Reporte de Malwarebytes.com
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 6/11/21
Hora del análisis: 11:31
Archivo de registro: a8c8bd2e-3f16-11ec-800d-a01d48084f0d.json
-Información del software-
Versión: 4.4.10.144
Versión de los componentes: 1.0.1499
Versión del paquete de actualización: 1.0.46874
Licencia: Prueba
-Información del sistema-
SO: Windows 10 (Build 18363.476)
CPU: x64
Sistema de archivos: NTFS
Usuario: Oprekin-PC\Samuel
-Resumen del análisis-
Tipo de análisis: Análisis personalizado
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 385724
Amenazas detectadas: 54
Amenazas en cuarentena: 52
Tiempo transcurrido: 5 hr, 26 min, 31 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Activado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 18
Trojan.Clipper, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Smart Clock, En cuarentena, 3975, 962915, , , , , ,
Trojan.Clipper, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B363D0CD-C5C1-4092-9C15-1A2553C6828E}, En cuarentena, 3975, 962915, , , , , ,
Trojan.Clipper, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{B363D0CD-C5C1-4092-9C15-1A2553C6828E}, En cuarentena, 3975, 962915, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\UpdateCore0x300, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B9E5605D-0D50-487C-8696-979698CC6C70}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{B9E5605D-0D50-487C-8696-979698CC6C70}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\UpdateCore0x302, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{771C0F29-90A2-43BF-9D29-EB63FC043F3C}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{771C0F29-90A2-43BF-9D29-EB63FC043F3C}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\UpdateCore0x303, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3787F03E-05A1-40B5-9DB8-859B4EBCD854}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{3787F03E-05A1-40B5-9DB8-859B4EBCD854}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\UpdateCore0x304, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{82D0F664-11A4-4251-BF9A-0B10982B0141}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{82D0F664-11A4-4251-BF9A-0B10982B0141}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\UpdateCore0x301, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{AC223847-4E39-439A-8A2E-2C3374C9F653}, En cuarentena, 584, 962485, , , , , ,
Trojan.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{AC223847-4E39-439A-8A2E-2C3374C9F653}, En cuarentena, 584, 962485, , , , , ,
Valor del registro: 5
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-21-602489459-2997762162-3949720032-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LOWRISKFILETYPES, En cuarentena, 6477, 251589, 1.0.46874, , ame, , ,
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LOWRISKFILETYPES, Error durante la eliminación, 6477, 251589, 1.0.46874, , ame, , ,
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LOWRISKFILETYPES, En cuarentena, 6477, 251589, 1.0.46874, , ame, , ,
PUM.Optional.LowRiskFileTypes, HKU\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LOWRISKFILETYPES, Error durante la eliminación, 6477, 251589, 1.0.46874, , ame, , ,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTOFFERTHROUGHWUAU, En cuarentena, 6816, 676880, 1.0.46874, , ame, , ,
Datos del registro: 0
(No hay elementos maliciosos detectados)
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 1
Trojan.Dropper, C:\ProgramData\Posse, En cuarentena, 593, 930778, 1.0.46874, , ame, , ,
Archivo: 30
Trojan.Clipper, C:\WINDOWS\SYSTEM32\TASKS\Smart Clock, En cuarentena, 3975, 962915, 1.0.46874, , ame, , FD97A2DEAD43983DED531C73E95CD8FD, DAA459B041A27230ACFEC7729D9FBFEA70D8C7706E7C02796C562C5E56AF97B8
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\UpdateCore0x300, En cuarentena, 584, 962485, 1.0.46874, , ame, , C7C6643719A38FDF4A336A27A92F290A, F1E340C922A52532E6F7004D2412AAE2A8040C6A5C6EE9B0373C75801B4D1388
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\UpdateCore0x302, En cuarentena, 584, 962485, 1.0.46874, , ame, , A0F651CFAEDCF95BDB7AC5C76A28D59F, BB7147F2BE4AECA1B2143C48DA7944E4F4A5088115FD9171C7A5EBDD8CC996DF
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\UpdateCore0x303, En cuarentena, 584, 962485, 1.0.46874, , ame, , 0996E76B7DEBEF6E98CE88C515B28AAF, AF8C34898DF947A248DF192000EFB557238838657E3BA1A3A3A6160C442D384E
Trojan.MalPack.GS, C:\USERS\SAMUEL\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\SmartClock.lnk, En cuarentena, 8131, 940420, , , , , 3DF6E17F3093509B19C4566DC32504E3, F4BCF1F93E763FBFC09B6B00B2BB38757EE02C7779F5F9F4FA854FBFB7FC2DB2
Trojan.MalPack.GS, C:\USERS\SAMUEL\APPDATA\ROAMING\SMART CLOCK\SMARTCLOCK.EXE, En cuarentena, 8131, 940420, 1.0.46874, 33DD3358F4C309A26152F65C, dds, 01498447, 93881C3C3D456D1F8624E71E30CD1AD8, 53863A0AE081AE7F054A03910733D5BEF86D6FE6B3F5C4B41D21D6A65908FDBE
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\UpdateCore0x304, En cuarentena, 584, 962485, 1.0.46874, , ame, , 8A0F0300797CD62233717FED3FF269D5, 653519F9652E259D50715A56CB730A17147980269DC8E685BDC84058E3ED6B3A
Trojan.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\UpdateCore0x301, En cuarentena, 584, 962485, 1.0.46874, , ame, , 9A2B1D375FB017EB1EEE7651712B6205, BFF749B21697FD20876C62D060FFF122CA239DD283DE365AB422DC42924F4398
Malware.Heuristic.1001, C:\PROGRAM FILES (X86)\2K SPORTS\NBA 2K13\RLD.DLL, En cuarentena, 1000001, 980983, 1.0.46874, 0000000000000000000003E9, dds, 01498447, FDEF6A4605EF15CA791BDFA88BAA69B7, BADC7A779B85DCB05E739C7B2CE1CDB116CF356BE70E3361587BCCC611A30E1C
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\GOOGLE\UPDATE\GPU_UPDATE.EXE, En cuarentena, 898, 930555, 1.0.46874, , ame, , 0820A2AA39E5FB39661E84F4D97301F1, 794B37D03568CEDD4452A3FBA8A5BE05F30196A1F17CD03B2981BA66318AC9A6
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\GOOGLE\UPDATE\IT_UPDATE.EXE, En cuarentena, 898, 734456, 1.0.46874, , ame, , A7168BD94F951899E8A37523BDE461DC, C1F09C6CA6C683E1605EDD5F9C3B3CC9B9524D60D2BD961647C959F17593A1D5
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\MICROSOFT\UPDATE\GPU_UPDATE.EXE, En cuarentena, 898, 930555, 1.0.46874, , ame, , 0820A2AA39E5FB39661E84F4D97301F1, 794B37D03568CEDD4452A3FBA8A5BE05F30196A1F17CD03B2981BA66318AC9A6
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\MICROSOFT\UPDATE\IT_UPDATE.EXE, En cuarentena, 898, 734456, 1.0.46874, , ame, , A7168BD94F951899E8A37523BDE461DC, C1F09C6CA6C683E1605EDD5F9C3B3CC9B9524D60D2BD961647C959F17593A1D5
Malware.AI.1340338516, C:\USERS\SAMUEL\APPDATA\LOCAL\MOZILLA\UPDATE\DOWNLOAD.EXE, En cuarentena, 1000000, 0, 1.0.46874, 363C19111728CDBE4FE3F154, dds, 01498447, 56E17751A0F1F506EE7CA9F35BD77738, E18A786A55C051E51495FE92C156B98BF292ECAC8F55E872233AE59582B0126E
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\MOZILLA\UPDATE\GPU_UPDATE.EXE, En cuarentena, 898, 930555, 1.0.46874, 8F02730CE88CE662F850A154, dds, 01498447, 0820A2AA39E5FB39661E84F4D97301F1, 794B37D03568CEDD4452A3FBA8A5BE05F30196A1F17CD03B2981BA66318AC9A6
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\MOZILLA\UPDATE\IT_UPDATE.EXE, En cuarentena, 898, 734456, 1.0.46874, 5C69EE531FED0A0A6C69970D, dds, 01498447, A7168BD94F951899E8A37523BDE461DC, C1F09C6CA6C683E1605EDD5F9C3B3CC9B9524D60D2BD961647C959F17593A1D5
Malware.AI.1340338516, C:\USERS\SAMUEL\APPDATA\LOCAL\NAMANG\DOWNLOAD.EXE, En cuarentena, 1000000, 0, 1.0.46874, 363C19111728CDBE4FE3F154, dds, 01498447, 56E17751A0F1F506EE7CA9F35BD77738, E18A786A55C051E51495FE92C156B98BF292ECAC8F55E872233AE59582B0126E
Malware.AI.1340338516, C:\USERS\SAMUEL\APPDATA\LOCAL\PACKAGES\UPDATE\DOWNLOAD.EXE, En cuarentena, 1000000, 0, 1.0.46874, 363C19111728CDBE4FE3F154, dds, 01498447, 56E17751A0F1F506EE7CA9F35BD77738, E18A786A55C051E51495FE92C156B98BF292ECAC8F55E872233AE59582B0126E
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\PACKAGES\UPDATE\GPU_UPDATE.EXE, En cuarentena, 898, 930555, 1.0.46874, 8F02730CE88CE662F850A154, dds, 01498447, 0820A2AA39E5FB39661E84F4D97301F1, 794B37D03568CEDD4452A3FBA8A5BE05F30196A1F17CD03B2981BA66318AC9A6
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\PACKAGES\UPDATE\IT_UPDATE.EXE, En cuarentena, 898, 734456, 1.0.46874, 5C69EE531FED0A0A6C69970D, dds, 01498447, A7168BD94F951899E8A37523BDE461DC, C1F09C6CA6C683E1605EDD5F9C3B3CC9B9524D60D2BD961647C959F17593A1D5
Malware.AI.1340338516, C:\USERS\SAMUEL\APPDATA\LOCAL\UPDATE\DOWNLOAD.EXE, En cuarentena, 1000000, 0, 1.0.46874, 363C19111728CDBE4FE3F154, dds, 01498447, 56E17751A0F1F506EE7CA9F35BD77738, E18A786A55C051E51495FE92C156B98BF292ECAC8F55E872233AE59582B0126E
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\UPDATE\GPU_UPDATE.EXE, En cuarentena, 898, 930555, 1.0.46874, 8F02730CE88CE662F850A154, dds, 01498447, 0820A2AA39E5FB39661E84F4D97301F1, 794B37D03568CEDD4452A3FBA8A5BE05F30196A1F17CD03B2981BA66318AC9A6
RiskWare.BitCoinMiner, C:\USERS\SAMUEL\APPDATA\LOCAL\UPDATE\IT_UPDATE.EXE, En cuarentena, 898, 734456, 1.0.46874, 5C69EE531FED0A0A6C69970D, dds, 01498447, A7168BD94F951899E8A37523BDE461DC, C1F09C6CA6C683E1605EDD5F9C3B3CC9B9524D60D2BD961647C959F17593A1D5
Trojan.AVKill, C:\USERS\SAMUEL\APPDATA\SYSTEM_INIT.BAT, En cuarentena, 3903, 962298, 1.0.46874, , ame, , 54B7094663E2913C12F05DB604C9AB58, 2816672EFA589CB85AB27DD874D68A992075CCADC8834EAE8A27B0A3BB275815
Malware.Heuristic.1003, C:\USERS\SAMUEL\DOWNLOADS\NR2_SETUP\NR2_SETUP\MSIMG32.DLL, En cuarentena, 1000001, 0, 1.0.46874, 0000000000000000000003EB, dds, 01498447, 58FAAF6C5D6B400E87FBEE1AEAD4216F, 7285C599FC2F1CC90F0620C0A42B6E34B9FD906B726803C82F5EC1B8F37D7A66
RiskWare.Tool.CK, C:\USERS\SAMUEL\DOWNLOADS\SOUND FORGE PRO 10\SOUND FORGE PRO 10\SOUND FORGE PRO 10.0 CRACKING TOOLS ABELINO MC.RAR\SONY VEGAS PRO 10 CRACKING TOOLS\KEYGEN.EXE, En cuarentena, 7207, 133397, 1.0.46874, 01C6154EBCD28F562586D076, dds, 01498447, D41582DC6CEBCE220298A1EBF116363A, 016CD123F5806ACCA448E71F7310E9E2784B8F25E05417F975F7E181281E4BD0
RiskWare.Tool.HCK, C:\USERS\SAMUEL\DOWNLOADS\SOUND FORGE PRO 10\SOUND FORGE PRO 10\SOUND FORGE PRO 10.0 CRACKING TOOLS ABELINO MC.RAR\SONY VEGAS PRO 10 CRACKING TOOLS\SONYVEGASPRO PATCH.EXE, En cuarentena, 7217, 138555, 1.0.46874, 0000000000000000000003EB, dds, 01498447, FC9FC6FE89061ACC405DF329C2192895, DDD1035A2B3A3BE0FE0B6B97B99A0CE2E33733EC031FCFDED81B10EF88564FE3
PUP.Optional.DotSetupIo.BundleInstaller, C:\USERS\SAMUEL\DOWNLOADS\ATUBE_CATCHER_V2.16.323.235.2.EXE, En cuarentena, 13889, 943421, 1.0.46874, , ame, , 2A3059DD0AE52B5110CB372FC93264E1, 4B7767538F0CACF36AEC177F328C017F95393CC37FE63212855BD298E20219BA
PUP.Optional.DotSetupIo.BundleInstaller, C:\USERS\SAMUEL\DOWNLOADS\ATUBE_CATCHER_V4.21.76.193.77.EXE, En cuarentena, 13889, 943421, 1.0.46874, , ame, , 2A3059DD0AE52B5110CB372FC93264E1, 4B7767538F0CACF36AEC177F328C017F95393CC37FE63212855BD298E20219BA
PUP.Optional.BundleInstaller, C:\USERS\SAMUEL\DOWNLOADS\UTORRENT.EXE, En cuarentena, 517, 875791, 1.0.46874, , ame, , C7C8F54708D4867BD0E1FD8D0AF1A73B, 6850ECC63BA46B91559AB8AEF1BF890F7E3DD26622A9D0935CD84D425DA798FE
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
Reporte del AdwCleaner
# -------------------------------
# Malwarebytes AdwCleaner 8.3.0.0
# -------------------------------
# Build: 06-29-2021
# Database: 2021-10-26.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 11-06-2021
# Duration: 00:00:07
# OS: Windows 10 Pro
# Cleaned: 3
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\ProgramData\WinThruster
Deleted C:\Users\Samuel\AppData\Roaming\Smart Clock
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKLM\Software\Wow6432Node\\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474}
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [1588 octets] - [06/11/2021 17:53:44]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########