| |||||||
| Foro de Virus y Spywares Ayuda con: Malwares - Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc.) Plantéanos tu problema en este sector. No ponga su log de HijackThis aquí !! |
![]() |
| | Enviar a: | Herramientas |
![]() | ![]() |
| InfoSpyware | ||
| |
![]() | ![]() |
| ||||
| Re: winlogon.exe De nuevo hola ch40s! descarga Manual de CCleaner ya que tienes unos cookies luego apaga restaurar sistema y luego vuelve a encenderlo, que el virus se encuntra ahi. descarga FAQs de Virus y Spywares y utiliza flash desinfector creara una carpeta para que no te vuelvas a infectar por usb y si tienes algun pendrive o memoria extraible o cel, los enchufas y utilizas el flash desinfector asi estos tambien quedan invulnerables. descarga las ultimas actualizaciones de microsoft tambien pone el link de tu anterior ayuda para ver que fue lo que se te hizo hacer |
![]() | ![]() |
| ||||
| Re: winlogon.exe De nuevo sino has esto Abrir una consola de comandos (cmd.exe) Finalizar el proceso del explorador (explorer.exe): taskkill /f /im explorer.exe Tipear: cd \Recycler Quitar los atributos de la carpeta Cita:
Cita:
Ir a la carpeta Recycler y veremos nuestra carpeta llamada virus . Accedemos a la carpeta y veremos el contenido: ise.exe, isee.exe y desktop.ini. Procedemos a eliminar esos archivos y limpiamos la ruta del registro HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAX5-90401C608512}. luego has esto nuevamente pero cambiando s-1-5-21-5160635273-6646667949-851270155-9121 por Cita:
http://www.megaupload.com/?d=1WYYI1LT copia y pega este link y utiliza el progama para esto si no quieres hacerlo asi has esto tambien puedes ir a (Listado de procedimientos)modo apuevas de fallo (modo seguro) y pasar malware bytes que te hicieron descargar en en modo examen completo pasa tambien Manual de CCleaner y como te dije anteriormente pasa flash desinfector y apaga restaurar sistema luego comenta si sige igual si tienes tiempo pasaFREE ANTIVIRUS - Download ActiveScan 2.0 and clean your PC - PANDA SECURITY y vemos de que otra manera solucionarlo suerte!! y saludos!! |
![]() | ![]() |
| ||||
| Re: winlogon.exe De nuevo si quieres hacerlo de forma facil y ver si funciona descarga Manual de OTMoveit copia este codigo Código: :files C:\recycler\s-1-5-21-5160635273-6646667949-851270155-9121\winlogon.exe C:\recycler\s-1-5-21-6317615227-0591264501-966182552-1512\winlogon.exe C:\recycler\s-1-5-21-5861326053-2323784844-550667850-3947\winlogon.exe :commands [emptytemp] [purity] [Reboot] Cita:
|
![]() | ![]() |
| ||||
| Re: winlogon.exe De nuevo Bueno hice lo ultimo que me dijiste estos son los reportes como lo ves ? ;************************************************* ************************************************** ************************************************** ****************************** ANALYSIS: 2009-11-05 18:44:15 PROTECTIONS: 1 MALWARE: 4 SUSPECTS: 0 ;************************************************* ************************************************** ************************************************** ****************************** PROTECTIONS Description Version Active Updated ;================================================= ================================================== ================================================== ============================== NOD32 Antivirus 3.0.645.0 No No ;================================================= ================================================== ================================================== ============================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;================================================= ================================================== ================================================== ============================== 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@atdmt[2].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@atdmt[3].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@ad.yieldmanager[1].txt 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@serving-sys[1].txt 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@serving-sys[2].txt 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@bs.serving-sys[2].txt 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\illusion\cookies\illusion@bs.serving-sys[1].txt ;================================================= ================================================== ================================================== ============================== SUSPECTS Sent Location ;================================================= ================================================== ================================================== ============================== ;================================================= ================================================== ================================================== ============================== VULNERABILITIES Id Severity Description ;================================================= ================================================== ================================================== ============================== 214076 HIGH MS09-059 971486 HIGH MS09-058 214074 HIGH MS09-057 214073 HIGH MS09-056 214072 HIGH MS09-055 214071 HIGH MS09-054 213109 HIGH MS09-046 212494 HIGH MS09-042 212493 HIGH MS09-041 212490 HIGH MS09-038 212530 HIGH MS09-034 211784 HIGH MS09-032 211781 HIGH MS09-029 210625 HIGH MS09-026 210624 HIGH MS09-025 210621 HIGH MS09-022 210618 HIGH MS09-019 208380 HIGH MS09-015 208379 HIGH MS09-014 208378 HIGH MS09-013 208377 HIGH MS09-012 206981 HIGH MS09-007 206980 HIGH MS09-006 205735 HIGH MS09-002 204670 HIGH MS09-001 203806 HIGH MS08-078 203508 HIGH MS08-073 203505 HIGH MS08-071 202465 HIGH MS08-068 201683 HIGH MS08-067 201258 HIGH MS08-066 201256 HIGH MS08-064 201255 HIGH MS08-063 201253 HIGH MS08-061 201250 HIGH MS08-058 209275 HIGH MS08-049 209273 HIGH MS08-045 196455 MEDIUM MS08-037 194862 HIGH MS08-032 194861 HIGH MS08-031 194860 HIGH MS08-030 191618 HIGH MS08-025 191617 HIGH MS08-024 191616 HIGH MS08-023 191614 HIGH MS08-021 191613 HIGH MS08-020 187735 HIGH MS08-010 ;================================================= ================================================== ================================================== ============================== All processes killed ========== FILES ========== C:\recycler\s-1-5-21-5160635273-6646667949-851270155-9121\winlogon.exe moved successfully. C:\recycler\s-1-5-21-6317615227-0591264501-966182552-1512\winlogon.exe moved successfully. File move failed. C:\recycler\s-1-5-21-5861326053-2323784844-550667850-3947\winlogon.exe scheduled to be moved on reboot. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Illusion ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 44320939 bytes ->Java cache emptied: 25493570 bytes ->FireFox cache emptied: 100240077 bytes ->Google Chrome cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 219018218 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 371.11 mb OTM by OldTimer - Version 3.0.0.6 log created on 11042009_210344 Files moved on Reboot... C:\recycler\s-1-5-21-5861326053-2323784844-550667850-3947\winlogon.exe moved successfully. Registry entries deleted on Reboot... |
![]() | ![]() |
| ||||
| Re: winlogon.exe De nuevo solo tienes un par de cookies pasa ccleaner. eliminas estas entradas manualmente si siguen estando Cita:
Microsoft Update ya que sigen apareciendo vulnerabilidades como esta funcionando ahora tu pc? saludos!!! |
![]() |
| Herramientas | |
| |
![]() |
Temas Similares | ![]() |
| Tema | Autor | Foro | Respuestas | Último mensaje |
| Nuevo diseño para el Foro Otoño-Invierno FS - 2008. | ElPiedra | Novedades y Políticas | 74 | 07/08/08 09:59:11 |
| Nuevo Kaspersky v.8 2009 [New] | santi93 | Noticias de Informática Gral. | 0 | 06/06/08 15:53:03 |
| DelPSGuard v5.0.2 15/4/2009 | ElPiedra | Actualización de AntiSpywares | 2 | 19/12/07 03:10:53 |
| Log hijackthis: Posible infeccion por una pagina web china (Solucionado) | AJ522 | Temas Solucionados | 29 | 30/09/06 09:25:48 |
| Problema con spyware (solucionado) | dodox | Temas Solucionados | 28 | 05/02/06 18:40:46 |