ok gracias y parece que, si, no borro del todo el virus altruistic pero siento que ya esta borrado por completo muchas gracias por la ayuda aqui esta el analisis
Program : RogueKiller Anti-Malware
Version : 15.8.0.0
x64 : Yes
Program Date : Jan 26 2023
Location : C:\Users\WILSON\Downloads\RogueKiller_portable64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19044) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : WILSON
User is Admin : Yes
Date : 2023/02/13 23:52:56
Type : Removal
Aborted : No
Scan Mode : Standard
Duration : 439
Found items : 15
Total scanned : 71595
Signatures Version : 20230209_084111
Truesight Driver : Yes
Updates Count : 7
************************* Warnings *************************
************************* Removal *************************
[PUP.Gen1 (Potencialmente Malicioso)] HKEY_USERS\S-1-5-21-1692289895-2484174982-3683579246-1001\Software\AppHelper -- -> Borrado
[+] scan_what : 2
[+] vendors : PUP.Gen1
[+] Name : HKEY_USERS\S-1-5-21-1692289895-2484174982-3683579246-1001\Software\AppHelper
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 0
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Suspicious.Path (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F6AB2CF6-C97D-486E-915A-8855B12E7646} -- [%_WILSON_appdata%\.Salwyrr\launcher\bootstrap\jre\bin\javaw.exe] -> Borrado
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{F6AB2CF6-C97D-486E-915A-8855B12E7646}
[+] value : [%_WILSON_appdata%\.Salwyrr\launcher\bootstrap\jre\bin\javaw.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 1
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{1ED5A6D0-003F-446F-A2B9-477E8464F6FE} -- [%_WILSON_appdata%\.Salwyrr\launcher\jre\bin\javaw.exe] -> Borrado
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{1ED5A6D0-003F-446F-A2B9-477E8464F6FE}
[+] value : [%_WILSON_appdata%\.Salwyrr\launcher\jre\bin\javaw.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 2
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{227984F7-21BF-4238-A8A7-1CE2D9B389E2} -- [%_WILSON_appdata%\.Salwyrr\launcher\java-runtime-alpha\bin\javaw.exe] -> Borrado
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{227984F7-21BF-4238-A8A7-1CE2D9B389E2}
[+] value : [%_WILSON_appdata%\.Salwyrr\launcher\java-runtime-alpha\bin\javaw.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 3
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{011D8F33-34BC-4D02-96E2-22D5176441CA} -- [%_WILSON_appdata%\.Salwyrr\launcher\bootstrap\jre\bin\java.exe] -> Borrado
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{011D8F33-34BC-4D02-96E2-22D5176441CA}
[+] value : [%_WILSON_appdata%\.Salwyrr\launcher\bootstrap\jre\bin\java.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 4
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{CE8D1A73-F13E-4B02-8657-36A30FE715B2} -- [%_WILSON_appdata%\.Salwyrr\launcher\java-runtime-alpha\bin\java.exe] -> Borrado
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{CE8D1A73-F13E-4B02-8657-36A30FE715B2}
[+] value : [%_WILSON_appdata%\.Salwyrr\launcher\java-runtime-alpha\bin\java.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 5
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[Suspicious.Path (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{30FE3A74-DA40-48CD-A492-B44BDE383568} -- [%_WILSON_appdata%\.Salwyrr\launcher\jre\bin\java.exe] -> Borrado
[+] scan_what : 1
[+] vendors : Suspicious.Path
[+] Name : HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{30FE3A74-DA40-48CD-A492-B44BDE383568}
[+] value : [%_WILSON_appdata%\.Salwyrr\launcher\jre\bin\java.exe]
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 6
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : -1
[PUM.Policies (Potencialmente Malicioso)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- -> Reemplazado (2)
[+] scan_what : 1
[+] vendors : PUM.Policies
[+] Name : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin
[+] Type : Registry
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 4
[+] id : 7
[+] status : 3
[+] status_str : Reemplazado (2)
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Adw.Dealply (Malicioso)] JJS-UI.lnk -- %USERPROFILE%\Desktop\JJS-UI.lnk (lnk => C:\Users\WILSON\AppData\Local\Programs\JJS-UI\JJS-UI.exe []) -> Borrado
[+] scan_what : 1
[+] vendors : Adw.Dealply
[+] Name : JJS-UI.lnk
[+] value : %USERPROFILE%\Desktop\JJS-UI.lnk (lnk => C:\Users\WILSON\AppData\Local\Programs\JJS-UI\JJS-UI.exe [])
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 8
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Adw.Dealply (Malicioso)] JJS-UI.lnk -- %_WILSON_appdata%\Microsoft\Windows\Start Menu\Programs\JJS-UI.lnk (lnk => C:\Users\WILSON\AppData\Local\Programs\JJS-UI\JJS-UI.exe []) -> Borrado
[+] scan_what : 1
[+] vendors : Adw.Dealply
[+] Name : JJS-UI.lnk
[+] value : %_WILSON_appdata%\Microsoft\Windows\Start Menu\Programs\JJS-UI.lnk (lnk => C:\Users\WILSON\AppData\Local\Programs\JJS-UI\JJS-UI.exe [])
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 9
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[PUP.OnlineIO (Potencialmente Malicioso)] AdvinstAnalytics -- %localappdata%\AdvinstAnalytics -> Borrado
[+] scan_what : 1
[+] vendors : PUP.OnlineIO
[+] Name : AdvinstAnalytics
[+] value : %localappdata%\AdvinstAnalytics
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 10
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Adw.Dealply (Malicioso)] JJS-UI -- %localappdata%\Programs\JJS-UI -> Borrado
[+] scan_what : 1
[+] vendors : Adw.Dealply
[+] Name : JJS-UI
[+] value : %localappdata%\Programs\JJS-UI
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 11
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Adw.Dealply (Malicioso)] Altruistic -- %programdata%\Altruistic -> Borrado
[+] scan_what : 1
[+] vendors : Adw.Dealply
[+] Name : Altruistic
[+] value : %programdata%\Altruistic
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 12
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0
[Adw.Dealply (Malicioso)] JJS-UI.lnk -- %USERPROFILE%\Desktop\JJS-UI.lnk (lnk => C:\Users\WILSON\AppData\Local\Programs\JJS-UI\JJS-UI.exe []) -> Encontrado
[+] scan_what : 1
[+] vendors : Adw.Dealply
[+] Name : JJS-UI.lnk
[+] value : %USERPROFILE%\Desktop\JJS-UI.lnk (lnk => C:\Users\WILSON\AppData\Local\Programs\JJS-UI\JJS-UI.exe [])
[+] Type : File/Folder
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 2
[+] id : 13
[+] status : 1
[+] status_str : Encontrado
[+] removed : No
[+] status_choice : 2
[+] malpe_score : 0
[PUP.Gen0 (Potencialmente Malicioso)] Chameleon -- dmpojjilddefgnhiicjcmhbkjgbbclob -> Borrado
[+] scan_what : 1
[+] vendors : PUP.Gen0
[+] Name : Chameleon
[+] value : dmpojjilddefgnhiicjcmhbkjgbbclob
[+] Type : Browser
[+] file_vtscore : 0
[+] file_vttotal : 0
[+] is_malicious : Yes
[+] detection_level : 3
[+] id : 14
[+] status : 3
[+] status_str : Borrado
[+] removed : Yes
[+] status_choice : 2
[+] malpe_score : 0