Pc infectada

Hola @Gonzalo_Rodrigo_Orda

Ejecutaste la herramienta de desinstalación de AVG? :thinking:

Te consulto pues quedaron muchísimos restos de Spybot, AVg y Malwarebytes.

Veremos si por fin podemos eliminarlos, con mucha atención sigue estos pasos:

1.- Muy Importante >>> Realizar una copia de Seguridad de su Registro.

  • Descarga/Ejecuta DelFix desde el escritorio de Windows.
  • Clic Derecho, “Ejecutar como Administrador”.
  • En la ventana principal, marca solamente la casilla “Create Registry Backup”.
  • Clic en Run.

Al terminar se abrirá un reporte llamado DelFix.txt, guárdelo por si fuera necesario y cierre la herramienta…

Luego ve a::

2.- Inicio >>> Ejecutar >>> Escribe notepad.exe o abra un nuevo archivo Notepad y copie y pegue lo siguiente:

Start::
CloseProcesses:
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupSvc.exe
(AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\TuneUp\TuneupUI.exe <2>
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd. -> Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
HKLM\...\Run: [AVGUI.exe] => "C:\Program Files\AVG\Antivirus\AvLaunch.exe" /gui
HKLM\...\Run: [TuneupUI.exe] => C:\Program Files\AVG\TuneUp\TuneupUI.exe [2609680 2020-08-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [6788032 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\84.0.4147.125\Installer\chrmstp.exe [2020-08-11] (Google LLC -> Google LLC)
BootExecute: autocheck autochk * icarus_rvrt.exesdnclean64.exe
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restricción <==== ATENCIÓN
Task: {49D10266-6188-45E5-B7BF-4471A9D93069} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [7651984 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {630773AA-D52F-4EBB-9268-A30E98926D92} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [6944304 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: {8E71F49E-41C6-4CBE-B71E-0C6398E20BC6} - System32\Tasks\AVG\AVG TuneUp Update => C:\Program Files\Common Files\AVG\Icarus\avg-tu\icarus.exe [5151368 2020-07-08] (AVG Technologies USA, LLC -> AVG Technologies)
Task: {A930E652-32EF-43A4-BEF1-0FCECEC219DF} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe
Task: {AC573465-A9A5-49AD-B415-AF91A88FA20A} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe
Task: {BCA91E99-85BE-4676-9E48-E0D5915F8EA6} - System32\Tasks\AVG\AVG TuneUp Update BugReport => C:\Program Files\AVG\TuneUp\AvBugReport.exe [2812656 2020-08-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
Task: {FD9288F7-4A3D-4B2D-A0F1-C2C7D68377AC} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [7192192 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Ningún archivo]
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [Ningún archivo]
R2 CleanupPSvc; C:\Program Files\AVG\TuneUp\TuneupSvc.exe [12987160 2020-08-02] (AVG Technologies USA, LLC -> AVG Technologies CZ, s.r.o.)
S2 MBAMInstallerService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe [6316568 2020-08-02] (Malwarebytes Inc -> Malwarebytes)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3892256 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [3943664 2018-04-20] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233712 2018-02-06] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-08-02] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
2020-08-11 20:17 - 2020-08-11 20:17 - 000000000 ____D C:\Users\usuario\AppData\Roaming\AVG
2020-08-11 20:04 - 2020-08-11 20:33 - 000062939 _____ C:\Users\usuario\Desktop\mb-clean-results.txt
2020-08-11 20:02 - 2020-08-11 20:02 - 004146112 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgremoverx.exe
2020-08-11 19:49 - 2020-08-11 19:49 - 000858912 _____ (Malwarebytes) C:\Users\usuario\Downloads\mb-clean-3.1.0.1035.exe
2020-08-11 19:49 - 2020-08-11 19:49 - 000566128 _____ (Malwarebytes) C:\Users\usuario\Downloads\mbam-clean-2.3.0.1001.exe
2020-08-11 19:46 - 2020-08-11 19:47 - 013099408 _____ (AVG Technologies CZ, s.r.o.) C:\Users\usuario\Downloads\avgclear.exe
2020-08-10 20:25 - 2020-08-11 20:16 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2020-08-10 20:25 - 2020-08-10 20:25 - 000001460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2020-08-10 20:25 - 2020-08-10 20:25 - 000001448 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2020-08-10 20:25 - 2020-08-10 20:25 - 000000000 ____D C:\WINDOWS\system32\Tasks\Safer-Networking
2020-08-10 20:25 - 2020-08-10 20:25 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2020-08-10 20:25 - 2020-08-10 20:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2020-08-10 20:25 - 2018-02-06 19:04 - 000032168 _____ (Safer-Networking Ltd.) C:\WINDOWS\system32\sdnclean64.exe
2020-08-10 20:08 - 2020-08-10 21:22 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-08-10 20:04 - 2020-08-10 20:05 - 000425304 _____ (Secure By Design Inc.) C:\Users\usuario\Downloads\Ninite 7Zip AVG CDBurnerXP IrfanView Malwarebytes Installer.exe
2020-08-10 12:31 - 2020-08-10 12:31 - 000000000 ___HD C:\$AV_AVG
2020-08-02 19:54 - 2020-08-02 19:54 - 000001993 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-08-02 19:54 - 2020-08-02 19:53 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-08-02 19:46 - 2020-08-02 19:46 - 000000000 ____D C:\Program Files\Malwarebytes
2020-08-02 19:46 - 2020-08-02 19:46 - 000000000 ____D C:\Malwarebytes
2020-08-02 19:25 - 2020-08-02 19:25 - 000002023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG TuneUp.lnk
2020-08-02 19:24 - 2020-07-08 19:40 - 000129416 _____ (AVG Technologies) C:\WINDOWS\system32\icarus_rvrt.exe
2020-08-02 19:04 - 2020-08-11 19:55 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2020-08-02 18:55 - 2020-08-02 19:25 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVG
2020-08-02 18:54 - 2020-08-11 20:16 - 000000000 ____D C:\Program Files\Common Files\AVG
2020-08-02 18:54 - 2020-08-11 11:48 - 000004266 _____ C:\WINDOWS\system32\Tasks\Antivirus Emergency Update
2020-08-02 16:12 - 2020-08-11 20:16 - 000000000 ____D C:\Program Files\AVG
2020-08-02 16:11 - 2020-08-11 20:24 - 000000000 ____D C:\ProgramData\AVG
2020-07-16 23:36 - 2019-03-19 01:52 - 000000000 ____D C:\WINDOWS\system32\oobe
AV: Spybot - Search and Destroy (Enabled - Up to date) {F77C7796-45C4-531E-0DAE-B4A8229B11C8}
AV: AVG Antivirus (Enabled - Up to date) {18A975F9-A60C-37D8-E30B-4BEF31AD3411}
FW: AVG Antivirus (Enabled) {2092F4DC-EC63-3680-C854-E2DACF7E736A}
ContextMenuHandlers1: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers1: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2018-03-23] (Safer-Networking Ltd. -> Safer-Networking Ltd.)
FirewallRules: [TCP Query User{09F693C1-D23B-4077-9303-6A98D319197F}D:\lex10e\lex10e\servidor\lexsvrm.exe] => (Allow) D:\lex10e\lex10e\servidor\lexsvrm.exe => Ningún archivo
FirewallRules: [UDP Query User{E2ECD1ED-4D95-45EC-82A6-9D9C3A053F7C}D:\lex10e\lex10e\servidor\lexsvrm.exe] => (Allow) D:\lex10e\lex10e\servidor\lexsvrm.exe => Ningún archivo
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
C:\Program Files (x86)\Spybot - Search & Destroy 2
C:\Program Files\Common Files\AVG
C:\Program Files\Malwarebytes

CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
End::
  • Lo guarda bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

Nota: Es necesario que el ejecutable Frst.exe/Frst64.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajará.

3.- Inicie su ordenador en >>> Modo Seguro >>> Aplicable a Windows 10. o Windows 7.

  • Ejecute Frst.exe o Frst64.exe. según el caso.
  • Presione el botón Fix/Corregir y aguarde a que termine.
  • La Herramienta guardará el reporte en su escritorio (Fixlog.txt).
  • Reinicia y lo pega en su próxima respuesta.

Nos comentas…

Salu2