Fix result of Farbar Recovery Scan Tool (x86) Version: 06.10.2018
Ran by Usuario (08-10-2018 11:35:34) Run:1
Running from C:\Documents and Settings\Usuario\Escritorio
Loaded Profiles: Usuario (Available Profiles: Usuario & NeroMediaHomeUser.4 & Administrador)
Boot Mode: Safe Mode (minimal)
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
(EnigmaSoft Limited) C:\Archivos de programa\EnigmaSoft\SpyHunter\ShKernel.exe
C:\Archivos de programa\EnigmaSoft
HKU\S-1-5-21-329068152-1326574676-1177238915-1003\...\Run: [5ff9e5d3] => C:\ProgramData\5ff9e5d3\5ff9e5d3.exe [937776 2018-08-10] (AutoIt Team)
C:\ProgramData\5ff9e5d3
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
S4 IntelIde; no ImagePath
S1 mbamchameleon; \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys [X]
S3 VComm; system32\DRIVERS\VComm.sys [X]
S3 VcommMgr; System32\Drivers\VcommMgr.sys [X]
2018-09-28 14:25 - 2018-10-06 12:27 - 000054456 _____ (EnigmaSoft Limited) C:\WINDOWS\system32\Drivers\EnigmaFileMonDriver.sys
2014-03-04 19:34 - 2014-03-04 19:34 - 000212992 _____ (Realtek Semiconductor Corp.) C:\Documents and Settings\Administrador.EQUIPO-A70B2DD8\Configuracin local\temp\RtkBtMnt.exe
2018-10-05 20:50 - 2018-10-05 20:50 - 000001536 _____ () C:\Documents and Settings\Usuario\Configuracin local\temp\NEventMessages.dll
2018-03-25 11:34 - 2018-03-25 11:34 - 000001536 ____N () C:\Documents and Settings\Usuario\Configuracin local\temp\NOSEventMessages.dll
ContextMenuHandlers6: [_Movavivc11] -> {1C604495-4D32-476e-8D7E-FBF50F6C80BF} => -> No File
Task: C:\WINDOWS\Tasks\Sepasclonuly System.job => C:\Archivos de programa\Andsepherjosh\xliluck.exe
C:\Archivos de programa\Andsepherjosh
Shortcut: C:\Documents and Settings\Usuario\Favoritos\Sitio para descargas de NCH Software.lnk
Shortcut: C:\Documents and Settings\All Users.WINDOWS\Men Inicio\Programas\Bayer HealthCare\GLUCOFACTS Deluxe\GLUCOFACTS Deluxe v3.05.lnk -> C:\Archivos de programa\Bayer HealthCare\GLUCOFACTS Deluxe\run.bat ()
ShortcutWithArgument: C:\Documents and Settings\Usuario\Datos de programa\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Archivos de programa\Google\Chrome\Application\chrome.exe (Google Inc.) -> --disable-infobars
AlternateDataStreams: C:\WINDOWS\system32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57} [26]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:1CE11B51 [98]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:373E1720 [118]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:5C321E34 [119]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:DBC416F8 [144]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:1CE11B51 [98]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:373E1720 [118]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:5C321E34 [119]
AlternateDataStreams: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp:DBC416F8 [144]
HOSTS:
REMOVEPROXY:
EMPTYTEMP:
CMD: netsh winsock reset
CMD: ipconfig /renew
CMD: ipconfig /flushdns
CMD: bitsadmin /reset /allusers
END
*****************
Error: Restore point can only be created in normal mode.
Processes closed successfully.
C:\Archivos de programa\EnigmaSoft\SpyHunter\ShKernel.exe
C:\Archivos de programa\EnigmaSoft\SpyHunter\ShKernel.exe => No running process found
C:\Archivos de programa\EnigmaSoft => moved successfully
"HKU\S-1-5-21-329068152-1326574676-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Run\\5ff9e5d3" => removed successfully.
C:\ProgramData\5ff9e5d3 => moved successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Google => removed successfully.
HKLM\System\CurrentControlSet\Services\IntelIde => removed successfully.
IntelIde => service removed successfully.
HKLM\System\CurrentControlSet\Services\mbamchameleon => removed successfully.
mbamchameleon => service removed successfully.
HKLM\System\CurrentControlSet\Services\VComm => removed successfully.
VComm => service removed successfully.
HKLM\System\CurrentControlSet\Services\VcommMgr => removed successfully.
VcommMgr => service removed successfully.
C:\WINDOWS\system32\Drivers\EnigmaFileMonDriver.sys => moved successfully
"C:\Documents and Settings\Administrador.EQUIPO-A70B2DD8\Configuracin local\temp\RtkBtMnt.exe" => not found
"C:\Documents and Settings\Usuario\Configuracin local\temp\NEventMessages.dll" => not found
"C:\Documents and Settings\Usuario\Configuracin local\temp\NOSEventMessages.dll" => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\_Movavivc11 => removed successfully.
HKLM\Software\Classes\CLSID\{1C604495-4D32-476e-8D7E-FBF50F6C80BF} => not found
C:\WINDOWS\Tasks\Sepasclonuly System.job => moved successfully
"C:\Archivos de programa\Andsepherjosh" => not found
Shortcut: C:\Documents and Settings\Usuario\Favoritos\Sitio para descargas de NCH Software.lnk => not found.
C:\Documents and Settings\All Users.WINDOWS\Men Inicio\Programas\Bayer HealthCare\GLUCOFACTS Deluxe\GLUCOFACTS Deluxe v3.05.lnk => not found.
C:\Documents and Settings\Usuario\Datos de programa\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => Shortcut argument removed successfully.
C:\WINDOWS\system32 => ":{4B9A1497-0817-47C4-9612-D6A1C53ACF57}" ADS removed successfully.
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp => ":1CE11B51" ADS removed successfully.
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp => ":373E1720" ADS removed successfully.
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp => ":5C321E34" ADS removed successfully.
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp => ":DBC416F8" ADS removed successfully.
"C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp" => ":1CE11B51" ADS not found.
"C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp" => ":373E1720" ADS not found.
"C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp" => ":5C321E34" ADS not found.
"C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp" => ":DBC416F8" ADS not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
========= RemoveProxy: =========
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully.
HKU\S-1-5-21-329068152-1326574676-1177238915-1003\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully.
"HKU\S-1-5-21-329068152-1326574676-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully.
"HKU\S-1-5-21-329068152-1326574676-1177238915-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully.
========= End of RemoveProxy: =========
========= netsh winsock reset =========
Restablecer satisfactoriamente el cat logo Winsock.
Debe reiniciar el equipo para finalizar el restablecimiento.
========= End of CMD: =========
========= ipconfig /renew =========
Configuración IP de Windows
Error interno: Solicitud no compatible.
Póngase en contacto con los servicios de soporte técnico de Microsoft para
obtener ayuda.
Información adicional: no se puede encontrar el nombre de host.
========= End of CMD: =========
========= ipconfig /flushdns =========
Configuración IP de Windows
Error interno: Solicitud no compatible.
Póngase en contacto con los servicios de soporte técnico de Microsoft para
obtener ayuda.
Información adicional: no se puede encontrar el nombre de host.
========= End of CMD: =========
========= bitsadmin /reset /allusers =========
"bitsadmin" no se reconoce como un comando interno o externo,
programa o archivo por lotes ejecutable.
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache => 402265 B
Java, Flash, Steam htmlcache => 16458570 B
Windows/system/dllcache/drivers => 340519 B
Edge => 0 B
Chrome => 6591609 B
Firefox => 77409497 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Documents and Settings => 0 B
Default User.WINDOWS => 66164 B
All Users.WINDOWS => 0 B
systemprofile => 527531127 B
LocalService.NT AUTHORITY => 131644 B
NetworkService.NT AUTHORITY => 2180803 B
Usuario => 7496972 B
NeroMediaHomeUser.4 => 2463550 B
Administrador.EQUIPO-A70B2DD8 => 69801747 B
RecycleBin => 60411 B
EmptyTemp: => 678 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 11:37:11 ====
Pues Miguelgrado, ya no salta el error al reiniciar. Supongo que el informe confirmará lo que te digo.
muchísimas gracias por tu interés, crack.
Volveré cuando tenga otro problemilla, espero tardar.
Lo dicho, mil gracias compañer@.