20] (Bluestack Systems, Inc -> Bluestack System Inc.)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2016-09-22] (Disc Soft Ltd -> Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2016-09-22] (Disc Soft Ltd -> Disc Soft Ltd)
R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [246952 2021-10-19] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
S3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [284408 2021-10-19] (Microsoft Windows Hardware Compatibility Publisher -> AO Kaspersky Lab)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech -> Logitech Inc.)
R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech -> Logitech Inc.)
R3 rtl819xpn64; C:\Windows\System32\DRIVERS\rtl819xp.sys [622624 2010-02-01] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam620.sys [58512 2012-07-03] (Realtek Semiconductor Corp -> Realtek Corporation)
S3 RvNetMP60; C:\Windows\System32\DRIVERS\RvNetMP60.sys [69048 2018-12-25] (Famatech Corp. -> Famatech Corp.)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [27136 2017-08-30] (OpenVPN Technologies, Inc. -> The OpenVPN Project)
R1 VBoxUSBMon; C:\Windows\System32\DRIVERS\VBoxUSBMon.sys [127432 2016-12-03] (Duodian Online Technology Co. Ltd. -> BigNox Corporation)
R3 wovad_micarray; C:\Windows\System32\drivers\womic.sys [35696 2017-11-25] (Beijing Wolicheng Technology Co., Ltd. -> Windows (R) Win 7 DDK provider)
S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X]
S2 BlueStacksDrv; \??\C:\Program Files\BlueStacks\BstkDrv_bgp.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WacHidRouter; system32\DRIVERS\wachidrouter.sys [X]
S3 wacomrouterfilter; system32\DRIVERS\wacomrouterfilter.sys [X]
S3 WinRing0_1_2_0; \??\C:\Users\Carlos Luna\AppData\Local\Temp\tmpE675.tmp [X] <==== ATTENTION
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
S1 YSDrv; \??\C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Three months (created) (Whitelisted) =========
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-11-03 20:11 - 2021-11-03 20:13 - 000021478 _____ C:\Users\Carlos Luna\Desktop\FRST.txt
2021-11-03 20:02 - 2021-11-03 20:03 - 000001970 _____ C:\Users\Carlos Luna\Desktop\netcfg_2021-11-03_20-02-55.dat
2021-11-03 10:11 - 2021-11-03 10:11 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\CrashDumps
2021-11-03 01:03 - 2021-11-03 01:03 - 000000031 _____ C:\Users\Carlos Luna\Documents\recover network settings.txt
2021-11-02 19:01 - 2021-11-02 19:01 - 000005478 _____ C:\NetworkSettings.txt
2021-11-02 18:59 - 2021-11-02 19:00 - 000005478 _____ C:\Windows\system32\NetworkSettings.txt
2021-11-02 18:58 - 2021-11-02 18:58 - 001053600 _____ (ESET) C:\Users\Carlos Luna\Desktop\esetuninstaller.exe
2021-11-01 15:33 - 2021-11-03 20:11 - 000000000 ____D C:\Users\Carlos Luna\Desktop\FRST-OlderVersion
2021-10-31 20:20 - 2021-10-31 20:20 - 000000186 _____ C:\Users\Carlos Luna\Documents\fixlist.txt
2021-10-30 19:13 - 2021-10-30 19:10 - 000038441 _____ C:\Users\Carlos Luna\Documents\FRST.txt
2021-10-28 17:52 - 2021-11-03 20:04 - 000000000 ____D C:\ProgramData\MCShield
2021-10-28 17:52 - 2021-10-28 17:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MCShield
2021-10-28 17:52 - 2021-10-28 17:52 - 000000000 ____D C:\Program Files (x86)\MCShield
2021-10-28 17:44 - 2021-10-28 17:45 - 002856736 _____ (MyCity) C:\Users\Carlos Luna\Desktop\MCShield-Setup.exe
2021-10-26 22:53 - 2021-10-26 22:53 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Carlos Luna\Downloads\iExplore.exe
2021-10-25 20:29 - 2021-11-03 20:12 - 000000000 ____D C:\FRST
2021-10-25 19:16 - 2021-11-03 20:11 - 002311168 _____ (Farbar) C:\Users\Carlos Luna\Desktop\FRST64.exe
2021-10-24 19:45 - 2021-10-24 19:48 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\niemiro
2021-10-24 01:54 - 2021-10-24 01:54 - 002316112 _____ (niemiro) C:\Users\Carlos Luna\Desktop\SFCFix.exe
2021-10-24 01:20 - 2021-10-24 01:20 - 010228313 _____ (Macrovision Corporation) C:\Users\Carlos Luna\Downloads\asmwsoftpcoptimizersetup.exe
2021-10-24 01:04 - 2021-10-24 01:05 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Windupdate
2021-10-24 00:28 - 2021-10-28 22:08 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\ElevatedDiagnostics
2021-10-24 00:11 - 2021-10-24 00:11 - 003298367 _____ C:\Users\Carlos Luna\Downloads\Windows6.1-KB3050265-x64.msu
2021-10-23 23:01 - 2021-10-23 23:02 - 000000000 ____D C:\Program Files\TEST
2021-10-23 21:43 - 2021-10-23 21:43 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\EOSUserHelper
2021-10-23 21:42 - 2021-10-23 21:42 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Epic Games
2021-10-23 21:30 - 2021-10-23 21:30 - 000000000 ____D C:\Users\Default\AppData\Local\Epic Games
2021-10-21 20:11 - 2021-10-21 20:19 - 000000000 ____D C:\Users\Carlos Luna\Downloads\backups
2021-10-21 18:01 - 2021-10-21 18:01 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\CEF
2021-10-20 22:52 - 2021-10-20 22:53 - 000388608 _____ (Trend Micro Inc.) C:\Users\Carlos Luna\Downloads\HijackThis.exe
2021-10-19 12:08 - 2021-10-19 12:08 - 000004352 _____ C:\Windows\system32\Tasks\Opera GX scheduled assistant Autoupdate 1634663272
2021-10-19 05:27 - 2021-10-19 05:27 - 000284408 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_klark.sys
2021-10-19 05:25 - 2021-10-19 05:25 - 000246952 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klupd_klif_arkmon.sys
2021-10-19 02:18 - 2021-10-19 02:18 - 000057449 _____ C:\Windows\system32\NOTICE_mod
2021-10-18 22:48 - 2021-10-18 22:48 - 000909824 _____ (Farbar) C:\Users\Carlos Luna\Downloads\FSS.exe
2021-10-18 22:47 - 2021-10-18 22:48 - 201686784 _____ (SUPERAntiSpyware) C:\Users\Carlos Luna\Downloads\SUPERAntiSpyware.exe
2021-10-17 02:19 - 2021-10-17 02:19 - 000000000 ____D C:\ProgramData\Emsisoft
2021-10-17 00:57 - 2021-10-17 00:57 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Carlos Luna\Downloads\rkill.exe
2021-10-14 14:58 - 2021-10-26 12:39 - 000004100 _____ C:\Windows\system32\Tasks\Opera GX scheduled Autoupdate 1634241479
2021-10-14 14:58 - 2021-10-14 14:58 - 000001437 _____ C:\Users\Carlos Luna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera GX Browser.lnk
2021-10-13 21:05 - 2021-10-13 21:06 - 000000083 _____ C:\Users\Carlos Luna\Documents\lista cosas.txt
2021-10-12 02:37 - 2021-10-12 02:37 - 000001085 _____ C:\Users\Carlos Luna\Desktop\Windows Media Player.lnk
2021-10-11 02:36 - 2021-10-11 02:36 - 000001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2021-10-11 02:35 - 2021-10-11 02:35 - 000000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2021-10-08 16:24 - 2021-10-08 16:24 - 000000000 ____D C:\.android
2021-10-08 04:10 - 2021-10-08 04:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project64 2.3
2021-10-08 04:10 - 2021-10-08 04:10 - 000000000 ____D C:\Program Files (x86)\Project64 3.0
2021-09-27 15:15 - 2021-09-27 20:37 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\GUI
2021-09-26 13:30 - 2021-11-03 10:12 - 000000000 ____D C:\ProgramData\BlueStacks_nxt
2021-09-26 13:30 - 2021-09-27 18:10 - 000000000 ____D C:\Program Files\BlueStacks_nxt
2021-09-26 13:26 - 2021-09-26 13:26 - 001168608 _____ (BlueStack Systems Inc.) C:\Users\Carlos Luna\Downloads\BlueStacksMicroInstaller_5.3.70.1004_native.exe
2021-08-30 00:49 - 2021-10-10 23:03 - 000000995 _____ C:\Users\Carlos Luna\Desktop\Genshin Impact.lnk
2021-08-06 18:53 - 2021-09-26 13:32 - 000001987 _____ C:\Users\Public\Desktop\BlueStacks 5.lnk
==================== Three months (modified) ==================
(If an entry is included in the fixlist, the file/folder will be moved.)
2021-11-03 20:11 - 2009-07-13 23:45 - 000023936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2021-11-03 20:11 - 2009-07-13 23:45 - 000023936 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2021-11-03 20:05 - 2020-07-17 23:22 - 000000000 ____D C:\ProgramData\NVIDIA
2021-11-03 20:04 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2021-11-03 20:03 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2021-11-03 19:59 - 2016-04-14 00:33 - 000000000 ____D C:\Windows\pss
2021-11-03 17:31 - 2020-10-21 01:14 - 000000000 ____D C:\Program Files\Genshin Impact
2021-11-03 10:11 - 2015-04-19 18:58 - 000007630 _____ C:\Users\Carlos Luna\AppData\Local\Resmon.ResmonCfg
2021-11-03 08:57 - 2014-07-04 16:56 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Adobe
2021-11-03 01:02 - 2014-06-22 19:37 - 000000000 ____D C:\Program Files (x86)\Steam
2021-11-02 21:38 - 2017-05-05 20:31 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\discord
2021-11-02 21:10 - 2017-05-05 20:30 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Discord
2021-11-02 18:52 - 2020-03-13 03:31 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\Sun
2021-11-02 18:52 - 2014-05-10 22:18 - 000000000 ____D C:\Program Files\Java
2021-11-02 18:47 - 2014-03-12 19:31 - 000000000 ____D C:\Windows\system32\Macromed
2021-11-02 18:47 - 2014-03-12 19:26 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2021-11-01 20:53 - 2016-06-08 15:05 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\.minecraft
2021-10-30 17:55 - 2014-08-07 03:52 - 000000132 _____ C:\Users\Carlos Luna\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2021-10-28 18:29 - 2020-03-22 18:03 - 000689126 _____ C:\Windows\system32\perfh007.dat
2021-10-28 18:29 - 2020-03-22 18:03 - 000149098 _____ C:\Windows\system32\perfc007.dat
2021-10-28 18:29 - 2014-03-12 20:39 - 000745504 _____ C:\Windows\system32\perfh00A.dat
2021-10-28 18:29 - 2014-03-12 20:39 - 000158582 _____ C:\Windows\system32\perfc00A.dat
2021-10-28 18:29 - 2009-07-14 00:13 - 002514704 _____ C:\Windows\system32\PerfStringBackup.INI
2021-10-28 18:28 - 2018-08-09 13:46 - 000000000 ____D C:\Users\Carlos Luna\Documents\Hermanos
2021-10-25 20:23 - 2018-08-09 13:33 - 000000000 ____D C:\Users\Carlos Luna\Documents\Carlos
2021-10-25 19:58 - 2014-04-11 01:54 - 000000000 ____D C:\Users\Carlos Luna\Documents\My Games
2021-10-24 00:28 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2021-10-23 02:22 - 2021-08-02 01:56 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\vlc
2021-10-21 02:15 - 2014-03-12 19:32 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\Adobe
2021-10-21 02:04 - 2021-03-11 21:40 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\Opera Software
2021-10-21 01:46 - 2015-10-24 19:03 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Series
2021-10-20 23:09 - 2014-04-19 03:42 - 000000000 ____D C:\Program Files (x86)\Adobe
2021-10-20 16:10 - 2009-01-01 01:05 - 000000000 ___RD C:\Program Files (x86)\ASUS
2021-10-19 05:17 - 2009-01-01 00:26 - 000154328 _____ C:\Users\Carlos Luna\AppData\Local\GDIPFONTCACHEV1.DAT
2021-10-19 02:57 - 2009-07-13 23:45 - 005165616 _____ C:\Windows\system32\FNTCACHE.DAT
2021-10-19 02:07 - 2016-06-08 15:04 - 000000000 ____D C:\Program Files (x86)\Minecraft
2021-10-19 02:06 - 2014-04-19 03:17 - 000000000 ____D C:\ProgramData\Adobe
2021-10-19 02:03 - 2015-02-16 14:11 - 000000000 ____D C:\Program Files (x86)\Java
2021-10-18 22:24 - 2019-02-06 20:46 - 000000000 ____D C:\Windows\system32\DAX2
2021-10-18 22:23 - 2021-05-01 02:22 - 000000000 ____D C:\Windows\SysWOW64\RTCOM
2021-10-18 22:05 - 2015-10-24 19:03 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Archives
2021-10-18 22:02 - 2014-03-12 20:50 - 000000000 ____D C:\Windows\system32\Tasks\Games
2021-10-18 14:41 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2021-10-14 14:56 - 2016-01-14 23:46 - 000000000 ____D C:\Users\Carlos Luna\AppData\Roaming\Opera Software
2021-10-12 00:06 - 2009-01-01 03:16 - 000000000 ____D C:\Windows\Panther
2021-10-11 02:35 - 2009-07-14 02:45 - 000000000 ___RD C:\Users\Public\Recorded TV
2021-10-11 02:14 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2021-10-10 23:03 - 2020-10-21 01:14 - 000000000 ____D C:\Users\Carlos Luna\AppData\Local\miHoYo
2021-10-10 23:03 - 2020-10-21 01:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genshin Impact
2021-10-10 13:31 - 2014-03-12 20:50 - 000018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2021-10-10 01:13 - 2009-07-14 00:08 - 000032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2021-10-08 16:24 - 2014-07-08 15:40 - 000000000 ____D C:\ProgramData\Apple
2021-10-08 03:55 - 2015-01-14 14:34 - 000000000 ____D C:\Users\Carlos Luna\Downloads\Zips
==================== Files in the root of some directories ========
2014-10-07 03:30 - 2016-03-28 23:20 - 000000132 _____ () C:\Users\Carlos Luna\AppData\Roaming\Prefs. de formato OpenEXR de Adobe CS6
2014-08-07 03:52 - 2021-10-30 17:55 - 000000132 _____ () C:\Users\Carlos Luna\AppData\Roaming\Prefs. de formato PNG de Adobe CS6
2016-02-15 18:17 - 2017-09-18 11:15 - 002447075 _____ () C:\Users\Carlos Luna\AppData\Roaming\PS13_panel.log
2020-06-26 00:10 - 2020-06-26 00:10 - 000000045 _____ () C:\Users\Carlos Luna\AppData\Roaming\WB.CFG
2016-08-03 21:50 - 2017-09-17 09:56 - 000001456 _____ () C:\Users\Carlos Luna\AppData\Local\Adobe Guardar para Web 13.0 Prefs
2021-01-10 12:03 - 2021-01-10 12:04 - 000000774 _____ () C:\Users\Carlos Luna\AppData\Local\install_info.txt
2015-08-07 11:17 - 2015-08-07 11:17 - 013545694 _____ () C:\Users\Carlos Luna\AppData\Local\package.nw.new
2018-08-31 01:09 - 2018-12-29 02:20 - 000000600 _____ () C:\Users\Carlos Luna\AppData\Local\PUTTY.RND
2015-04-19 18:58 - 2021-11-03 10:11 - 000007630 _____ () C:\Users\Carlos Luna\AppData\Local\Resmon.ResmonCfg
2019-10-18 02:55 - 2020-07-25 01:51 - 000000077 _____ () C:\Users\Carlos Luna\AppData\Local\update_progress.txt
2019-12-06 23:13 - 2019-12-06 23:13 - 000017408 _____ () C:\Users\Carlos Luna\AppData\Local\WebpageIcons.db
2018-06-21 16:19 - 2018-06-21 16:19 - 000000000 _____ () C:\Users\Carlos Luna\AppData\Local\{A194310A-E09D-4DA5-9E3E-1171E9EEAB3E}
==================== SigCheck ============================
(There is no automatic fix for files that do not pass verification.)
==================== End of FRST.txt ========================