Mi notebook se infecto al descargar un ISO

Hola @Carolina_Saggio

Tu equipo esta raro, llamare a un compañero de Hard para que nos eche una mano para verificar tu disco.

Intentemos terminar con la limpieza haber si nos deja.

Te dejo los pasos, recuerda colocar los ejecutables en el escritorio >>> Modo Normal


1.- Muy Importante >>> Realizar una copia de Seguridad de su Registro.

  • Descarga DelFix en el escritorio de Windows.
  • Clic Derecho, “Ejecutar como Administrador”.
  • En la ventana principal, marca solamente la casilla “Create Registry Backup”.
  • Clic en Run.

Al terminar se abrirá un reporte llamado DelFix.txt, guárdelo por si fuera necesario y cierre la herramienta…

2.- Desactiva Temporalmente tu antivirus.

3.- Abre un nuevo archivo Notepad y copia y pega este contenido:


Start
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction ? <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\...\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2409424 2018-04-24] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2386384 2018-04-24] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\...\RunOnce: [Application Restart #2] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [16093512 2015-08-15] (Lenovo (Beijing) Limited -> Lenovo(beijing) Limited)
HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\...\RunOnce: [Application Restart #3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1587680 2018-12-12] (Google Inc -> Google Inc.)
HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\...\RunOnce: [Application Restart #4] => C:\Windows\RTFTrack.exe [5060864 2015-11-11] (Realtek Semiconductor Corp -> Realtek semiconductor)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
CHR Extension: (Chrome Media Router) - C:\Users\Caro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-27]
CHR HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Caro\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2017-03-21]
CHR HKU\S-1-5-21-4145286444-108475074-2886558672-1009\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Caro\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2017-03-21]
CHR HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03212019223050082\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
FF Plugin: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-05-29] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-05-29] (Oracle America, Inc. -> Oracle Corporation)
S1 ZmQ1OTY5NzQ2MmViZjA0; \??\C:\WINDOWS\system32\drivers\ZmQ1OTY5NzQ2MmViZjA0 [X]
2019-03-13 00:05 - 2019-03-13 00:05 - 010607000 _____ (McAfee, Inc.) C:\Users\Caro\Downloads\MCPR.exe
2019-03-13 00:11 - 2018-05-29 02:41 - 000000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2019-03-10 18:54 - 2018-07-26 22:05 - 000000648 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-4145286444-108475074-2886558672-1009.job
2019-03-10 18:54 - 2018-07-26 22:05 - 000000552 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-4145286444-108475074-2886558672-1009.job
CustomCLSID: HKU\S-1-5-21-4145286444-108475074-2886558672-1009_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Caro\AppData\Local\GoToMeeting\8953\G2MOutlookAddin64.dll => No File
CustomCLSID: HKU\S-1-5-21-4145286444-108475074-2886558672-1009-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-03232019024006980_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Caro\AppData\Local\GoToMeeting\8953\G2MOutlookAddin64.dll => No File
ContextMenuHandlers1: [ContextMenuExt] -> {6ADF19E3-77A3-4395-ADB4-9FD7D351EB3E} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
Task: {5E1F9D01-1F53-47CF-89E6-303C4E5107EC} - no filepath
Task: {8C4298DB-5950-4E87-AC81-36679A0AF032} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {F84AE722-1E42-4351-B7BE-3DEF1499004C} - no filepath
AlternateDataStreams: C:\Users\Caro\OneDrive\Documentos\CyberLink:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\Caro\OneDrive\Documentos\Lenovo:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\Caro\OneDrive\Documentos\Plantillas personalizadas de Office:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
AlternateDataStreams: C:\Users\Caro\OneDrive\Documentos\WBS Schedule Pro:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194]
FirewallRules: [{4964FC4B-F48F-4934-9E84-65641CB9287D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe No File
FirewallRules: [{440E1684-EC4E-43DF-A50D-59B0BEFD88D7}] => (Allow) C:\Program Files (x86)\Common Files\Mcafee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{F485ED72-1381-4C95-80C6-65E984914B0D}] => (Allow) C:\Program Files\Common Files\McAfee\MMSSHost\MMSSHost.exe No File
FirewallRules: [{AD90C594-2F9E-412E-87A3-9D49110727B6}] => (Allow) C:\Program Files (x86)\lXAYLUeDDfS.exe No File
FirewallRules: [{3AAFFCE5-D672-45B3-AAE9-051CE33B9229}] => (Allow) C:\Program Files (x86)\TZEA.exe No File

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
END
  • Lo guardas bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

Nota: Es necesario que el ejecutable Frst.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajara.

  • Ejecutas Frst.exe.
  • Presionas el botón Fix y aguardas a que termine.
  • La Herramienta guardara el reporte en tu escritorio (Fixlog.txt).
  • Lo pegas en tu próxima respuesta.

Nos comentas .

Salu2.