“Conocimientos software>Antivirus Software

¿Cómo deshacerse del gusano troyano Cripta

2013/5/9
cripta troyano es el nombre general para virus troyanos con cripta como parte del nombre . Estos troyanos son capaces de conectarse a Internet y descargar programas maliciosos por sí mismos. El spyware descargado puede robar su información confidencial privada y ayudar en el robo de identidad. Cripta es también un troyano de puerta trasera , lo que significa que permite la conexión remota a su equipo por los hackers. Esto puede resultar en información robada , los correos electrónicos no autorizados enviados desde su bandeja de entrada y daños informáticos . Retire Cripta inmediatamente si se detecta . Instrucciones
Sistema End Procesos
1

Prensa y teclas Ctrl \\ " , \\ " "cambio \\" \\ \\ \\ " Esc " , al mismo tiempo para iniciar Windows Administrador de tareas.

2 Haga clic en la \\ "Procesos \\ " pestaña , pulse \\ "Ctrl \\ " y seleccione \\ " wtemp32.exe \\ " y \\ "nuevo . exe \\ " los procesos del sistema .

3 Haga clic en el \\ " Terminar proceso \\ " botón y cierre el Administrador de tareas.
Eliminar entradas del registro
4

Ir a "Inicio \\ " \\ menú y haga clic en \\ " Run \\".
5

Escriba \\ "regedit \\ " y haga clic en \\ " Aceptar \\ " para iniciar el Editor del Registro
6

Busque y elimine las siguientes entradas del registro : .

HKEY_CLASSES_ROOT \\ \\ SymantecFilterCheck
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { E3C1BC70 - 1607- 43BD - A055 - ACB4BF8DBA88 }
HKEY_CLASSES_ROOT \\ \\ NewBopoMediumPop.PopBopo
HKEY_CLASSES_ROOT \\ \\ NexiAdPopup.DILogc
; HKEY_CLASSES_ROOT \\ \\ NexiAdPopup.DILogc.1
HKEY_CLASSES_ROOT \\ \\ NexkAdPopup.DKLogc
HKEY_CLASSES_ROOT \\ \\ NexkAdPopup.DKLogc.1 < br /> HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Services \\ \\ skyxpserver
HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Services \\ \\ lixrfy
HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Services \\ \\ Abel
HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Services \\ \\ enqueue
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { 75EA2845 - EAD5 - 486E - A339 - 59FED49289A6 }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { C80F2C34 - B4A7 - 4F23 - A99E - D55DB29DC30D }
HKEY_CLASSES_ROOT \\ \\ Interface \\ \\ { 3C563030 - 29AA - 496A - 85F9 - 2A91F3A7D203 }
HKEY_CLASSES_ROOT \\ \\ TypeLib \\ \\ { 9B74BBC9 - 9516 - 4C06 - 9A9B - 4594386F429D }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ 60c2551e
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Winlogon \\ \\ Notifique \\ \\ pmnnNfCV
HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Services \\ \\ undzg
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { 3229DFCD - 3EAF - 4712 - ED45 - 4876FEDC170C }
; HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { 1CBD78E7 - dEF4 - 49F2 - 9B35 - 33130D278FFe }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { 3440A80C - 343C - 47A9 - A316 - D2421DE313E1 }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { 52B1DFC7 - AAFC - 4362 - B103 - 868B0683C697 }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { a04c370e - 0f0a - 4cc0 - A898 - 145d19cb5136 }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { CF46BFB3 - 2ACC - 441b - B82B - 36B9562C7FF1 }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { e5c5fe36 - 0f5a - 4368 - 9a77 - be6f882a915e }
HKEY_CLASSES_ROOT \\ \\ MSEvents.MSEvents
HKEY_CLASSES_ROOT \\ \\ MSEvents.MSEvents.1 < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Winlogon \\ \\ Notify \\ \\ gebcy
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Winlogon \\ \\ Notifique \\ \\ geedc
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Explorer \\ \\ Browser Helper Objects \\ \\ { 1CBD78E7 - dEF4 - 49F2 - 9B35 - 33130D278FFe }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Explorer \\ \\ Browser Helper Objects \\ \\ { 3440A80C - 343C - 47A9 - A316 - D2421DE313E1 }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ Explorer \\ \\ \\ Browser Helper Objects \\ \\ { 52B1DFC7 - AAFC - 4362 - B103 - 868B0683C697 }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ Explorer \\ \\ \\ Browser Helper Objects \\ \\ { a04c370e - 0f0a - 4cc0 - A898 - 145d19cb5136 }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Explorer \\ \\ Browser Helper Objects \\ \\ { CF46BFB3 - 2ACC - 441b - B82B - 36B9562C7FF1 }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Explorer \\ \\ Browser Helper Objects \\ \\ { e5c5fe36 - 0f5a - 4368 - 9a77 - be6f882a915e }
HKEY_CLASSES_ROOT \\ \\ CLSID \\ \\ { bfbc1a78 - CDDD -1672 - 876e - 324d6c4686e9 }
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Winlogon \\ \\ Notify \\ \\ __c007C212
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Winlogon \\ \\ Notify \\ \\ __c00E2400
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Winlogon \\ \\ Notify \\ \\ __c00F26F
HKLM \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run Microsoft Updates wtemp32.exe
HKLM \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ RunServices Microsoft actualizaciones wtemp32.exe
HKCU \\ \\ Software \\ \\ Microsoft \\ \\ OLE Microsoft Updates wtemp32.exe
HKLM \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Ole EnableDCOMN
HKLM \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Lsa restrictanonymous 1
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ cfmpgzwd.exe < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ 3572
7

Repita el mismo para:
< br /> HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Session Manager @ ^ ^ PendingFileRenameOperations = ^ \\ \\ \\ \\ C : ? ? \\ \\ Archivos de programa \\ \\ foobar2000 \\ \\ components \\ \\ foo_ui_yqllyrics.dll < br /> HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Session Manager @ ^ ^ PendingFileRenameOperations = ^ \\ \\ \\ \\ C: ? ? \\ \\ Archivos de programa \\ \\ The KMPlayer \\ \\ Plugins \\ \\ gen_yqllyrics.dll < br /> HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Session Manager @ ^ ^ PendingFileRenameOperations = ^ \\ \\ \\ \\ C: ? ? \\ \\ Archivos de programa \\ \\ The KMPlayer \\ \\ Plugins \\ \\ vis_yqllyrics.dll < br /> HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Session Manager @ ^ ^ PendingFileRenameOperations = ^ \\ \\ \\ \\ C: ? \\ \\ Archivos de programa \\ \\ Yiqilai \\ \\ temp \\ \\ foo_ui_yqllyrics.dll
HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Session Manager @ ^ ^ PendingFileRenameOperations = ^ \\ \\ \\ \\ C: ? \\ \\ Archivos de programa \\ \\ Yiqilai \\ \\ temp \\ \\ gen_yqllyrics.dll
HKEY_LOCAL_MACHINE \\ \\ SYSTEM \\ \\ CurrentControlSet \\ \\ Control \\ \\ Session Manager @ ^ ^ PendingFileRenameOperations = ^ \\ \\ \\ \\ C: ? \\ \\ Archivos de programa \\ \\ Yiqilai \\ \\ temp \\ \\ vis_yqllyrics.dll
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ SvcHost @ ^ lixrfy
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ policies \\ \\ Explorer \\ \\ Run @ ^ victoria aggior < br /> HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ Framework biblioteca de módulos
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ Framework biblioteca de módulos < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ livemgr < br /> HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft @ ^ WinID
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion @ ^ dmdai.exe
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ mmva
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ SysDriver32
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ Servicio de ejecución de Windows
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ \\ \\ VIE2.exe
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ sistema
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ System Run
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ System Update
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ 360rpt.EXE @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ 360safe.EXE @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ 360safebox.EXE @ ^ ^ depurador ^ = C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ 360tray.EXE @ ^ depurador ^ ^ = C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ ANTIARP.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ ArSwp . EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Ast.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ autorun.exe @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image Opciones de ejecución de archivos \\ \\ AutoRunKiller.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ AvMonitor.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ AVP.COM @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ AVP.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ CCenter.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
8

Remover estos entradas :

HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ FrameworkService.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ GFUpd.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ GuardField.EXE @ ^ depurador ^ = ^ C : \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ hijackthis.exe @ ^ ^ = depurador ^ C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ IceSword.EXE @ ^ depurador ^ ^ = C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ Iparmor.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ KASARP . EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ kav32.EXE @ ^ depurador ^ = ^ C: \\ \\ WINDOWS \\ system32 \\ dllcache \\ \\ \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ CurrentVersion \\ \\ \\ Image File Execution Options archivo \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image : \\ \\ KAVPFW.EXE @ ^ ^ = ^ depurador C Opciones de ejecución \\ \\ kavstart.EXE @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ kissvc.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ kmailmon.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ KPfwSvc.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ KRegEx.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ KVMonxp.KXP @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ KVSrvXP.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ KVWSC.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ kwatch.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Mmsk.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Navapsvc.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ nod32krn.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv . exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ nod32kui.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ PFW.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ QQDoctor.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RAV.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ ravmon.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RAVMOND.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
9

Por último , eliminar estas entradas :

HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Ravservice.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RavStub.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RavTask.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RAVTRAY.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Regedit.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
; HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ rfwmain.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ rfwProxy.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe < ; br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ rfwsrv.EXE @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv . exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Rfwstub.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RsAgent.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Rsaupd.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RsMain.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ rsnetsvr.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ RSTray.EXE @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Runiep.EXE @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ safeboxTray.EXE @ ^ ^ depurador ^ = C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ ScanFrm.EXE @ ^ depurador ^ ^ = C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ archivos de imagen Opciones de ejecución \\ \\ SREngLdr.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ TrojanDetector . EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Trojanwall.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ TrojDie.KXP @ ^ ^ = ^ depurador C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image Opciones de ejecución de archivos \\ \\ VPC32.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ Vptray.exe @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows NT \\ \\ CurrentVersion \\ \\ Image File Execution Options \\ \\ WOPTILITIES.EXE @ ^ ^ = ^ depurador de C: \\ \\ WINDOWS \\ \\ system32 \\ \\ dllcache \\ \\ spoolsv.exe < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ MSMGS
HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ \\ \\ VIE2.exe < , br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ Redist32 < br /> HKEY_LOCAL_MACHINE \\ \\ SOFTWARE \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ u3y5uhnu
HKEY_CURRENT_USER \\ \\ Software \\ \\ Microsoft \\ \\ Windows \\ \\ CurrentVersion \\ \\ Run @ ^ A00FCDEFF8.exe
página 10

Cierre el Editor del Registro.
Eliminar archivos
11

Haga clic en el menú Inicio y, a continuación, haga clic en \\ "Buscar \\".
12

Compruebe la opción \\ "Todos los archivos y carpetas \\ " y seleccione la unidad de disco duro en el menú desplegable.
13

Escriba \\ " w32myztic - f.vxe \\ "y pulse \\ " Intro. \\ "Eliminar todos los resultados de búsqueda y repita para \\" install_cong1.exe , \\ "\\" install_conga1.exe , \\ " \\ " nuevo . exe , \\ "\\" install_conga1.exe , \\ "\\" install_cong1.exe \\ "y \\ " wtemp32.exe . \\ "
14

Reinicie el equipo.

Antivirus Software
Cómo acelerar LiveUpdate en Norton 360
Cómo quitar AVG 7.5
¿Cómo deshacerse de Trojan.JS /Redirector.Cq
Problemas más comunes que pueden afectar a un análisis de seguridad
¿Cómo deshacerse de los virus de Seguridad Win
Características del troyano Brojack Virus
Cómo activar su programa anti -virus Software
Cómo configurar Norton 360
Conocimientos Informáticos © http://www.ordenador.online