Resultados de la corrección de Farbar Recovery Scan Tool (x64) Versión: 02-06-2020 Ejecutado por RUBEN (05-06-2020 15:23:44) Run:2 Ejecutado desde C:\Users\Media Service\Desktop Perfiles cargados: RUBEN Modo de Inicio: Safe Mode (minimal) ============================================== fixlist contenido: ***************** Start CloseProcesses: HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATENCIÓN HKU\S-1-5-21-721675818-2333492642-993102402-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize C:\Program Files (x86)\Lavasoft HKU\S-1-5-21-721675818-2333492642-993102402-1001\...\MountPoints2: {cb828214-a587-11e9-907b-fc4596f0a1a4} - "D:\startme.exe" HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\83.0.4103.61\Installer\chrmstp.exe [2020-06-01] (Google LLC -> Google LLC) FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN Task: {35C71688-9F89-49E3-8854-5B26DBF40F20} - System32\Tasks\DashlaneUpgradeCheck => net [Argument = start "Dashlane Upgrade Service"] Task: {9A025675-3CBB-4FD9-A47C-66036CA05001} - \Microsoft\Windows\UNP\RunCampaignManager -> Ningún archivo <==== ATENCIÓN Task: {EB86BAB4-8D95-4EB8-A405-2F76AE144474} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe [125656 2013-10-10] (Red Giant Software LLC -> ) Task: {F5EB56A0-9DF4-43B0-9BEF-8F623A5BA7FC} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [473904 2017-02-21] (Acer Incorporated -> Acer Incorporated) Task: {927DDFA7-BEC2-4A8D-8EA3-211118212191} - System32\Tasks\BacKGroundAgent => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe Task: {B75A45F3-8CA0-425E-8CD5-385698CFD1DB} - System32\Tasks\User Boot Experience Task => C:\OEM\Preload\FUBService\FUBService.exe [30976 2015-05-14] (Acer Incorporated -> ) HKU\S-1-5-21-721675818-2333492642-993102402-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer17win10.msn.com/?pc=ACTE HKU\S-1-5-21-721675818-2333492642-993102402-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COS2&ptag=D051320-A915F698E57&form=CONMHP&conlogo=CT3335818 SearchScopes: HKU\S-1-5-21-721675818-2333492642-993102402-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COS2&ptag=D051320-N0700A915F698E57&form=CONBDF&conlogo=CT3335818&q={searchTerms} FF Extension: (Avast SafePrice | Comparaciones, ofertas y cupones) - C:\Users\Media Service\AppData\Roaming\Mozilla\Firefox\Profiles\z19x5o42.default\Extensions\sp@avast.com.xpi [2020-06-01] FF Extension: (Avast Online Security) - C:\Users\Media Service\AppData\Roaming\Mozilla\Firefox\Profiles\z19x5o42.default\Extensions\wrc@avast.com.xpi [2020-06-01] FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN -> VideoLAN) CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] 2020-05-27 20:35 - 2020-05-27 20:35 - 000000000 _____ () C:\Users\Media Service\AppData\Local\oobelibMkey.log 2018-06-21 23:02 - 2018-06-21 23:05 - 000282248 _____ () C:\Users\Media Service\AppData\Local\TempWER-831473921-0.sysdata.xml ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> Ningún archivo ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Ningún archivo ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> Ningún archivo ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> Ningún archivo ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Ningún archivo ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> Ningún archivo ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> Ningún archivo FirewallRules: [TCP Query User{2C975A27-1882-446B-8273-85594D9FFF3E}C:\users\media service\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\media service\appdata\roaming\utorrent\utorrent.exe => Ningún archivo FirewallRules: [UDP Query User{9536B87E-2809-4494-B4FC-3F370B46C1C0}C:\users\media service\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\media service\appdata\roaming\utorrent\utorrent.exe => Ningún archivo CMD: ipconfig /flushdns CMD: ipconfig /renew CMD: bitsadmin /reset /allusers CMD: netsh winsock reset CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset RemoveProxy: EmptyTemp: Hosts: END ***************** Procesos cerrados correctamente. HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATENCIÓN => restaurado correctamente "HKU\S-1-5-21-721675818-2333492642-993102402-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Web Companion" => eliminado correctamente "C:\Program Files (x86)\Lavasoft" => no encontrado HKU\S-1-5-21-721675818-2333492642-993102402-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb828214-a587-11e9-907b-fc4596f0a1a4} => eliminado correctamente HKLM\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96} => eliminado correctamente HKLM\SOFTWARE\Policies\Mozilla => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{35C71688-9F89-49E3-8854-5B26DBF40F20}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35C71688-9F89-49E3-8854-5B26DBF40F20}" => eliminado correctamente C:\WINDOWS\System32\Tasks\DashlaneUpgradeCheck => movido correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DashlaneUpgradeCheck" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A025675-3CBB-4FD9-A47C-66036CA05001}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A025675-3CBB-4FD9-A47C-66036CA05001}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => no encontrado "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB86BAB4-8D95-4EB8-A405-2F76AE144474}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB86BAB4-8D95-4EB8-A405-2F76AE144474}" => eliminado correctamente C:\WINDOWS\System32\Tasks\Red Giant Link => movido correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Red Giant Link" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F5EB56A0-9DF4-43B0-9BEF-8F623A5BA7FC}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5EB56A0-9DF4-43B0-9BEF-8F623A5BA7FC}" => eliminado correctamente C:\WINDOWS\System32\Tasks\Software Update Application => movido correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Update Application" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{927DDFA7-BEC2-4A8D-8EA3-211118212191}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{927DDFA7-BEC2-4A8D-8EA3-211118212191}" => eliminado correctamente C:\WINDOWS\System32\Tasks\BacKGroundAgent => movido correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BacKGroundAgent" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B75A45F3-8CA0-425E-8CD5-385698CFD1DB}" => eliminado correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B75A45F3-8CA0-425E-8CD5-385698CFD1DB}" => eliminado correctamente C:\WINDOWS\System32\Tasks\User Boot Experience Task => movido correctamente "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\User Boot Experience Task" => eliminado correctamente HKU\S-1-5-21-721675818-2333492642-993102402-1001\Software\Microsoft\Internet Explorer\Main\\"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" => valor restaurado correctamente HKU\S-1-5-21-721675818-2333492642-993102402-1001\Software\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" => valor restaurado correctamente HKU\S-1-5-21-721675818-2333492642-993102402-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => eliminado correctamente C:\Users\Media Service\AppData\Roaming\Mozilla\Firefox\Profiles\z19x5o42.default\Extensions\sp@avast.com.xpi => movido correctamente C:\Users\Media Service\AppData\Roaming\Mozilla\Firefox\Profiles\z19x5o42.default\Extensions\wrc@avast.com.xpi => movido correctamente "HKLM\Software\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-05-29] (VideoLAN" => no encontrado C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll => movido correctamente HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => eliminado correctamente HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => eliminado correctamente C:\Users\Media Service\AppData\Local\oobelibMkey.log => movido correctamente C:\Users\Media Service\AppData\Local\TempWER-831473921-0.sysdata.xml => movido correctamente HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => eliminado correctamente HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => eliminado correctamente