Fueron dos scans, uno ayer (el primero) y otro hace unos minutos (el segundo)
Primero:
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 2/19/19
Scan Time: 11:35 PM
Log File: 32f7f0ee-34b8-11e9-99f2-3c5282de4ff3.json
-Software Information-
Version: 3.7.1.2839
Components Version: 1.0.538
Update Package Version: 1.0.9346
License: Trial
-System Information-
OS: Windows 10 (Build 17763.253)
CPU: x64
File System: NTFS
User: ERICKS-HP-LAPTO\geric
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 316388
Threats Detected: 8
Threats Quarantined: 8
Time Elapsed: 4 min, 43 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 1
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\WINLOGUI.EXE, Quarantined, [603], [582017],1.0.9346
Module: 1
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\WINLOGUI.EXE, Quarantined, [603], [582017],1.0.9346
Registry Key: 0
(No malicious items detected)
Registry Value: 1
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|winlogui, Quarantined, [603], [582017],1.0.9346
Registry Data: 3
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|ANTIVIRUSDISABLENOTIFY, Replaced, [13193], [293294],1.0.9346
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|FIREWALLDISABLENOTIFY, Replaced, [13193], [293295],1.0.9346
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Replaced, [13193], [293296],1.0.9346
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 2
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\WINLOGUI.EXE, Quarantined, [603], [582017],1.0.9346
Misplaced.Legit.BatBitRst, C:\PROGRAM FILES (X86)\YEPUESWN.EXE, Quarantined, [10717], [632788],1.0.9346
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
Segundo:
Malwarebytes
www.malwarebytes.com
-Log Details-
Scan Date: 2/20/19
Scan Time: 1:41 PM
Log File: 4f0bab38-352e-11e9-8d85-3c5282de4ff3.json
-Software Information-
Version: 3.7.1.2839
Components Version: 1.0.538
Update Package Version: 1.0.9356
License: Trial
-System Information-
OS: Windows 10 (Build 17763.253)
CPU: x64
File System: NTFS
User: System
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 316656
Threats Detected: 2
Threats Quarantined: 2
Time Elapsed: 11 min, 13 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 0
(No malicious items detected)
Registry Data: 1
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Replaced, [13195], [293296],1.0.9356
Data Stream: 0
(No malicious items detected)
Folder: 0
(No malicious items detected)
File: 1
Misplaced.Legit.BatBitRst, C:\PROGRAM FILES (X86)\YEPUESWN.EXE, Quarantined, [10718], [632788],1.0.9356
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
RKill:
Rkill 2.9.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2019 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 02/20/2019 12:24:32 PM in x64 mode.
Windows Version: Windows 10 Home
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* No issues found.
Program finished at: 02/20/2019 12:25:55 PM
Execution time: 0 hours(s), 1 minute(s), and 23 seconds(s)