Hola @SanMar,
Olvidé mencionar lo de la calculadora; realicé ambos pasos, ya que el primero no me dejaba desinstalar, y en el segundo paso, se realizaron las copias, pero sigue cerrándose a los 2 segundos. Windows Defender si está activo, siempre lo verifico.
Comentando lo último que me solicitaste:
Cheat Engine, la verdad lo utilizo bastante para pruebas de programas, pero de todas formas lo desinstalé con Revo.
Hice la copia del Registro como me lo pediste, y está guardada.
Desactivé el antivirus con el script de la vez pasada.
Copié y pegué el script para FRST y lo guardé en la fixlist, pero te comento que le borré unas líneas, ya que eran archivos creados por mi. Los script *.bat en mis carpetas son todos creados por mi, con los que analizo mi computador. Por ejemplo “BAM” es “busqueda automática de modificaciones”.
MIO 2019-06-28 10:46 - 2019-06-28 11:00 - 000002522 _____ C:\Users\Absent\BAM.bat
MIO 2019-07-08 13:58 - 2019-06-05 18:07 - 000000000 ____D
MOTOR GRAFICO UE C:\Users\Absent\AppData\Local\UnrealEngine
MIO 2019-06-21 20:44 - 2019-05-02 08:11 - 000003691 ___RX C:\Users\Absent\Downloads\Organizador.bat
MIO 2019-06-28 10:46 - 2019-06-28 11:00 - 000002522 _____ () C:\Users\Absent\BAM.bat
Realicé también los de USBFix, aunque la verdad no conecto ningún tipo de almacenamiento al computador.
Ahora pego los reportes arrojados por los programas y además adjunto el anterior sobre la calculadora:
FRST LOG
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-07-2019 01
Ran by Absent (19-07-2019 11:18:20) Run:4
Running from C:\Users\Absent\Desktop
Loaded Profiles: Absent (Available Profiles: Absent)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
2019-07-04 20:04 - 2019-07-04 20:04 - 000000000 ____D C:\Users\Absent\AppData\Local\Backup {E1A2D7FE-C50A-BB46-A892-9EAE8CFA6236} - copia
2019-06-21 18:54 - 2019-06-21 18:54 - 000000012 ___SH C:\WINDOWS\65612460883F
2019-06-21 18:56 - 2019-06-21 18:56 - 000126464 _____ C:\Users\Absent\AppData\Local\lobby.dat
2019-06-21 18:55 - 2019-06-21 18:55 - 000825856 _____ C:\Default.xml
HKLM\...\Drivers32: [vidc.i420] => C:\Windows\SysWOW64\i420vfw.dll [70656 2004-01-25] (www.helixcommunity.org) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [vidc.yv12] => C:\Windows\SysWOW64\yv12vfw.dll [70656 2004-01-25] (www.helixcommunity.org) [File not signed]
HKLM\Software\...\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
Task: {A1404501-4D56-4533-97C7-D335686F3B46} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\Absent\Downloads\esetonlinescanner_esn.exe
Task: {AE956413-7C92-47B3-9109-441FB4B21A03} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\Absent\Downloads\esetonlinescanner_esn.exe
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL
S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2019-07-15] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)
C:\WINDOWS\xhunter1.sys
2019-06-21 20:27 - 2004-01-25 00:00 - 000070656 ___SH (www.helixcommunity.org) C:\WINDOWS\SysWOW64\yv12vfw.dll
2019-06-21 20:27 - 2004-01-25 00:00 - 000070656 ___SH (www.helixcommunity.org) C:\WINDOWS\SysWOW64\i420vfw.dll
2019-06-21 18:54 - 2019-06-21 19:05 - 000000000 ____D C:\Program Files (x86)\gujhd
2019-07-15 15:04 - 2019-02-01 18:13 - 000074552 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys
2019-07-11 15:47 - 2019-03-14 14:20 - 000000000 ____D C:\Program Files (x86)\Cheat Engine 6.8.3
C:\Program Files (x86)\Cheat Engine 6.8.3
2019-07-06 16:11 - 2019-03-14 14:21 - 000001166 _____ C:\Users\Absent\Cheat Engine.lnk
2019-07-01 12:54 - 2019-01-04 15:13 - 000000000 ____D C:\WINDOWS\System32\Tasks\momag
2019-06-21 19:47 - 2019-05-07 13:49 - 000000000 ____D C:\Users\Absent\AppData\Local\ESET
2018-11-16 19:30 - 2019-02-13 20:29 - 000000245 _____ () C:\Users\Absent\mdatac.dat
2018-11-16 17:17 - 2018-11-18 16:30 - 001999539 _____ () C:\Users\Absent\Test.exe
2019-06-21 18:56 - 2019-06-21 18:56 - 000126464 _____ () C:\Users\Absent\AppData\Local\lobby.dat
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => -> No File
ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
AlternateDataStreams: C:\Users\Absent\Datos de programa:7dd1e1189f9fcf05a559dccee48d89c6 [362]
AlternateDataStreams: C:\Users\Absent\Datos de programa:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
AlternateDataStreams: C:\Users\Absent\AppData\Roaming:7dd1e1189f9fcf05a559dccee48d89c6 [362]
AlternateDataStreams: C:\Users\Absent\AppData\Roaming:fbd50e2f7662a5c33287ddc6e65ab5a1 [394]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [440]
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
*****************
Processes closed successfully.
Restore point was successfully created.
C:\Users\Absent\AppData\Local\Backup {E1A2D7FE-C50A-BB46-A892-9EAE8CFA6236} - copia => moved successfully
C:\WINDOWS\65612460883F => moved successfully
C:\Users\Absent\AppData\Local\lobby.dat => moved successfully
C:\Default.xml => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\\vidc.i420 => value restored successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\\VIDC.RTV1" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\\vidc.yv12" => not found
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{503739d0-4c5e-4cfd-b3ba-d881334f0df2}" => removed successfully
HKLM\Software\Classes\CLSID\{503739d0-4c5e-4cfd-b3ba-d881334f0df2} => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1404501-4D56-4533-97C7-D335686F3B46}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1404501-4D56-4533-97C7-D335686F3B46}" => removed successfully
C:\WINDOWS\System32\Tasks\EOSv3 Scheduler onTime => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EOSv3 Scheduler onTime" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE956413-7C92-47B3-9109-441FB4B21A03}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE956413-7C92-47B3-9109-441FB4B21A03}" => removed successfully
C:\WINDOWS\System32\Tasks\EOSv3 Scheduler onLogOn => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EOSv3 Scheduler onLogOn" => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\System\CurrentControlSet\Services\xhunter1 => removed successfully
xhunter1 => service removed successfully
C:\WINDOWS\xhunter1.sys => moved successfully
C:\WINDOWS\SysWOW64\yv12vfw.dll => moved successfully
C:\WINDOWS\SysWOW64\i420vfw.dll => moved successfully
C:\Program Files (x86)\gujhd => moved successfully
"C:\WINDOWS\xhunter1.sys" => not found
"C:\Program Files (x86)\Cheat Engine 6.8.3" => not found
"C:\Program Files (x86)\Cheat Engine 6.8.3" => not found
C:\Users\Absent\Cheat Engine.lnk => moved successfully
C:\WINDOWS\System32\Tasks\momag => moved successfully
C:\Users\Absent\AppData\Local\ESET => moved successfully
C:\Users\Absent\mdatac.dat => moved successfully
C:\Users\Absent\Test.exe => moved successfully
"C:\Users\Absent\AppData\Local\lobby.dat" => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\UAContextMenu => removed successfully
HKLM\Software\Classes\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\CLSID\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\UAContextMenu => removed successfully
HKLM\Software\Classes\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\UAContextMenu => removed successfully
HKLM\Software\Classes\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => not found
"HKU\\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
"HKU\\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
"HKU\\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found
HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found
C:\Users\Absent\Datos de programa => ":7dd1e1189f9fcf05a559dccee48d89c6" ADS removed successfully
C:\Users\Absent\Datos de programa => ":fbd50e2f7662a5c33287ddc6e65ab5a1" ADS removed successfully
"C:\Users\Absent\AppData\Roaming" => ":7dd1e1189f9fcf05a559dccee48d89c6" ADS not found.
"C:\Users\Absent\AppData\Roaming" => ":fbd50e2f7662a5c33287ddc6e65ab5a1" ADS not found.
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File) => Error: No automatic fix found for this entry.
========= ipconfig /flushdns =========
Configuraci¢n IP de Windows
Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS.
========= End of CMD: =========
========= ipconfig /renew =========
Configuraci¢n IP de Windows
Error al renovar la interfaz Ethernet 3: no se puede establecer contacto con el
servidor DHCP. La solicitud super¢ el tiempo de espera.
========= End of CMD: =========
========= bitsadmin /reset /allusers =========
BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.
0 out of 0 jobs canceled.
========= End of CMD: =========
========= netsh winsock reset =========
El cat logo Winsock se restableci¢ correctamente.
Debe reiniciar el equipo para completar el restablecimiento.
========= End of CMD: =========
========= netsh advfirewall reset =========
Aceptar
========= End of CMD: =========
========= netsh advfirewall set allprofiles state ON =========
Aceptar
========= End of CMD: =========
========= netsh int ipv4 reset =========
Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.
========= End of CMD: =========
========= netsh int ipv6 reset =========
Reenv¡o de compartimiento se restableci¢ correctamente.
Compartimiento se restableci¢ correctamente.
Protocolo de control se restableci¢ correctamente.
Solicitud de secuencia eco se restableci¢ correctamente.
Global se restableci¢ correctamente.
Interfaz se restableci¢ correctamente.
Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente.
Direcciones de multidifusi¢n se restableci¢ correctamente.
Direcci¢n de unidifusi¢n se restableci¢ correctamente.
Vecino se restableci¢ correctamente.
Ruta de acceso se restableci¢ correctamente.
Posible se restableci¢ correctamente.
Directiva de prefijo se restableci¢ correctamente.
Vecino de proxy se restableci¢ correctamente.
Ruta se restableci¢ correctamente.
Prefijo de sitio se restableci¢ correctamente.
Subinterfaz se restableci¢ correctamente.
Patr¢n de reactivaci¢n se restableci¢ correctamente.
Resolver vecino se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
Error al restablecer .
Acceso denegado.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
se restableci¢ correctamente.
Reinicie el equipo para completar esta acci¢n.
========= End of CMD: =========
========= RemoveProxy: =========
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-3126805088-1096401988-3500408547-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-3126805088-1096401988-3500408547-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
========= End of RemoveProxy: =========
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12801749 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 1305356 B
Edge => 18001 B
Chrome => 23227058 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 6696 B
NetworkService => 0 B
Absent => 2000727 B
RecycleBin => 0 B
EmptyTemp: => 45.1 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 11:20:13 ====
USBFix log
# ----------------------------------------------------
# UsbFix Antivirus Free
# ----------------------------------------------------
# Versión : 11.016
# Base de datos : 2019.05.21
# Contacto : https://www.usb-antivirus.com/es/contacto
# ----------------------------------------------------
# Tipo de escaneo : Full
# Usuario : Absent (Administrador)
# Dispositivo : ABSENTPPC
# Comenzó : 19/07/2019 11:32:57
# ----------------------------------------------------
------------ | Discos analizados |
C:\ NTFS (34GB/111GB) [Fixed]
D:\ NTFS (136GB/443GB) [Fixed]
E:\ NTFS (76GB/146GB) [Fixed]
F:\ NTFS (47GB/195GB) [Fixed]
G:\ NTFS (2GB/21GB) [Fixed]
H:\ NTFS (12GB/124GB) [Fixed]
------------ | Elemento(s) infectado(s) |
Borrado! C:\Users\Absent\AppData\Local\MEGAsync
Borrado! C:\Users\Absent\AppData\Local\MEGAsync
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\libsodium.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\MEGA Website.url
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\MEGAsync.exe
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\MEGAupdater.exe
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\msvcp140.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\platforms\qwindows.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\ShellExtX64.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\ssleay32.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\swresample-2.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\swscale-4.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\ucrtbase.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\uninst.exe
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\vccorlib140.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync\vcruntime140.dll
Borrado! C:\Users\Absent\AppData\Local\MEGAsync
Borrado! C:\Users\Absent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk
Borrado! C:\Users\Absent\AppData\Roaming\Microsoft\Windows\win_a.dat
------------ | Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
04 - HKCU\..\Run : [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
04 - HKCU\..\Run : [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - [x64] HKLM\..\Run : [SecurityHealth] %windir%\system32\SecurityHealthSystray.exe
04 - HKU\S-1-5-19\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
04 - HKU\S-1-5-20\..\Run : [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
04 - HKU\S-1-5-21-3126805088-1096401988-3500408547-1000\..\Run : [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
04 - HKU\S-1-5-21-3126805088-1096401988-3500408547-1000\..\Run : [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
04 - HKU\S-1-5-21-3126805088-1096401988-3500408547-1000\..\Run : [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
------------ | Tasks |
Task - BlueStacksHelper --> C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe -sr
Task - CCleaner Update --> C:\Program Files\CCleaner\CCUpdate.exe
Task - CCleanerSkipUAC --> "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Task - GoogleUpdateTaskMachineCore --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Task - GoogleUpdateTaskMachineUA --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Task - MSIAfterburner --> C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s
Task - NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvBackend\NvBatteryBoostCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerBatteryBoostCheck.log
Task - NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
Task - NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> "C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe"
Task - NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
Task - NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
Task - NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
Task - NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
Task - NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
Task - NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
Task - NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} --> C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
Task - User_Feed_Synchronization-{35C83302-2B05-4DF8-9B0D-47D37575E842} --> C:\WINDOWS\system32\msfeedssync.exe sync
------------ | C:\ %SystemDrive% - Disco fijo (NTFS) |
[19/07/2019 - 11:11:03 | A | 0 Ko] - DelFix.txt
[19/07/2019 - 11:21:04 | ASH | 3145728 Ko] - pagefile.sys
[19/07/2019 - 11:21:05 | ASH | 16384 Ko] - swapfile.sys
[30/04/2019 - 17:11:33 | SH | 0 Ko] - bootTel.dat
[28/06/2019 - 11:07:41 | SHD] - $Recycle.Bin
[16/11/2018 - 10:57:19 | HD] - $Windows.~WS
[14/07/2009 - 01:08:56 | SHD] - Documents and Settings
[01/09/2018 - 12:10:00 | SHD] - Archivos de programa
[15/09/2018 - 03:33:50 | D] - PerfLogs
[16/11/2018 - 13:19:16 | RD] - Users
[16/11/2018 - 13:21:07 | SHD] - Recovery
[31/01/2019 - 18:16:44 | D] - LIN
[06/06/2019 - 21:16:02 | D] - ESD
[04/07/2019 - 20:07:25 | RD] - Program Files
[08/07/2019 - 09:49:06 | HD] - ProgramData
[12/07/2019 - 15:02:02 | D] - AdwCleaner
[19/07/2019 - 11:18:40 | D] - Windows
[19/07/2019 - 11:22:49 | D] - FRST
[19/07/2019 - 11:29:43 | RD] - Program Files (x86)
------------ | D:\ - Disco fijo (NTFS) |
[22/06/2019 - 16:08:56 | HD] - msdownld.tmp
[02/02/2019 - 16:49:45 | ASH | 3314940 Ko] - hiberfil.sys
[02/02/2019 - 16:49:45 | ASH | 1310720 Ko] - pagefile.sys
[02/02/2019 - 16:49:45 | ASH | 262144 Ko] - swapfile.sys
[14/04/2014 - 17:29:38 | AHD] - SYSTEM.SAV
[13/11/2018 - 12:57:52 | SHD] - Config.Msi
[10/12/2018 - 09:07:15 | SHD] - $Recycle.Bin
[03/08/2012 - 19:21:37 | RASH | 8 Ko] - BOOTSECT.BAK
[13/11/2018 - 14:29:54 | HD] - $WINDOWS.~BT
[25/07/2012 - 23:44:30 | RASH | 389 Ko] - bootmgr
[03/08/2012 - 19:21:36 | SHD] - Boot
[22/08/2013 - 10:45:52 | SHD] - Documents and Settings
[01/09/2013 - 08:49:48 | D] - SWSetup
[14/04/2014 - 16:00:19 | SHD] - Archivos de programa
[19/04/2014 - 18:13:43 | RHD] - MSOCache
[21/04/2014 - 21:18:17 | HD] - HP
[16/02/2015 - 15:28:31 | D] - PaintToolSAI
[30/10/2015 - 03:18:34 | ASH | 0 Ko] - BOOTNXT
[30/10/2015 - 03:24:24 | D] - PerfLogs
[13/02/2016 - 09:07:41 | D] - Logs
[09/04/2016 - 08:20:16 | D] - inetpub
[09/04/2016 - 14:58:55 | D] - AMD
[09/04/2016 - 15:03:36 | SHD] - Recovery
[22/01/2017 - 18:38:45 | RD] - Users
[29/06/2017 - 19:39:35 | HD] - ProgramData
[13/11/2018 - 14:18:05 | D] - Windows10Upgrade
[13/11/2018 - 14:18:09 | HD] - $GetCurrent
[14/11/2018 - 14:40:29 | RD] - Program Files
[14/11/2018 - 17:24:31 | D] - Program Files (x86)
[02/02/2019 - 16:47:49 | D] - Windows
[21/06/2019 - 12:29:51 | D] - BACKUP ABSENT
[12/07/2019 - 15:01:45 | D] - Action!
[12/07/2019 - 15:01:48 | D] - Games
------------ | E:\ - Disco fijo (NTFS) |
[01/09/2018 - 12:10:08 | SHD] - $RECYCLE.BIN
[12/01/2016 - 21:33:30 | ADC] - Absen
[13/01/2016 - 18:16:21 | AD] - Popcorn Time
[07/02/2016 - 15:26:26 | D] - Películas
[14/02/2017 - 10:13:04 | ADC] - Celular
[28/11/2017 - 15:50:37 | RD] - Nosotros
[28/11/2017 - 17:00:44 | RD] - Imagenes
[08/04/2018 - 14:03:14 | ADC] - Libros
[25/08/2018 - 11:45:14 | D] - Los Simpsons
[01/09/2018 - 12:58:40 | D] - DRIVERS
[18/01/2019 - 18:04:34 | D] - Función Malau 2019
[08/04/2019 - 20:40:33 | RD] - Música
[16/05/2019 - 12:41:05 | D] - Tablet
[10/06/2019 - 17:16:09 | D] - Games
[28/06/2019 - 08:28:02 | AD] - JDownloader
[03/07/2019 - 18:41:23 | D] - Fotos
------------ | F:\ - Disco fijo (NTFS) |
[07/06/2019 - 13:13:32 | HD] - msdownld.tmp
[19/07/2019 - 11:21:05 | ASH | 5505024 Ko] - pagefile.sys
[19/11/2018 - 07:59:12 | SHD] - $RECYCLE.BIN
[22/08/2016 - 12:21:16 | SHD] - Recovery
[30/05/2019 - 15:21:46 | D] - SteamLibrary
[08/06/2019 - 19:30:51 | D] - Games
[09/06/2019 - 16:31:20 | D] - Descargas JD
[12/07/2019 - 15:02:00 | D] - CPY_SAVES
------------ | G:\ - Disco fijo (NTFS) |
[26/07/2012 - 15:57:10 | RASH | 1319 Ko] - bootmgr.efi
[10/12/2018 - 09:07:15 | SHD] - $RECYCLE.BIN
[26/07/2012 - 14:44:32 | RASH | 389 Ko] - bootmgr
[01/09/2013 - 09:50:33 | RSHD] - EFI
[01/09/2013 - 09:50:33 | RASHD] - hp
[01/09/2013 - 09:50:33 | RSHD] - boot
[01/09/2013 - 09:50:33 | RSD] - recovery
[01/09/2013 - 09:50:33 | SHD] - RM_Reserve
[09/04/2016 - 15:38:11 | RSHD] - preload
------------ | H:\ - Disco fijo (NTFS) |
[06/06/2019 - 15:03:37 | SHC | 0 Ko] - desktop.ini
[12/12/2018 - 08:34:49 | SHDC] - $RECYCLE.BIN
[27/01/2019 - 12:56:15 | DC] - Backup Celu
[30/04/2019 - 12:03:03 | DC] - Samsung j7 Duos
[30/04/2019 - 16:42:16 | D] - Backup Disco Notebook
[07/05/2019 - 16:22:38 | DC] - IObit
[07/05/2019 - 16:22:52 | DC] - Nueva carpeta
[01/06/2019 - 10:13:22 | DC] - Programas
[06/06/2019 - 15:03:21 | SHDC] - MSOCache
[09/06/2019 - 17:25:32 | D] - gta
[18/06/2019 - 12:48:07 | D] - Mario Kart 8
Elemento(s) infectado(s) : 3
Elementos analizados : 104984 en 00h 00m 11s
# UsbFix-Report-02.txt [10399B]
------------ | E.O.F |
FRST CALC.EXE
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-07-2019 01
Ran by Absent (18-07-2019 10:30:27) Run:3
Running from C:\Users\Absent\Desktop
Loaded Profiles: Absent (Available Profiles: Absent)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
Replace: C:\Windows\WinSxS\amd64_microsoft-windows-calc_31bf3856ad364e35_10.0.17763.1_none_9a83eb2072e563f9\calc.exe C:\Windows\System32\calc.exe
Replace: C:\Windows\WinSxS\wow64_microsoft-windows-calc_31bf3856ad364e35_10.0.17763.1_none_a4d89572a74625f4\calc.exe C:\Windows\SysWOW64\calc.exe
Reboot:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
C:\Windows\System32\calc.exe => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-calc_31bf3856ad364e35_10.0.17763.1_none_9a83eb2072e563f9\calc.exe copied successfully to C:\Windows\System32\calc.exe
C:\Windows\SysWOW64\calc.exe => moved successfully
C:\Windows\WinSxS\wow64_microsoft-windows-calc_31bf3856ad364e35_10.0.17763.1_none_a4d89572a74625f4\calc.exe copied successfully to C:\Windows\SysWOW64\calc.exe
=========== EmptyTemp: ==========
BITS transfer queue => 7888896 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 20359555 B
Java, Flash, Steam htmlcache => 17070070 B
Windows/system/drivers => 3380027 B
Edge => 175081 B
Chrome => 355448387 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 1244726 B
systemprofile32 => 42449 B
LocalService => 1436 B
LocalService => 0 B
NetworkService => 14670 B
NetworkService => 0 B
Absent => 18517545 B
RecycleBin => 104 B
EmptyTemp: => 404.5 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 10:31:25 ====
Muchas gracias, Saludos!