Windows 8 no inicia error srttrail.txt Reporte incluído

Hola, estoy intentando revivir la laptop de mi esposa. Se apago repentinamente y entro en el bucle de reparación. Al intentar la reparación automática tengo el resultado de que windows/system32/logfiles/srt/srttrail.txt

Intenté hacer troubleshooting seguí los pasos de este video https://www.youtube.com/watch?v=MNvxcN8s2fM nada sirvió y eventualmente llegué a este foro. Descargué FRT scanee el equipo y tengo el reporte

podrían ayudarme por favor?

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-06-2020
Ran by SYSTEM on MININT-AON08RU (09-06-2020 21:10:25)
Running from F:\
Platform: WIN_8 (X64) Language: Inglés (Estados Unidos)
Boot Mode: Recovery
ATTENTION: Could not load system hive.
La operaci�n se complet� correctamente.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKLM-x32\...\Winlogon: [Userinit] 
HKLM\...\Winlogon: [Shell]  <=== ATTENTION
HKLM-x32\...\Winlogon: [Shell]  <=== ATTENTION
HKLM\...\InprocServer32: [Default-wbemess]  <==== ATTENTION
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox]  <==== ATTENTION
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI]  <==== ATTENTION
HKU\Default\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2018-10-20] (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-09 21:10 - 2020-06-09 21:10 - 000000000 ____D C:\FRST
2020-06-09 20:28 - 2020-06-09 20:29 - 000000000 ____D C:\Windows\System32\config\backup02
2020-06-09 20:27 - 2020-06-09 20:28 - 000000000 ____D C:\Windows\System32\config\backup01
2020-06-09 14:35 - 2020-06-09 14:35 - 000072337 _____ C:\Windows\System32\config\backup1
2020-06-09 14:35 - 2020-06-09 14:35 - 000000000 ____D C:\Windows\System32\config\backup1p
2020-06-09 14:33 - 2020-06-09 14:34 - 000000000 ____D C:\Windows\System32\config\backup
2020-06-09 14:23 - 2020-06-09 14:23 - 000032768 _____ C:\bcdbackup
2020-06-04 01:52 - 2020-06-04 01:53 - 000000000 ___HD C:\$SysReset
2020-05-28 09:56 - 2020-05-28 09:56 - 000053261 _____ C:\Users\jimena\Desktop\BLAISTEN Internet Payment Gateway.pdf
2020-05-25 11:25 - 2020-06-04 05:56 - 000000000 ____D C:\Windows\UpdateAssistant

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-08 19:50 - 2018-07-28 16:18 - 000000000 ____D C:\Windows\System32\SleepStudy
2020-06-08 19:50 - 2018-04-11 15:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-06-07 20:10 - 2018-04-11 15:30 - 000000000 ____D C:\Windows\CbsTemp
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ___HD C:\Program Files\WindowsApps
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\AppReadiness
2020-06-07 17:09 - 2018-07-28 19:18 - 001799978 _____ C:\Windows\System32\PerfStringBackup.INI
2020-06-07 17:09 - 2018-04-12 08:18 - 000804866 _____ C:\Windows\System32\perfh00A.dat
2020-06-07 17:09 - 2018-04-12 08:18 - 000160492 _____ C:\Windows\System32\perfc00A.dat
2020-06-07 17:09 - 2018-04-11 15:36 - 000000000 ____D C:\Windows\INF
2020-06-07 17:06 - 2016-05-20 07:06 - 000000000 __SHD C:\Users\jimena\IntelGraphicsProfiles
2020-06-07 17:05 - 2018-07-28 19:22 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-04 11:55 - 2018-02-13 09:33 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-04 05:57 - 2018-03-06 04:37 - 000000000 ____D C:\Windows\System32\Drivers\wd
2020-06-04 05:52 - 2018-07-28 19:07 - 000000000 ____D C:\users\jimena
2020-06-04 01:53 - 2018-02-05 16:04 - 000000000 _____ C:\Recovery.txt
2020-05-29 06:19 - 2018-07-28 19:22 - 000003358 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2505358239-225056662-2694394933-1001
2020-05-29 06:19 - 2016-05-20 07:16 - 000000000 ___RD C:\Users\jimena\OneDrive
2020-05-26 09:10 - 2020-05-08 11:55 - 000000000 ____D C:\Program Files\UNP
2020-05-25 14:25 - 2018-02-13 09:20 - 000000000 ___RD C:\Users\jimena\3D Objects
2020-05-25 14:25 - 2016-02-13 05:08 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-05-25 14:23 - 2018-07-28 16:18 - 000234176 _____ C:\Windows\System32\FNTCACHE.DAT
2020-05-25 14:21 - 2018-04-11 13:04 - 000524288 _____ C:\Windows\System32\config\BBI
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\TextInput
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\oobe
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\Dism
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\UNP
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\DiagSvcs
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Program Files\Windows Defender
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\SystemResetPlatform
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\oobe
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\appraiser
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellExperiences
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellComponents
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\Provisioning
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\bcastdvr
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-05-25 14:17 - 2018-04-11 13:04 - 000000000 ____D C:\Windows\System32\Dism
2020-05-25 14:13 - 2018-04-11 15:38 - 000017800 _____ C:\Windows\System32\OEMDefaultAssociations.xml
2020-05-25 11:35 - 2018-03-05 09:22 - 000000000 ____D C:\Windows\System32\MRT
2020-05-25 11:27 - 2018-03-05 09:21 - 120636720 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2020-05-25 11:13 - 2018-02-13 09:20 - 000000000 ____D C:\Users\jimena\AppData\Local\Packages

==================== KnownDLLs (Whitelisted) =========================


==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2020-05-08 17:07] - [2019-10-02 02:48] - 000678400 _____ (Microsoft Corporation) F1CB5F4E4B2804C4D9A401CCEFFD85CF

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2020-05-08 17:00] - [2019-10-02 02:34] - 004098912 _____ (Microsoft Corporation) EA043F4A77826199143350288DAD220C

C:\Windows\SysWOW64\explorer.exe
[2020-05-08 17:00] - [2019-10-02 01:22] - 003751824 _____ (Microsoft Corporation) 352E16B87A4F12E162BA357D9AD20A14

C:\Windows\System32\svchost.exe
[2019-02-13 13:24] - [2019-01-08 21:39] - 000085472 _____ (Microsoft Corporation) 0861726716C9610CE5F6BCF3F4858DA1

C:\Windows\SysWOW64\svchost.exe
[2019-02-13 13:23] - [2019-01-08 21:43] - 000071456 _____ (Microsoft Corporation) C01CB20D971C3262F1F856B4539DD27C

C:\Windows\System32\services.exe
[2020-05-08 17:06] - [2019-11-27 21:09] - 000636848 _____ (Microsoft Corporation) 1B285CE722E2D2F12481C4CE5E83CEA4

C:\Windows\System32\User32.dll
[2020-05-08 17:03] - [2020-01-07 01:54] - 001639864 _____ (Microsoft Corporation) D7369E33F2066DA033B2923B27AE5AAA

C:\Windows\SysWOW64\User32.dll
[2020-05-08 17:03] - [2020-01-07 00:15] - 001628496 _____ (Microsoft Corporation) AFDF4E5F0DE0606A16F65C4B9D0D89DE

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2020-05-08 17:09] - [2019-09-12 20:13] - 001154048 _____ (Microsoft Corporation) 09CD2CCFC59F1AD796C233DF9C074C38

C:\Windows\System32\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:19] - 000767232 _____ (Microsoft Corporation) 37C8D784EF2FFB9106CCA462ED6DB968

C:\Windows\SysWOW64\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:12] - 000573808 _____ (Microsoft Corporation) 3775EB86C55D2E03C4642E51DD53F740

C:\Windows\System32\dllhost.exe => MD5 is legit
C:\Windows\SysWOW64\dllhost.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============

HKLM\...\.exe:  =>  <==== ATTENTION
HKLM\...\exefile\DefaultIcon:  <==== ATTENTION
HKLM\...\exefile\shell\open\command:  <==== ATTENTION

==================== Restore Points  =========================

Restore point date: 2020-06-04 05:56
Restore point date: 2020-06-07 20:19

==================== Memory info =========================== 

Percentage of memory in use: 16%
Total physical RAM: 3981.89 MB
Available physical RAM: 3321.6 MB
Total Virtual: 3981.89 MB
Available Virtual: 3329.03 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:185.41 GB) (Free:62.23 GB) NTFS
Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.21 GB) NTFS
Drive f: (NO NAME) (Removable) (Total:3.65 GB) (Free:2.65 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS

\\?\Volume{ba0b1fe6-ff09-49e1-9d4e-ca9c1dc945d8}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.48 GB) NTFS
\\?\Volume{e7935b82-7559-45b2-b6dd-a0234758a351}\ () (Fixed) (Total:0.89 GB) (Free:0.45 GB) NTFS
\\?\Volume{a8d87fdf-5c62-44ca-a5a4-e6c3392f240b}\ (Restore) (Fixed) (Total:20.01 GB) (Free:8.12 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 57788C0B)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
==================== End of FRST.txt ========================

Hola @E_Chanes

Bienvenido al Foro!!

Este error es de muy difícil solución.

Es un Windows 8 o un 8.1?

Por que no has actualizado a Windows 10?

Has intentado Restaurar Sistema desde las Opciones Avanzadas?

Nos comentas.

Salu2

La computadora es de mi esposa. Le daba un uso básico, de captura de texto y email. No hizo el upgrade porque creo que ni estaba enterado de el.

Al intentar restaurar sistema te refieres a restaurar a opciones de fábrica?

Gracias por la respuesta, sabía que era un problema dificil al ver hilos con situaciones muy similares. Me podrías detallar qué es lo que sucede?

Creo que la opción más sensata sería formatearla. No tenemos un disco de restauración y no sé si tiene su windows key, pero lo más seguro es que no, nos mudamos de país y la clave y papeles no vinieron en la mudanza.

Hola @E_Chanes

No exactamente, sino a restaurar desde las Opciones Avanzadas de Windows 8 >>> Restaurar Sistema a una Fecha anterior al problema. También puede intentarse desde Opciones Avanzadas - Símbolo del Sistema.

Ya que en FRST se ven dos puntos de Restauración:

  • Restore point date: 2020-06-04 05:56

  • Restore point date: 2020-06-07 20:19

Si alguno de esos puntos es anterior al problema puedes intentar desde las Opciones Avanzadas de Windows 8. De todas las opciones eliges arrancar desde Símbolo del Sistema y una vez allí escribes tal cual:

  • rstrui.exe >>> Presionas enter.

En este punto debería darte las opciones para restaurar a esas fechas.

Aquí tienes los pasos para crear el DVD o Usb de arranque con un Windows 8/8.1 según el caso.

Algo sucede que no se sabe con exactitud, puede ser algo que se instala incorrectamente, o un corte de corriente, o etc etc hace que se dañe el arranque de forma severa, y ni las recomendaciones de Microsoft funcionan para reparar.

Lo es pero si lo deseas primero intentamos todas las opciones, es un problema que me empeño en solucionar aunque hasta ahora no lo he logrado… :thinking: :thinking: :thinking:

En el enlace que te deje para Restaurar Sistema esta como hacerte de uno.

No te preocupes por ello a partir de Windows 8 la clave o key queda digamos grabada en el Hardware y si quieres formatear podríamos hacerlo directamente con Windows 10 y así actualizar el equipo.

Nos comentas cualquier duda.

Salu2

muchísimas gracias, en serio. Mañana probaremos con la restauración, lo había intentado desde la pantalla azul, pero no me permitía. Sí, una de las fechas de restauración es previa al problema.

Gracias, me mantengo informando por acá como sigue esto.

Hola nuevamente @E_Chanes

Perfecto por acá esperamos tus comentarios…:coffee:

Salu2

Buen día!

intenté con el comando rstrui.exe y no pude continuar. No me deja seleccionar c:

Cualquier aporte se agradece.

Actualmente se encuentra restaurando el sistema despues de intentar con el comando

rstrui.exe /offline:C:\windows=active

En mi siguiente comentario les aviso que paso.

Recordé que una de las primeras acciones que intenté fue restaurar el sistema de esta manera y no me lo permitió, me acordé cuando vi la siguiente pantalla, que fue el mismo error de antes.

Hola @E_Chanes

Realiza lo siguiente:

1.- En el equipo limpio:

Inicio >>> Ejecutar >>> Escribe notepad.exe.

Ahora copie y pege dentro del Notepad:

start::
HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKLM-x32\...\Winlogon: [Userinit] 
HKLM\...\Winlogon: [Shell]  <=== ATTENTION
HKLM-x32\...\Winlogon: [Shell]  <=== ATTENTION
HKLM\...\InprocServer32: [Default-wbemess]  <==== ATTENTION
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox]  <==== ATTENTION
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI]  <==== ATTENTION
HKLM\...\.exe:  =>  <==== ATTENTION
HKLM\...\exefile\DefaultIcon:  <==== ATTENTION
HKLM\...\exefile\shell\open\command:  <==== ATTENTION
end::

Lo guardas bajo el nombre de fixlist.txt en la misma USB donde se encuentra frst.exe o frst64.exe <<< Esto es muy importante.

2.- En el equipo complicado:

Inicia nuevamente las opciones de Recuperación del Sistema hasta seleccionar Símbolo del Sistema. Para Windows 8.

  • Una vez dentro de la Ventana de Comandos escribe tal cual x:frst.exe o x:frst64.exe según el caso donde x debe ser reemplazada por la letra de Su unidad Usb.
  • Presionas Enter. Se abrirá la ventana del programa.
  • Presionas una sola vez el botón Fix y esperas a que termine.
  • Se guardara un reporte en su unidad Usb llamado Fixlog.txt que pegará en su próxima respuesta.
  • Cierre la ventana del programa si quedo abierta.
  • En la Consola escribes tal cual: shutdown /r esto reiniciará el equipo y ve si puedes entrar en modo normal.

Salu2

Hola @SanMar

acá el reporte

Fix result of Farbar Recovery Scan Tool (x64) Version: 06-06-2020
Ran by SYSTEM (12-06-2020 17:32:09) Run:1
Running from E:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKLM-x32\...\Winlogon: [Userinit] 
HKLM\...\Winlogon: [Shell]  <=== ATTENTION
HKLM-x32\...\Winlogon: [Shell]  <=== ATTENTION
HKLM\...\InprocServer32: [Default-wbemess]  <==== ATTENTION
HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox]  <==== ATTENTION
HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI]  <==== ATTENTION
HKLM\...\.exe:  =>  <==== ATTENTION
HKLM\...\exefile\DefaultIcon:  <==== ATTENTION
HKLM\...\exefile\shell\open\command:  <==== ATTENTION

*****************

HKLM\...\Winlogon: [Userinit]  <==== ATTENTION => Could not restore
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"="userinit.exe" => value restored successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"="Explorer.exe" => value restored successfully
HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"="Explorer.exe" => value restored successfully
HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\\"Default"="%systemroot%\system32\wbem\wbemess.dll" => value restored successfully
HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\"Default"="%systemroot%\system32\wbem\fastprox.dll" => value restored successfully
HKLM\Software\Classes\CLSID\{7986d495-ce42-4926-8afc-26dfa299cadb}\InprocServer32\\"Default"="%SystemRoot%\system32\authui.dll" => value restored successfully
HKLM\Software\Classes\.exe\\"Default"="exefile" => value restored successfully
HKLM\Software\Classes\exefile\DefaultIcon\\"Default"="%1" => value restored successfully
HKLM\Software\Classes\exefile\shell\open\command\\"Default"=""%1" %*" => value restored successfully

==== End of Fixlog 17:32:09 ==== 

el comando “shutdown /r” no lo reconocía.

Usé exit y reinicié, sigue en el bucle de reparación automática.

Espero para seguir instrucciones

Gracias

Hola @E_Chanes

Corre FRST desde la USB y las Opciones Avanzadas tal como lo hiciste la primera vez, y nos traes un nuevo reporte.

Salu2

Hola, buen día @SanMar acá el nuevo reporte

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-06-2020
Ran by SYSTEM on MININT-1K5ICHS (13-06-2020 14:16:34)
Running from F:\
Platform: WIN_8 (X64) Language: Inglés (Estados Unidos)
Boot Mode: Recovery
ATTENTION: Could not load system hive.
La operaci�n se complet� correctamente.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\RunOnce: [*Restore] => C:\WINDOWS\system32\rstrui.exe [266752 2018-08-30] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKU\Default\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2018-10-20] (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-09 21:10 - 2020-06-13 14:16 - 000000000 ____D C:\FRST
2020-06-09 20:28 - 2020-06-09 20:29 - 000000000 ____D C:\Windows\System32\config\backup02
2020-06-09 20:27 - 2020-06-09 20:28 - 000000000 ____D C:\Windows\System32\config\backup01
2020-06-09 14:35 - 2020-06-09 14:35 - 000072337 _____ C:\Windows\System32\config\backup1
2020-06-09 14:35 - 2020-06-09 14:35 - 000000000 ____D C:\Windows\System32\config\backup1p
2020-06-09 14:33 - 2020-06-09 14:34 - 000000000 ____D C:\Windows\System32\config\backup
2020-06-09 14:23 - 2020-06-09 14:23 - 000032768 _____ C:\bcdbackup
2020-06-04 01:52 - 2020-06-04 01:53 - 000000000 ___HD C:\$SysReset
2020-05-28 09:56 - 2020-05-28 09:56 - 000053261 _____ C:\Users\jimena\Desktop\BLAISTEN Internet Payment Gateway.pdf
2020-05-25 11:25 - 2020-06-04 05:56 - 000000000 ____D C:\Windows\UpdateAssistant

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-08 19:50 - 2018-07-28 16:18 - 000000000 ____D C:\Windows\System32\SleepStudy
2020-06-08 19:50 - 2018-04-11 15:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-06-07 20:10 - 2018-04-11 15:30 - 000000000 ____D C:\Windows\CbsTemp
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ___HD C:\Program Files\WindowsApps
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\AppReadiness
2020-06-07 17:09 - 2018-07-28 19:18 - 001799978 _____ C:\Windows\System32\PerfStringBackup.INI
2020-06-07 17:09 - 2018-04-12 08:18 - 000804866 _____ C:\Windows\System32\perfh00A.dat
2020-06-07 17:09 - 2018-04-12 08:18 - 000160492 _____ C:\Windows\System32\perfc00A.dat
2020-06-07 17:09 - 2018-04-11 15:36 - 000000000 ____D C:\Windows\INF
2020-06-07 17:06 - 2016-05-20 07:06 - 000000000 __SHD C:\Users\jimena\IntelGraphicsProfiles
2020-06-07 17:05 - 2018-07-28 19:22 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-04 11:55 - 2018-02-13 09:33 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-04 05:57 - 2018-03-06 04:37 - 000000000 ____D C:\Windows\System32\Drivers\wd
2020-06-04 05:52 - 2018-07-28 19:07 - 000000000 ____D C:\users\jimena
2020-06-04 01:53 - 2018-02-05 16:04 - 000000000 _____ C:\Recovery.txt
2020-05-29 06:19 - 2018-07-28 19:22 - 000003358 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2505358239-225056662-2694394933-1001
2020-05-29 06:19 - 2016-05-20 07:16 - 000000000 ___RD C:\Users\jimena\OneDrive
2020-05-26 09:10 - 2020-05-08 11:55 - 000000000 ____D C:\Program Files\UNP
2020-05-25 14:25 - 2018-02-13 09:20 - 000000000 ___RD C:\Users\jimena\3D Objects
2020-05-25 14:25 - 2016-02-13 05:08 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-05-25 14:23 - 2018-07-28 16:18 - 000234176 _____ C:\Windows\System32\FNTCACHE.DAT
2020-05-25 14:21 - 2018-04-11 13:04 - 000524288 _____ C:\Windows\System32\config\BBI
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\TextInput
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\oobe
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\Dism
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\UNP
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\DiagSvcs
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Program Files\Windows Defender
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\SystemResetPlatform
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\oobe
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\appraiser
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellExperiences
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellComponents
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\Provisioning
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\bcastdvr
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-05-25 14:17 - 2018-04-11 13:04 - 000000000 ____D C:\Windows\System32\Dism
2020-05-25 14:13 - 2018-04-11 15:38 - 000017800 _____ C:\Windows\System32\OEMDefaultAssociations.xml
2020-05-25 11:35 - 2018-03-05 09:22 - 000000000 ____D C:\Windows\System32\MRT
2020-05-25 11:27 - 2018-03-05 09:21 - 120636720 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2020-05-25 11:13 - 2018-02-13 09:20 - 000000000 ____D C:\Users\jimena\AppData\Local\Packages

==================== KnownDLLs (Whitelisted) =========================


==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2020-05-08 17:07] - [2019-10-02 02:48] - 000678400 _____ (Microsoft Corporation) F1CB5F4E4B2804C4D9A401CCEFFD85CF

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2020-05-08 17:00] - [2019-10-02 02:34] - 004098912 _____ (Microsoft Corporation) EA043F4A77826199143350288DAD220C

C:\Windows\SysWOW64\explorer.exe
[2020-05-08 17:00] - [2019-10-02 01:22] - 003751824 _____ (Microsoft Corporation) 352E16B87A4F12E162BA357D9AD20A14

C:\Windows\System32\svchost.exe
[2019-02-13 13:24] - [2019-01-08 21:39] - 000085472 _____ (Microsoft Corporation) 0861726716C9610CE5F6BCF3F4858DA1

C:\Windows\SysWOW64\svchost.exe
[2019-02-13 13:23] - [2019-01-08 21:43] - 000071456 _____ (Microsoft Corporation) C01CB20D971C3262F1F856B4539DD27C

C:\Windows\System32\services.exe
[2020-05-08 17:06] - [2019-11-27 21:09] - 000636848 _____ (Microsoft Corporation) 1B285CE722E2D2F12481C4CE5E83CEA4

C:\Windows\System32\User32.dll
[2020-05-08 17:03] - [2020-01-07 01:54] - 001639864 _____ (Microsoft Corporation) D7369E33F2066DA033B2923B27AE5AAA

C:\Windows\SysWOW64\User32.dll
[2020-05-08 17:03] - [2020-01-07 00:15] - 001628496 _____ (Microsoft Corporation) AFDF4E5F0DE0606A16F65C4B9D0D89DE

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2020-05-08 17:09] - [2019-09-12 20:13] - 001154048 _____ (Microsoft Corporation) 09CD2CCFC59F1AD796C233DF9C074C38

C:\Windows\System32\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:19] - 000767232 _____ (Microsoft Corporation) 37C8D784EF2FFB9106CCA462ED6DB968

C:\Windows\SysWOW64\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:12] - 000573808 _____ (Microsoft Corporation) 3775EB86C55D2E03C4642E51DD53F740

C:\Windows\System32\dllhost.exe => MD5 is legit
C:\Windows\SysWOW64\dllhost.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============


==================== Restore Points  =========================

Restore point date: 2020-06-04 05:56
Restore point date: 2020-06-07 20:19

==================== Memory info =========================== 

Percentage of memory in use: 16%
Total physical RAM: 3981.89 MB
Available physical RAM: 3319.35 MB
Total Virtual: 3981.89 MB
Available Virtual: 3326.61 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:185.41 GB) (Free:62.23 GB) NTFS
Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.21 GB) NTFS
Drive f: (NO NAME) (Removable) (Total:3.65 GB) (Free:2.65 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS

\\?\Volume{ba0b1fe6-ff09-49e1-9d4e-ca9c1dc945d8}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.48 GB) NTFS
\\?\Volume{e7935b82-7559-45b2-b6dd-a0234758a351}\ () (Fixed) (Total:0.89 GB) (Free:0.45 GB) NTFS
\\?\Volume{a8d87fdf-5c62-44ca-a5a4-e6c3392f240b}\ (Restore) (Fixed) (Total:20.01 GB) (Free:8.12 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 57788C0B)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
==================== End of FRST.txt ========================

Hola @E_Chanes

Realiza nuevamente lo siguiente:

1.- En el equipo limpio:

Inicio >>> Ejecutar >>> Escribes notepad.exe.

Ahora copia y pega dentro del Notepad:

start::
HKLM\...\RunOnce: [*Restore] => C:\WINDOWS\system32\rstrui.exe [266752 2018-08-30] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2018-10-20] (Microsoft Corporation)
end::

Lo guardas bajo el nombre de fixlist.txt en la misma USB donde se encuentra frst.exe o frst64.exe <<< Esto es muy importante.

2.- En el equipo complicado:

Inicia nuevamente las opciones de Recuperación del Sistema hasta seleccionar Símbolo del Sistema. Para Windows 8.

  • Una vez dentro de la Ventana de Comandos escribe tal cual x:frst.exe o x:frst64.exe según el caso donde x debe ser reemplazada por la letra de Su unidad Usb.
  • Presionas Enter. Se abrirá la ventana del programa.
  • Presionas una sola vez el botón Fix y esperas a que termine.
  • Se guardara un reporte en su unidad Usb llamado Fixlog.txt que pegará en su próxima respuesta.
  • Cierre la ventana del programa si quedo abierta.
  • Cierras la consola, reinicias el equipo y ve si puedes ingresar en Modo Normal

Nos comentas.

Salu2

Hola Buen día y gracias por la atención.

Acá está el fixlog.

    Fix result of Farbar Recovery Scan Tool (x64) Version: 06-06-2020
Ran by SYSTEM (15-06-2020 14:02:07) Run:2
Running from E:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
HKLM\...\RunOnce: [*Restore] => C:\WINDOWS\system32\rstrui.exe [266752 2018-08-30] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2018-10-20] (Microsoft Corporation)

*****************

"HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\*Restore" => removed successfully
HKLM\...\Winlogon: [Userinit]  <==== ATTENTION => Could not restore
"HKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}" => not found

==== End of Fixlog 14:02:07 ====

Y volví a hacer un scan despues de esto

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-06-2020
Ran by SYSTEM on MININT-SMR8FA8 (15-06-2020 14:02:37)
Running from E:\
Platform: WIN_8 (X64) Language: Inglés (Estados Unidos)
Boot Mode: Recovery
ATTENTION: Could not load system hive.
La operaci�n se complet� correctamente.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKU\Default\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2018-10-20] (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-09 21:10 - 2020-06-15 14:02 - 000000000 ____D C:\FRST
2020-06-09 20:28 - 2020-06-09 20:29 - 000000000 ____D C:\Windows\System32\config\backup02
2020-06-09 20:27 - 2020-06-09 20:28 - 000000000 ____D C:\Windows\System32\config\backup01
2020-06-09 14:35 - 2020-06-09 14:35 - 000072337 _____ C:\Windows\System32\config\backup1
2020-06-09 14:35 - 2020-06-09 14:35 - 000000000 ____D C:\Windows\System32\config\backup1p
2020-06-09 14:33 - 2020-06-09 14:34 - 000000000 ____D C:\Windows\System32\config\backup
2020-06-09 14:23 - 2020-06-09 14:23 - 000032768 _____ C:\bcdbackup
2020-06-04 01:52 - 2020-06-04 01:53 - 000000000 ___HD C:\$SysReset
2020-05-28 09:56 - 2020-05-28 09:56 - 000053261 _____ C:\Users\jimena\Desktop\BLAISTEN Internet Payment Gateway.pdf
2020-05-25 11:25 - 2020-06-04 05:56 - 000000000 ____D C:\Windows\UpdateAssistant

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-08 19:50 - 2018-07-28 16:18 - 000000000 ____D C:\Windows\System32\SleepStudy
2020-06-08 19:50 - 2018-04-11 15:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-06-07 20:10 - 2018-04-11 15:30 - 000000000 ____D C:\Windows\CbsTemp
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ___HD C:\Program Files\WindowsApps
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\AppReadiness
2020-06-07 17:09 - 2018-07-28 19:18 - 001799978 _____ C:\Windows\System32\PerfStringBackup.INI
2020-06-07 17:09 - 2018-04-12 08:18 - 000804866 _____ C:\Windows\System32\perfh00A.dat
2020-06-07 17:09 - 2018-04-12 08:18 - 000160492 _____ C:\Windows\System32\perfc00A.dat
2020-06-07 17:09 - 2018-04-11 15:36 - 000000000 ____D C:\Windows\INF
2020-06-07 17:06 - 2016-05-20 07:06 - 000000000 __SHD C:\Users\jimena\IntelGraphicsProfiles
2020-06-07 17:05 - 2018-07-28 19:22 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-04 11:55 - 2018-02-13 09:33 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-04 05:57 - 2018-03-06 04:37 - 000000000 ____D C:\Windows\System32\Drivers\wd
2020-06-04 05:52 - 2018-07-28 19:07 - 000000000 ____D C:\users\jimena
2020-06-04 01:53 - 2018-02-05 16:04 - 000000000 _____ C:\Recovery.txt
2020-05-29 06:19 - 2018-07-28 19:22 - 000003358 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2505358239-225056662-2694394933-1001
2020-05-29 06:19 - 2016-05-20 07:16 - 000000000 ___RD C:\Users\jimena\OneDrive
2020-05-26 09:10 - 2020-05-08 11:55 - 000000000 ____D C:\Program Files\UNP
2020-05-25 14:25 - 2018-02-13 09:20 - 000000000 ___RD C:\Users\jimena\3D Objects
2020-05-25 14:25 - 2016-02-13 05:08 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-05-25 14:23 - 2018-07-28 16:18 - 000234176 _____ C:\Windows\System32\FNTCACHE.DAT
2020-05-25 14:21 - 2018-04-11 13:04 - 000524288 _____ C:\Windows\System32\config\BBI
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\TextInput
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\oobe
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\Dism
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\UNP
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\DiagSvcs
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Program Files\Windows Defender
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\SystemResetPlatform
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\oobe
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\appraiser
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellExperiences
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellComponents
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\Provisioning
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\bcastdvr
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-05-25 14:17 - 2018-04-11 13:04 - 000000000 ____D C:\Windows\System32\Dism
2020-05-25 14:13 - 2018-04-11 15:38 - 000017800 _____ C:\Windows\System32\OEMDefaultAssociations.xml
2020-05-25 11:35 - 2018-03-05 09:22 - 000000000 ____D C:\Windows\System32\MRT
2020-05-25 11:27 - 2018-03-05 09:21 - 120636720 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2020-05-25 11:13 - 2018-02-13 09:20 - 000000000 ____D C:\Users\jimena\AppData\Local\Packages

==================== KnownDLLs (Whitelisted) =========================


==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2020-05-08 17:07] - [2019-10-02 02:48] - 000678400 _____ (Microsoft Corporation) F1CB5F4E4B2804C4D9A401CCEFFD85CF

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2020-05-08 17:00] - [2019-10-02 02:34] - 004098912 _____ (Microsoft Corporation) EA043F4A77826199143350288DAD220C

C:\Windows\SysWOW64\explorer.exe
[2020-05-08 17:00] - [2019-10-02 01:22] - 003751824 _____ (Microsoft Corporation) 352E16B87A4F12E162BA357D9AD20A14

C:\Windows\System32\svchost.exe
[2019-02-13 13:24] - [2019-01-08 21:39] - 000085472 _____ (Microsoft Corporation) 0861726716C9610CE5F6BCF3F4858DA1

C:\Windows\SysWOW64\svchost.exe
[2019-02-13 13:23] - [2019-01-08 21:43] - 000071456 _____ (Microsoft Corporation) C01CB20D971C3262F1F856B4539DD27C

C:\Windows\System32\services.exe
[2020-05-08 17:06] - [2019-11-27 21:09] - 000636848 _____ (Microsoft Corporation) 1B285CE722E2D2F12481C4CE5E83CEA4

C:\Windows\System32\User32.dll
[2020-05-08 17:03] - [2020-01-07 01:54] - 001639864 _____ (Microsoft Corporation) D7369E33F2066DA033B2923B27AE5AAA

C:\Windows\SysWOW64\User32.dll
[2020-05-08 17:03] - [2020-01-07 00:15] - 001628496 _____ (Microsoft Corporation) AFDF4E5F0DE0606A16F65C4B9D0D89DE

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2020-05-08 17:09] - [2019-09-12 20:13] - 001154048 _____ (Microsoft Corporation) 09CD2CCFC59F1AD796C233DF9C074C38

C:\Windows\System32\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:19] - 000767232 _____ (Microsoft Corporation) 37C8D784EF2FFB9106CCA462ED6DB968

C:\Windows\SysWOW64\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:12] - 000573808 _____ (Microsoft Corporation) 3775EB86C55D2E03C4642E51DD53F740

C:\Windows\System32\dllhost.exe => MD5 is legit
C:\Windows\SysWOW64\dllhost.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============


==================== Restore Points  =========================

Restore point date: 2020-06-04 05:56
Restore point date: 2020-06-07 20:19

==================== Memory info =========================== 

Percentage of memory in use: 16%
Total physical RAM: 3981.89 MB
Available physical RAM: 3319.13 MB
Total Virtual: 3981.89 MB
Available Virtual: 3326.18 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:185.41 GB) (Free:62.23 GB) NTFS
Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.21 GB) NTFS
Drive e: (NO NAME) (Removable) (Total:3.65 GB) (Free:2.65 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS

\\?\Volume{ba0b1fe6-ff09-49e1-9d4e-ca9c1dc945d8}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.48 GB) NTFS
\\?\Volume{e7935b82-7559-45b2-b6dd-a0234758a351}\ () (Fixed) (Total:0.89 GB) (Free:0.45 GB) NTFS
\\?\Volume{a8d87fdf-5c62-44ca-a5a4-e6c3392f240b}\ (Restore) (Fixed) (Total:20.01 GB) (Free:8.12 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 57788C0B)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
==================== End of FRST.txt ========================

Hola @E_Chanes

Gracias por adelantarte entendí que no reinicio… :fearful:

Vamos a ir en dos pasos:

Paso 1:

Hasta aquí lo que ya as hecho pero cambia el FIX:

Realiza nuevamente lo siguiente:

1.- En el equipo limpio:

Inicio >>> Ejecutar >>> Escribes notepad.exe.

Ahora copia y pega dentro del Notepad:

start::
Folder: C:\Windows\System32\config
CMD: bootrec.exe /fixmbr
CMD: bootrec.exe /fixboot
end::

Lo guardas bajo el nombre de fixlist.txt en la misma USB donde se encuentra frst.exe o frst64.exe <<< Esto es muy importante.

2.- En el equipo complicado:

Inicia nuevamente las opciones de Recuperación del Sistema hasta seleccionar Símbolo del Sistema. Para Windows 8.

  • Una vez dentro de la Ventana de Comandos escribe tal cual x:frst.exe o x:frst64.exe según el caso donde x debe ser reemplazada por la letra de Su unidad Usb.
  • Presionas Enter. Se abrirá la ventana del programa.
  • Presionas una sola vez el botón Fix y esperas a que termine.
  • Se guardara un reporte en su unidad Usb llamado Fixlog.txt que pegará en su próxima respuesta.

NO cierres la ventana del programa.

Paso 2:

En Search/Buscar escribes tal cual:

  • winlogon.exe; explorer.exe; svchost.exe; services.exe; User32.dll; rpcss.dll; dnsapi.dll

Nota: ten en cuenta que cada nombre de archivo esta separado por un punto y coma y un espacio. El analisis puede demorar.

buscar

Presionas en el botón Buscar Archivos/Search File.

  • Al finalizar se abrirá un archivo llamado Search.txt que quedará grabado también en tu Unidad Usb.

Cierras la ventana del programa y de CMD, reinicias y prueba entrar en Modo Normal

Por tu seguridad, imprime los pasos.

Nos traes ambos reportes.

Salu2

Hola @SanMar Acá ambos reportes

Aún no inicia :frowning:

Farbar Recovery Scan Tool (x64) Version: 06-06-2020
Ran by SYSTEM (16-06-2020 02:19:44)
Running from E:\
Boot Mode: Recovery

================== Search Files: "winlogon.exe; explorer.exe; svhost.exe; services.exe; User32.dll; rpcss.dll; dnsapi.dll" =============

C:\Windows\explorer.exe
[2020-05-08 17:00][2019-10-02 02:34] 004098912 _____ (Microsoft Corporation) EA043F4A77826199143350288DAD220C

C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.17134.376_none_b917f9b8f7e76970\user32.dll
[2018-11-13 12:14][2018-10-21 03:37] 001626656 _____ (Microsoft Corporation) 80C661ABE79DE151456280D27FA83243

C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.17134.1_none_bd0da2eb0ae7a717\user32.dll
[2018-04-11 15:34][2018-04-11 15:34] 001626536 _____ (Microsoft Corporation) B9DFDDCD276872A0A71A3A6081FE3019

C:\Windows\WinSxS\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.17134.1246_none_920a284143ead3eb\user32.dll
[2020-05-08 17:03][2020-01-07 00:15] 001628496 _____ (Microsoft Corporation) AFDF4E5F0DE0606A16F65C4B9D0D89DE

C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.17134.1_none_4189ddbc174796a4\explorer.exe
[2018-04-11 15:35][2018-04-11 15:35] 003611360 _____ (Microsoft Corporation) 166AB1B9462E5C1D6D18EC5EC0B6A5F7

C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.17134.165_none_3d9e006004402967\explorer.exe
[2018-08-07 11:25][2018-07-06 04:06] 003611368 _____ (Microsoft Corporation) 499B0D1F6277F17B3BAC525B8717C064

C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.17134.1098_none_16a0d6cc50363d8b\explorer.exe
[2020-05-08 17:00][2019-10-02 01:22] 003751824 _____ (Microsoft Corporation) 352E16B87A4F12E162BA357D9AD20A14

C:\Windows\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.17134.915_none_81ab2bd9ad80b211\dnsapi.dll
[2020-05-08 17:03][2019-07-08 19:12] 000573808 _____ (Microsoft Corporation) 3775EB86C55D2E03C4642E51DD53F740

C:\Windows\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.17134.441_none_8186b16fad9caec5\dnsapi.dll
[2018-12-12 12:37][2018-11-08 17:46] 000573504 _____ (Microsoft Corporation) B668D6FD24465E11155B47808553DA61

C:\Windows\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.17134.1_none_8560ea69c0b0c1cb\dnsapi.dll
[2018-04-11 15:34][2018-04-11 15:34] 000573392 _____ (Microsoft Corporation) E393B53837F6778C8FE0B27B58478B37

C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.17134.320_none_517df21c2af88079\winlogon.exe
[2018-10-31 15:26][2018-09-07 23:40] 000677888 _____ (Microsoft Corporation) 749CA1F1B638E4E4A8A1F0990377012F

C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.17134.1_none_55438d6e3e1be1df\winlogon.exe
[2018-04-11 15:34][2018-04-11 15:34] 000677376 _____ (Microsoft Corporation) F9017F2DC455AD373DF036F5817A8870

C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.17134.1067_none_2a579c68770d2320\winlogon.exe
[2020-05-08 17:07][2019-10-02 02:48] 000678400 _____ (Microsoft Corporation) F1CB5F4E4B2804C4D9A401CCEFFD85CF

C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.17134.376_none_aec34f66c386a775\user32.dll
[2018-11-13 12:14][2018-10-21 05:00] 001639560 _____ (Microsoft Corporation) CEC499E17074BEF1CF32BB0AF742F2D2

C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.17134.1_none_b2b8f898d686e51c\user32.dll
[2018-04-11 15:34][2018-04-11 15:34] 001639448 _____ (Microsoft Corporation) 1B795B9EC9E0EAADC5B37006BBE44646

C:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.17134.1246_none_87b57def0f8a11f0\user32.dll
[2020-05-08 17:03][2020-01-07 01:54] 001639864 _____ (Microsoft Corporation) D7369E33F2066DA033B2923B27AE5AAA

C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_10.0.17134.1_none_249951c665cda55f\services.exe
[2018-04-11 15:34][2018-04-11 15:34] 000636944 _____ (Microsoft Corporation) E2F4C75AFA20E742DE1B70372F15DCD7

C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_10.0.17134.191_none_2089037e52e22699\services.exe
[2018-08-15 18:25][2018-07-13 20:19] 000636944 _____ (Microsoft Corporation) 2FC61B2CF84792516D543CA94139A92C

C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_10.0.17134.1184_none_f9a4d5c09ec4e85c\services.exe
[2020-05-08 17:06][2019-11-27 21:09] 000636848 _____ (Microsoft Corporation) 1B285CE722E2D2F12481C4CE5E83CEA4

C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.17134.1_none_37353369e2e6d4a9\explorer.exe
[2018-04-11 15:34][2018-04-11 15:34] 003933184 _____ (Microsoft Corporation) AD5296B280E8F522A8A897C96BAB0E1D

C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.17134.165_none_3349560dcfdf676c\explorer.exe
[2018-08-07 11:25][2018-07-06 06:17] 003932672 _____ (Microsoft Corporation) E4A81EDDFF8B844D85C8B45354E4144E

C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.17134.1098_none_0c4c2c7a1bd57b90\explorer.exe
[2020-05-08 17:00][2019-10-02 02:34] 004098912 _____ (Microsoft Corporation) EA043F4A77826199143350288DAD220C

C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.17134.915_none_77568187791ff016\dnsapi.dll
[2020-05-08 17:03][2019-07-08 19:19] 000767232 _____ (Microsoft Corporation) 37C8D784EF2FFB9106CCA462ED6DB968

C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.17134.441_none_7732071d793becca\dnsapi.dll
[2018-12-12 12:37][2018-11-08 18:48] 000766704 _____ (Microsoft Corporation) 86FE93AFDD8B2BCD389E30839A652181

C:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.17134.1_none_7b0c40178c4fffd0\dnsapi.dll
[2018-04-11 15:34][2018-04-11 15:34] 000766608 _____ (Microsoft Corporation) 912DDBEC210B4B47941319BF991CFD98

C:\Windows\WinSxS\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_10.0.17134.523_none_4b88d1ab93e44913\rpcss.dll
[2019-01-16 10:29][2018-12-31 22:41] 001159680 _____ (Microsoft Corporation) 2383579559B1EB66C4FA2297119CEDD0

C:\Windows\WinSxS\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_10.0.17134.1_none_4f4b6853a70a6426\rpcss.dll
[2018-04-11 15:34][2018-04-11 15:34] 001159168 _____ (Microsoft Corporation) 1914D0E999F9F63E96980F1D0F504737

C:\Windows\WinSxS\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_10.0.17134.1038_none_245c5fa7dffe7303\rpcss.dll
[2020-05-08 17:09][2019-09-12 20:13] 001154048 _____ (Microsoft Corporation) 09CD2CCFC59F1AD796C233DF9C074C38

C:\Windows\SysWOW64\dnsapi.dll
[2020-05-08 17:03][2019-07-08 19:12] 000573808 _____ (Microsoft Corporation) 3775EB86C55D2E03C4642E51DD53F740

C:\Windows\SysWOW64\explorer.exe
[2020-05-08 17:00][2019-10-02 01:22] 003751824 _____ (Microsoft Corporation) 352E16B87A4F12E162BA357D9AD20A14

C:\Windows\SysWOW64\user32.dll
[2020-05-08 17:03][2020-01-07 00:15] 001628496 _____ (Microsoft Corporation) AFDF4E5F0DE0606A16F65C4B9D0D89DE

C:\Windows\System32\dnsapi.dll
[2020-05-08 17:03][2019-07-08 19:19] 000767232 _____ (Microsoft Corporation) 37C8D784EF2FFB9106CCA462ED6DB968

C:\Windows\System32\rpcss.dll
[2020-05-08 17:09][2019-09-12 20:13] 001154048 _____ (Microsoft Corporation) 09CD2CCFC59F1AD796C233DF9C074C38

C:\Windows\System32\services.exe
[2020-05-08 17:06][2019-11-27 21:09] 000636848 _____ (Microsoft Corporation) 1B285CE722E2D2F12481C4CE5E83CEA4

C:\Windows\System32\user32.dll
[2020-05-08 17:03][2020-01-07 01:54] 001639864 _____ (Microsoft Corporation) D7369E33F2066DA033B2923B27AE5AAA

C:\Windows\System32\winlogon.exe
[2020-05-08 17:07][2019-10-02 02:48] 000678400 _____ (Microsoft Corporation) F1CB5F4E4B2804C4D9A401CCEFFD85CF

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-WOW64-Package~~amd64~~10.0.18362.1\wow64_microsoft-windows-user32_31bf3856ad364e35_10.0.18362.1_none_a9ea868f1ef5b00d\user32.dll
[2020-05-08 13:45][2019-03-18 17:24] 001661552 _____ (Microsoft Corporation) 5AA0F4573AB4E6B12E0542A23857E1EE

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-WOW64-Package~~amd64~~10.0.18362.1\wow64_microsoft-windows-explorer_31bf3856ad364e35_10.0.18362.1_none_2e66c1602b559f9a\explorer.exe
[2020-05-08 13:44][2019-03-18 17:23] 003916048 _____ (Microsoft Corporation) E7DF2EB06967000D3E72598D8FECEE83

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-WOW64-Package~~amd64~~10.0.18362.1\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.18362.1_none_723dce0dd4becac1\dnsapi.dll
[0][0] 000000000 _____ () 

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-Package~~amd64~~10.0.18362.1\amd64_microsoft-windows-winlogon_31bf3856ad364e35_10.0.18362.1_none_422071125229ead5\winlogon.exe
[2020-05-08 13:42][2019-03-18 18:18] 000844800 _____ (Microsoft Corporation) 0DAE4B9FB1E2043C18B7A7E7CBA5964B

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-Package~~amd64~~10.0.18362.1\amd64_microsoft-windows-user32_31bf3856ad364e35_10.0.18362.1_none_9f95dc3cea94ee12\user32.dll
[2020-05-08 13:41][2019-03-18 18:31] 001654544 _____ (Microsoft Corporation) 44F5E9206813B92918F5BB5F42F8E5D0

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-Package~~amd64~~10.0.18362.1\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_10.0.18362.1_none_1176356a79dbae55\services.exe
[0][0] 000000000 _____ () 

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-Package~~amd64~~10.0.18362.1\amd64_microsoft-windows-explorer_31bf3856ad364e35_10.0.18362.1_none_2412170df6f4dd9f\explorer.exe
[2020-05-08 13:37][2019-03-18 18:33] 004554160 _____ (Microsoft Corporation) 9FBBF189473A313776019D2EAA72A47A

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-Package~~amd64~~10.0.18362.1\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.18362.1_none_67e923bba05e08c6\dnsapi.dll
[2020-05-08 13:36][2019-03-18 14:46] 000818888 _____ (Microsoft Corporation) 2B1627A5E6EFAA1C100A1CD87E37F7DA

C:\Windows\SoftwareDistribution\Download\6bc1b596af179e5b7ebcef1a64e8e4d7\amd64_Microsoft-Windows-Client-Desktop-Required-Package~~amd64~~10.0.18362.1\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_10.0.18362.1_none_3c284bf7bb186d1c\rpcss.dll
[2020-05-08 13:40][2019-03-18 14:04] 001261568 _____ (Microsoft Corporation) 34EA1A04B3D62138CFD3ABD866AB589A

X:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2012-07-25 22:12][2012-07-25 22:12] 000516608 _____ (Microsoft Corporation) 93AB226C07A9789B2EC7B41F73602F76

X:\Windows\WinSxS\amd64_microsoft-windows-user32_31bf3856ad364e35_6.2.9200.16384_none_260213a5f720b529\user32.dll
[2012-07-25 22:12][2012-07-25 22:12] 001342464 _____ (Microsoft Corporation) 1D08594400EE1B500B93256795FE30AE

X:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
[2012-07-25 21:26][2012-07-25 21:26] 000410624 _____ (Microsoft Corporation) 754A2CC1F32107EA87CBD305ABE3E618

X:\Windows\WinSxS\amd64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_6.2.9200.16384_none_ee555b24ace9cfdd\dnsapi.dll
[2012-07-25 22:12][2012-07-25 22:12] 000604672 _____ (Microsoft Corporation) 4D10F9BB8243BCBF39774BF4D6B0D108

X:\Windows\WinSxS\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.2.9200.16384_none_c2948360c7a43433\rpcss.dll
[2012-07-25 22:12][2012-07-25 22:12] 000817152 _____ (Microsoft Corporation) 1EC6E533C954BDDF2A37E7851A7E58FD

X:\Windows\System32\dnsapi.dll
[2012-07-25 22:12][2012-07-25 22:12] 000604672 _____ (Microsoft Corporation) 4D10F9BB8243BCBF39774BF4D6B0D108

X:\Windows\System32\rpcss.dll
[2012-07-25 22:12][2012-07-25 22:12] 000817152 _____ (Microsoft Corporation) 1EC6E533C954BDDF2A37E7851A7E58FD

X:\Windows\System32\services.exe
[2012-07-25 21:26][2012-07-25 21:26] 000410624 _____ (Microsoft Corporation) 754A2CC1F32107EA87CBD305ABE3E618

X:\Windows\System32\user32.dll
[2012-07-25 22:12][2012-07-25 22:12] 001342464 _____ (Microsoft Corporation) 1D08594400EE1B500B93256795FE30AE

X:\Windows\System32\winlogon.exe
[2012-07-25 22:12][2012-07-25 22:12] 000516608 _____ (Microsoft Corporation) 93AB226C07A9789B2EC7B41F73602F76


====== End of Search ====== 

acá el sigioente

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06-06-2020
Ran by SYSTEM on MININT-GJ4NGMB (16-06-2020 02:30:22)
Running from E:\
Platform: WIN_8 (X64) Language: Inglés (Estados Unidos)
Boot Mode: Recovery
ATTENTION: Could not load system hive.
La operaci�n se complet� correctamente.

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Winlogon: [Userinit]  <==== ATTENTION
HKU\Default\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{89820200-ECBD-11cf-8B85-00AA005B4340}] -> regsvr32.exe /s /n /i:U %SystemRoot%\System32\shell32.dll
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll [2018-10-20] (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-09 21:10 - 2020-06-16 02:30 - 000000000 ____D C:\FRST
2020-06-09 20:28 - 2020-06-09 20:29 - 000000000 ____D C:\Windows\System32\config\backup02
2020-06-09 20:27 - 2020-06-09 20:28 - 000000000 ____D C:\Windows\System32\config\backup01
2020-06-09 14:35 - 2020-06-09 14:35 - 000072337 _____ C:\Windows\System32\config\backup1
2020-06-09 14:35 - 2020-06-09 14:35 - 000000000 ____D C:\Windows\System32\config\backup1p
2020-06-09 14:33 - 2020-06-09 14:34 - 000000000 ____D C:\Windows\System32\config\backup
2020-06-09 14:23 - 2020-06-09 14:23 - 000032768 _____ C:\bcdbackup
2020-06-04 01:52 - 2020-06-04 01:53 - 000000000 ___HD C:\$SysReset
2020-05-28 09:56 - 2020-05-28 09:56 - 000053261 _____ C:\Users\jimena\Desktop\BLAISTEN Internet Payment Gateway.pdf
2020-05-25 11:25 - 2020-06-04 05:56 - 000000000 ____D C:\Windows\UpdateAssistant

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-06-08 19:50 - 2018-07-28 16:18 - 000000000 ____D C:\Windows\System32\SleepStudy
2020-06-08 19:50 - 2018-04-11 15:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-06-07 20:10 - 2018-04-11 15:30 - 000000000 ____D C:\Windows\CbsTemp
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ___HD C:\Program Files\WindowsApps
2020-06-07 19:25 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\AppReadiness
2020-06-07 17:09 - 2018-07-28 19:18 - 001799978 _____ C:\Windows\System32\PerfStringBackup.INI
2020-06-07 17:09 - 2018-04-12 08:18 - 000804866 _____ C:\Windows\System32\perfh00A.dat
2020-06-07 17:09 - 2018-04-12 08:18 - 000160492 _____ C:\Windows\System32\perfc00A.dat
2020-06-07 17:09 - 2018-04-11 15:36 - 000000000 ____D C:\Windows\INF
2020-06-07 17:06 - 2016-05-20 07:06 - 000000000 __SHD C:\Users\jimena\IntelGraphicsProfiles
2020-06-07 17:05 - 2018-07-28 19:22 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2020-06-04 11:55 - 2018-02-13 09:33 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-06-04 05:57 - 2018-03-06 04:37 - 000000000 ____D C:\Windows\System32\Drivers\wd
2020-06-04 05:52 - 2018-07-28 19:07 - 000000000 ____D C:\users\jimena
2020-06-04 01:53 - 2018-02-05 16:04 - 000000000 _____ C:\Recovery.txt
2020-05-29 06:19 - 2018-07-28 19:22 - 000003358 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2505358239-225056662-2694394933-1001
2020-05-29 06:19 - 2016-05-20 07:16 - 000000000 ___RD C:\Users\jimena\OneDrive
2020-05-26 09:10 - 2020-05-08 11:55 - 000000000 ____D C:\Program Files\UNP
2020-05-25 14:25 - 2018-02-13 09:20 - 000000000 ___RD C:\Users\jimena\3D Objects
2020-05-25 14:25 - 2016-02-13 05:08 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-05-25 14:23 - 2018-07-28 16:18 - 000234176 _____ C:\Windows\System32\FNTCACHE.DAT
2020-05-25 14:21 - 2018-04-11 13:04 - 000524288 _____ C:\Windows\System32\config\BBI
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\TextInput
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\oobe
2020-05-25 14:18 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\SysWOW64\Dism
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\UNP
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___SD C:\Windows\System32\DiagSvcs
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Windows\ImmersiveControlPanel
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ___RD C:\Program Files\Windows Defender
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\SystemResetPlatform
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\oobe
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\System32\appraiser
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellExperiences
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\ShellComponents
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\Provisioning
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\PolicyDefinitions
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Windows\bcastdvr
2020-05-25 14:17 - 2018-04-11 15:38 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2020-05-25 14:17 - 2018-04-11 13:04 - 000000000 ____D C:\Windows\System32\Dism
2020-05-25 14:13 - 2018-04-11 15:38 - 000017800 _____ C:\Windows\System32\OEMDefaultAssociations.xml
2020-05-25 11:35 - 2018-03-05 09:22 - 000000000 ____D C:\Windows\System32\MRT
2020-05-25 11:27 - 2018-03-05 09:21 - 120636720 ____C (Microsoft Corporation) C:\Windows\System32\MRT.exe
2020-05-25 11:13 - 2018-02-13 09:20 - 000000000 ____D C:\Users\jimena\AppData\Local\Packages

==================== KnownDLLs (Whitelisted) =========================


==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe
[2020-05-08 17:07] - [2019-10-02 02:48] - 000678400 _____ (Microsoft Corporation) F1CB5F4E4B2804C4D9A401CCEFFD85CF

C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2020-05-08 17:00] - [2019-10-02 02:34] - 004098912 _____ (Microsoft Corporation) EA043F4A77826199143350288DAD220C

C:\Windows\SysWOW64\explorer.exe
[2020-05-08 17:00] - [2019-10-02 01:22] - 003751824 _____ (Microsoft Corporation) 352E16B87A4F12E162BA357D9AD20A14

C:\Windows\System32\svchost.exe
[2019-02-13 13:24] - [2019-01-08 21:39] - 000085472 _____ (Microsoft Corporation) 0861726716C9610CE5F6BCF3F4858DA1

C:\Windows\SysWOW64\svchost.exe
[2019-02-13 13:23] - [2019-01-08 21:43] - 000071456 _____ (Microsoft Corporation) C01CB20D971C3262F1F856B4539DD27C

C:\Windows\System32\services.exe
[2020-05-08 17:06] - [2019-11-27 21:09] - 000636848 _____ (Microsoft Corporation) 1B285CE722E2D2F12481C4CE5E83CEA4

C:\Windows\System32\User32.dll
[2020-05-08 17:03] - [2020-01-07 01:54] - 001639864 _____ (Microsoft Corporation) D7369E33F2066DA033B2923B27AE5AAA

C:\Windows\SysWOW64\User32.dll
[2020-05-08 17:03] - [2020-01-07 00:15] - 001628496 _____ (Microsoft Corporation) AFDF4E5F0DE0606A16F65C4B9D0D89DE

C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2020-05-08 17:09] - [2019-09-12 20:13] - 001154048 _____ (Microsoft Corporation) 09CD2CCFC59F1AD796C233DF9C074C38

C:\Windows\System32\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:19] - 000767232 _____ (Microsoft Corporation) 37C8D784EF2FFB9106CCA462ED6DB968

C:\Windows\SysWOW64\dnsapi.dll
[2020-05-08 17:03] - [2019-07-08 19:12] - 000573808 _____ (Microsoft Corporation) 3775EB86C55D2E03C4642E51DD53F740

C:\Windows\System32\dllhost.exe => MD5 is legit
C:\Windows\SysWOW64\dllhost.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Association (Whitelisted) =============


==================== Restore Points  =========================

Restore point date: 2020-06-04 05:56
Restore point date: 2020-06-07 20:19

==================== Memory info =========================== 

Percentage of memory in use: 20%
Total physical RAM: 3981.89 MB
Available physical RAM: 3161.87 MB
Total Virtual: 3981.89 MB
Available Virtual: 3263.68 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:185.41 GB) (Free:62.23 GB) NTFS
Drive d: (Data) (Fixed) (Total:258.34 GB) (Free:258.21 GB) NTFS
Drive e: (NO NAME) (Removable) (Total:3.65 GB) (Free:2.65 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.02 GB) NTFS

\\?\Volume{ba0b1fe6-ff09-49e1-9d4e-ca9c1dc945d8}\ (Recovery) (Fixed) (Total:0.88 GB) (Free:0.48 GB) NTFS
\\?\Volume{e7935b82-7559-45b2-b6dd-a0234758a351}\ () (Fixed) (Total:0.89 GB) (Free:0.45 GB) NTFS
\\?\Volume{a8d87fdf-5c62-44ca-a5a4-e6c3392f240b}\ (Restore) (Fixed) (Total:20.01 GB) (Free:8.12 GB) NTFS

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 57788C0B)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
==================== End of FRST.txt ========================

Hola @E_Chanes

Para que no haya errores borra los Fixlist anteriores del USB.

Realiza nuevamente lo siguiente:

1.- En el equipo limpio:

Inicio >>> Ejecutar >>> Escribes notepad.exe.

Ahora copia y pega dentro del Notepad:

start::
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll
C:\Windows\SysWOW64\scecli.dll
Folder: C:\Windows\System32\config\backup02
Folder: C:\Windows\System32\config\backup01
Folder: C:\Windows\System32\config\backup1
Folder: C:\Windows\System32\config\backup1p
Folder: C:\Windows\System32\config\backup
CMD: bootrec.exe /fixmbr
CMD: bootrec.exe /fixboot
end::

Lo guardas bajo el nombre de fixlist.txt en la misma USB donde se encuentra frst.exe o frst64.exe <<< Esto es muy importante.

2.- En el equipo complicado:

Inicia nuevamente las opciones de Recuperación del Sistema hasta seleccionar Símbolo del Sistema. Para Windows 8.

  • Una vez dentro de la Ventana de Comandos escribe tal cual x:frst.exe o x:frst64.exe según el caso donde x debe ser reemplazada por la letra de Su unidad Usb.
  • Presionas Enter. Se abrirá la ventana del programa.
  • Presionas una sola vez el botón Fix y esperas a que termine.
  • Se guardara un reporte en su unidad Usb llamado Fixlog.txt que pegará en su próxima respuesta.
  • Cierre la ventana del programa si quedo abierta.
  • Cierras la consola, reinicias el equipo y ve si puedes ingresar en Modo Normal

Si no arranca debemos ir pensando en reinstalar el SO, dime tienen archivos que necesitan recuperar?

Han decidido si vas a reinstalar un Windows 8/8.1 o si quieres ir directamente a un Windows 10 (creo que esto seria lo mejor para el equipo), recuerdas cuanta Ram tiene?

Salu2

Hola @SanMar disculpa la tardanza, fue un fin de semana algo ocupado.

recién realicé el ultipo proceso que aconsejaste, la computadora continúa en el loop Te comparto el último reporte

Fix result of Farbar Recovery Scan Tool (x64) Version: 06-06-2020
Ran by SYSTEM (22-06-2020 12:48:18) Run:3
Running from F:\
Boot Mode: Recovery
==============================================

fixlist content:
*****************
HKLM\Software\...\Winlogon\GPExtensions: [{827D319E-6EAC-11D2-A4EA-00C04F79F83A}] -> C:\Windows\SysWOW64\scecli.dll
C:\Windows\SysWOW64\scecli.dll
Folder: C:\Windows\System32\config\backup02
Folder: C:\Windows\System32\config\backup01
Folder: C:\Windows\System32\config\backup1
Folder: C:\Windows\System32\config\backup1p
Folder: C:\Windows\System32\config\backup
CMD: bootrec.exe /fixmbr
CMD: bootrec.exe /fixboot

*****************

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}" => not found
C:\Windows\SysWOW64\scecli.dll => moved successfully

========================= Folder: C:\Windows\System32\config\backup02 ========================

2020-06-09 20:29 - 2020-06-09 14:35 - 000072337 ____A [EB92E561CAD7E648413E313222B0C82D] () C:\Windows\System32\config\backup02\backup1
2020-06-09 20:29 - 2020-05-25 14:21 - 000524288 ____A [2F8297866DCB1ED98100A7BC2DF41919] () C:\Windows\System32\config\backup02\BBI
2020-06-09 20:29 - 2018-07-28 12:17 - 000028672 ____A [3987130357A084D5BE7FBC367EF39DA2] () C:\Windows\System32\config\backup02\BCD-Template
2020-06-09 20:29 - 2020-06-07 20:12 - 078643200 ____A [D252EBD7007744FCB4BD5C70D0F69D71] () C:\Windows\System32\config\backup02\COMPONENTS
2020-06-09 20:29 - 2020-05-25 14:21 - 000786432 ____A [3E6D6252C41C4A6E012EF6DD850274E0] () C:\Windows\System32\config\backup02\DEFAULT
2020-06-09 20:29 - 2020-06-04 05:54 - 005505024 ____A [51F321F7FBD79CF42E3C2326701A14D6] () C:\Windows\System32\config\backup02\DRIVERS
2020-06-09 20:29 - 2020-05-08 14:39 - 000032768 ____A [20255C2075D952EC3552F48FED44C9E0] () C:\Windows\System32\config\backup02\ELAM
2020-06-09 20:29 - 2020-05-25 14:21 - 000057344 ____A [5B3D7C59A69F5DC66DAD02F011C3C3C2] () C:\Windows\System32\config\backup02\SAM
2020-06-09 20:29 - 2020-05-25 14:21 - 000057344 ____A [6A254EF4BFE79230C6D5B9A6C8AB8F53] () C:\Windows\System32\config\backup02\SECURITY
2020-06-09 20:29 - 2020-06-04 02:14 - 082837504 ____A [7AF6BC4C96CE078DE824DF3428BB4F24] () C:\Windows\System32\config\backup02\software
2020-06-09 20:29 - 2020-06-04 02:14 - 015990784 ____A [B66C85C28870DA049FE4FBABC0D683BE] () C:\Windows\System32\config\backup02\system
2020-06-09 20:29 - 2018-07-28 12:12 - 000008192 ____A [3BB53F59F1DE4574AC493EFB24192025] () C:\Windows\System32\config\backup02\userdiff

====== End of Folder: ======


========================= Folder: C:\Windows\System32\config\backup01 ========================

2020-06-09 20:28 - 2020-06-09 14:35 - 000072337 ____A [EB92E561CAD7E648413E313222B0C82D] () C:\Windows\System32\config\backup01\backup1
2020-06-09 20:28 - 2020-05-25 14:21 - 000524288 ____A [2F8297866DCB1ED98100A7BC2DF41919] () C:\Windows\System32\config\backup01\BBI
2020-06-09 20:28 - 2018-07-28 12:17 - 000028672 ____A [3987130357A084D5BE7FBC367EF39DA2] () C:\Windows\System32\config\backup01\BCD-Template
2020-06-09 20:28 - 2020-06-07 20:12 - 078643200 ____A [D252EBD7007744FCB4BD5C70D0F69D71] () C:\Windows\System32\config\backup01\COMPONENTS
2020-06-09 20:28 - 2020-05-25 14:21 - 000786432 ____A [3E6D6252C41C4A6E012EF6DD850274E0] () C:\Windows\System32\config\backup01\DEFAULT
2020-06-09 20:28 - 2020-06-04 05:54 - 005505024 ____A [51F321F7FBD79CF42E3C2326701A14D6] () C:\Windows\System32\config\backup01\DRIVERS
2020-06-09 20:28 - 2020-05-08 14:39 - 000032768 ____A [20255C2075D952EC3552F48FED44C9E0] () C:\Windows\System32\config\backup01\ELAM
2020-06-09 20:28 - 2020-05-25 14:21 - 000057344 ____A [5B3D7C59A69F5DC66DAD02F011C3C3C2] () C:\Windows\System32\config\backup01\SAM
2020-06-09 20:28 - 2020-05-25 14:21 - 000057344 ____A [6A254EF4BFE79230C6D5B9A6C8AB8F53] () C:\Windows\System32\config\backup01\SECURITY
2020-06-09 20:28 - 2020-06-04 02:14 - 082837504 ____A [7AF6BC4C96CE078DE824DF3428BB4F24] () C:\Windows\System32\config\backup01\software
2020-06-09 20:28 - 2020-06-04 02:14 - 015990784 ____A [B66C85C28870DA049FE4FBABC0D683BE] () C:\Windows\System32\config\backup01\system
2020-06-09 20:28 - 2018-07-28 12:12 - 000008192 ____A [3BB53F59F1DE4574AC493EFB24192025] () C:\Windows\System32\config\backup01\userdiff

====== End of Folder: ======


========================= Folder: C:\Windows\System32\config\backup1 ========================

C:\Windows\System32\config\backup1 = File

====== End of Folder: ======


========================= Folder: C:\Windows\System32\config\backup1p ========================


====== End of Folder: ======


========================= Folder: C:\Windows\System32\config\backup ========================

2020-06-09 14:34 - 2020-05-25 14:21 - 000524288 ____A [2F8297866DCB1ED98100A7BC2DF41919] () C:\Windows\System32\config\backup\BBI
2020-06-09 14:34 - 2018-07-28 12:17 - 000028672 ____A [3987130357A084D5BE7FBC367EF39DA2] () C:\Windows\System32\config\backup\BCD-Template
2020-06-09 14:34 - 2020-06-07 20:12 - 078643200 ____A [D252EBD7007744FCB4BD5C70D0F69D71] () C:\Windows\System32\config\backup\COMPONENTS
2020-06-09 14:34 - 2020-05-25 14:21 - 000786432 ____A [3E6D6252C41C4A6E012EF6DD850274E0] () C:\Windows\System32\config\backup\DEFAULT
2020-06-09 14:34 - 2020-06-04 05:54 - 005505024 ____A [51F321F7FBD79CF42E3C2326701A14D6] () C:\Windows\System32\config\backup\DRIVERS
2020-06-09 14:34 - 2020-05-08 14:39 - 000032768 ____A [20255C2075D952EC3552F48FED44C9E0] () C:\Windows\System32\config\backup\ELAM
2020-06-09 14:34 - 2020-05-25 14:21 - 000057344 ____A [5B3D7C59A69F5DC66DAD02F011C3C3C2] () C:\Windows\System32\config\backup\SAM
2020-06-09 14:34 - 2020-05-25 14:21 - 000057344 ____A [6A254EF4BFE79230C6D5B9A6C8AB8F53] () C:\Windows\System32\config\backup\SECURITY
2020-06-09 14:34 - 2020-06-04 02:14 - 082837504 ____A [7AF6BC4C96CE078DE824DF3428BB4F24] () C:\Windows\System32\config\backup\software
2020-06-09 14:34 - 2020-06-04 02:14 - 015990784 ____A [B66C85C28870DA049FE4FBABC0D683BE] () C:\Windows\System32\config\backup\system
2020-06-09 14:34 - 2018-07-28 12:12 - 000008192 ____A [3BB53F59F1DE4574AC493EFB24192025] () C:\Windows\System32\config\backup\userdiff

====== End of Folder: ======


========= bootrec.exe /fixmbr =========

La operación se completó correctamente.

========= End of CMD: =========


========= bootrec.exe /fixboot =========

La operación se completó correctamente.

========= End of CMD: =========


==== End of Fixlog 12:48:26 ==== 

Me parece que lo mejor sería volver a instalar el sistema. Hay archivos, principalmente fotos, que a mi esposa le interesaría recuperar. podría sacar el disco duro, tengo un adaptador para sata y conectarlo a mi computadora, accesar al DD y sacarlos?

Me parece que la laptop tiene 4gb de ram

Gracias por toda la ayuda

Hola @E_Chanes

Puedes intentar ya que tienes el adaptador.

Una vez que lo logres, vuelves por aquí así te digo como continuar.

Salu2