Pido disculpas por enterarme ahora de este tema pero.....
Por favor! revisad el archivo Tector 32bits, no quiero faltar al respeto a nadie pero llevo 3 horas desinstalando programas que no paran de instalarse solos. para que no le pase a nadie mas, ¡no rcomiendo ni bajar ni ejecutar ese archivo!
Aqui un informe por si sirve de algo:
# AdwCleaner v4.200 - Registro generado 05/04/2015 en 10:22:54
# Actualizado 29/03/2015 por Xplode
# Base de datos : 2015-03-29.1 [Servidor]
# Sistema operativo : Windows 7 Enterprise Service Pack 1 (x64)
# Nombre de usuario : Alguien - OT2
# Ejecutado desde : C:\Users\Alguien\Downloads\adwcleaner_4.200.exe
# Opción : Limpiar
***** [ Servicios ] *****
- Servicio Eliminar : globalUpdate
- Servicio Eliminar : globalUpdatem
- Servicio Eliminar : IHProtect Service
- Servicio Eliminar : WindowsMangerProtect
***** [ Archivos / Carpetas ] *****
Carpeta Eliminar : C:\ProgramData\WindowsMangerProtect
Carpeta Eliminar : C:\ProgramData\IHProtectUpDate
Carpeta Eliminar : C:\ProgramData\4a265b5e00007924
Carpeta Eliminar : C:\Program Files (x86)\globalUpdate
Carpeta Eliminar : C:\Program Files (x86)\XTab
Carpeta Eliminar : C:\Users\Alguien\AppData\Local\globalUpdate
Carpeta Eliminar : C:\Users\Alguien\AppData\Local\BoBrowser
Carpeta Eliminar : C:\Users\Alguien\AppData\Roaming\Systweak
Carpeta Eliminar : C:\Users\Alguien\AppData\Roaming\IHlpr
Carpeta Eliminar : C:\Users\Alguien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer
Archivo Eliminar : C:\Windows\System32\roboot64.exe
Archivo Eliminar : C:\Users\Alguien\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BoBrowser.lnk
Archivo Eliminar : C:\Users\Alguien\AppData\Roaming\Mozilla\Firefox\Profiles\4dps2fpb.default\invalidprefs.js
Archivo Eliminar : C:\Users\Alguien\AppData\Roaming\Mozilla\Firefox\Profiles\4dps2fpb.default\user.js
***** [ Tareas programadas... ] *****
Tarea Eliminar : ASP
Tarea Eliminar : globalUpdateUpdateTaskMachineCore
Tarea Eliminar : globalUpdateUpdateTaskMachineUA
Tarea Eliminar : Run_Bobby_Browser
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-1-6
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-1-7
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-10_user
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-11
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-3
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-4
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-5
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-5_user
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-6
Tarea Eliminar : ae00ba5d-3d37-4090-b879-dad0554732cf-7
***** [ Accesos directos ] *****
Acceso directo Desinfectado : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Acceso directo Desinfectado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Acceso directo Desinfectado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Acceso directo Desinfectado : C:\Users\Alguien\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registro ] *****
Valor Eliminar : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [searchengine@gmail.com]
Valor Eliminar : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [istart_ffnt@gmail.com]
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Llave Eliminar : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Llave Eliminar : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Llave Eliminar : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Llave Eliminar : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Llave Eliminar : HKCU\Software\Mozilla\Extends
Llave Eliminar : HKLM\SOFTWARE\MICROSOFT\MEDIAPLAYER\SHIMINCLUSIONLIST\bobrowser.exe
Llave Eliminar : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Llave Eliminar : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Llave Eliminar : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Datos Restauró : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Datos Restauró : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Datos Restauró : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command
Llave Eliminar : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Llave Eliminar : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Llave Eliminar : HKCU\Software\GlobalUpdate
Llave Eliminar : HKCU\Software\InstalledBrowserExtensions
Llave Eliminar : HKCU\Software\Optimizer Pro
Llave Eliminar : HKCU\Software\simplytech
Llave Eliminar : HKCU\Software\systweak
Llave Eliminar : HKCU\Software\WajIEnhance
Llave Eliminar : HKCU\Software\TNT2
Llave Eliminar : HKCU\Software\Super Optimizer
Llave Eliminar : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Llave Eliminar : HKCU\Software\AppDataLow\Software\Crossrider
Llave Eliminar : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Llave Eliminar : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Llave Eliminar : HKLM\SOFTWARE\GlobalUpdate
Llave Eliminar : HKLM\SOFTWARE\InstalledBrowserExtensions
Llave Eliminar : HKLM\SOFTWARE\SupDp
Llave Eliminar : HKLM\SOFTWARE\systweak
Llave Eliminar : HKLM\SOFTWARE\Wajam Web Enhancer
Llave Eliminar : HKLM\SOFTWARE\Clara
Llave Eliminar : HKLM\SOFTWARE\mystartsearchSoftware
Llave Eliminar : HKLM\SOFTWARE\IHProtect
Llave Eliminar : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Llave Eliminar : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Llave Eliminar : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Llave Eliminar : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Llave Eliminar : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Llave Eliminar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
Llave Eliminar : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Llave Eliminar : [x64] HKLM\SOFTWARE\Wajam Web Enhancer
***** [ Navegadores Web ] *****
-\\ Internet Explorer v9.0.8112.16470
Configuración Restauró : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Configuración Restauró : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Configuración Restauró : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Configuración Restauró : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Configuración Restauró : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Configuración Restauró : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Configuración Restauró : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Configuración Restauró : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Configuración Restauró : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Configuración Restauró : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v36.0.4 (x86 es-ES)
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("browser.search.searchengine.alias", "mystartsearch");
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("browser.search.searchengine.iconURL", "hxxp://www.mystartsearch.com/favicon.ico");
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("browser.search.searchengine.name", "mystartsearch");
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("browser.search.searchengine.url", "hxxp://www.mystartsearch.com/web/?type=ds&ts=1428216005&from=ima&uid=KINGSTONXSV300S37A240G_50026B774903441A&q={searchTerms}");
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("browser.search.selectedEngine", "mystartsearch");
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.ILP6iVFsaRe2SpDE.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[...]
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.KewNYv9MrM64Ipll.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[...]
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.Q7tBiSh1IqzTUgd5.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[...]
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.Zwl7tjhn6Nb7JDHU.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[...]
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.istart_ffnt@gmail.com.install-event-fired", true);
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.jdO74ncHty6V5c2X.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\[...]
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.quick_start.enable_search1", false);
[4dps2fpb.default\prefs.js] - Línea Eliminar : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v38.0.2125.104
[C:\Users\Alguien\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Eliminar [Startup_URLs] : hxxp://www.trovi.com/?gd=&ctid=CT3321848&octid=EB_ORIGINAL_CTID&ISID=M0422C554-6D16-471E-A911-9816D442B590&SearchSource=55&CUI=&UM=8&UP=SPCFC4E76C-7C96-44AD-978B-E6424E51182E&SSPV=
[C:\Users\Alguien\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminar [Homepage] : hxxp://www.mystartsearch.com/?type=hp&ts=1428216005&from=ima&uid=KINGSTONXSV300S37A240G_50026B774903441A
[C:\Users\Alguien\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Eliminar [Startup_URLs] : hxxp://www.mystartsearch.com/?type=hp&ts=1428216005&from=ima&uid=KINGSTONXSV300S37A240G_50026B774903441A
-\\ Comodo Dragon v
-\\ Opera v0.0.0.0
-\\ Chrome Canary v
*************************
AdwCleaner[R0].txt - [13846 bytes] - [12/01/2015 11:27:24]
AdwCleaner[R1].txt - [17852 bytes] - [05/04/2015 10:16:42]
AdwCleaner[S0].txt - [14519 bytes] - [12/01/2015 11:36:47]
AdwCleaner[S1].txt - [15355 bytes] - [05/04/2015 10:22:54]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [15415 bytes] ##########