Pues como podeis leer en el titulo me he descargado un archvio de mejor torrent y era un malaware como os e podido leer por aqui. Archivo vbs en mejor torrent ya hice lo que pone en este post pero no se si está bien os dejo los informes.
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 8/1/21
Hora del análisis: 22:04
Archivo de registro: 1c4af98e-51f5-11eb-9a9f-fcaa14d9a8de.json
-Información del software-
Versión: 4.3.0.98
Versión de los componentes: 1.0.1130
Versión del paquete de actualización: 1.0.35423
Licencia: Gratis
-Información del sistema-
SO: Windows 10 (Build 19041.685)
CPU: x64
Sistema de archivos: NTFS
Usuario: DESKTOP-946LB9P\Ivan
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 309120
Amenazas detectadas: 14
Amenazas en cuarentena: 14
Tiempo transcurrido: 9 min, 16 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 4
PUP.Optional.Conduit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En cuarentena, 139, 236865, , , , , ,
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En cuarentena, 139, 236865, , , , , ,
PUP.Optional.Conduit, HKU\S-1-5-21-2955591635-108404769-2477485047-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, En cuarentena, 139, 236865, 1.0.35423, , ame, , ,
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\nladljmabboanhihfkjacnnkgjhnokhj, En cuarentena, 7683, 550469, 1.0.35423, , ame, , ,
Valor del registro: 2
PUP.Optional.Conduit, HKU\S-1-5-21-2955591635-108404769-2477485047-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, En cuarentena, 139, 236865, 1.0.35423, , ame, , ,
PUP.Optional.Conduit, HKU\S-1-5-21-2955591635-108404769-2477485047-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURL, En cuarentena, 139, 236865, 1.0.35423, , ame, , ,
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 0
(No hay elementos maliciosos detectados)
Archivo: 8
Trojan.WMIHijacker, C:\USERS\IVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\WORLD OF WARSHIPS.LNK, Sustituido, 10555, 514947, 1.0.35423, , ame, , F193CB9030D36BE9E31DB2E806BADB51, DD4155A1CE01F20DE3DF62D88B90954497D7FA07F8E2200A7F8D6F4C788E1989
Trojan.WMIHijacker, C:\USERS\IVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\WORLD OF TANKS.LNK, Sustituido, 10555, 514947, 1.0.35423, , ame, , 5168DE0A47D3B3F9E8EB1E61D57403BC, 51C21F5DD6A5472B4B3904D620B8B8EDCF4F376F92C7B468270BE768FAC592C2
Trojan.WMIHijacker, C:\USERS\IVAN\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\WARFACE.LNK, Sustituido, 10555, 514947, 1.0.35423, , ame, , 5D43A1B4BE578985ACB6BCB6510AC272, BC86DC247DF285BE46CE0C383F2BD7DC9FF74E5D47374637FF60B86C46D24713
Malware.AI.3322026345, C:\USERS\IVAN\APPDATA\ROAMING\UTORRENT\UPDATES\3.5.5_45776.EXE, En cuarentena, 1000000, 0, 1.0.35423, 003A98F6104CB33CC6021969, dds, 01063878, 1BF678B622715B47F55B4452C7179096, 7BDFE9BD77D2D838455EB775D9792A9677F50A277BEEF01BEF6CA20BE2001EF3
Trojan.WMIHijacker, C:\USERS\IVAN\DESKTOP\WARFACE.LNK, Sustituido, 10555, 514947, 1.0.35423, , ame, , 40CABF12B4D1731DEDD53EEA2F71CAB6, 4BAD03407677146C5B3C6F48B29D71D628822C25A437AC73E641E583E6954611
Trojan.WMIHijacker, C:\USERS\IVAN\DESKTOP\WORLD OF TANKS.LNK, Sustituido, 10555, 514947, 1.0.35423, , ame, , 2BF5A4C7A1F9E5DA6B3783F88F892AA2, 4F02CAEBA7D20AC402B3B5C76EA23224A8BEAAB037A6EB036615983AA97EAFC9
Trojan.WMIHijacker, C:\USERS\IVAN\DESKTOP\WORLD OF WARSHIPS.LNK, Sustituido, 10555, 514947, 1.0.35423, , ame, , B72895C2AF71E84BD017E5850F1DE9E4, A3BC3BC2DED906DBC0846DA8050B7C05CC952EBF06F507F8F9317C72CF89D30E
PUP.Optional.BundleInstaller, C:\USERS\IVAN\DOWNLOADS\UTWEB_INSTALLER.EXE, En cuarentena, 150, 790622, 1.0.35423, , ame, , B3C26480934A4C81593DFC81E8D80FD7, 405E773CF7E4D96F6D9F1ABE3CD3D7B707142BA3399FBE0753EF13173F9D011D
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build: 10-08-2020
# Database: 2020-09-29.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 01-08-2021
# Duration: 00:00:26
# OS: Windows 10 Home
# Cleaned: 19
# Failed: 2
***** [ Services ] *****
Deleted WCAssistantService
***** [ Folders ] *****
Deleted C:\ProgramData\Application Data\Lavasoft\Web Companion
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
Deleted C:\Users\Ivan\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_MRPQ523XMEO0CM2M0N5VJ25Z3NZKGEP4
Deleted C:\Users\Ivan\AppData\Local\Lavasoft\WEBCOMPANION.EXE_URL_SIQ0LWF3TZGXP2KHFKLLYBK3IDTBEHNG
Deleted C:\Users\Ivan\AppData\Roaming\Lavasoft\Web Companion
Not Deleted C:\Program Files (x86)\Lavasoft\Web Companion
Not Deleted C:\ProgramData\Lavasoft\Web Companion
***** [ Files ] *****
Deleted C:\Users\Ivan\Downloads\Hola-Setup.exe
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run|Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Web Companion
Deleted HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{811cf048-ed96-4ad4-a9f3-099001c60c4b}|DisplayIcon
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{811cf048-ed96-4ad4-a9f3-099001c60c4b}|DisplayName
Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{811cf048-ed96-4ad4-a9f3-099001c60c4b}|UninstallString
Deleted HKLM\System\Setup\FirstBoot\Services\WCAssistantService
Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKU\.DEFAULT\Software\Mozilla\NativeMessagingHosts\com.webcompanion.native
Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [3529 octets] - [08/01/2021 22:15:58]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by Ivan (Administrator) on 08/01/2021 at 22:28:04,73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 3
Successfully deleted: C:\ProgramData\lavasoft\web companion (Folder)
Successfully deleted: C:\Users\Ivan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm (Folder)
Successfully deleted: C:\Program Files (x86)\lavasoft\web companion (Folder)
Registry: 3
Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_C76D497934B1A0EE0E3BF23C3F10F9A7 (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08/01/2021 at 22:34:44,31
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~