Me Aparecen Popups Con Publicidad

Muchísimas Gracias Por la Ayuda No He Actualizado Windows Porque mi Espacio Es Algo Reducido Pero Lo Hare Despues De Marcar Como Solucionado Mi Problema :slight_smile:

Fix result of Farbar Recovery Scan Tool (x64) Version: 15-07-2019 01
Ran by Normal (18-07-2019 02:34:51) Run:1
Running from C:\Users\Normal\Desktop
Loaded Profiles: Normal (Available Profiles: defaultuser0 & Normal)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\RunOnce: [] => [X]
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction ? <==== ATTENTION
Task: {51B02C18-1DE2-471C-84CF-E6656417FFF2} - System32\Tasks\{3DCB0C89-2F74-2E1A-48BA-2860FFFF93C0} => C:\Users\Normal\AppData\Roaming\Recodul\Gomatafo.exe
C:\Users\Normal\AppData\Roaming\Recodul
Task: C:\Windows\Tasks\{3DCB0C89-2F74-2E1A-48BA-2860FFFF93C0}.job => C:\Users\Normal\AppData\Roaming\Recodul\Gomatafo.exe
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2393600599-662570708-1542540813-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2393600599-662570708-1542540813-1001 -> {44177982-996D-4b79-B29F-5B60E13A5169} URL = hxxp://www.baidu.com/s?wd={searchTerms}&tn=98012088_2_dg&ch=1&ie=utf-8
SearchScopes: HKU\S-1-5-21-2393600599-662570708-1542540813-1001 -> {e5badea7-e1c2-fbf1-87ac-061d1440d15b} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-11-12] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @kingsfot.com/npkws -> C:\program files (x86)\kingsoft\kingsoft antivirus\npkws.dll [No File]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2019-02-11]
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2019-02-11]
S2 KMSEmulator; temp.exe [X]
S1 bafkwdyy; \??\C:\Windows\system32\drivers\bafkwdyy.sys [X]
S0 bootsafe; system32\drivers\bootsafe64_ev.sys [X]
S1 ckmyfrde; \??\C:\Windows\system32\drivers\ckmyfrde.sys [X]
S1 cwwrngng; \??\C:\Windows\system32\drivers\cwwrngng.sys [X]
S1 djsktwhu; \??\C:\Windows\system32\drivers\djsktwhu.sys [X]
S1 fergugjp; \??\C:\Windows\system32\drivers\fergugjp.sys [X]
S1 fsjdmqwg; \??\C:\Windows\system32\drivers\fsjdmqwg.sys [X]
S1 fvxicksk; \??\C:\Windows\system32\drivers\fvxicksk.sys [X]
S1 heyhyfoz; \??\C:\Windows\system32\drivers\heyhyfoz.sys [X]
S1 ihkebpsg; \??\C:\Windows\system32\drivers\ihkebpsg.sys [X]
S2 ksapi64; system32\drivers\ksapi64.sys [X]
S1 lxpsrkaf; \??\C:\Windows\system32\drivers\lxpsrkaf.sys [X]
S1 mubblxro; \??\C:\Windows\system32\drivers\mubblxro.sys [X]
S1 nggolwdv; \??\C:\Windows\system32\drivers\nggolwdv.sys [X]
S1 nmyrotat; \??\C:\Windows\system32\drivers\nmyrotat.sys [X]
S1 rjwfcbio; \??\C:\Windows\system32\drivers\rjwfcbio.sys [X]
NETSVCx32: dg597 -> no filepath.
2019-07-16 22:40 - 2019-07-16 22:40 - 000000085 _____ C:\Windows\wininit.ini
2019-07-15 18:42 - 2019-07-15 18:42 - 000003372 _____ C:\Windows\System32\Tasks\{D9E7C655-6C3E-4848-936D-33A40A8BAC87}
2019-07-12 13:27 - 2019-07-12 13:27 - 000244616 _____ C:\Users\Normal\AppData\Roaming\Melem
2019-06-25 12:26 - 2019-06-25 12:26 - 000116667 _____ C:\Users\Normal\AppData\Roaming\Dokaraficu
2019-07-04 01:26 - 2019-07-04 01:26 - 000362246 _____ C:\Users\Normal\AppData\Roaming\Pahenolefas
2019-07-17 14:56 - 2019-05-12 00:25 - 000000000 ____D C:\ProgramData\{B7AA8B96-9F82-F3EE-C7DA-DBC62F32031E}
2019-07-17 14:56 - 2018-07-18 12:48 - 000000000 ____D C:\Users\Normal\AppData\Local\Baheb
2019-07-17 14:56 - 2018-06-26 13:17 - 000000000 ____D C:\Users\Normal\AppData\Local\Fobumud
2019-07-17 14:56 - 2017-03-12 15:12 - 000000000 ____D C:\Users\Normal\AppData\Roaming\Kubapiboka
2019-07-17 14:05 - 2019-02-24 13:25 - 000000000 _RSHD C:\streamer
C:\streamer
2019-07-17 13:26 - 2019-05-12 00:26 - 000000000 ____D C:\Users\Normal\AppData\Roaming\Recodul
2019-07-17 13:26 - 2018-09-29 12:08 - 000000000 ____D C:\Users\Normal\AppData\Roaming\IObit
2019-07-17 13:26 - 2018-09-29 12:08 - 000000000 ____D C:\ProgramData\IObit
2019-07-17 13:26 - 2018-09-29 12:08 - 000000000 ____D C:\Program Files (x86)\IObit
2019-07-17 11:04 - 2019-04-23 22:20 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2019-07-16 22:40 - 2019-04-23 22:20 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2019-07-15 21:55 - 2017-08-06 03:16 - 000000000 ____D C:\ProgramData\Norton
2019-07-15 21:41 - 2017-08-06 03:16 - 000000000 ____D C:\ProgramData\NortonInstaller
2018-02-01 13:41 - 2018-02-01 13:41 - 000000052 _____ () C:\Users\Normal\AppData\Local\b5wqke8ztn
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ContextMenuHandlers1: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} =>  -> No File
ContextMenuHandlers1: [kwansvc] -> {367F6AE2-6809-4bed-B09B-228893FB33DD} =>  -> No File
ContextMenuHandlers1: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ContextMenuHandlers2: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} =>  -> No File
ContextMenuHandlers2: [kwansvc] -> {367F6AE2-6809-4bed-B09B-228893FB33DD} =>  -> No File
ContextMenuHandlers2: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ContextMenuHandlers3: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ContextMenuHandlers4: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} =>  -> No File
ContextMenuHandlers4: [kwansvc] -> {367F6AE2-6809-4bed-B09B-228893FB33DD} =>  -> No File
ContextMenuHandlers4: [MEGA (Context menu)] -> {0229E5E7-09E9-45CF-9228-0228EC7D5F17} => C:\Users\Normal\AppData\Local\MEGAsync\ShellExtX64.dll -> No File
ContextMenuHandlers5: [kwansvc] -> {367F6AE2-6809-4bed-B09B-228893FB33DD} =>  -> No File
FirewallRules: [{802F434E-D60A-42BF-803E-F3EC495259B7}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.0.3\DriverBooster.exe No File
FirewallRules: [{1449D679-FA6E-433A-90C3-9CFC30891389}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.0.3\DriverBooster.exe No File
FirewallRules: [{A665AB85-E6BF-499D-9D20-2EDDCD49D668}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.0.3\DBDownloader.exe No File
FirewallRules: [{96F9D511-06C5-4019-A9F4-FD2259EBC9A8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.0.3\DBDownloader.exe No File
FirewallRules: [{E8364BA5-7E1F-4CB9-9F30-4693EB00B756}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.0.3\AutoUpdate.exe No File
FirewallRules: [{02EAB122-F8A2-4D58-941C-43780D31DDDE}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.0.3\AutoUpdate.exe No File

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
*****************

Processes closed successfully.
Restore point was successfully created.
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\" => not found
"HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\TaskbarNoNotification" => removed successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\HideSCAHealth" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => value restored successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{51B02C18-1DE2-471C-84CF-E6656417FFF2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51B02C18-1DE2-471C-84CF-E6656417FFF2}" => removed successfully
C:\Windows\System32\Tasks\{3DCB0C89-2F74-2E1A-48BA-2860FFFF93C0} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{3DCB0C89-2F74-2E1A-48BA-2860FFFF93C0}" => removed successfully
C:\Users\Normal\AppData\Roaming\Recodul => moved successfully
C:\Windows\Tasks\{3DCB0C89-2F74-2E1A-48BA-2860FFFF93C0}.job => moved successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{e5badea7-e1c2-fbf1-87ac-061d1440d15b} => removed successfully
HKLM\Software\Classes\CLSID\{e5badea7-e1c2-fbf1-87ac-061d1440d15b} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{e5badea7-e1c2-fbf1-87ac-061d1440d15b} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{e5badea7-e1c2-fbf1-87ac-061d1440d15b} => not found
"HKU\S-1-5-21-2393600599-662570708-1542540813-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-2393600599-662570708-1542540813-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{44177982-996D-4b79-B29F-5B60E13A5169} => removed successfully
HKLM\Software\Classes\CLSID\{44177982-996D-4b79-B29F-5B60E13A5169} => not found
HKU\S-1-5-21-2393600599-662570708-1542540813-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{e5badea7-e1c2-fbf1-87ac-061d1440d15b} => removed successfully
HKLM\Software\Classes\CLSID\{e5badea7-e1c2-fbf1-87ac-061d1440d15b} => not found
"HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-11-12] (Oracle America, Inc." => not found
C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll => moved successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@kingsfot.com/npkws => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx => moved successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ngpampappnmepgilojfohadhhmbhlaek => removed successfully
"C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx" => not found
HKLM\System\CurrentControlSet\Services\KMSEmulator => removed successfully
KMSEmulator => service removed successfully
HKLM\System\CurrentControlSet\Services\bafkwdyy => removed successfully
bafkwdyy => service removed successfully
HKLM\System\CurrentControlSet\Services\bootsafe => removed successfully
bootsafe => service removed successfully
HKLM\System\CurrentControlSet\Services\ckmyfrde => removed successfully
ckmyfrde => service removed successfully
HKLM\System\CurrentControlSet\Services\cwwrngng => removed successfully
cwwrngng => service removed successfully
HKLM\System\CurrentControlSet\Services\djsktwhu => removed successfully
djsktwhu => service removed successfully
HKLM\System\CurrentControlSet\Services\fergugjp => removed successfully
fergugjp => service removed successfully
HKLM\System\CurrentControlSet\Services\fsjdmqwg => removed successfully
fsjdmqwg => service removed successfully
HKLM\System\CurrentControlSet\Services\fvxicksk => removed successfully
fvxicksk => service removed successfully
HKLM\System\CurrentControlSet\Services\heyhyfoz => removed successfully
heyhyfoz => service removed successfully
HKLM\System\CurrentControlSet\Services\ihkebpsg => removed successfully
ihkebpsg => service removed successfully
HKLM\System\CurrentControlSet\Services\ksapi64 => removed successfully
ksapi64 => service removed successfully
HKLM\System\CurrentControlSet\Services\lxpsrkaf => removed successfully
lxpsrkaf => service removed successfully
HKLM\System\CurrentControlSet\Services\mubblxro => removed successfully
mubblxro => service removed successfully
HKLM\System\CurrentControlSet\Services\nggolwdv => removed successfully
nggolwdv => service removed successfully
HKLM\System\CurrentControlSet\Services\nmyrotat => removed successfully
nmyrotat => service removed successfully
HKLM\System\CurrentControlSet\Services\rjwfcbio => removed successfully
rjwfcbio => service removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs dg597 => removed successfully
C:\Windows\wininit.ini => moved successfully
C:\Windows\System32\Tasks\{D9E7C655-6C3E-4848-936D-33A40A8BAC87} => moved successfully
C:\Users\Normal\AppData\Roaming\Melem => moved successfully
C:\Users\Normal\AppData\Roaming\Dokaraficu => moved successfully
C:\Users\Normal\AppData\Roaming\Pahenolefas => moved successfully
C:\ProgramData\{B7AA8B96-9F82-F3EE-C7DA-DBC62F32031E} => moved successfully
C:\Users\Normal\AppData\Local\Baheb => moved successfully
C:\Users\Normal\AppData\Local\Fobumud => moved successfully
C:\Users\Normal\AppData\Roaming\Kubapiboka => moved successfully
C:\streamer => moved successfully
"C:\streamer" => not found
"C:\Users\Normal\AppData\Roaming\Recodul" => not found
C:\Users\Normal\AppData\Roaming\IObit => moved successfully
C:\ProgramData\IObit => moved successfully
C:\Program Files (x86)\IObit => moved successfully
C:\Program Files (x86)\Spybot - Search & Destroy 2 => moved successfully
C:\ProgramData\Spybot - Search & Destroy => moved successfully
C:\ProgramData\Norton => moved successfully
C:\ProgramData\NortonInstaller => moved successfully
C:\Users\Normal\AppData\Local\b5wqke8ztn => moved successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Pending) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Synced) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Syncing) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\duba_64bit => removed successfully
HKLM\Software\Classes\CLSID\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\kwansvc => removed successfully
HKLM\Software\Classes\CLSID\{367F6AE2-6809-4bed-B09B-228893FB33DD} => not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\MEGA (Context menu) => removed successfully
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\duba_64bit => removed successfully
HKLM\Software\Classes\CLSID\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => not found
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\kwansvc => removed successfully
HKLM\Software\Classes\CLSID\{367F6AE2-6809-4bed-B09B-228893FB33DD} => not found
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\MEGA (Context menu) => removed successfully
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\MEGA (Context menu) => removed successfully
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\duba_64bit => removed successfully
HKLM\Software\Classes\CLSID\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\kwansvc => removed successfully
HKLM\Software\Classes\CLSID\{367F6AE2-6809-4bed-B09B-228893FB33DD} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MEGA (Context menu) => removed successfully
HKLM\Software\Classes\CLSID\{0229E5E7-09E9-45CF-9228-0228EC7D5F17} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\kwansvc => removed successfully
HKLM\Software\Classes\CLSID\{367F6AE2-6809-4bed-B09B-228893FB33DD} => not found
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{802F434E-D60A-42BF-803E-F3EC495259B7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1449D679-FA6E-433A-90C3-9CFC30891389}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A665AB85-E6BF-499D-9D20-2EDDCD49D668}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{96F9D511-06C5-4019-A9F4-FD2259EBC9A8}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E8364BA5-7E1F-4CB9-9F30-4693EB00B756}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{02EAB122-F8A2-4D58-941C-43780D31DDDE}" => removed successfully

========= ipconfig /flushdns =========


Configuracion IP de Windows

Se vacio correctamente la cache de resolucion de DNS.

========= End of CMD: =========


========= ipconfig /renew =========


Configuracion IP de Windows

No se puede realizar ninguna operacion en Ethernet mientras los medios
esten desconectados.
No se puede realizar ninguna operacion en Conexion de area local* 10 mientras los medios
esten desconectados.

Adaptador de Ethernet Ethernet:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS especifico para la conexion. . : cantv.net

Adaptador de LAN inalambrica Conexion de area local* 10:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS especifico para la conexion. . : 

Adaptador de LAN inalambrica Wi-Fi:

   Sufijo DNS especifico para la conexion. . : 
   Vinculo: direccion IPv6 local. . . : fe80::89b:abdb:4c10:681d%8
   Direccion IPv4. . . . . . . . . . . . . . : 192.168.0.111
   Mascara de subred . . . . . . . . . . . . : 255.255.255.0
   Puerta de enlace predeterminada . . . . . : 192.168.0.1

Adaptador de tunel isatap.{4C57F94B-94E8-45C3-AAB4-26C468C27CF8}:

   Estado de los medios. . . . . . . . . . . : medios desconectados
   Sufijo DNS especifico para la conexion. . : 

========= End of CMD: =========


========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {45DF854D-7627-4652-809F-FAA8259CAFE1}.
{51E4F461-2F25-4F39-A413-F0567AF01420} canceled.
{9DCEE33B-82FD-4F3F-A570-57B6546B9DBF} canceled.
{9795E54B-FD66-40BD-B47B-AB15DA0BBF49} canceled.
{37BC0E1D-68B4-4C5A-BC27-AAEFCF6831EA} canceled.
Unable to cancel {2C809721-8C92-421B-A105-9215A99FB268}.
4 out of 6 jobs canceled.

========= End of CMD: =========


========= netsh winsock reset =========


El catalogo Winsock se restablecio correctamente.
Debe reiniciar el equipo para completar el restablecimiento.


========= End of CMD: =========


========= netsh advfirewall reset =========

Aceptar


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Aceptar


========= End of CMD: =========


========= netsh int ipv4 reset =========

Global se restablecio correctamente.
Interfaz se restablecio correctamente.
Direccion de unidifusion se restablecio correctamente.
Vecino se restablecio correctamente.
Ruta de acceso se restablecio correctamente.
Ruta se restablecio correctamente.
Error al restablecer .
Acceso denegado.

 se restablecio correctamente.
Reinicie el equipo para completar esta accion.


========= End of CMD: =========


========= netsh int ipv6 reset =========

Interfaz se restablecio correctamente.
Vecino se restablecio correctamente.
Ruta de acceso se restablecio correctamente.
Error al restablecer .
Acceso denegado.

 se restablecio correctamente.
 se restablecio correctamente.
Reinicie el equipo para completar esta accion.


========= End of CMD: =========


========= RemoveProxy: =========

"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-2393600599-662570708-1542540813-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-2393600599-662570708-1542540813-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========

Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 32768 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 43636093 B
Java, Flash, Steam htmlcache => 12919462 B
Windows/system/drivers => 69572 B
Edge => 33554 B
Chrome => 0 B
Firefox => 0 B
Opera => 169863498 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 1051354 B
systemprofile32 => 27624 B
LocalService => 5006 B
NetworkService => 5314 B
defaultuser0 => 128 B
Normal => 48666320 B

RecycleBin => 35829241 B
EmptyTemp: => 297.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 02:39:57 ====

Desde Aquí Mil Gracias Ya No Tengo El Virus Por El Que Comenzó El Post Y Ahora Tampoco El Streamer Muchas Gracias Marcare Como Solucionado Este Post

Hola @Edgardo1

Para eliminar las herramientas utilizadas:

Descargas >> [size=2]Delfix[/size], a tu escritorio.

  • Doble clic para ejecutarlo.(Si usas Windows Vista/7 /8 /10,presiona clic derecho y selecciona >> “Ejecutar como Administrador”)
  • Marca las casilla Remove disinfection tools y Purgue Sistem Restore
  • Pulsar en Run.

Se abrirá el informe (DelFix.txt), guárdalo por si fuera necesario y cierra la herramienta.


Que bueno que hayamos podido resolver tu consulta…:+1:

Para otros problemas, ya sabes donde encontrarnos. :wink:

Tema Solucionado

Salu2.