Here are the logs:
Fix result of Farbar Recovery Scan Tool (x64) Version: 08-12-2017
Ran by Erick L Jefe (08-12-2017 12:08:49) Run:6
Running from C:\Users\Erick L Jefe\Desktop\New folder
Loaded Profiles: Erick L Jefe (Available Profiles: Erick L Jefe)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\muzwg
S4 dkspqk; C:\Windows\System32\drivers\xjbxhm.sys [79064 2017-12-07] (Malwarebytes)
C:\Windows\System32\drivers\xjbxhm.sys
S4 fhlvrqs; C:\Windows\System32\drivers\ejed.sys [79064 2017-12-06] (Malwarebytes)
C:\Windows\System32\drivers\ejed.sys
S4 tqswgmlv; C:\Windows\System32\drivers\qogpht.sys
C:\Windows\System32\drivers\qogpht.sys
U0 muzwg; C:\Wi\ndowssystem32\drivers\exbdhknr.sys [X]
2017-12-06 16:26 - 2017-09-29 08:42 - 000040448 _____ (Microsoft Corporation) C:\Users\Erick L Jefe\AppData\Local\Temp\19611.exe
2017-12-06 16:32 - 2017-09-29 08:42 - 000040448 _____ (Microsoft Corporation) C:\Users\Erick L Jefe\AppData\Local\Temp\20868.exe
2017-12-06 16:41 - 2017-09-29 08:42 - 000040448 _____ (Microsoft Corporation) C:\Users\Erick L Jefe\AppData\Local\Temp\22648.exe
2017-12-06 20:41 - 2017-09-29 08:42 - 000040448 _____ (Microsoft Corporation) C:\Users\Erick L Jefe\AppData\Local\Temp\4149.exe
Task: {CD63B593-E363-4D76-BE12-BC0B8ACEA07C} - \DefenderUpdate -> No File <==== ATTENTION
Shortcut: C:\Users\Erick L Jefe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Intеrnеt Еxрlorer.lnk -> C:\Users\Erick L Jefe\AppData\Roaming\Browsers\exe.erolpxei.bat (No File) <==== Cyrillic
Shortcut: C:\Users\Erick L Jefe\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооgle Chrоme.lnk -> C:\Users\Erick L Jefe\AppData\Roaming\Browsers\exe.emorhc.bat (No File) <==== Cyrillic
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Chrоme.lnk -> C:\Users\Erick L Jefe\AppData\Roaming\Browsers\exe.emorhc.bat (No File) <==== Cyrillic
Shortcut: C:\Users\Public\Desktop\Gооglе Chrоme.lnk -> C:\Users\Erick L Jefe\AppData\Roaming\Browsers\exe.emorhc.bat (No File) <==== Cyrillic
Shortcut: C:\Users\Public\Desktop\Аеrоsоft Lаuncher.lnk -> C:\Users\Erick L Jefe\AppData\Roaming\Browsers\exe.rehcnualtfosorea.bat (No File) <==== Cyrillic
HKLM\...\StartupApproved\Run32: => "Optimizer.exe"
HKU\S-1-5-21-3728291697-3449938618-998988-1001\...\StartupApproved\StartupFolder: => "Browge.vbs"
HKU\S-1-5-21-3728291697-3449938618-998988-1001\...\StartupApproved\Run: => "6OF5FTH8RGXJBYJ"
HKU\S-1-5-21-3728291697-3449938618-998988-1001\...\StartupApproved\Run: => "8KKM8W4BXAZ6L65"
HKU\S-1-5-21-3728291697-3449938618-998988-1001\...\StartupApproved\Run: => "72BG8KY2Z7K0YT3"
HKU\S-1-5-21-3728291697-3449938618-998988-1001\...\StartupApproved\Run: => "CP4FAFOFLLPEEX2"
HKU\S-1-5-21-3728291697-3449938618-998988-1001\...\StartupApproved\Run: => "KY16P3BLNNUVFX1"
FirewallRules: [{1D3A8365-B4AA-4B98-ADBA-B12794E96351}] => (Allow) LPort=445
FirewallRules: [{0358029B-9F5A-4D8E-BA02-E1A135E74B24}] => (Allow) LPort=19284
FirewallRules: [{49D7B3E1-1650-4143-803D-E3B6F83CCF35}] => (Allow) LPort=19285
FirewallRules: [{927CE115-F775-4A9C-B5E3-E12EED2AD124}] => (Allow) LPort=8888
FirewallRules: [{A830914A-F5A3-47B4-9399-7860DC7BEAC8}] => (Allow) LPort=8888
FirewallRules: [{F2C495F1-B0A5-4150-BDCC-8872BD0467A1}] => (Allow) LPort=26789
FirewallRules: [{608061AC-FEBA-4344-8075-6C671456C1CC}] => (Allow) LPort=26820
FirewallRules: [{E7C5E413-4712-42E1-9801-243B5C2E8055}] => (Allow) LPort=26822
EmptyTemp:
Hosts:
CMD: ipconfig /flushDNS
end
*****************
Processes closed successfully.
Restore point was successfully created.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\muzwg => key not found
dkspqk => service not found.
"C:\Windows\System32\drivers\xjbxhm.sys" => not found.
fhlvrqs => service not found.
"C:\Windows\System32\drivers\ejed.sys" => not found.
tqswgmlv => service not found.
"C:\Windows\System32\drivers\qogpht.sys" => not found.
muzwg => service not found.
"C:\Users\Erick L Jefe\AppData\Local\Temp\19611.exe" => not found.
"C:\Users\Erick L Jefe\AppData\Local\Temp\20868.exe" => not found.
"C:\Users\Erick L Jefe\AppData\Local\Temp\22648.exe" => not found.
"C:\Users\Erick L Jefe\AppData\Local\Temp\4149.exe" => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD63B593-E363-4D76-BE12-BC0B8ACEA07C} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DefenderUpdate => key not found
C:\Users\Erick L Jefe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Intеrnеt Еxрlorer.lnk => not found.
C:\Users\Erick L Jefe\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gооgle Chrоme.lnk => not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gооglе Chrоme.lnk => not found.
C:\Users\Public\Desktop\Gооglе Chrоme.lnk => not found.
C:\Users\Public\Desktop\Аеrоsоft Lаuncher.lnk => not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32\\Optimizer.exe => value not found.
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Optimizer.exe => value not found.
C:\Users\Erick L Jefe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Browge.vbs => not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\StartupFolder\\Browge.vbs => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\6OF5FTH8RGXJBYJ => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\6OF5FTH8RGXJBYJ => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\8KKM8W4BXAZ6L65 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\8KKM8W4BXAZ6L65 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\72BG8KY2Z7K0YT3 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\72BG8KY2Z7K0YT3 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\CP4FAFOFLLPEEX2 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CP4FAFOFLLPEEX2 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\KY16P3BLNNUVFX1 => value not found.
HKU\S-1-5-21-3728291697-3449938618-998988-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KY16P3BLNNUVFX1 => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1D3A8365-B4AA-4B98-ADBA-B12794E96351} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0358029B-9F5A-4D8E-BA02-E1A135E74B24} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{49D7B3E1-1650-4143-803D-E3B6F83CCF35} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{927CE115-F775-4A9C-B5E3-E12EED2AD124} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A830914A-F5A3-47B4-9399-7860DC7BEAC8} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F2C495F1-B0A5-4150-BDCC-8872BD0467A1} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{608061AC-FEBA-4344-8075-6C671456C1CC} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E7C5E413-4712-42E1-9801-243B5C2E8055} => value not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
========= ipconfig /flushDNS =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
=========== EmptyTemp: ==========
BITS transfer queue => 7364608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 197136985 B
Java, Flash, Steam htmlcache => 26377907 B
Windows/system/drivers => 21527209 B
Edge => 454307659 B
Chrome => 16185565 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 174741 B
systemprofile32 => 247813858 B
LocalService => 120540 B
NetworkService => 229458 B
Erick L Jefe => 538595538 B
RecycleBin => 0 B
EmptyTemp: => 1.4 GB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 12:09:47 ====
SophosVirusRemovalTool_cloud4.log
SophosVirusRemovalTool.log
Fixlog.txt