Adjunto el reporte de Malwarebytes:
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 7/3/20
Hora del análisis: 18:23
Archivo de registro: 3c625bba-60c2-11ea-99b1-eca86b9904a2.json
-Información del software-
Versión: 4.1.0.56
Versión de los componentes: 1.0.835
Versión del paquete de actualización: 1.0.20362
Licencia: Prueba
-Información del sistema-
SO: Windows 7 Service Pack 1
CPU: x86
Sistema de archivos: NTFS
Usuario: DISLORTH-WORK\Disloth
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 302594
Amenazas detectadas: 70
Amenazas en cuarentena: 70
Tiempo transcurrido: 42 min, 9 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 1
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MinerGate, En cuarentena, 850, 726324, , , ,
Valor del registro: 2
RiskWare.BitCoinMiner, HKU\S-1-5-21-838994074-81632765-970354094-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|MinerGateGui, En cuarentena, 850, 726324, , , ,
PUP.Optional.Imali.Generic, HKU\S-1-5-21-838994074-81632765-970354094-1000\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|hijfkjphpcbbabdnpkmgcdnpfhjldbhm, En cuarentena, 4576, 443118, , , ,
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 12
RiskWare.BitCoinMiner, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\MINERGATE, En cuarentena, 850, 411852, 1.0.20362, , ame,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\USERS\DISLOTH\APPDATA\LOCAL\MINERGATE, En cuarentena, 850, 411853, 1.0.20362, , ame,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\imageformats, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\platforms, En cuarentena, 850, 726324, , , ,
PUP.Optional.Imali.Generic, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, Sustituido, 4576, 443118, , , ,
PUP.Optional.Imali.Generic, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HIJFKJPHPCBBABDNPKMGCDNPFHJLDBHM, En cuarentena, 4576, 443118, 1.0.20362, , ame,
PUP.Optional.Funmoods, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, En cuarentena, 334, 455241, , , ,
PUP.Optional.SearchModule, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, En cuarentena, 303, 458372, , , ,
Adware.Elex.ShrtCln, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, En cuarentena, 298, 454717, , , ,
Adware.Elex.ShrtCln, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, En cuarentena, 298, 454717, , , ,
PUP.Optional.Funmoods, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, En cuarentena, 334, 455241, , , ,
Archivo: 55
RiskWare.BitCoinMiner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MinerGate\MinerGate.lnk, En cuarentena, 850, 411852, , , ,
RiskWare.BitCoinMiner, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MinerGate\Uninstall.lnk, En cuarentena, 850, 411852, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\aeon.log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\bcn.log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\bcn.log.old, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\dsh.log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\fcn.log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\minergate.log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\minergate.log.old, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\log\xmr.log, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\.achievements, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\.achievements.bak, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\.lock, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\.miners_lock, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\[email protected], En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\[email protected], En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\miners.ini, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\miners.ini.IK2336, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Users\Disloth\AppData\Local\minergate\pools.config, En cuarentena, 850, 411853, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\imageformats\qico.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\platforms\qwindows.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\libeay32.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\minergate.exe, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\OpenCL.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\Qt5Core.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\Qt5Gui.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\Qt5Network.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\Qt5WebSockets.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\Qt5Widgets.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\ssleay32.dll, En cuarentena, 850, 726324, , , ,
RiskWare.BitCoinMiner, C:\Program Files\MinerGate\Uninstall.exe, En cuarentena, 850, 726324, , , ,
PUP.Optional.Imali.Generic, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Sustituido, 4576, 443118, , , ,
PUP.Optional.Imali.Generic, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Sustituido, 4576, 443118, , , ,
PUP.Optional.Imali.Generic, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HIJFKJPHPCBBABDNPKMGCDNPFHJLDBHM\0.8_0\REDIRECT.JS, En cuarentena, 4576, 443118, 1.0.20362, , ame,
PUP.Optional.Cgminer, C:\USERS\DISLOTH\DOWNLOADS\CGMINER-3.7.2-WINDOWS.ZIP, En cuarentena, 10872, 45746, 1.0.20362, , ame,
RiskWare.BitCoinMiner.VMP, C:\USERS\DISLOTH\DOWNLOADS\CLAYMORE'S DUAL ETHEREUM+DECRED_SIACOIN_LBRY_PASCAL_BLAKE2S_KECCAK AMD+NVIDIA GPU MINER V12.0 - CATALYST 15.12-18.X - CUDA 8.0_10.0_9.1_7.5_6.5.ZIP, En cuarentena, 7803, 616646, 1.0.20362, , ame,
RiskWare.BitCoinMiner, C:\USERS\DISLOTH\DOWNLOADS\CLAYMORE'S DUAL ETHEREUM+DECRED_SIACOIN_LBRY_PASCAL_BLAKE2S_KECCAK AMD+NVIDIA GPU MINER V14.5 BETA.ZIP, En cuarentena, 850, 685990, 1.0.20362, , ame,
RiskWare.BitCoinMiner, C:\USERS\DISLOTH\DOWNLOADS\MINERGATE-5.22-WIN32.EXE, En cuarentena, 850, 472639, 1.0.20362, , ame,
RiskWare.BitCoinMiner, C:\USERS\DISLOTH\DOWNLOADS\XMR-STAK-WIN64.ZIP, En cuarentena, 850, 497806, 1.0.20362, , ame,
RiskWare.BitCoinMiner, C:\USERS\DISLOTH\DESKTOP\RIG\ESCRITORIO MINA\V9.8.ZIP, En cuarentena, 850, 556050, 1.0.20362, , ame,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000007.ldb, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000009.ldb, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000010.log, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000011.ldb, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\Users\Disloth\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, En cuarentena, 334, 455241, , , ,
PUP.Optional.Funmoods, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, 334, 455241, 1.0.20362, , ame,
PUP.Optional.SearchModule, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, 303, 458372, 1.0.20362, , ame,
Adware.Elex.ShrtCln, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, 298, 454717, 1.0.20362, , ame,
Adware.Elex.ShrtCln, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, 298, 454717, 1.0.20362, , ame,
PUP.Optional.Funmoods, C:\USERS\DISLOTH\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Sustituido, 334, 455241, 1.0.20362, , ame,
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
Adjunto el reporte de AdwCleaner:
# -------------------------------
# Malwarebytes AdwCleaner 8.0.3.0
# -------------------------------
# Build: 03-03-2020
# Database: 2020-03-02.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-07-2020
# Duration: 00:00:05
# OS: Windows 7 Ultimate
# Cleaned: 20
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files\minergate
Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
Deleted C:\Users\Disloth\AppData\Roaming\Tencent
***** [ Files ] *****
Deleted C:\Users\Disloth\AppData\Roaming\Mozilla\Firefox\Profiles\eu0q8ksl.default\searchplugins\yahoo-lavasoft.xml
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Lavasoft\Web Companion
Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|AndroidServer.exe
Deleted HKLM\Software\Lavasoft\Web Companion
***** [ Chromium (and derivatives) ] *****
Deleted NeoBux AdAlert - oaepeijninfcgjdnighjnlgdkkgpnaen
***** [ Chromium URLs ] *****
Deleted AVG Secure Search
Deleted Softonic ES
Deleted claro.com.pa
Deleted nabble.com
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.SamsungSmartSwitch File C:\Users\Disloth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Smart Switch.lnk
Deleted Preinstalled.SamsungSmartSwitch File C:\Users\Public\Desktop\Smart Switch.lnk
Deleted Preinstalled.SamsungSmartSwitch Folder C:\Program Files\SAMSUNG\SMART SWITCH PC
Deleted Preinstalled.SamsungSmartSwitch Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAMSUNG\SMART SWITCH PC
Deleted Preinstalled.SamsungSmartSwitch Folder C:\Users\Disloth\AppData\Roaming\SAMSUNG\SMART SWITCH PC
Deleted Preinstalled.SamsungSmartSwitch Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
Deleted Preinstalled.SamsungSmartSwitch Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [3100 octets] - [07/03/2020 19:11:19]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
# -------------------------------
# Malwarebytes AdwCleaner 8.0.3.0
# -------------------------------
# Build: 03-03-2020
# Database: 2020-03-02.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 03-07-2020
# Duration: 00:00:19
# OS: Windows 7 Ultimate
# Scanned: 31902
# Detected: 20
***** [ Services ] *****
No malicious services found.
***** [ Folders ] *****
PUP.Optional.BitCoinMiner C:\Program Files\minergate
PUP.Optional.Legacy C:\Users\Disloth\AppData\Roaming\Tencent
PUP.Optional.WebCompanion C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion
***** [ Files ] *****
PUP.Optional.Legacy C:\Users\Disloth\AppData\Roaming\Mozilla\Firefox\Profiles\eu0q8ksl.default\searchplugins\yahoo-lavasoft.xml
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious WMI found.
***** [ Shortcuts ] *****
No malicious shortcuts found.
***** [ Tasks ] *****
No malicious tasks found.
***** [ Registry ] *****
PUP.Optional.Legacy HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION|AndroidServer.exe
PUP.Optional.WebCompanion HKCU\Software\Lavasoft\Web Companion
PUP.Optional.WebCompanion HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
PUP.Optional.WebCompanion HKLM\Software\Lavasoft\Web Companion
***** [ Chromium (and derivatives) ] *****
PUP.Optional.Legacy NeoBux AdAlert - oaepeijninfcgjdnighjnlgdkkgpnaen
***** [ Chromium URLs ] *****
PUP.Optional.Legacy AVG Secure Search
PUP.Optional.Legacy claro.com.pa
PUP.Optional.Legacy nabble.com
PUP.Optional.SofTonicAssistant Softonic ES
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries found.
***** [ Firefox URLs ] *****
No malicious Firefox URLs found.
***** [ Hosts File Entries ] *****
No malicious hosts file entries found.
***** [ Preinstalled Software ] *****
Preinstalled.SamsungSmartSwitch File C:\Users\Disloth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Smart Switch.lnk
Preinstalled.SamsungSmartSwitch File C:\Users\Public\Desktop\Smart Switch.lnk
Preinstalled.SamsungSmartSwitch Folder C:\Program Files\SAMSUNG\SMART SWITCH PC
Preinstalled.SamsungSmartSwitch Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAMSUNG\SMART SWITCH PC
Preinstalled.SamsungSmartSwitch Folder C:\Users\Disloth\AppData\Roaming\SAMSUNG\SMART SWITCH PC
Preinstalled.SamsungSmartSwitch Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
Preinstalled.SamsungSmartSwitch Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########