Fix result of Farbar Recovery Scan Tool (x64) Version: 20.02.2019 Ran by Esteban Cárdenas (20-02-2019 23:06:37) Run:1 Running from C:\Users\Esteban Cárdenas\Desktop Loaded Profiles: Esteban Cárdenas & (Available Profiles: Esteban Cárdenas) Boot Mode: Normal ============================================== fixlist content: ***************** Start CloseProcesses: CreateRestorePoint: (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe C:\Program Files\Common Files\McAfee (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe HKLM\...\Policies\Explorer: [NoActiveDesktop] C:\Windows\SysWOW64\1 [0 2017-04-29] () HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] C:\Windows\SysWOW64\1 [0 2017-04-29] () HKU\S-1-5-21-425742559-3532017336-187542989-1001\...\MountPoints2: {332490d8-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001\...\MountPoints2: {33249fef-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001\...\MountPoints2: {44885646-c20b-11e8-b943-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001\...\MountPoints2: {d157db3d-a215-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {332490d8-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {33249fef-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {44885646-c20b-11e8-b943-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {d157db3d-a215-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {332490d8-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {33249fef-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {44885646-c20b-11e8-b943-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {d157db3d-a215-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" GroupPolicy: Restriction ? <==== ATTENTION Tcpip\Parameters: [DhcpNameServer] 190.157.8.33 190.157.8.1 Tcpip\..\Interfaces\{1786339f-d71c-448f-9a92-9565bb62d23f}: [DhcpNameServer] 190.157.8.33 190.157.8.1 Tcpip\..\Interfaces\{726d753f-cbd0-4be9-9152-47b3304cc512}: [DhcpNameServer] 190.157.8.33 190.157.8.1 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764191888&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764227764&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\S-1-5-21-425742559-3532017336-187542989-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764218620&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B HKU\S-1-5-21-425742559-3532017336-187542989-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764218620&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764218620&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE SearchScopes: HKU\S-1-5-21-425742559-3532017336-187542989-1001 -> DefaultScope {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = SearchScopes: HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977 -> DefaultScope {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = SearchScopes: HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030 -> DefaultScope {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = CHR Profile: C:\Users\Esteban C�rdenas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2019-02-18] <==== ATTENTION CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hdkdmoacnkphoadmfidlhfdobieblphn] - C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx [2017-04-16] CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kaebhgioafceeldhgjmendlfhbfjefmo] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [2017-03-02] CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hdkdmoacnkphoadmfidlhfdobieblphn] - C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx [2017-04-16] CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kaebhgioafceeldhgjmendlfhbfjefmo] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [2017-03-02] CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hdkdmoacnkphoadmfidlhfdobieblphn] - C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx [2017-04-16] CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kaebhgioafceeldhgjmendlfhbfjefmo] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [2017-03-02] CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [hdkdmoacnkphoadmfidlhfdobieblphn] - C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx [2017-04-16] CHR HKLM-x32\...\Chrome\Extension: [kaebhgioafceeldhgjmendlfhbfjefmo] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [2017-03-02] S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [242704 2016-09-08] (McAfee, Inc. -> McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [384016 2016-09-08] (McAfee, Inc. -> McAfee, Inc.) S3 mfevtp; C:\windows\system32\mfevtps.exe [331280 2016-09-08] (McAfee, Inc. -> McAfee, Inc.) C:\windows\system32\mfevtps.exe R0 avdevprot; C:\WINDOWS\System32\DRIVERS\avdevprot.sys [60920 2017-06-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\WINDOWS\System32\DRIVERS\avdevprot.sys R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [38048 2017-06-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG) C:\WINDOWS\System32\Drivers\avusbflt.sys S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [88120 2016-09-09] (McAfee, Inc. -> McAfee, Inc.) C:\WINDOWS\System32\drivers\cfwids.sys R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [477752 2016-09-09] (McAfee, Inc. -> McAfee, Inc.) C:\WINDOWS\System32\drivers\mfeaack.sys R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [364088 2016-09-09] (McAfee, Inc. -> McAfee, Inc.) C:\WINDOWS\System32\drivers\mfeavfk.sys S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85656 2016-09-09] (Microsoft Windows Early Launch Anti-malware Publisher -> McAfee, Inc.) C:\WINDOWS\System32\drivers\mfeelamk.sys R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [512056 2016-09-09] (McAfee, Inc. -> McAfee, Inc.) C:\WINDOWS\System32\drivers\mfefirek.sys R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [884792 2016-09-09] (McAfee, Inc. -> McAfee, Inc.) C:\WINDOWS\System32\drivers\mfehidk.sys R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [252984 2016-09-09] (McAfee, Inc. -> McAfee, Inc.) C:\WINDOWS\System32\drivers\mfewfpk.sys 2019-02-19 00:11 - 2017-04-03 02:56 - 002975136 _____ (Avira Operations GmbH & Co. KG) C:\Users\Esteban C�rdenas\Desktop\avira_registry_cleaner_en.exe ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => -> No File ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers1_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File ContextMenuHandlers4_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File ContextMenuHandlers5_.DEFAULT: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File Task: {0281EE93-93A0-441B-AC90-E5588034606B} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION FirewallRules: [{599FC873-7A83-41C8-83EF-589593531BC4}] => (Allow) C:\Program Files\CyberLink\PowerDirector14\PDR10.EXE No File FirewallRules: [{ECAB360C-7D41-482A-BAEF-78F03FD22563}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe No File FirewallRules: [{95BFA925-6EB6-4AC3-BF77-81EF176D9E6D}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe No File FirewallRules: [{4FDA7895-2C60-4BC4-B645-36319C561E60}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe No File FirewallRules: [{84C9FE5F-AECB-43B1-894E-8A98948FD1CD}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe No File FirewallRules: [{E739C17F-1E65-4221-8EB4-0710E3744666}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe No File FirewallRules: [{183420A3-C69C-4BE9-9B0A-D098D347296F}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe No File CMD: ipconfig /flushdns CMD: ipconfig /renew CMD: bitsadmin /reset /allusers CMD: netsh winsock reset CMD: netsh advfirewall set allprofiles state ON CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset RemoveProxy: EmptyTemp: Hosts: END ***************** Processes closed successfully. Restore point was successfully created. C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe => Could not close process "C:\Program Files\Common Files\McAfee" folder move: Could not move "C:\Program Files\Common Files\McAfee" => Scheduled to move on reboot. C:\Windows\System32\mfevtps.exe => Could not close process C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe => Could not close process "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktop" => removed successfully "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktopChanges" => removed successfully HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{332490d8-aa6a-11e8-b942-ccb0da353ad8} => removed successfully HKLM\Software\Classes\CLSID\{332490d8-aa6a-11e8-b942-ccb0da353ad8} => not found HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{33249fef-aa6a-11e8-b942-ccb0da353ad8} => removed successfully HKLM\Software\Classes\CLSID\{33249fef-aa6a-11e8-b942-ccb0da353ad8} => not found HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44885646-c20b-11e8-b943-ccb0da353ad8} => removed successfully HKLM\Software\Classes\CLSID\{44885646-c20b-11e8-b943-ccb0da353ad8} => not found HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d157db3d-a215-11e8-b942-ccb0da353ad8} => removed successfully HKLM\Software\Classes\CLSID\{d157db3d-a215-11e8-b942-ccb0da353ad8} => not found HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {332490d8-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {33249fef-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {44885646-c20b-11e8-b943-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\...\MountPoints2: {d157db3d-a215-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {332490d8-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {33249fef-aa6a-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {44885646-c20b-11e8-b943-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\...\MountPoints2: {d157db3d-a215-11e8-b942-ccb0da353ad8} - "F:\HiSuiteDownLoader.exe" => Error: No automatic fix found for this entry. C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer" => removed successfully "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1786339f-d71c-448f-9a92-9565bb62d23f}\\DhcpNameServer" => removed successfully "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{726d753f-cbd0-4be9-9152-47b3304cc512}\\DhcpNameServer" => removed successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page" => removed successfully "HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL" => removed successfully HKU\S-1-5-21-425742559-3532017336-187542989-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully HKU\S-1-5-21-425742559-3532017336-187542989-1001\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764218620&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131384702764218620&GUID=1A9D675D-5B11-4A91-88FB-15C95BA03A2B => Error: No automatic fix found for this entry. HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE => Error: No automatic fix found for this entry. "HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully SearchScopes: HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977 -> DefaultScope {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = => Error: No automatic fix found for this entry. SearchScopes: HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030 -> DefaultScope {2211d4a5-48d0-47f5-a7cd-81e861470f7f} URL = => Error: No automatic fix found for this entry. "C:\Users\Esteban C�rdenas\AppData\Local\Google\Chrome\User Data\ChromeDefaultData" => not found HKLM\SOFTWARE\Google\Chrome\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh => removed successfully HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Google\Chrome\Extensions\hdkdmoacnkphoadmfidlhfdobieblphn => removed successfully C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx => moved successfully HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Google\Chrome\Extensions\kaebhgioafceeldhgjmendlfhbfjefmo => removed successfully C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx => moved successfully CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hdkdmoacnkphoadmfidlhfdobieblphn] - C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx [2017-04-16] => Error: No automatic fix found for this entry. CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kaebhgioafceeldhgjmendlfhbfjefmo] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [2017-03-02] => Error: No automatic fix found for this entry. CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [hdkdmoacnkphoadmfidlhfdobieblphn] - C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx [2017-04-16] => Error: No automatic fix found for this entry. CHR HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kaebhgioafceeldhgjmendlfhbfjefmo] - C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx [2017-03-02] => Error: No automatic fix found for this entry. HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh => removed successfully HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hdkdmoacnkphoadmfidlhfdobieblphn => removed successfully "C:\Program Files (x86)\EagleGet\addon\eagleget_newtab.crx" => not found HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kaebhgioafceeldhgjmendlfhbfjefmo => removed successfully "C:\Program Files (x86)\EagleGet\addon\eagleget_cext@eagleget.com.crx" => not found HKLM\System\CurrentControlSet\Services\mfefire => could not remove, key could be protected mfemms => Unable to stop service. HKLM\System\CurrentControlSet\Services\mfemms => could not remove, key could be protected HKLM\System\CurrentControlSet\Services\mfevtp => could not remove, key could be protected Could not move "C:\windows\system32\mfevtps.exe" => Scheduled to move on reboot. avdevprot => Unable to stop service. HKLM\System\CurrentControlSet\Services\avdevprot => removed successfully avdevprot => service removed successfully C:\WINDOWS\System32\DRIVERS\avdevprot.sys => moved successfully avusbflt => Unable to stop service. HKLM\System\CurrentControlSet\Services\avusbflt => removed successfully avusbflt => service removed successfully C:\WINDOWS\System32\Drivers\avusbflt.sys => moved successfully HKLM\System\CurrentControlSet\Services\cfwids => removed successfully cfwids => service removed successfully C:\WINDOWS\System32\drivers\cfwids.sys => moved successfully mfeaack => Unable to stop service. HKLM\System\CurrentControlSet\Services\mfeaack => could not remove, key could be protected Could not move "C:\WINDOWS\System32\drivers\mfeaack.sys" => Scheduled to move on reboot. mfeavfk => Unable to stop service. HKLM\System\CurrentControlSet\Services\mfeavfk => could not remove, key could be protected Could not move "C:\WINDOWS\System32\drivers\mfeavfk.sys" => Scheduled to move on reboot. HKLM\System\CurrentControlSet\Services\mfeelamk => could not remove, key could be protected Could not move "C:\WINDOWS\System32\drivers\mfeelamk.sys" => Scheduled to move on reboot. mfefirek => Unable to stop service. HKLM\System\CurrentControlSet\Services\mfefirek => could not remove, key could be protected Could not move "C:\WINDOWS\System32\drivers\mfefirek.sys" => Scheduled to move on reboot. mfehidk => Unable to stop service. HKLM\System\CurrentControlSet\Services\mfehidk => could not remove, key could be protected Could not move "C:\WINDOWS\System32\drivers\mfehidk.sys" => Scheduled to move on reboot. mfewfpk => Unable to stop service. HKLM\System\CurrentControlSet\Services\mfewfpk => could not remove, key could be protected Could not move "C:\WINDOWS\System32\drivers\mfewfpk.sys" => Scheduled to move on reboot. "C:\Users\Esteban C�rdenas\Desktop\avira_registry_cleaner_en.exe" => not found HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\EPP => removed successfully HKLM\Software\Classes\CLSID\{09A47860-11B0-4DA5-AFA5-26D86198A780} => not found HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\EPP => removed successfully HKLM\Software\Classes\CLSID\{09A47860-11B0-4DA5-AFA5-26D86198A780} => not found HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found "HKU\\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found "HKU\\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found "HKU\\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\ FileSyncEx" => not found HKLM\Software\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => not found "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0281EE93-93A0-441B-AC90-E5588034606B}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0281EE93-93A0-441B-AC90-E5588034606B}" => removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{599FC873-7A83-41C8-83EF-589593531BC4}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ECAB360C-7D41-482A-BAEF-78F03FD22563}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{95BFA925-6EB6-4AC3-BF77-81EF176D9E6D}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4FDA7895-2C60-4BC4-B645-36319C561E60}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{84C9FE5F-AECB-43B1-894E-8A98948FD1CD}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E739C17F-1E65-4221-8EB4-0710E3744666}" => removed successfully "HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{183420A3-C69C-4BE9-9B0A-D098D347296F}" => removed successfully ========= ipconfig /flushdns ========= Configuraci¢n IP de Windows Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS. ========= End of CMD: ========= ========= ipconfig /renew ========= Configuraci¢n IP de Windows No se puede realizar ninguna operaci¢n en VPN - VPN Client mientras los medios est‚n desconectados. No se puede realizar ninguna operaci¢n en Ethernet mientras los medios est‚n desconectados. No se puede realizar ninguna operaci¢n en Conexi¢n de  rea local* 2 mientras los medios est‚n desconectados. No se puede realizar ninguna operaci¢n en Conexi¢n de red Bluetooth mientras los medios est‚n desconectados. Adaptador de Ethernet VPN - VPN Client: Estado de los medios. . . . . . . . . . . : medios desconectados Sufijo DNS espec¡fico para la conexi¢n. . : Adaptador de Ethernet Ethernet: Estado de los medios. . . . . . . . . . . : medios desconectados Sufijo DNS espec¡fico para la conexi¢n. . : Adaptador de LAN inal mbrica Conexi¢n de  rea local* 2: Estado de los medios. . . . . . . . . . . : medios desconectados Sufijo DNS espec¡fico para la conexi¢n. . : Adaptador de LAN inal mbrica Wi-Fi: Sufijo DNS espec¡fico para la conexi¢n. . : V¡nculo: direcci¢n IPv6 local. . . : fe80::c41a:2593:b77:7b6%8 Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.5 M scara de subred . . . . . . . . . . . . : 255.255.255.0 Puerta de enlace predeterminada . . . . . : 192.168.0.1 Adaptador de Ethernet Conexi¢n de red Bluetooth: Estado de los medios. . . . . . . . . . . : medios desconectados Sufijo DNS espec¡fico para la conexi¢n. . : ========= End of CMD: ========= ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= ========= netsh winsock reset ========= El cat logo Winsock se restableci¢ correctamente. Debe reiniciar el equipo para completar el restablecimiento. ========= End of CMD: ========= ========= netsh advfirewall set allprofiles state ON ========= Aceptar ========= End of CMD: ========= ========= netsh int ipv4 reset ========= Reenv¡o de compartimiento se restableci¢ correctamente. Compartimiento se restableci¢ correctamente. Protocolo de control se restableci¢ correctamente. Solicitud de secuencia eco se restableci¢ correctamente. Global se restableci¢ correctamente. Interfaz se restableci¢ correctamente. Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente. Direcciones de multidifusi¢n se restableci¢ correctamente. Direcci¢n de unidifusi¢n se restableci¢ correctamente. Vecino se restableci¢ correctamente. Ruta de acceso se restableci¢ correctamente. Posible se restableci¢ correctamente. Directiva de prefijo se restableci¢ correctamente. Vecino de proxy se restableci¢ correctamente. Ruta se restableci¢ correctamente. Prefijo de sitio se restableci¢ correctamente. Subinterfaz se restableci¢ correctamente. Patr¢n de reactivaci¢n se restableci¢ correctamente. Resolver vecino se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. Error al restablecer . Acceso denegado. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. Reinicie el equipo para completar esta acci¢n. ========= End of CMD: ========= ========= netsh int ipv6 reset ========= Reenv¡o de compartimiento se restableci¢ correctamente. Compartimiento se restableci¢ correctamente. Protocolo de control se restableci¢ correctamente. Solicitud de secuencia eco se restableci¢ correctamente. Global se restableci¢ correctamente. Interfaz se restableci¢ correctamente. Direcci¢n de difusi¢n por proximidad (a se restableci¢ correctamente. Direcciones de multidifusi¢n se restableci¢ correctamente. Direcci¢n de unidifusi¢n se restableci¢ correctamente. Vecino se restableci¢ correctamente. Ruta de acceso se restableci¢ correctamente. Posible se restableci¢ correctamente. Directiva de prefijo se restableci¢ correctamente. Vecino de proxy se restableci¢ correctamente. Ruta se restableci¢ correctamente. Prefijo de sitio se restableci¢ correctamente. Subinterfaz se restableci¢ correctamente. Patr¢n de reactivaci¢n se restableci¢ correctamente. Resolver vecino se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. Error al restablecer . Acceso denegado. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. se restableci¢ correctamente. Reinicie el equipo para completar esta acci¢n. ========= End of CMD: ========= ========= RemoveProxy: ========= HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-425742559-3532017336-187542989-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02192019235137977\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-425742559-3532017336-187542989-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02202019084707030\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully ========= End of RemoveProxy: ========= C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. =========== EmptyTemp: ========== BITS transfer queue => 10772480 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 176869525 B Java, Flash, Steam htmlcache => 0 B Windows/system/drivers => 1578853 B Edge => 1985 B Chrome => 281703 B Firefox => 0 B Opera => 430259831 B Temp, IE cache, history, cookies, recent: Default => 6656 B Users => 0 B ProgramData => 0 B Public => 0 B systemprofile => 0 B systemprofile32 => 0 B LocalService => 269712 B NetworkService => 14216 B Esteban Cárdenas => 8290746 B RecycleBin => 1670745754 B EmptyTemp: => 2.1 GB temporary data Removed. ================================