Here the results of the Farbar R
Fix result of Farbar Recovery Scan Tool (x64) Version: 28-04-2021
Ran by YPC3 (04-05-2021 17:30:20) Run:3
Running from C:\Users\LAPC\Desktop\# UNO
Loaded Profiles: YPC3
Boot Mode: Normal
==============================================
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_433.dll [2020-09-15] (Adobe Inc. -> )
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_433.dll [2020-09-15] (Adobe Inc. -> )
2021-04-29 16:43 - 2021-04-29 16:43 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignec5c7d73d2ebf726
2021-04-29 16:43 - 2021-04-29 16:43 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign5599c53cdbc089d4
2021-04-27 16:09 - 2021-04-27 16:09 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignee557e8a0eea052d
2021-04-27 14:10 - 2021-04-27 14:10 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignb5668fac1289089f
2021-04-27 10:15 - 2021-04-27 10:15 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign149160c4e5bb8830
2021-04-27 10:12 - 2021-04-27 10:12 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignc2cc468ae48cd25a
2021-04-27 10:12 - 2021-04-27 10:12 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignab7453ee49a5a17a
2021-04-27 10:12 - 2021-04-27 10:12 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign7088d5d792253d59
2021-04-27 10:12 - 2021-04-27 10:12 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign6028a02c729ca397
2021-04-27 10:11 - 2021-04-27 10:11 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsigna7476cf2898d7e7e
2021-04-27 10:11 - 2021-04-27 10:11 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign4afade2e2a026653
2021-04-27 10:05 - 2021-04-27 10:05 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign650de012317aa68a
2021-04-27 10:05 - 2021-04-27 10:05 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign4fe19451f31c6989
2021-04-27 10:05 - 2021-04-27 10:05 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign0bf3864f0bd81058
2021-04-27 09:30 - 2021-04-27 09:30 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign99a4a4460c6dec4c
2021-04-27 09:04 - 2021-04-27 09:04 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsigneb663db6a8bb032c
2021-04-27 09:04 - 2021-04-27 09:04 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign4b30c9cd2914cc69
2021-04-27 09:04 - 2021-04-27 09:04 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign2be9fa5cb1515f10
2021-04-26 13:37 - 2021-04-26 13:37 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign93eb77bf46d2db4b
2021-04-26 13:36 - 2021-04-26 13:36 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign939541647a99d3c1
2021-04-26 13:32 - 2021-04-26 13:32 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign5ebc04d8ed828660
2021-04-26 13:02 - 2021-04-26 13:02 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignd034d3186591396d
2021-04-26 11:12 - 2021-04-26 11:12 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignac92544101bff369
2021-04-26 10:50 - 2021-04-26 10:50 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign35065bbc7661428e
2021-04-26 10:01 - 2021-04-26 10:01 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign10cfac3665ca3970
2021-04-26 10:00 - 2021-04-26 10:00 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsigned6c8413599ecba7
2021-04-26 10:00 - 2021-04-26 10:00 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsignc6037b3ea15a5678
2021-04-26 10:00 - 2021-04-26 10:00 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign40e5c76a447fa5bb
2021-04-26 08:41 - 2021-04-26 08:41 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsigna209d15090dbf41e
2021-04-26 08:39 - 2021-04-26 08:39 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsigne4e3136ed8414eae
2021-04-26 08:39 - 2021-04-26 08:39 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign0ceabe6ffb1c7d50
2021-04-17 22:21 - 2021-04-17 22:21 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign797af77be8b8cde0
2021-04-17 22:21 - 2021-04-17 22:21 - 000000000 ____D C:\Users\LAPC\AppData\Local\Tempzxpsign57ce748b2426268c
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
C:\WINDOWS\system32\Tasks\InstallShield® Setup Engine Kernel
C:\Program Files (x86)\Common Files\InstallShield
Task: {2092D4C2-6213-4011-B598-A0F186F4A712} - System32\Tasks\Optimize Thumbnail Cache => C:\Program Files (x86)\Common Files\installshield\engine\8\intel 32\isupdate.exe [61104 2020-09-26] (Flexera Software LLC -> InstallShield®) [File not signed]
2021-04-19 22:48 - 2021-04-19 22:48 - 000000000 ____D C:\WINDOWS\system32\Tasks\MEGA
2021-04-19 22:48 - 2021-04-19 22:48 - 000000000 ____D C:\WINDOWS\system32\Tasks\COMODO
HKLM\...\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] => C:\Program Files\COMODO
2021-04-19 22:40 - 2020-03-28 13:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
2021-04-26 13:24 - 2020-04-02 16:16 - 000000000 ____D C:\Users\LAPC\AppData\Roaming\MiPony
2021-04-19 22:40 - 2020-04-02 16:16 - 000000000 ____D C:\Users\LAPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiPony
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
AutoConfigURL: [HKLM] => hxxp://127.0.0.1:86/
AutoConfigURL: [HKLM-x32] => hxxp://127.0.0.1:86/
AutoConfigURL: [{1C5A8DD3-4F41-4B45-910B-D3D379B045D4}] => hxxp://127.0.0.1:86/
ManualProxies: 0hxxp://127.0.0.1:86/
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
cmd: netsh winsock reset catalog
cmd: netsh int ip reset C:\resettcpip.txt
cmd: netsh advfirewall reset
cmd: netsh advfirewall set allprofiles state ON
cmd: Bitsadmin /Reset /Allusers
cmd: ipconfig /flushdns
Removeproxy:
Powershell: Get-Process -Id (Get-NetTCPConnection -LocalPort 86).OwningProcess
*****************
Restore point was successfully created.
Processes closed successfully.
HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer => not found
"C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_433.dll" => not found
"HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_433.dll [2020-09-15] (Adobe Inc." => not found
"C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_433.dll" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignec5c7d73d2ebf726" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign5599c53cdbc089d4" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignee557e8a0eea052d" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignb5668fac1289089f" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign149160c4e5bb8830" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignc2cc468ae48cd25a" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignab7453ee49a5a17a" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign7088d5d792253d59" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign6028a02c729ca397" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsigna7476cf2898d7e7e" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign4afade2e2a026653" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign650de012317aa68a" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign4fe19451f31c6989" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign0bf3864f0bd81058" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign99a4a4460c6dec4c" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsigneb663db6a8bb032c" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign4b30c9cd2914cc69" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign2be9fa5cb1515f10" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign93eb77bf46d2db4b" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign939541647a99d3c1" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign5ebc04d8ed828660" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignd034d3186591396d" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignac92544101bff369" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign35065bbc7661428e" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign10cfac3665ca3970" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsigned6c8413599ecba7" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsignc6037b3ea15a5678" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign40e5c76a447fa5bb" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsigna209d15090dbf41e" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsigne4e3136ed8414eae" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign0ceabe6ffb1c7d50" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign797af77be8b8cde0" => not found
"C:\Users\LAPC\AppData\Local\Tempzxpsign57ce748b2426268c" => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => not found
"C:\WINDOWS\system32\Tasks\InstallShield® Setup Engine Kernel" => not found
"C:\Program Files (x86)\Common Files\InstallShield" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2092D4C2-6213-4011-B598-A0F186F4A712}" => not found
"C:\WINDOWS\System32\Tasks\Optimize Thumbnail Cache" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Thumbnail Cache" => not found
"C:\WINDOWS\system32\Tasks\MEGA" => not found
"C:\WINDOWS\system32\Tasks\COMODO" => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}" => not found
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO" => not found
"C:\Users\LAPC\AppData\Roaming\MiPony" => not found
"C:\Users\LAPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MiPony" => not found
"HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxySettingsPerUser" => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL" => not found
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL" => not found
HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\ProxyMgr\{1C5A8DD3-4F41-4B45-910B-D3D379B045D4} => not found
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => not found
========= netsh winsock reset catalog =========
El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.
========= End of CMD: =========
========= netsh int ip reset C:\resettcpip.txt =========
Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.
========= End of CMD: =========
========= netsh advfirewall reset =========
Aceptar
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Aceptar
========= End of CMD: =========
========= Bitsadmin /Reset /Allusers =========
BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.
0 out of 0 jobs canceled.
========= End of CMD: =========
========= ipconfig /flushdns =========
Configuraci¢n IP de Windows
Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.
========= End of CMD: =========
========= RemoveProxy: =========
========= End of RemoveProxy: =========
========= Get-Process -Id (Get-NetTCPConnection -LocalPort 86).OwningProcess =========
Get-NetTCPConnection : Clase no válida
En C:\FRST\tmp.ps1: 1 Carácter: 18
+ Get-Process -Id (Get-NetTCPConnection -LocalPort 86).OwningProcess
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : MetadataError: (MSFT_NetTCPConnection:ROOT/StandardCimv2/MSFT_NetTCPConnection) [Get-Net
TCPConnection], CimException
+ FullyQualifiedErrorId : HRESULT 0x80041010,Get-NetTCPConnection
Get-Process : No se puede enlazar el argumento al parámetro 'Id' porque es nulo.
En C:\FRST\tmp.ps1: 1 Carácter: 17
+ Get-Process -Id (Get-NetTCPConnection -LocalPort 86).OwningProcess
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidData: (:) [Get-Process], ParameterBindingValidationException
+ FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,Microsoft.PowerShell.Commands.GetProcessC
ommand
========= End of Powershell: =========
The system needed a reboot.
==== End of Fixlog 17:30:46 ====



This topic is locked
Back to top







