Al hacer busqueda en google se abre en otra pagina el buscador de yahoo

Hola

Inicia el PC en Modo a Prueba de Fallos:

Abrí un nuevo archivo Notepad y copia y pega este contenido:

Start
CreateRestorePoint:
CloseProcesses
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe
(McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(McAfee, LLC.) C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe
C:\Program Files\McAfee
C:\Program Files\SUPERAntiSpyware
C:\Program Files (x86)\Zemana AntiMalware
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [8899504 2018-09-10] (SUPERAntiSpyware)
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\Run: [710b983e] => C:\ProgramData\710b983e\710b983e.exe [0 ] (AutoIt Team)
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\MountPoints2: {7cd6a871-e66f-11e8-83b4-0071cca1738a} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\MountPoints2: {81254b63-68b2-11e8-839f-0071cca1738a} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\MountPoints2: {82657131-2850-11e8-8393-0071cca1738a} - "F:\HiSuiteDownLoader.exe" 
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter "C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter" "C:\Program Files\McAfee\TrueKey\McAfeeTrueKeyPasswordFilter"
Startup: C:\Users\Juan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\b710b983ee09b41bae829ba721b618c0.lnk [2018-11-20]
ShortcutTarget: b710b983ee09b41bae829ba721b618c0.lnk -> C:\ELDEJUAN\cldfislawl.exe (AutoIt Team)
GroupPolicy: Restriction ? <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll [2018-04-23] (Intel Security)
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie64.dll [2018-04-23] (Intel Security)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\McAfee\TrueKey\MSIE\truekey_ie.dll [2018-04-23] (Intel Security)
FF ProfilePath: C:\Users\Juan\AppData\Roaming\Mozilla\Firefox\Profiles\1llm696p.default-1496663317932 [2018-11-20]
FF Extension: (uBlock Origin) - C:\Users\Juan\AppData\Roaming\Mozilla\Firefox\Profiles\1llm696p.default-1496663317932\Extensions\[email protected] [2018-10-19]
FF Extension: (Firefox protect Pro) - C:\Users\Juan\AppData\Roaming\Mozilla\Firefox\Profiles\1llm696p.default-1496663317932\Extensions\{bc8d18c2-ccec-4bd6-9fca-bf30f94d1dee}.xpi [2017-10-18]
FF Extension: (Firefox Monitor) - C:\Users\Juan\AppData\Roaming\Mozilla\Firefox\Profiles\1llm696p.default-1496663317932\features\{e1d3af13-f888-4591-bd39-0d3d6c87e7e2}\[email protected] [2018-11-18]
FF HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\Firefox\Extensions: [[email protected]] - C:\Users\Juan\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found
FF Plugin HKU\S-1-5-21-1046919139-3393652339-1846237276-1002: @acestream.net/acestreamplugin,version=3.1.32 -> C:\Users\Juan\AppData\Roaming\ACEStream\player\npace_plugin.dll [No File]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 TrueKey; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.Service.exe [355280 2018-10-10] (McAfee, LLC.)
R2 TrueKeyScheduler; C:\Program Files\McAfee\TrueKey\McTkSchedulerService.exe [355280 2018-10-10] (McAfee, LLC.)
R2 TrueKeyServiceHelper; C:\Program Files\McAfee\TrueKey\McAfee.TrueKey.ServiceHelper.exe [193656 2018-10-10] (McAfee, LLC.)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15775888 2017-08-09] (Copyright 2017.)
2018-11-20 11:21 - 2018-11-20 11:21 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Juan\Downloads\iExplore.exe
2018-11-20 11:21 - 2018-11-20 11:21 - 000988112 _____ (Bleeping Computer, LLC) C:\Users\Juan\Downloads\iExplore64.exe
2018-11-20 11:01 - 2018-11-20 11:01 - 000001232 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2018-11-20 11:01 - 2018-11-20 11:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2018-11-20 11:01 - 2018-11-20 11:01 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-11-20 11:00 - 2018-11-20 11:00 - 006625600 _____ (Zemana Ltd. ) C:\Users\Juan\Downloads\Zemana.AntiMalware.Setup.exe
2018-11-20 11:00 - 2018-11-20 11:00 - 000000000 ____D C:\Users\Juan\AppData\Local\Zemana
2018-11-20 10:35 - 2016-05-13 17:31 - 000001204 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk
2018-11-20 10:35 - 2016-05-13 17:31 - 000001190 _____ C:\Users\Public\Desktop\True Key.lnk
2018-05-04 12:17 - 2018-05-04 12:17 - 000328375 _____ () C:\Users\Juan\AppData\Roaming\PE.bin
2016-01-30 15:11 - 2016-01-30 15:12 - 000009728 _____ () C:\Users\Juan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-04-29 18:58 - 2018-06-08 11:16 - 000007605 _____ () C:\Users\Juan\AppData\Local\resmon.resmoncfg
Task: {16EDA9FC-EB83-4288-B6B8-E1715D41A734} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {2D87AA58-C577-46D2-B12E-EA78165FDCF5} - System32\Tasks\{02559A64-7F5D-4CAF-A692-3A67456543BA} => C:\WINDOWS\system32\pcalua.exe -a E:\setup.exe -d E:\
Task: {3642946C-0984-4DEC-8BBC-46458CDBC199} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {548D00B7-DD0C-41A9-9103-C9BD16CA288F} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {74CB0E54-185A-4DD0-ADCD-58312DD0A2A4} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {771B071F-2AE4-40B5-A99D-A0514F27F3A1} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {C0CAB52E-BAB5-408F-B1F4-1C99B4E64903} - \WPD\SqmUpload_S-1-5-21-1046919139-3393652339-1846237276-1002 -> No File <==== ATTENTION
Task: {C1BA4C8A-036A-403C-969C-B8F8225F9ACA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {E859639A-4A57-47DE-891C-0D05D6A90750} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {ED477525-45E5-4644-BAF3-58613335E041} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-10-29] (AVAST Software)
Task: {EE3AA746-BA55-4798-A94A-BD05A797F17C} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {EED666F1-6168-4288-9D5E-CA52C6D3282F} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {FB722081-0028-4C02-9C54-B028AA820DB4} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\StartupApproved\Run: => "SUPERAntiSpyware"
HKU\S-1-5-21-1046919139-3393652339-1846237276-1002\...\StartupApproved\Run: => "710b983e"
CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
  • Lo guardas bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

Nota: Es necesario que el ejecutable Frst.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajara.

  • Ejecutas Frst.exe.
  • Presionas el botón Fix y aguardas a que termine.
  • La Herramienta guardara el reporte en tu escritorio (Fixlog.txt).
  • Lo pegas en tu próxima respuesta.

Saludos