Hola de nuevo, antes de nada agradecerte por contestar y ayudarme, aqui estan los reportes del malwarebyte y del adwcleaner:
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 23/4/19
Hora del análisis: 12:00
Archivo de registro: 90911132-65ae-11e9-8f10-4c72b9e26374.json
-Información del software-
Versión: 3.7.1.2839
Versión de los componentes: 1.0.563
Versión del paquete de actualización: 1.0.10290
Licencia: Prueba
-Información del sistema-
SO: Windows 10 (Build 17134.590)
CPU: x64
Sistema de archivos: NTFS
Usuario: sandrita-pc\sandra
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 313431
Amenazas detectadas: 95
Amenazas en cuarentena: 95
Tiempo transcurrido: 15 min, 40 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 26
PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\LAUNCHSIGNUP, En cuarentena, [607], [315082],1.0.10290
PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{540DAA6F-9AF8-4B62-A675-C56287336C13}, En cuarentena, [607], [315082],1.0.10290
PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{540DAA6F-9AF8-4B62-A675-C56287336C13}, En cuarentena, [607], [315082],1.0.10290
PUP.Optional.CrossRider, HKU\S-1-5-21-139378632-3801230044-3849559780-1001_Classes\LOCAL SETTINGS\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APPCONTAINER\STORAGE\WINDOWS_IE_AC_001\SOFTWARE\Crossrider, En cuarentena, [437], [253010],1.0.10290
PUP.Optional.CouponMarvel, HKU\S-1-5-21-139378632-3801230044-3849559780-1001\SOFTWARE\lollipop, En cuarentena, [2490], [253334],1.0.10290
PUP.Optional.SysTweak, HKU\S-1-5-21-139378632-3801230044-3849559780-1001\SOFTWARE\systweak, En cuarentena, [1504], [327156],1.0.10290
PUP.Optional.ShopperPro, HKLM\SOFTWARE\SHOPPERPRO, En cuarentena, [159], [243020],1.0.10290
PUP.Optional.SearchTheWeb, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchTheWebARP, En cuarentena, [7072], [469008],1.0.10290
PUP.Optional.SysTweak, HKLM\SOFTWARE\WOW6432NODE\systweak, En cuarentena, [1504], [327155],1.0.10290
PUP.Optional.Vittalia, HKLM\SOFTWARE\WOW6432NODE\Vittalia, En cuarentena, [684], [315309],1.0.10290
Adware.1ClickDownload, HKLM\SOFTWARE\CLASSES\APPID\{C007DADD-132A-624C-088E-59EE6CF0711F}, En cuarentena, [550], [169917],1.0.10290
Adware.1ClickDownload, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C007DADD-132A-624C-088E-59EE6CF0711F}, En cuarentena, [550], [169917],1.0.10290
Adware.1ClickDownload, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{C007DADD-132A-624C-088E-59EE6CF0711F}, En cuarentena, [550], [169917],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\TYPELIB\{14EF423E-3EE8-44AE-9337-07AC3F27B744}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\INTERFACE\{A9582D7B-F24A-441D-9D26-450D58F3CD17}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\INTERFACE\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A9582D7B-F24A-441D-9D26-450D58F3CD17}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A9582D7B-F24A-441D-9D26-450D58F3CD17}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{14EF423E-3EE8-44AE-9337-07AC3F27B744}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{14EF423E-3EE8-44AE-9337-07AC3F27B744}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}, En cuarentena, [7455], [170040],1.0.10290
Adware.Kajajugt, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}, En cuarentena, [7455], [170040],1.0.10290
PUP.Optional.Iminent, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}, En cuarentena, [95], [169753],1.0.10290
PUP.Optional.Iminent, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}, En cuarentena, [95], [169753],1.0.10290
Valor del registro: 9
PUP.Optional.CouponMarvel, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, En cuarentena, [2490], [-1],0.0.0
PUP.Optional.CouponMarvel, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, En cuarentena, [2490], [-1],0.0.0
PUP.Optional.MyPCBackup, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{540DAA6F-9AF8-4B62-A675-C56287336C13}|PATH, En cuarentena, [607], [315079],1.0.10290
PUP.Optional.Iminent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXT\CLSID|{58124A0B-DC32-4180-9BFF-E0E21AE34026}, En cuarentena, [95], [538246],1.0.10290
PUP.Optional.Iminent, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXT\CLSID|{977AE9CC-AF83-45E8-9E03-E2798216E2D5}, En cuarentena, [95], [538247],1.0.10290
PUP.Optional.ShopperPro, HKLM\SOFTWARE\SHOPPERPRO|DBLOCATION, En cuarentena, [159], [243020],1.0.10290
PUP.Optional.BrowserProtect, HKU\S-1-5-21-139378632-3801230044-3849559780-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TABBEDBROWSING|BPROTECTSHOWTABSWELCOME, En cuarentena, [921], [538248],1.0.10290
PUP.Optional.Iminent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXT\CLSID|{58124A0B-DC32-4180-9BFF-E0E21AE34026}, En cuarentena, [95], [538246],1.0.10290
PUP.Optional.Iminent, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXT\CLSID|{977AE9CC-AF83-45E8-9E03-E2798216E2D5}, En cuarentena, [95], [538247],1.0.10290
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 7
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}\{FBC0652C-7B29-4FB6-8ADA-91F54B267AD4}\1.5, En cuarentena, [3634], [180957],1.0.10290
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}\{FBC0652C-7B29-4FB6-8ADA-91F54B267AD4}, En cuarentena, [3634], [180957],1.0.10290
PUP.Optional.VBates, C:\USERS\SANDRA\APPDATA\LOCALLOW\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}, En cuarentena, [3634], [180957],1.0.10290
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\Company\Product\1.0, En cuarentena, [3634], [247040],1.0.10290
PUP.Optional.VBates, C:\USERS\SANDRA\APPDATA\LOCALLOW\COMPANY\PRODUCT, En cuarentena, [3634], [247040],1.0.10290
PUP.Optional.SysTweak, C:\Users\sandra\AppData\Roaming\systweak\BeforeUninstall, En cuarentena, [1504], [327152],1.0.10290
PUP.Optional.SysTweak, C:\USERS\SANDRA\APPDATA\ROAMING\SYSTWEAK, En cuarentena, [1504], [327152],1.0.10290
Archivo: 53
PUP.Optional.MyPCBackup, C:\WINDOWS\SYSTEM32\TASKS\LAUNCHSIGNUP, En cuarentena, [607], [315082],1.0.10290
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}\{FBC0652C-7B29-4FB6-8ADA-91F54B267AD4}\1.5\config.js, En cuarentena, [3634], [180957],1.0.10290
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}\{FBC0652C-7B29-4FB6-8ADA-91F54B267AD4}\1.5\tree.js, En cuarentena, [3634], [180957],1.0.10290
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}\{FBC0652C-7B29-4FB6-8ADA-91F54B267AD4}\1.5\wlist.js, En cuarentena, [3634], [180957],1.0.10290
PUP.Optional.VBates, C:\USERS\SANDRA\APPDATA\LOCALLOW\COMPANY\PRODUCT\1.0\LOCALSTORAGEIE.TXT, En cuarentena, [3634], [247040],1.0.10290
PUP.Optional.VBates, C:\Users\sandra\AppData\LocalLow\Company\Product\1.0\localStorageIE_backup.txt, En cuarentena, [3634], [247040],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_couponxplorer.dl.myway.com_0.localstorage, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_couponxplorer.dl.myway.com_0.localstorage-journal, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_easypdfcombine.dl.myway.com_0.localstorage, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_easypdfcombine.dl.myway.com_0.localstorage-journal, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_everydaylookup.dl.myway.com_0.localstorage, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_everydaylookup.dl.myway.com_0.localstorage-journal, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_televisionfanatic.dl.myway.com_0.localstorage, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_televisionfanatic.dl.myway.com_0.localstorage-journal, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_videodownloadconverter.dl.myway.com_0.localstorage, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_videodownloadconverter.dl.myway.com_0.localstorage-journal, En cuarentena, [1745], [443124],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_couponxplorer.dl.tb.ask.com_0.localstorage, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_couponxplorer.dl.tb.ask.com_0.localstorage-journal, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_easypdfcombine.dl.tb.ask.com_0.localstorage, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_easypdfcombine.dl.tb.ask.com_0.localstorage-journal, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_everydaylookup.dl.tb.ask.com_0.localstorage, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_everydaylookup.dl.tb.ask.com_0.localstorage-journal, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_televisionfanatic.dl.tb.ask.com_0.localstorage, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_televisionfanatic.dl.tb.ask.com_0.localstorage-journal, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_videodownloadconverter.dl.tb.ask.com_0.localstorage, En cuarentena, [1745], [443123],1.0.10290
PUP.Optional.MindSpark.Generic, C:\USERS\SANDRA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\http_videodownloadconverter.dl.tb.ask.com_0.localstorage-journal, En cuarentena, [1745], [443123],1.0.10290
PUM.Optional.FireFoxSearchOverride, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KZECYQFM.DEFAULT\USER.JS, En cuarentena, [14592], [302273],1.0.10290
PUM.Optional.FireFoxSearchOverride, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\USER.JS, En cuarentena, [14592], [302273],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
PUP.Optional.Iminent, C:\USERS\SANDRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SOLO_491952\PREFS.JS, Sustituido, [95], [301714],1.0.10290
Generic.Malware/Suspicious, C:\USERS\SANDRA\DESKTOP\MICROSFOT OFFICE 2013 64 BITS\ACTIVADOR PARA WINDOWS 8.1\KMSPICO_SETUP.EXE, En cuarentena, [0], [392686],1.0.10290
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
-------------------------------
Malwarebytes AdwCleaner 7.3.0.0
-------------------------------
Build: 04-04-2019
Database: 2019-04-18.2 (Cloud)
-------------------------------
Mode: Clean
-------------------------------
Start: 04-23-2019
Duration: 00:01:14
OS: Windows 10 Home
Cleaned: 275
Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files (x86)\globalUpdate
Deleted C:\Program Files (x86)\predm
Deleted C:\ProgramData\WPM
Deleted C:\ProgramData\apn
Deleted C:\ProgramData\eSafe
Deleted C:\Users\sandra\AppData\LocalLow\Check Point Software Technologies LTD
Deleted C:\Users\sandra\AppData\Local\DProtect
Deleted C:\Users\sandra\AppData\Local\globalUpdate
Deleted C:\Users\sandra\AppData\Local\lollipop
Deleted C:\Users\sandra\AppData\Roaming\FreeSoftwareUpdater
Deleted C:\Users\sandra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YTDownloader
***** [ Files ] *****
Deleted C:\Users\Public\Desktop\eBay.lnk
Deleted C:\Users\sandra\AppData\Roaming\Mozilla\Firefox\Profiles\Solo_491952\invalidprefs.js
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
Deleted C:\Windows\System32\Tasks\YTDOWNLOADER
Deleted C:\Windows\System32\Tasks\YTDOWNLOADERUPD
***** [ Registry ] *****
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{13AFB5D6-796C-46F6-9F40-B5F0B6AC0D9}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{2046475E-E9EC-47B4-AB42-8E9CFE4BED21}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{2165ECAF-3B-4337-B9F1-1C8763654DE}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{26253711-59FB-498B-8FFE-EFB4CB85AE0}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{27667108-D621-47DE-81BA-16767593A35}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{276F2352-F9B7-4506-A830-3D9ED8D348D}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{2B9FC037-B33D-4F8C-BF3F-D5E2365E6386}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{2C8A8615-B38-4611-85AB-438838EBAE6}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{4CF42ED0-ACC-4D46-8C26-36A1A0A41B67}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{4EB51A76-4170-4D83-A616-688CD6AB866D}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{5265EA2B-DF7-4139-A24C-832C53DCDF6}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{531BBE97-A44C-431E-BF7E-F62913B6D4B}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{5B0EFCDA-C378-4291-BD9E-C5CFAC8CBFC}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{65AF13DB-A9D-40E8-84F5-32BD4B828EFC}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{67FD222E-EFD5-4BDB-817B-DBEDBD31E4B}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{7899841F-14A-4773-A253-AF782A41F5C3}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{7A46186D-6259-45FD-9416-C35A7777EF80}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{7BA33697-F09C-4E37-BEFD-DF73DCB16913}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{7FEDC9C9-E64-420B-943-1675F4F817A6}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{8DE8DB81-D480-4239-89FE-98307B878FA}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{90011C30-7019-4239-B94F-45BD626025B4}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{9CD858F-C662-4761-87FC-C424C724B04C}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{A440F97-1767-4BCD-95C8-6597395A66F}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{A702C7A2-E9C9-4890-9AC8-17F0CAC858D3}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{B2076CF7-9D-4300-9F4E-8C7AA89B989F}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{BDE20566-78B9-4706-A93D-45701657172}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{C3208206-4B03-4CCA-BFEF-7083B03E2096}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{C6DF7BA7-26AF-4272-ABC8-B012697DA34B}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{C7096FE2-D44-4274-A3C3-A6C60E5D7D}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{D15A7510-DE75-46A9-A622-B7EE1F1C7E6}
Deleted HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{F248B5ED-EAFE-4EFE-BE5E-1319D5A9A87}
Deleted HKCU\Software\AppDataLow\Software\Smartbar
Deleted HKCU\Software\BABSOLUTION
Deleted HKCU\Software\Conduit
Deleted HKCU\Software\ContextTrue
Deleted HKCU\Software\GlobalUpdate
Deleted HKCU\Software\InstalledBrowserExtensions
Deleted HKCU\Software\Microsoft\Internet Explorer\AboutUrls|Tabs
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\re-markable.net
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\search.zonealarm.com
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\softonic.com
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\sweet-page.com
Deleted HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.sweet-page.com
Deleted HKCU\Software\Microsoft\Internet Explorer\SearchScopes{70F6650C-495F-472D-971C-FED14090A71D}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Deleted HKCU\Software\Mozilla\Extends
Deleted HKCU\Software\SIMPLYTECH
Deleted HKCU\Software\Softonic
Deleted HKCU\Software\YTDownloader
Deleted HKCU\Software\delta
Deleted HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Deleted HKLM\SOFTWARE\Classes\AppID\escort.DLL
Deleted HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Deleted HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Deleted HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Deleted HKLM\SOFTWARE\Classes\Record{181480C8-90AC-3430-B39A-CD121E034A1A}
Deleted HKLM\SOFTWARE\Classes\Record{2009AF2F-5786-3067-8799-B97F7832FDD6}
Deleted HKLM\SOFTWARE\Classes\Record{425E7597-03A2-338D-B72A-0E51FFE77A7E}
Deleted HKLM\SOFTWARE\Classes\Record{8F54FA54-1DF8-3B20-890C-CDD95364BC95}
Deleted HKLM\SOFTWARE\Classes\Record{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
Deleted HKLM\SOFTWARE\Classes\Record{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|BackgroundHost.exe
Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD|BackgroundHost.exe
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{21B0CBB8-A6CC-4EAA-98F4-F9EE87F0AF68}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{AE2CFD64-67C0-45DC-AA91-8D873CFEEFD4}
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader
Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloaderUpd
Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{485216F8-76CD-4148-944D-EE883FB9FF6E}
Deleted HKLM\Software\Classes\AppID{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Deleted HKLM\Software\Classes\AppID{09C554C3-109B-483C-A06B-F14172F1A947}
Deleted HKLM\Software\Classes\AppID{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Deleted HKLM\Software\Classes\AppID{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}
Deleted HKLM\Software\Classes\AppID{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Deleted HKLM\Software\Classes\AppID{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Deleted HKLM\Software\Classes\CLSID{AE07101B-46D4-4A98-AF68-0333EA26E113}
Deleted HKLM\Software\Classes\CLSID{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Deleted HKLM\Software\Classes\Interface{021B4049-F57D-4565-A693-FD3B04786BFA}
Deleted HKLM\Software\Classes\Interface{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Deleted HKLM\Software\Classes\Interface{06844020-CD0B-3D3D-A7FE-371153013E49}
Deleted HKLM\Software\Classes\Interface{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Deleted HKLM\Software\Classes\Interface{10D3722F-23E6-3901-B6C1-FF6567121920}
Deleted HKLM\Software\Classes\Interface{1675E62B-F911-3B7B-A046-EB57261212F3}
Deleted HKLM\Software\Classes\Interface{192929F2-9273-3894-91B0-F54671C4C861}
Deleted HKLM\Software\Classes\Interface{2932897E-3036-43D9-8A64-B06447992065}
Deleted HKLM\Software\Classes\Interface{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Deleted HKLM\Software\Classes\Interface{32B80AD6-1214-45F4-994E-78A5D482C000}
Deleted HKLM\Software\Classes\Interface{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Deleted HKLM\Software\Classes\Interface{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Deleted HKLM\Software\Classes\Interface{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Deleted HKLM\Software\Classes\Interface{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Deleted HKLM\Software\Classes\Interface{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Deleted HKLM\Software\Classes\Interface{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Deleted HKLM\Software\Classes\Interface{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Deleted HKLM\Software\Classes\Interface{72227B7F-1F02-3560-95F5-592E68BACC0C}
Deleted HKLM\Software\Classes\Interface{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Deleted HKLM\Software\Classes\Interface{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Deleted HKLM\Software\Classes\Interface{8C68913C-AC3C-4494-8B9C-984D87C85003}
Deleted HKLM\Software\Classes\Interface{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Deleted HKLM\Software\Classes\Interface{923F6FB8-A390-370E-A0D2-DD505432481D}
Deleted HKLM\Software\Classes\Interface{94952EC4-DB66-3F32-BE4C-F0BB875EA98E}
Deleted HKLM\Software\Classes\Interface{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Deleted HKLM\Software\Classes\Interface{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Deleted HKLM\Software\Classes\Interface{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Deleted HKLM\Software\Classes\Interface{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Deleted HKLM\Software\Classes\Interface{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Deleted HKLM\Software\Classes\Interface{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Deleted HKLM\Software\Classes\Interface{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Deleted HKLM\Software\Classes\Interface{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Deleted HKLM\Software\Classes\Interface{D25B101F-8188-3B43-9D85-201F372BC205}
Deleted HKLM\Software\Classes\Interface{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Deleted HKLM\Software\Classes\Interface{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Deleted HKLM\Software\Classes\Interface{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Deleted HKLM\Software\Classes\Interface{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Deleted HKLM\Software\Classes\Interface{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Deleted HKLM\Software\Classes\Interface{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Deleted HKLM\Software\Classes\Interface{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Deleted HKLM\Software\Classes\Interface{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Deleted HKLM\Software\Classes\Interface{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Deleted HKLM\Software\Classes\Interface{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Deleted HKLM\Software\Classes\Interface{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Deleted HKLM\Software\Classes\Prod.cap
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Main|Default_Search_URL
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Main|Search Bar
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Main|Search Page
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Main|Start Default_Page_URL
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Main|Start Page
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\SearchURI|(Default)
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\SearchUrl|(Default)
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Search|Default_Search_URL
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Search|Search Bar
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Search|Search Page
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Search|Start Default_Page_URL
Deleted HKLM\Software\Classes\Software\Microsoft\Internet Explorer\Search|Start Page
Deleted HKLM\Software\Classes\TypeLib{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Deleted HKLM\Software\Classes\TypeLib{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Deleted HKLM\Software\Classes\TypeLib{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Deleted HKLM\Software\Classes\TypeLib{82351433-9094-11D1-A24B-00A0C932C7DF}
Deleted HKLM\Software\Classes\TypeLib{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Deleted HKLM\Software\Classes\TypeLib{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Deleted HKLM\Software\Classes\TypeLib{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Deleted HKLM\Software\Classes\TypeLib{E69D4A59-73DE-4E38-9FB3-740EC4D9060D}
Deleted HKLM\Software\InstalledBrowserExtensions
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Deleted HKLM\Software\Wow6432Node\5d6d9dcbd35e415
Deleted HKLM\Software\Wow6432Node\Conduit
Deleted HKLM\Software\Wow6432Node\GlobalUpdate
Deleted HKLM\Software\Wow6432Node\InstalledBrowserExtensions
Deleted HKLM\Software\Wow6432Node\MaxPower
Deleted HKLM\Software\Wow6432Node\PIP
Deleted HKLM\Software\Wow6432Node\SiteSee
Deleted HKLM\Software\Wow6432Node\SoftwareUpdater
Deleted HKLM\Software\Wow6432Node\Wpm
Deleted HKLM\Software\Wow6432Node\YTDownloader
Deleted HKLM\Software\Wow6432Node\Classes\AppID\escorTlbr.DLL
Deleted HKLM\Software\Wow6432Node\Classes\AppID\escort.DLL
Deleted HKLM\Software\Wow6432Node\Classes\AppID\escortApp.DLL
Deleted HKLM\Software\Wow6432Node\Classes\AppID\escortEng.DLL
Deleted HKLM\Software\Wow6432Node\Classes\AppID\esrv.EXE
Deleted HKLM\Software\Wow6432Node\Classes\AppID{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Deleted HKLM\Software\Wow6432Node\Classes\AppID{09C554C3-109B-483C-A06B-F14172F1A947}
Deleted HKLM\Software\Wow6432Node\Classes\AppID{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Deleted HKLM\Software\Wow6432Node\Classes\AppID{8D5CFE57-B0FD-4396-97A2-DFD0B7DA935B}
Deleted HKLM\Software\Wow6432Node\Classes\AppID{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Deleted HKLM\Software\Wow6432Node\Classes\AppID{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{438FAE3E-BDEF-44D3-AB8B-0C7C8350DF59}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{61AB12E1-A5FF-11D1-B2E9-444553540000}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{6DC82D15-92F2-11D1-A255-00A0C932C7DF}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{82351441-9094-11D1-A24B-00A0C932C7DF}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{987D9269-F8A1-408F-BF62-4397D2F5363E}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{AE07101B-46D4-4A98-AF68-0333EA26E113}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Deleted HKLM\Software\Wow6432Node\Classes\CLSID{F1963E76-845B-474C-8C7F-D69A96D8AA34}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{021B4049-F57D-4565-A693-FD3B04786BFA}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{06844020-CD0B-3D3D-A7FE-371153013E49}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{10D3722F-23E6-3901-B6C1-FF6567121920}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{1675E62B-F911-3B7B-A046-EB57261212F3}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{192929F2-9273-3894-91B0-F54671C4C861}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{2932897E-3036-43D9-8A64-B06447992065}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{32B80AD6-1214-45F4-994E-78A5D482C000}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{72227B7F-1F02-3560-95F5-592E68BACC0C}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{8C68913C-AC3C-4494-8B9C-984D87C85003}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{923F6FB8-A390-370E-A0D2-DD505432481D}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{94952EC4-DB66-3F32-BE4C-F0BB875EA98E}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{D25B101F-8188-3B43-9D85-201F372BC205}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Deleted HKLM\Software\Wow6432Node\Classes\Interface{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{82351433-9094-11D1-A24B-00A0C932C7DF}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Deleted HKLM\Software\Wow6432Node\Classes\TypeLib{E69D4A59-73DE-4E38-9FB3-740EC4D9060D}
Deleted HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Deleted HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|BackgroundHost.exe
Deleted HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD|BackgroundHost.exe
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Deleted HKLM\Software\Wow6432Node\delta
Deleted HKLM\Software\Wow6432Node{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\SrvUpdater
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\Wpm
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\WsysSvc
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\srvPlgProtect
Deleted HKU.DEFAULT\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-18\Software\shopperz
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
[+] Delete Tracing Keys
[+] Reset Winsock
AdwCleaner[S00].txt - [31647 octets] - [23/04/2019 12:37:37]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
hice lo del ccleaner y me ha liberado bastante porqueria, imagino que habrá que hacer mas limpieza con otros programas pero me gustaria también saber que programas puedo desactivar/borrar del inicio a través del ccleaner, te adjunto imagen:

por cierto creo que el pc va un pelin mejor pero creo que puede ir bastante mejor, hay muchos programas que nose para que son y nose si borrarlos, quedo a la espera.
Saludos y muchisimas gracias.