Hola, gracias que sigas mi caso San.
Aclararte que el ISO que baje era para un pdf no se porqué estaba en ISO. El tema es que me infectó y ademas quise eliminarlo y no me dejó.
Tal como me pediste estoy ejecutando el Malware, lo que me aparecio es que hay 313 archivos infectados y lo que me resulto raro que me gustaria que me aclaren es que me encontré con que nombres de archivos infectados eliminados me volvieron a aparecer en el informe y no se porque, o no se si porque desactive Panda y el W defender . Tambien algunos arhivos dentro de Windows y la pregunta es si eliminarlos no afectará posteriormente mi pc.
Me gustaría poder adjuntar el txt pero no supe como hacerlo.
Te voy a ir contando que me va pasando.
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 10/3/19
Hora del análisis: 18:08
Archivo de registro: abc98ba8-4378-11e9-9529-f0761ceda24a.json
-Información del software-
Versión: 3.7.1.2839
Versión de los componentes: 1.0.538
Versión del paquete de actualización: 1.0.9622
Licencia: Prueba
-Información del sistema-
SO: Windows 10 (Build 17134.590)
CPU: x64
Sistema de archivos: NTFS
Usuario: LENOVO-PC\Caro
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 350912
Amenazas detectadas: 313
Amenazas en cuarentena: 310
Tiempo transcurrido: 31 min, 41 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 2
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\ZWQxMmNmZDc2YTdiNjF.exe, En cuarentena, [498], [556539],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python.exe, En cuarentena, [3868], [628577],1.0.9622
Módulo: 6
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\ZWQxMmNmZDc2YTdiNjF.exe, En cuarentena, [498], [556539],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_ctypes.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python.exe, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python3.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python37.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\vcruntime140.dll, En cuarentena, [3868], [628577],1.0.9622
Clave del registro: 59
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WinBoxes, En cuarentena, [3868], [628576],1.0.9622
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{D8FAB731-6142-4104-B52F-E6C153F8A82A}, En cuarentena, [3868], [628576],1.0.9622
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{D8FAB731-6142-4104-B52F-E6C153F8A82A}, En cuarentena, [3868], [628576],1.0.9622
Adware.Wajam, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, En cuarentena, [498], [-1],0.0.0
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WinBoxes_upd, En cuarentena, [3868], [628576],1.0.9622
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{58F838F3-8BA2-4388-91C6-767E633C1C8F}, En cuarentena, [3868], [628576],1.0.9622
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{58F838F3-8BA2-4388-91C6-767E633C1C8F}, En cuarentena, [3868], [628576],1.0.9622
PUP.Optional.Kuaizip, HKU\S-1-5-21-4145286444-108475074-2886558672-1009_Classes\KuaiZipMount.flac, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.7z, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.arj, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.cab, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.gz, En cuarentena, [1163], [358174],1.0.9622
Adware.Wajam, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NzMyN2RhNDk0, En cuarentena, [498], [556539],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.lzh, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.tar, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.tgz, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZip.z, En cuarentena, [1163], [358174],1.0.9622
PUP.Optional.Kuaizip, HKLM\SOFTWARE\CLASSES\KuaiZipMount.iso, En cuarentena, [1163], [358174],1.0.9622
Adware.PBot, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WinBoxes, En cuarentena, [3868], [628577],1.0.9622
PUP.Optional.MailRu, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}, En cuarentena, [251], [382913],1.0.9622
PUP.Optional.Wajam, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\WajIEnhance, En cuarentena, [202], [244670],1.0.9622
Adware.PBot, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\WinBoxes, En cuarentena, [3868], [628574],1.0.9622
PUP.Optional.MailRu, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\GOOGLE\CHROME\NATIVEMESSAGINGHOSTS\ru.mail.go.ext_info_host, En cuarentena, [251], [485554],1.0.9622
Adware.SearchAwesome, HKLM\SOFTWARE\WOW6432NODE\SrcAAAesom Browser Enhancer, En cuarentena, [7180], [509886],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ikpcpgklmefncbfgbdifkaphbaapgafh, En cuarentena, [315], [590559],1.0.9622
PUP.Optional.MailRu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}, En cuarentena, [251], [471429],1.0.9622
Adware.SearchAwesome, HKLM\SOFTWARE\SrcAAAesom Browser Enhancer, En cuarentena, [7180], [509886],1.0.9622
Adware.Wajam, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\NzMyN2RhNDk0, En cuarentena, [498], [533738],1.0.9622
PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, En cuarentena, [202], [170024],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{8E8F97CD-60B5-456F-A201-73065652D099}, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\CLASSES\IESearchPlugin.MailRuBHO, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\CLASSES\IESearchPlugin.MailRuBHO.1, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8E8F97CD-60B5-456F-A201-73065652D099}, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8E8F97CD-60B5-456F-A201-73065652D099}, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\InprocServer32, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}\InprocServer32, En cuarentena, [315], [351113],1.0.9622
PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}, En cuarentena, [315], [351113],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\awunacyv, En cuarentena, [6008], [571190],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{24A0CF41-F2F1-4B3D-BFF9-663B1BB6462A}, En cuarentena, [6008], [571190],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{24A0CF41-F2F1-4B3D-BFF9-663B1BB6462A}, En cuarentena, [6008], [571190],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\eixiosxneotu, En cuarentena, [6008], [622116],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4AC1B838-F387-4105-80FF-3BA7D548D9A6}, En cuarentena, [6008], [622116],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{4AC1B838-F387-4105-80FF-3BA7D548D9A6}, En cuarentena, [6008], [622116],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\{705DD530-FFA8-005B-15D0-A66D57DBCB6B}, En cuarentena, [6008], [601196],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{6BAA1617-6581-46D5-B207-C5F4FF958178}, En cuarentena, [6008], [601196],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{6BAA1617-6581-46D5-B207-C5F4FF958178}, En cuarentena, [6008], [601196],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\pkpohu, En cuarentena, [6008], [622117],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BD9775E4-8448-49CA-B91A-3125FA19F2C2}, En cuarentena, [6008], [622117],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{BD9775E4-8448-49CA-B91A-3125FA19F2C2}, En cuarentena, [6008], [622117],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\aluzii, En cuarentena, [6008], [622125],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EBAC15E7-EFE5-4098-A331-BBE79B9C6AC2}, En cuarentena, [6008], [622125],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{EBAC15E7-EFE5-4098-A331-BBE79B9C6AC2}, En cuarentena, [6008], [622125],1.0.9622
PUP.Optional.Wajam, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, En cuarentena, [202], [170024],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\{08537B65-4445-A400-B6ED-6A89BFC3BF4D}, En cuarentena, [6008], [601195],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{AC1506E3-8028-4EFB-BC0B-BD6EBA73F182}, En cuarentena, [6008], [601195],1.0.9622
Trojan.BitCoinMiner.BatBitRst, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{AC1506E3-8028-4EFB-BC0B-BD6EBA73F182}, En cuarentena, [6008], [601195],1.0.9622
PUP.Optional.Wajam, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9, En cuarentena, [202], [170024],1.0.9622
PUP.Optional.MailRu, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\iepoegkaoeljnbhagabakjodgpfniimo, En cuarentena, [251], [454830],1.0.9622
Valor del registro: 18
Adware.Wajam, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Error durante la eliminación, [498], [-1],0.0.0
Adware.Wajam, HKU\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, En cuarentena, [498], [-1],0.0.0
Adware.Wajam, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, En cuarentena, [498], [-1],0.0.0
Adware.Wajam, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Error durante la eliminación, [498], [-1],0.0.0
Adware.PBot, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinBoxes, En cuarentena, [3868], [628577],1.0.9622
PUP.Optional.MailRu, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}|URL, En cuarentena, [251], [382913],1.0.9622
PUP.Optional.MailRu, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}|FAVICONURLFALLBACK, En cuarentena, [251], [382913],1.0.9622
PUP.Optional.MailRu, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FFEBBF0A-C22C-4172-89FF-45215A135AC7}|SUGGESTIONSURL, En cuarentena, [251], [382913],1.0.9622
PUP.Optional.Kuaizip, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FILEEXTS\.bin\OPENWITHPROGIDS|KUAIZIPMOUNT.BIN, En cuarentena, [1163], [392706],1.0.9622
Adware.PBot.Generic, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinBoxes_upd, En cuarentena, [3740], [629213],1.0.9622
PUP.Optional.RussAd, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|IKPCPGKLMEFNCBFGBDIFKAPHBAAPGAFH, En cuarentena, [315], [590559],1.0.9622
PUP.Optional.MailRu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}|APPPATH, En cuarentena, [251], [471429],1.0.9622
Adware.PBot.Generic, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WINBOXES_UPD, En cuarentena, [3740], [646249],1.0.9622
Adware.Wajam, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\NzMyN2RhNDk0|DISPLAYNAME, En cuarentena, [498], [533738],1.0.9622
Adware.Wajam, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\NzMyN2RhNDk0|PUBLISHER, En cuarentena, [498], [533738],1.0.9622
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{58F838F3-8BA2-4388-91C6-767E633C1C8F}|PATH, En cuarentena, [3868], [628571],1.0.9622
Adware.PBot, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{D8FAB731-6142-4104-B52F-E6C153F8A82A}|PATH, En cuarentena, [3868], [628571],1.0.9622
PUP.Optional.MailRu, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|iepoegkaoeljnbhagabakjodgpfniimo, En cuarentena, [251], [454830],1.0.9622
Datos del registro: 1
Adware.MailRu.BatBitRst, HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Sustituido, [325], [481471],1.0.9622
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 11
PUP.Optional.MailRu, C:\PROGRAM FILES (X86)\MAIL.RU, En cuarentena, [251], [384138],1.0.9622
Trojan.Agent, C:\WINDOWS\SYSTEM32\SSL, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\WINDOWS\SYSWOW64\SSL, En cuarentena, [419], [479103],1.0.9622
Adware.Wajam, C:\WINDOWS\SYSWOW64\SSL, En cuarentena, [498], [533889],1.0.9622
Adware.OnlineIO, C:\WINDOWS\INSTALLER\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}, En cuarentena, [1198], [414815],1.0.9622
Adware.Wajam, C:\PROGRAM FILES\NzMyN2RhNDk0, En cuarentena, [498], [556539],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\js, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\USERS\CARO\APPDATA\ROAMING\WINBOXES, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\USERS\CARO\APPDATA\ROAMING\WinBoxes_upd, En cuarentena, [3740], [629213],1.0.9622
Archivo: 216
Adware.Zdengo, C:\WINDOWS\System32\drivers\ZmQ1OTY5NzQ2MmViZjA0, En cuarentena, [499], [626166],0.0.0
Adware.OnlineIO, C:\WINDOWS\INSTALLER\SOURCEHASH{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}, En cuarentena, [1198], [414818],1.0.9622
Trojan.Agent, C:\WINDOWS\SYSTEM32\SSL\XV.DB, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\System32\SSL\cert.db, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\System32\SSL\e1914b145176465a.cer, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\System32\SSL\x.db, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\System32\SSL\xtls.db, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\WINDOWS\SYSWOW64\SSL\XV.DB, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\SysWOW64\SSL\cert.db, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\SysWOW64\SSL\x.db, En cuarentena, [419], [479103],1.0.9622
Trojan.Agent, C:\Windows\SysWOW64\SSL\YzBhMmQzZGRmNjRm 2.cer, En cuarentena, [419], [479103],1.0.9622
Adware.PBot, C:\WINDOWS\SYSTEM32\TASKS\WinBoxes, En cuarentena, [3868], [628576],1.0.9622
Adware.Wajam, C:\WINDOWS\SYSWOW64\SSL\CERT.DB, En cuarentena, [498], [533889],1.0.9622
Adware.Wajam, C:\Windows\SysWOW64\SSL\x.db, En cuarentena, [498], [533889],1.0.9622
Adware.Wajam, C:\Windows\SysWOW64\SSL\xv.db, En cuarentena, [498], [533889],1.0.9622
Adware.Wajam, C:\Windows\SysWOW64\SSL\YzBhMmQzZGRmNjRm 2.cer, En cuarentena, [498], [533889],1.0.9622
Adware.PBot, C:\WINDOWS\SYSTEM32\TASKS\WinBoxes_upd, En cuarentena, [3868], [628576],1.0.9622
Adware.OnlineIO, C:\Windows\Installer\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}\online.exe, En cuarentena, [1198], [414815],1.0.9622
Adware.OnlineIO, C:\Windows\Installer\{52F7BE5C-2C3B-4C7B-A96D-F19B9EC1992D}\SystemFoldermsiexec.exe, En cuarentena, [1198], [414815],1.0.9622
Adware.Wajam, C:\PROGRAM FILES\NzMyN2RhNDk0\WBE_uninstall.dat, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\mozcrt19.dll, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\NGQ5MWQyO.ico, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\nspr4.dll, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\nss3.dll, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\NTExYjU2Ym.exe, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\plc4.dll, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\plds4.dll, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\service.dat, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\service_64.dat, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\softokn3.dll, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\Y2ViMzM0NDUwZGY0Y.exe, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\YThmOWNkM2NmN2U, En cuarentena, [498], [556539],1.0.9622
Adware.Wajam, C:\Program Files\NzMyN2RhNDk0\ZWQxMmNmZDc2YTdiNjF.exe, En cuarentena, [498], [556539],1.0.9622
PUP.Optional.MailRu, C:\USERS\CARO\FAVORITES\Mail.Ru.url, En cuarentena, [251], [471428],1.0.9622
Adware.PBot, C:\USERS\CARO\APPDATA\ROAMING\WINBOXES\PYTHON\api-ms-win-core-console-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\js\guid.js, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\js\storage.js, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\js\storage.js.sha1, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_ctypes.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_decimal.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_distutils_findvs.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_elementtree.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_hashlib.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_lzma.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_msi.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_multiprocessing.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_overlapped.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_queue.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_socket.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_sqlite3.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_ssl.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-handle-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-heap-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-interlocked-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-libraryloader-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-localization-l1-2-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-memory-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-namedpipe-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-processenvironment-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-processthreads-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-processthreads-l1-1-1.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-profile-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-rtlsupport-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-synch-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-synch-l1-2-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-sysinfo-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-timezone-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-util-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-conio-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-convert-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-environment-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-filesystem-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-heap-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-locale-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-math-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-multibyte-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-datetime-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-debug-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-errorhandling-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-file-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-file-l1-2-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-file-l2-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-core-string-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-private-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-process-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-runtime-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-stdio-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-string-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-time-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\api-ms-win-crt-utility-l1-1-0.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\libcrypto-1_1.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\libssl-1_1.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\pyexpat.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python.exe, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python3.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python37.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python37.zip, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\python37._pth, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\pythonw.exe, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\select.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\sqlite3.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\ucrtbase.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\unicodedata.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\vcruntime140.dll, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\winsound.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_asyncio.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_bz2.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\python\_contextvars.pyd, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\filter.bin, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\rules.ini, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\settings.ini, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\start.bin, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\start.pyc, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\subid.txt, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\time.txt, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\uninstall.exe, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot, C:\Users\Caro\AppData\Roaming\WinBoxes\uuid.txt, En cuarentena, [3868], [628577],1.0.9622
Adware.PBot.Generic, C:\USERS\CARO\APPDATA\ROAMING\WinBoxes_upd\PYTHON\pythonw.exe, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_ctypes.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_decimal.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_distutils_findvs.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_elementtree.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_hashlib.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_lzma.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_msi.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_multiprocessing.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_overlapped.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_queue.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_socket.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_sqlite3.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_ssl.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-handle-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-heap-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-interlocked-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-libraryloader-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-localization-l1-2-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-memory-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-namedpipe-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-processenvironment-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-processthreads-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-processthreads-l1-1-1.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-profile-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-rtlsupport-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-synch-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-synch-l1-2-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-sysinfo-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-timezone-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-util-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-conio-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-convert-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-environment-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-filesystem-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-heap-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-locale-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-math-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-multibyte-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-console-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-datetime-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-debug-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-errorhandling-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-file-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-file-l1-2-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-file-l2-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-core-string-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-private-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-process-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-runtime-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-stdio-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-string-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-time-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\api-ms-win-crt-utility-l1-1-0.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\libcrypto-1_1.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\libssl-1_1.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\pyexpat.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\python.exe, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\python3.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\python37.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\python37.zip, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\python37._pth, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\select.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\sqlite3.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\ucrtbase.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\unicodedata.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\vcruntime140.dll, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\winsound.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_asyncio.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_bz2.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\python\_contextvars.pyd, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\id.txt, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\path.txt, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\start.bin, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\start.pyc, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\subid.txt, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\time.txt, En cuarentena, [3740], [629213],1.0.9622
Adware.PBot.Generic, C:\Users\Caro\AppData\Roaming\WinBoxes_upd\utctimestamp.txt, En cuarentena, [3740], [629213],1.0.9622
PUP.Optional.RussAd, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sustituido, [315], [590559],1.0.9622
Adware.MailRu.BatBitRst, C:\USERS\CARO\FAVORITES\Искать в Интернете.URL, En cuarentena, [325], [648495],1.0.9622
Adware.MailRu.BatBitRst, C:\USERS\CARO\ONEDRIVE\ESCRITORIO\Искать в Интернете.URL, Error durante la eliminación, [325], [481462],1.0.9622
PUP.Optional.RussAd, C:\USERS\CARO\APPDATA\LOCAL\MAIL.RU\SPUTNIK\IE_ADDON_DLL.DLL, En cuarentena, [315], [351113],1.0.9622
Trojan.BitCoinMiner.BatBitRst, C:\WINDOWS\SYSTEM32\TASKS\awunacyv, En cuarentena, [6008], [571190],1.0.9622
Trojan.BitCoinMiner.BatBitRst, C:\WINDOWS\SYSTEM32\TASKS\eixiosxneotu, En cuarentena, [6008], [622116],1.0.9622
Trojan.BitCoinMiner.BatBitRst, C:\WINDOWS\SYSTEM32\TASKS\{705DD530-FFA8-005B-15D0-A66D57DBCB6B}, En cuarentena, [6008], [601196],1.0.9622
Trojan.BitCoinMiner.BatBitRst, C:\WINDOWS\SYSTEM32\TASKS\pkpohu, En cuarentena, [6008], [622117],1.0.9622
Trojan.BitCoinMiner.BatBitRst, C:\WINDOWS\SYSTEM32\TASKS\aluzii, En cuarentena, [6008], [622125],1.0.9622
Trojan.BitCoinMiner.BatBitRst, C:\WINDOWS\SYSTEM32\TASKS\{08537B65-4445-A400-B6ED-6A89BFC3BF4D}, En cuarentena, [6008], [601195],1.0.9622
Misplaced.Legit.BatBitRst, C:\PROGRAM FILES (X86)\TZEA.EXE, En cuarentena, [10828], [632788],1.0.9622
Misplaced.Legit.BatBitRst, C:\PROGRAM FILES (X86)\LXAYLUEDDFS.EXE, En cuarentena, [10828], [632788],1.0.9622
Misplaced.Legit.BatBitRst, C:\PROGRAM FILES (X86)\JKYUIJ.EXE, En cuarentena, [10828], [632798],1.0.9622
PUP.Optional.InstallCore.Generic, C:\USERS\CARO\DOWNLOADS\WBS CHART PRO_4017496038.EXE, En cuarentena, [542], [512142],1.0.9622
PUP.Optional.MailRu, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sustituido, [251], [454830],1.0.9622
PUP.Optional.MailRu, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sustituido, [251], [454830],1.0.9622
PUP.Optional.MailRu, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sustituido, [251], [454830],1.0.9622
PUP.Optional.Linkury.Generic, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\SyncData.sqlite3, Sustituido, [218], [454805],1.0.9622
PUP.Optional.Linkury.Generic, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, [218], [454805],1.0.9622
PUP.Optional.SonicSearch, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, [370], [519968],1.0.9622
PUP.Optional.SonicSearch, C:\USERS\CARO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, [370], [519968],1.0.9622
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
Bueno ejecute ADW Cleaner y cuando reinicie me tardó en iniciar … hasta que cuando inicio me puso un cartel azul que " se produjo un error al iniciar Windows" y un codigo QR que no pude sacarle foto, cuando me di cuenta de desaparecio y se apago. Asi que volvi a proceder a reiniciar.
# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-03-04.3 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-10-2019
# Duration: 00:00:13
# OS: Windows 10 Home Single Language
# Cleaned: 5
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|KuaiZip Shell Extension
Deleted HKLM\Software\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\chatango.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\chatango.com
Deleted HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2027 octets] - [10/03/2019 19:35:56]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
este es el informe del scan
# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-03-04.3 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 03-10-2019
# Duration: 00:00:29
# OS: Windows 10 Home Single Language
# Scanned: 31858
# Detected: 5
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
No malicious folders found.
***** [ Files ] *****
No malicious files found.
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.Legacy HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|KuaiZip Shell Extension
PUP.Optional.Legacy HKLM\Software\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\UCBrowser.exe
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\chatango.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\chatango.com
PUP.Winlogon.Heuristic HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries found.
***** [ Chromium URLs ] *****
No malicious Chromium URLs found.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
En la medida que estoy trabajando me aparece un cartel blanco escrito en verdad que me notifica " sitio web bloqueado debido a pop up" … no se a que se debe porque estoy trabajando en este problema y solo tengo abierto el chrome en el foro y las paginas que abro, pero me es muy molesto la notificacion.
Por otro lado informarte que la configuracion de windows estaba teniendo problemas cuando la quería usar. y tambien veo que al usar los programas veo mucho " claves del registro " y me pregunto que es