Virus "explorer.exe *32" no puedo eliminarlo

Hola @MFV2

Realiza lo siguiente:

Paso 1:

Desinstala con Revo Uninstaller en su Modo Avanzado:

  • Smart Defrag 6
  • Java 8 Update 181
  • Java 8 Update 231

Manual de Revo Uninstaller.

Luego de reiniciar:

Paso 2:

Con mucha atención:

1.- Muy Importante >>> Realizar una copia de Seguridad de su Registro.

  • Descarga/Ejecuta DelFix desde el escritorio de Windows.
  • Clic Derecho, “Ejecutar como Administrador”.
  • En la ventana principal, marca solamente la casilla “Create Registry Backup”.
  • Clic en Run.

Al terminar se abrirá un reporte llamado DelFix.txt, guárdelo por si fuera necesario y cierre la herramienta…

Luego ve a::

2.- Inicio >>> Ejecutar >>> Escribe notepad.exe o abra un nuevo archivo Notepad y copie y pegue lo siguiente:

Start::
CloseProcesses:
HKLM-x32\...\Winlogon: [Shell] C:\Windows\explorer.exe,
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\Policies\system: [EnableLUA] 1
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\Policies\Explorer: [MaxRecentDocs] 15
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: E - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {10734e41-1abb-11ea-a27c-eca86b9a1b51} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {1c37e67f-df73-11e7-868b-003067c7f37a} - E:\setup.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {5a9414b0-1978-11e8-a5c7-003067c7f37a} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {69d77cf1-6ab5-11ea-842e-eca86b9a1b51} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {70fcd81e-0492-11ea-926f-eca86b9a1b51} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {7c8f2aab-9bc5-11e8-bac9-003067c7f37a} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {7f15b64d-19d2-11e8-85f8-003067c7f37a} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {9ef9a9f5-19d3-11e8-8cd9-003067c7f37a} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {a7dafcb3-096e-11ea-a334-eca86b9a1b51} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {a80688a5-eb68-11e7-be35-003067c7f37a} - E:\AutoRun.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {b36b1e4e-aea5-11e7-9326-003067c7f37a} - E:\setup.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {b45acfd6-6d21-11ea-9aeb-eca86b9a1b51} - F:\setup.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {bbafa53f-a79b-11e8-b665-003067c7f37a} - E:\setup.exe
HKU\S-1-5-21-742525890-1094425155-3898857869-1000\...\MountPoints2: {dac4e8f5-1e54-11e8-a395-003067c7f37a} - E:\AutoRun.exe
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\78.0.3904.97\Installer\chrmstp.exe [2019-11-14] (Google LLC -> Google LLC)
GroupPolicy: Restricción ? <==== ATENCIÓN
Task: {03827903-096B-49E7-A9C0-48098CF567DD} - System32\Tasks\{B0FD5B69-51F4-46B4-862F-D286B826DAC1} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\Documents\Geometry Dash 2.1 - By PolloTv\_CommonRedist\vcredist\2010\vcredist_x86.exe" -d "C:\Users\Personal\Documents\Geometry Dash 2.1 - By PolloTv\_CommonRedist\vcredist\2010"
Task: {39493418-B5B3-4660-B473-41C2B6F00219} - System32\Tasks\{7A06A6B2-E249-40CE-AD31-6F04E5FF5235} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\Documents\1Juegos inútiles\AA-PVZ\cached\sounds\DX12-11.AquíyAhora\DX.V12.exe" -d "C:\Users\Personal\Documents\1Juegos inútiles\AA-PVZ\cached\sounds\DX12-11.AquíyAhora"
Task: {3A235821-C020-4140-AE03-1FCF0F293687} - \Driver Booster SkipUAC (Personal) -> Ningún archivo <==== ATENCIÓN
Task: {4674BCC3-D931-464C-BD9C-E4530356EE20} - System32\Tasks\{627F111D-9E78-4207-A673-EBBA788668F2} => C:\Windows\system32\pcalua.exe -a C:\Users\Personal\Downloads\Programs\NVIDIA_Performance_Drivers_x86_18.1.2.exe -d C:\Users\Personal\AppData\Roaming\IDM
Task: {65F52EB3-1C32-4A2C-A239-A632B31C4D21} - System32\Tasks\{E1DA1798-FEC6-4F68-A04A-FA6DB521BBFE} => C:\Windows\system32\pcalua.exe -a C:\Windows\unvise32.exe -d C:\Windows -c C:\PROGRA~2\Parallel Port Joystick\uninstal.log
Task: {6D2B622A-0401-4410-8BEA-7FE98E2EC208} - System32\Tasks\{470D37B7-D9D3-4BF1-B172-149A188E9D9E} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\MEmu\Saved Games\Downloads\MODS2\Alci's IMG Editor 1.5\Alci's IMG Editor 1.5.exe" -d "C:\Users\Personal\MEmu\Saved Games\Downloads\MODS2\Alci's IMG Editor 1.5"
Task: {942198AA-12B0-40C2-ACC8-E46E94D697BC} - System32\Tasks\SmartDefrag_Update => C:\Program Files (x86)\IObit\Smart Defrag\AutoUpdate.exe [3031824 2020-07-07] (IObit Information Technology -> IObit)
Task: {9FDBB7D3-F6F6-4A69-A655-2948EA769626} - System32\Tasks\{310234D1-B39E-4870-AA2F-271456CB03FE} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\Documents\MEGAsync Downloads\emulator +Street Fighter III Strike Fight for the Future POR FideRock.exe" -d "C:\Users\Personal\Documents\MEGAsync Downloads"
Task: {C116D9DD-2696-4480-A9DC-14A45B7AA28C} - \Driver Booster Update -> Ningún archivo <==== ATENCIÓN
Task: {E434A8ED-90EF-4FCD-9792-068198A30DE6} - System32\Tasks\{502736FF-F88E-4C74-9E04-3454B92E481A} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\Downloads\Snes9x 1.51\snes9x.exe" -d "C:\Users\Personal\Downloads\Snes9x 1.51"
Task: {ED8569AE-5CA0-4351-BC16-A56645A47551} - System32\Tasks\{ECD8B304-76C9-4860-B74A-16860C71F9C7} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\Desktop\The Binding of Isaac Afterbirth Plus Update 4\Redist\vcredist_x86.exe" -d "C:\Users\Personal\Desktop\The Binding of Isaac Afterbirth Plus Update 4\Redist"
Task: {FB13E65B-89DB-4B9C-A163-0BE7697B21CD} - System32\Tasks\{B5EB3E2A-0E80-49B3-AAC3-052C70C0C0F8} => C:\Windows\system32\pcalua.exe -a "C:\Users\Personal\Desktop\The Binding of Isaac Afterbirth Plus Update 4\Redist\vcredist_x64.exe" -d "C:\Users\Personal\Desktop\The Binding of Isaac Afterbirth Plus Update 4\Redist"
SearchScopes: HKU\S-1-5-21-742525890-1094425155-3898857869-1000 -> DefaultScope {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = 
FF Plugin: @java.com/DTPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\dtplugin\npDeployJava1.dll [2019-11-06] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.231.2 -> C:\Program Files\Java\jre1.8.0_231\bin\plugin2\npjp2.dll [2019-11-06] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Ningún archivo]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Ningún archivo]
CHR HKLM\...\Chrome\Extension: [miockbgloklamfiklogjaohlgekodeok]
CHR HKLM\...\Chrome\Extension: [obhdbhpjhfncnelcpknkffpdmpdcjpep]
CHR HKU\S-1-5-21-742525890-1094425155-3898857869-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [miockbgloklamfiklogjaohlgekodeok]
CHR HKU\S-1-5-21-742525890-1094425155-3898857869-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [obhdbhpjhfncnelcpknkffpdmpdcjpep]
CHR HKLM-x32\...\Chrome\Extension: [miockbgloklamfiklogjaohlgekodeok]
CHR HKLM-x32\...\Chrome\Extension: [obhdbhpjhfncnelcpknkffpdmpdcjpep]
S3 cpuz143; no ImagePath
S3 hackedl; no ImagePath
S4 IUFileFilter; no ImagePath
S3 olololo; no ImagePath
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit Information Technology -> IObit)
S3 cpuz145; \??\C:\Windows\temp\cpuz145\cpuz145_x64.sys [X]
2020-08-19 18:22 - 2019-09-12 09:59 - 000178960 _____ (IObit) C:\Windows\system32\IObitSmartDefragExtension.dll
2020-08-19 17:34 - 2020-08-19 17:34 - 000003016 _____ C:\Windows\system32\Tasks\SmartDefrag_Update
2020-08-19 17:34 - 2020-08-19 17:34 - 000001162 _____ C:\Users\Public\Desktop\Smart Defrag 6.lnk
2020-08-19 17:34 - 2020-08-19 17:34 - 000001162 _____ C:\ProgramData\Desktop\Smart Defrag 6.lnk
2020-08-19 17:34 - 2020-08-19 17:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2020-08-19 17:34 - 2017-03-09 13:53 - 000030744 _____ (IObit) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2020-08-20 00:45 - 2017-08-30 16:34 - 000000000 ____D C:\ProgramData\IObit
2020-08-20 00:00 - 2020-07-02 07:14 - 000000000 ____D C:\Windows\system32\Tasks\{2E7F16C8-DD05-B693-3DE3-19811D066569}
2020-08-19 17:35 - 2020-05-13 17:50 - 000000000 ____D C:\Program Files (x86)\IObit
2020-08-19 17:35 - 2017-08-30 16:33 - 000000000 ____D C:\Users\Personal\AppData\Roaming\IObit
2018-10-17 22:10 - 2018-08-18 22:10 - 000000032 ____R () C:\ProgramData\hash.dat
2019-12-19 14:43 - 2020-05-04 22:11 - 000000117 _____ () C:\Users\Personal\AppData\Roaming\D2Info0
2019-12-19 14:43 - 2020-05-04 22:12 - 000000008 _____ () C:\Users\Personal\AppData\Roaming\DofusAppId0_1
2019-12-19 14:56 - 2020-01-08 23:20 - 000000008 _____ () C:\Users\Personal\AppData\Roaming\DofusAppId0_2
2019-12-19 19:44 - 2020-01-10 21:38 - 000000008 _____ () C:\Users\Personal\AppData\Roaming\DofusAppId0_3
2019-12-19 20:01 - 2019-12-19 20:01 - 000000008 _____ () C:\Users\Personal\AppData\Roaming\DofusAppId0_4
2019-12-19 20:01 - 2019-12-19 20:03 - 000000008 _____ () C:\Users\Personal\AppData\Roaming\DofusAppId0_5
2018-11-23 20:12 - 2018-11-23 20:12 - 000000037 ___SH () C:\Users\Personal\AppData\Local\20986331705021ca58edc424.96250074
2019-11-17 15:23 - 2019-11-17 15:23 - 000000000 _____ () C:\Users\Personal\AppData\Local\oobelibMkey.log
2017-03-05 20:16 - 2017-03-11 15:14 - 000000552 _____ () C:\Users\Personal\AppData\Local\TroubleshooterConfig.json
2017-02-20 13:45 - 2017-02-20 13:45 - 000000000 _____ () C:\Users\Personal\AppData\Local\{01CBA828-D22C-4471-AAEC-96EFB7A150AC}
C:\Windows\SysWOW64\lastpass_1337.exe
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> Ningún archivo
ContextMenuHandlers1: [AIMP] -> [CC]{1F77B17B-F531-44DB-ACA4-76ABB5010A28} =>  -> Ningún archivo
ContextMenuHandlers1: [ANotepad++64] -> [ASC]{B298D29A-A6ED-11DE-BA8C-A68E55D89593} =>  -> Ningún archivo
ContextMenuHandlers1: [Mp3tagShell] -> [ASC]{6351E20C-35FA-4BE3-98FB-4CABF1363E12} =>  -> Ningún archivo
ContextMenuHandlers1: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\Windows\System32\IObitSmartDefragExtension.dll [2019-09-12] (IObit Information Technology -> IObit)
ContextMenuHandlers1: [SmartGameBoosterMenu] -> [CC]{96C86AD1-055D-457D-9C00-0D4A91ECF1B4} =>  -> Ningún archivo
ContextMenuHandlers6: [SmartDefragExtension] -> {189F1E63-33A7-404B-B2F6-8C76A452CC54} => C:\Windows\System32\IObitSmartDefragExtension.dll [2019-09-12] (IObit Information Technology -> IObit)
Shortcut: C:\Users\Personal\Desktop\Action!.lnk -> C:\Program Files (x86)\Mirillis\Action!\Action_Run.bat ()
AlternateDataStreams: C:\ProgramData:NT [40]
AlternateDataStreams: C:\ProgramData:NT2 [432]
AlternateDataStreams: C:\Users\All Users:NT [40]
AlternateDataStreams: C:\Users\All Users:NT2 [432]
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [432]
AlternateDataStreams: C:\ProgramData\Datos de programa:NT [40]
AlternateDataStreams: C:\ProgramData\Datos de programa:NT2 [432]
AlternateDataStreams: C:\Users\Personal\Datos de programa:NT [40]
AlternateDataStreams: C:\Users\Personal\Datos de programa:NT2 [432]
AlternateDataStreams: C:\Users\Personal\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\Personal\AppData\Roaming:NT2 [432]
FirewallRules: [TCP Query User{C57A9E94-304C-4B5E-9886-62256A7A4546}C:\program files\java\jre1.8.0_231\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_231\bin\javaw.exe
FirewallRules: [UDP Query User{9863FF6A-B10A-4D08-8623-B0C270CFA360}C:\program files\java\jre1.8.0_231\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_231\bin\javaw.exe
Folder: C:\8b5dd9f650321ec4b03a0188
Folder: C:\5b2b3a0da543125f9f1a1f9f
CMD: ipconfig /flushdns
CMD: ipconfig /renew
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
RemoveProxy:
EmptyTemp:
Hosts:
End::
  • Lo guarda bajo el nombre de fixlist.txt en el escritorio <<< Esto es muy importante.

Nota: Es necesario que el ejecutable Frst.exe/Frst64.exe y fixlist.txt se encuentren en la misma ubicación (escritorio) o si no la herramienta no trabajará.

3.- Inicie su ordenador en >>> Modo Seguro >>> Aplicable a Windows 10. o Windows 7.

  • Ejecute Frst.exe o Frst64.exe. según el caso.
  • Presione el botón Fix/Corregir y aguarde a que termine.
  • La Herramienta guardará el reporte en su escritorio (Fixlog.txt).
  • Reinicia y lo pega en su próxima respuesta.

Nos comentas luego de reiniciar, como sigue el equipo.

Paso 3:

Actualizas Java a su ultima versión.

https://www.java.com/es/download/

Salu2

2 Me gusta