Fix result of Farbar Recovery Scan Tool (x64) Version:26-07-2015 Ran by Rocio at 2015-07-26 10:34:51 Run:1 Running from C:\Users\Rocio\Desktop Loaded Profiles: Rocio (Available Profiles: Rocio & Invitado) Boot Mode: Normal ============================================== fixlist content: ***************** CreateRestorePoint: HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-07-20] (Comodo Security Solutions, Inc.) HKLM-x32\...\Run: [ClamWin] => C:\Program Files (x86)\ClamWin\bin\ClamTray.exe [86016 2015-07-25] (alch) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> No File Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - No File CHR HKLM-x32\...\Chrome\Extension: [idkknaphebegndgimgdpfnconcickdfn] - No Path Or update_url value R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-07-20] (Comodo Security Solutions, Inc.) S4 sjzgxw; No ImagePath S0 uezndl; No ImagePath S4 vqdtrh; No ImagePath U2 TMAgent; No ImagePath 2015-07-17 23:09 - 2015-07-17 23:13 - 00000000 ____D C:\ProgramData\F-Secure 2015-07-17 23:09 - 2015-07-17 23:09 - 00000000 ____D C:\Users\Rocio\AppData\Local\F-Secure 2015-07-15 23:32 - 2015-07-15 23:32 - 00380416 _____ C:\Users\Rocio\Downloads\vy5gb233.exe 2015-07-10 11:54 - 2015-07-10 11:54 - 00000738 _____ C:\Windows\SysWOW64\{7995330B-E01F-4645-B702-53481E7CB778}.cmdfile C:\Users\Invitado\R41301.EXE C:\Users\Invitado\R46346.EXE C:\Users\Invitado\R49651.EXE C:\Users\Invitado\R64290.EXE C:\Users\Invitado\R64913.EXE C:\Users\Invitado\R69396.EXE C:\Users\Rocio\grub.exe C:\Users\Rocio\RarExt.dll C:\Users\Rocio\rarnew.dat C:\Users\Rocio\rescue2usb.exe C:\Users\Rocio\syslinux.exe C:\Users\Rocio\zipnew.dat RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Restore point was successfully created. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\tvncontrol => value removed successfully HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ClamWin => value removed successfully "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. C:\Windows\system32\GroupPolicy\Machine => moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully. C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}" => key removed successfully "HKCR\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}" => key removed successfully "HKCR\PROTOCOLS\Handler\tmtbim" => key removed successfully "HKCR\CLSID\{0B37915C-8B98-4B9E-80D4-464D2C830D10}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\idkknaphebegndgimgdpfnconcickdfn" => key removed successfully GeekBuddyRSP => Service stopped successfully. GeekBuddyRSP => service removed successfully sjzgxw => service removed successfully uezndl => service removed successfully vqdtrh => service removed successfully TMAgent => service removed successfully C:\ProgramData\F-Secure => moved successfully. C:\Users\Rocio\AppData\Local\F-Secure => moved successfully. C:\Users\Rocio\Downloads\vy5gb233.exe => moved successfully. C:\Windows\SysWOW64\{7995330B-E01F-4645-B702-53481E7CB778}.cmdfile => moved successfully. C:\Users\Invitado\R41301.EXE => moved successfully. C:\Users\Invitado\R46346.EXE => moved successfully. C:\Users\Invitado\R49651.EXE => moved successfully. C:\Users\Invitado\R64290.EXE => moved successfully. C:\Users\Invitado\R64913.EXE => moved successfully. C:\Users\Invitado\R69396.EXE => moved successfully. C:\Users\Rocio\grub.exe => moved successfully. C:\Users\Rocio\RarExt.dll => moved successfully. C:\Users\Rocio\rarnew.dat => moved successfully. C:\Users\Rocio\rescue2usb.exe => moved successfully. C:\Users\Rocio\syslinux.exe => moved successfully. C:\Users\Rocio\zipnew.dat => moved successfully. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully HKU\S-1-5-21-4221762962-3014482106-3654835003-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully HKU\S-1-5-21-4221762962-3014482106-3654835003-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully ========= End of RemoveProxy: ========= ========= netsh advfirewall reset ========= Aceptar ========= End of CMD: ========= ========= netsh advfirewall set allprofiles state ON ========= Aceptar ========= End of CMD: ========= ========= ipconfig /flushdns ========= Configuraci¢n IP de Windows Se vaci¢ correctamente la cach‚ de resoluci¢n de DNS. ========= End of CMD: ========= ========= netsh winsock reset catalog ========= El catálogo Winsock se restableció correctamente. Debe reiniciar el equipo para completar el restablecimiento. ========= End of CMD: ========= ========= netsh int ip reset c:\resetlog.txt ========= Global se restableció correctamente. Interfaz se restableció correctamente. Reinicie el equipo para completar esta acción. ========= End of CMD: ========= ========= ipconfig /release ========= Configuraci¢n IP de Windows No se puede realizar ninguna operaci¢n en Conexi¢n de red inal mbrica 2 mientras los medios est‚n desconectados. Adaptador de Ethernet Conexi¢n de  rea local: Sufijo DNS espec¡fico para la conexi¢n. . : V¡nculo: direcci¢n IPv6 local. . . : fe80::20e7:e7c0:114:7b32%22 Puerta de enlace predeterminada . . . . . : Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica 2: Estado de los medios. . . . . . . . . . . : medios desconectados Sufijo DNS espec¡fico para la conexi¢n. . : Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica: Sufijo DNS espec¡fico para la conexi¢n. . : V¡nculo: direcci¢n IPv6 local. . . : fe80::2824:3f83:1c38:4662%20 Puerta de enlace predeterminada . . . . . : ========= End of CMD: ========= ========= ipconfig /renew ========= Configuraci¢n IP de Windows No se puede realizar ninguna operaci¢n en Conexi¢n de red inal mbrica 2 mientras los medios est‚n desconectados. Adaptador de Ethernet Conexi¢n de  rea local: Sufijo DNS espec¡fico para la conexi¢n. . : V¡nculo: direcci¢n IPv6 local. . . : fe80::20e7:e7c0:114:7b32%22 Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.7 M scara de subred . . . . . . . . . . . . : 255.255.255.0 Puerta de enlace predeterminada . . . . . : 192.168.0.1 Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica 2: Estado de los medios. . . . . . . . . . . : medios desconectados Sufijo DNS espec¡fico para la conexi¢n. . : Adaptador de LAN inal mbrica Conexi¢n de red inal mbrica: Sufijo DNS espec¡fico para la conexi¢n. . : V¡nculo: direcci¢n IPv6 local. . . : fe80::2824:3f83:1c38:4662%20 Direcci¢n IPv4. . . . . . . . . . . . . . : 192.168.0.17 M scara de subred . . . . . . . . . . . . : 255.255.255.0 Puerta de enlace predeterminada . . . . . : 192.168.0.1 ========= End of CMD: ========= ========= netsh int ipv4 reset ========= Interfaz se restableció correctamente. Reinicie el equipo para completar esta acción. ========= End of CMD: ========= ========= netsh int ipv6 reset ========= No hay valores configurados por el usuario para restablecer. ========= End of CMD: ========= ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.5.7601 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. 0 out of 0 jobs canceled. ========= End of CMD: ========= EmptyTemp: => 287.5 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 10:36:02 ====