Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 16/6/19
Hora del análisis: 23:04
Archivo de registro: 64209040-907a-11e9-a591-00241dd6a5ad.json
-Información del software-
Versión: 3.7.1.2839
Versión de los componentes: 1.0.586
Versión del paquete de actualización: 1.0.11080
Licencia: Gratis
-Información del sistema-
SO: Windows 8.1
CPU: x64
Sistema de archivos: NTFS
Usuario: EGONAUTA\Joker
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 391078
Amenazas detectadas: 99
Amenazas en cuarentena: 98
Tiempo transcurrido: 6 min, 25 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 6
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Módulo: 6
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, En cuarentena, [1229], [399420],1.0.11080
Clave del registro: 30
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Updater_Online_Application, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{39EB44D1-282B-48BC-8E9D-763BDBBFB157}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{39EB44D1-282B-48BC-8E9D-763BDBBFB157}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G1, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{467B26D0-BE04-4C8D-B376-286BCDF91B6E}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{467B26D0-BE04-4C8D-B376-286BCDF91B6E}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G2, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EEF0AAE1-92D0-486D-9765-11D64ECFA72D}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{EEF0AAE1-92D0-486D-9765-11D64ECFA72D}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G3, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{01F6FB4F-ED74-4A32-8FD0-C3DA11164552}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{01F6FB4F-ED74-4A32-8FD0-C3DA11164552}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G4, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{676D871D-4D2F-425B-9C32-8B26DF271110}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{676D871D-4D2F-425B-9C32-8B26DF271110}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G5, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{827FE1EB-12AC-4293-A98B-749899FB9798}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{827FE1EB-12AC-4293-A98B-749899FB9798}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Online Application V2G6, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5B08211A-5871-4FBD-BA50-AA7086931D92}, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{5B08211A-5871-4FBD-BA50-AA7086931D92}, En cuarentena, [1229], [399420],1.0.11080
PUP.Optional.Conduit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En cuarentena, [208], [236865],1.0.11080
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, En cuarentena, [208], [236865],1.0.11080
PUP.Optional.Conduit, HKU\S-1-5-21-1429871492-45722225-1832122274-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, En cuarentena, [208], [236865],1.0.11080
PUP.Optional.WebDiscoverBrowser, HKLM\SOFTWARE\WOW6432NODE\WebDiscoverBrowser, En cuarentena, [1645], [253915],1.0.11080
PUP.Optional.DefaultSearch, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\nladljmabboanhihfkjacnnkgjhnokhj, En cuarentena, [299], [550469],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online Application, En cuarentena, [1229], [527822],1.0.11080
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, En cuarentena, [3685], [321304],1.0.11080
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online.io Application, En cuarentena, [3685], [317312],1.0.11080
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, En cuarentena, [3685], [339688],1.0.11080
Valor del registro: 13
Trojan.Agent, HKU\S-1-5-21-1429871492-45722225-1832122274-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|21defe84, En cuarentena, [436], [667267],1.0.11080
PUP.Optional.Conduit, HKU\S-1-5-21-1429871492-45722225-1832122274-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, En cuarentena, [208], [236865],1.0.11080
PUP.Optional.Conduit, HKU\S-1-5-21-1429871492-45722225-1832122274-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURL, En cuarentena, [208], [236865],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{01F6FB4F-ED74-4A32-8FD0-C3DA11164552}|PATH, En cuarentena, [1229], [527820],1.0.11080
PUP.Optional.DefaultSearch, HKU\S-1-5-21-1429871492-45722225-1832122274-1001\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|NLADLJMABBOANHIHFKJACNNKGJHNOKHJ, En cuarentena, [299], [550469],1.0.11080
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}|CONTACT, En cuarentena, [3685], [333852],1.0.11080
PUP.Optional.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{39EB44D1-282B-48BC-8E9D-763BDBBFB157}|PATH, En cuarentena, [3685], [391427],1.0.11080
PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}|URLINFOABOUT, En cuarentena, [3685], [321304],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{467B26D0-BE04-4C8D-B376-286BCDF91B6E}|PATH, En cuarentena, [1229], [527820],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{5B08211A-5871-4FBD-BA50-AA7086931D92}|PATH, En cuarentena, [1229], [527820],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{676D871D-4D2F-425B-9C32-8B26DF271110}|PATH, En cuarentena, [1229], [527820],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{827FE1EB-12AC-4293-A98B-749899FB9798}|PATH, En cuarentena, [1229], [527820],1.0.11080
Adware.OnlineIO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{EEF0AAE1-92D0-486D-9765-11D64ECFA72D}|PATH, En cuarentena, [1229], [527820],1.0.11080
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 9
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0, Se eliminará al reiniciar, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application, Se eliminará al reiniciar, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\PROGRAM FILES (X86)\MICROLEAVES, Se eliminará al reiniciar, [1229], [399420],1.0.11080
Trojan.Agent, C:\PROGRAMDATA\21defe84, En cuarentena, [436], [667267],1.0.11080
PUP.Optional.OnlineIO, C:\WINDOWS\INSTALLER\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, En cuarentena, [3685], [391425],1.0.11080
Adware.OnlineIO, C:\Users\Joker\AppData\Roaming\Microleaves\Online Application 2.7.0\install\CFCBAA1, En cuarentena, [1229], [399763],1.0.11080
Adware.OnlineIO, C:\Users\Joker\AppData\Roaming\Microleaves\Online Application 2.7.0\install, En cuarentena, [1229], [399763],1.0.11080
Adware.OnlineIO, C:\Users\Joker\AppData\Roaming\Microleaves\Online Application 2.7.0, En cuarentena, [1229], [399763],1.0.11080
Adware.OnlineIO, C:\USERS\JOKER\APPDATA\ROAMING\MICROLEAVES, En cuarentena, [1229], [399763],1.0.11080
Archivo: 35
Adware.OnlineIO, C:\WINDOWS\TASKS\Updater_Online_Application.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Updater_Online_Application, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\PROGRAM FILES (X86)\MICROLEAVES\Online Application\Online Application Updater.exe, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online-Guardian.exe, Se eliminará al reiniciar, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online.io EULA.url, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Online.io Privacy.url, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Version 2.6.0\Uninstall Online Application.lnk, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\Program Files (x86)\Microleaves\Online Application\Online Application Updater.ini, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\TASKS\Online Application V2G1.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Online Application V2G1, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\TASKS\Online Application V2G2.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Online Application V2G2, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\TASKS\Online Application V2G3.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Online Application V2G3, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\TASKS\Online Application V2G4.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Online Application V2G4, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\TASKS\Online Application V2G5.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Online Application V2G5, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\TASKS\Online Application V2G6.job, En cuarentena, [1229], [399420],1.0.11080
Adware.OnlineIO, C:\WINDOWS\SYSTEM32\TASKS\Online Application V2G6, En cuarentena, [1229], [399420],1.0.11080
PUP.Optional.OnlineIO, C:\WINDOWS\INSTALLER\SOURCEHASH{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, En cuarentena, [3685], [391431],1.0.11080
Trojan.Agent, C:\PROGRAMDATA\21defe84\21defe84test.au3, En cuarentena, [436], [667267],1.0.11080
Trojan.Agent, C:\ProgramData\21defe84\21defe84.exe, En cuarentena, [436], [667267],1.0.11080
Trojan.Agent, C:\ProgramData\21defe84\PE.bin, En cuarentena, [436], [667267],1.0.11080
PUP.Optional.DefaultSearch, C:\USERS\JOKER\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Error durante la eliminación, [299], [550469],1.0.11080
PUP.Optional.OnlineIO, C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\online.exe, En cuarentena, [3685], [391425],1.0.11080
PUP.Optional.OnlineIO, C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\SystemFoldermsiexec.exe, En cuarentena, [3685], [391425],1.0.11080
Adware.OnlineIO, C:\Users\Joker\AppData\Roaming\Microleaves\Online Application 2.7.0\install\CFCBAA1\Basic Installer with memory detection.msi, En cuarentena, [1229], [399763],1.0.11080
PUP.Optional.Conduit, C:\USERS\JOKER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\YTM88G4Y.DEFAULT-1549782345937\PREFS.JS, Sustituido, [208], [301520],1.0.11080
RiskWare.DontStealOurSoftware, C:\USERS\JOKER\DOWNLOADS\MALWAREBYTES_PREMIUM_3.XX_PATCH.RAR, En cuarentena, [5315], [77942],1.0.11080
Generic.Malware/Suspicious, C:\USERS\JOKER\DOWNLOADS\VIP.EXE, En cuarentena, [0], [392686],1.0.11080
PUP.Optional.InstallCore, C:\USERS\JOKER\DOWNLOADS\UTORRENT_ACCELERATION_TOOL_0677735944.EXE, En cuarentena, [440], [78899],1.0.11080
CrackTool.Agent.Keygen, C:\USERS\JOKER\DESKTOP\MEDIA MONKEY TND.4.1.24.1883MM\KEYGEN-AMPED.RAR, En cuarentena, [7755], [571435],1.0.11080
PUP.Optional.DefaultSearch, C:\USERS\JOKER\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sustituido, [299], [469798],1.0.11080
Trojan.Chad, C:\USERS\JOKER\DESKTOP\PROGRAMAS INSTALADOS\PKC.EXE, En cuarentena, [9304], [269192],1.0.11080
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)