Compañeros
Según lo solicitado, procedo a copiar los reportes
Malwarebytes
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 3/8/20
Hora del análisis: 18:14
Archivo de registro: a3c59da6-d5d6-11ea-ba46-8c89a507cf98.json
-Información del software-
Versión: 4.1.2.73
Versión de los componentes: 1.0.990
Versión del paquete de actualización: 1.0.27893
Licencia: Prueba
-Información del sistema-
SO: Windows 7 Service Pack 1
CPU: x64
Sistema de archivos: NTFS
Usuario: MT-PC\MT
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Manual
Resultado: Completado
Objetos analizados: 224581
Amenazas detectadas: 23
Amenazas en cuarentena: 23
Tiempo transcurrido: 8 min, 32 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 3
Trojan.Agent.CK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\OInstall, En cuarentena, 3872, 400551, , , ,
Trojan.Agent.CK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{956504C6-232B-454F-A77F-5D292EF195A2}, En cuarentena, 3872, 400551, , , ,
Trojan.Agent.CK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{956504C6-232B-454F-A77F-5D292EF195A2}, En cuarentena, 3872, 400551, , , ,
Valor del registro: 3
Trojan.Agent.CK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{956504C6-232B-454F-A77F-5D292EF195A2}|PATH, En cuarentena, 3872, 400549, 1.0.27893, , ame,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, En cuarentena, 6899, 676881, 1.0.27893, , ame,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\MRT|DONTREPORTINFECTIONINFORMATION, En cuarentena, 6899, 676881, 1.0.27893, , ame,
Datos del registro: 3
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SECURITY CENTER|ANTIVIRUSDISABLENOTIFY, Sustituido, 13667, 293294, 1.0.27893, , ame,
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SECURITY CENTER|FIREWALLDISABLENOTIFY, Sustituido, 13667, 293295, 1.0.27893, , ame,
PUM.Optional.DisabledSecurityCenter, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SECURITY CENTER|UPDATESDISABLENOTIFY, Sustituido, 13667, 293296, 1.0.27893, , ame,
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 0
(No hay elementos maliciosos detectados)
Archivo: 14
Trojan.Agent.CK, C:\WINDOWS\SYSTEM32\TASKS\OINSTALL, En cuarentena, 3872, 400551, 1.0.27893, , ame,
Malware.Sandbox.1, C:\PROGRAMDATA\APPLE COMPUTER\INSTALLER CACHE\ITUNES 12.10.8.5\SETUPADMIN.EXE, En cuarentena, 1, 0, 1.0.27893, 1, dds, 00836467
MachineLearning/Anomalous.97%, C:\PROGRAM FILES (X86)\ATT2007\UPDATE.EXE, En cuarentena, 0, 392687, 1.0.27893, , shuriken,
Malware.AI.3820552348, C:\PROGRAM FILES (X86)\INTERNET DOWNLOAD MANAGER\PATCH [WWW.TECNOTUTOSHD.NET].EXE, En cuarentena, 1000000, 0, 1.0.27893, 4A754974497A47E0E3B9009C, dds, 00836467
Trojan.Agent, C:\USERS\MT\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\VHBRFTFT.EXE, En cuarentena, 499, 267367, 1.0.27893, , ame,
Trojan.Agent, C:\EBSIXC.EXE, En cuarentena, 499, 25717, 1.0.27893, 0000000000000000000003EC, dds, 00836467
Malware.AI.4107270089, C:\PROGRAM FILES (X86)\WEBCAM SURVEYOR\VERSION.DLL, En cuarentena, 1000000, 0, 1.0.27893, D9331FE04D0303F8F4CFF7C9, dds, 00836467
Generic.Malware/Suspicious, C:\USERS\MT\DOWNLOADS\Z3X 29.5.EXE, En cuarentena, 0, 392686, 1.0.27893, , shuriken,
Malware.AI.3820552348, C:\USERS\MT\DOWNLOADS\IDM 6.38 [WWW.TECNOTUTOSHD.NET].ZIP, En cuarentena, 1000000, 0, 1.0.27893, 4A754974497A47E0E3B9009C, dds, 00836467
MachineLearning/Anomalous.100%, C:\USERS\MT\DESKTOP\FREE4PC.ORG_WEBCAM SURVEYOR 3.8.1 BUILD 1135\KEYGEN.RAR, En cuarentena, 0, 392687, 1.0.27893, , shuriken,
Malware.AI.4107270089, C:\USERS\MT\DESKTOP\FREE4PC.ORG_WEBCAM SURVEYOR 3.8.1 BUILD 1135\KEYGEN\VERSION.DLL, En cuarentena, 1000000, 0, 1.0.27893, D9331FE04D0303F8F4CFF7C9, dds, 00836467
Trojan.Agent, C:\USERS\MT\DESKTOP\ADOBE PHOTOSHOP CS6.V13.0\PSCS6MGR.EXE, En cuarentena, 499, 267367, 1.0.27893, , ame,
Malware.AI.3820552348, C:\USERS\MT\DESKTOP\INTERNET DOWNLOAD MANAGER 6.38 [WWW.TECNOTUTOSHD.NET]\PATCH [WWW.TECNOTUTOSHD.NET].ZIP, En cuarentena, 1000000, 0, 1.0.27893, 4A754974497A47E0E3B9009C, dds, 00836467
Malware.AI.3820552348, C:\USERS\MT\DESKTOP\INTERNET DOWNLOAD MANAGER 6.38 [WWW.TECNOTUTOSHD.NET]\PATCH [WWW.TECNOTUTOSHD.NET]\PATCH [WWW.TECNOTUTOSHD.NET].EXE, En cuarentena, 1000000, 0, 1.0.27893, 4A754974497A47E0E3B9009C, dds, 00836467
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
AdwCleaner
# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build: 07-22-2020
# Database: 2020-07-20.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 08-03-2020
# Duration: 00:00:14
# OS: Windows 7 Ultimate
# Cleaned: 7
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
No malicious folders cleaned.
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
No malicious registry entries cleaned.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
Deleted Preinstalled.SamsungSmartSwitch File C:\Users\MT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Smart Switch.lnk
Deleted Preinstalled.SamsungSmartSwitch File C:\Users\Public\Desktop\Smart Switch.lnk
Deleted Preinstalled.SamsungSmartSwitch Folder C:\Program Files (x86)\SAMSUNG\SMART SWITCH PC
Deleted Preinstalled.SamsungSmartSwitch Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAMSUNG\SMART SWITCH PC
Deleted Preinstalled.SamsungSmartSwitch Folder C:\Users\MT\AppData\Roaming\SAMSUNG\SMART SWITCH PC
Deleted Preinstalled.SamsungSmartSwitch Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
Deleted Preinstalled.SamsungSmartSwitch Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2226 octets] - [03/08/2020 18:30:13]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Ultimate x64
Ran by MT (Administrator) on 03/08/2020 at 18:54:25,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 18
Successfully deleted: C:\Windows\system32\Tasks\Driver Easy Scheduled Scan (Task)
Successfully deleted: C:\Windows\Tasks\Driver Easy Scheduled Scan.job (Task)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AMNHMUW5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E0AXAQBT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1KTRDZ1 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\MT\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJYSQ89H (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AMNHMUW5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E0AXAQBT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1KTRDZ1 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YJYSQ89H (Temporary Internet Files Folder)
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03/08/2020 at 18:57:46,54
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
UsbFix
# ----------------------------------------------------
# UsbFix Antivirus Free
# ----------------------------------------------------
# Versión : 11.022
# Base de datos :
# Contacto : https://www.usb-antivirus.com/es/contacto
# ----------------------------------------------------
# Tipo de escaneo : Full
# Usuario : MT (Administrador)
# Dispositivo : MT-PC
# Comenzó : 03/08/2020 18:59:22
# ----------------------------------------------------
------------ | Discos analizados |
C:\ NTFS (47GB/298GB) [Fixed]
E:\ FAT32 (460GB/4GB) [Removable]
------------ | Elemento(s) infectado(s) |
Restorado! E:\eoenin.pif
Borrado! E:\eoenin.pif
------------ | Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
04 - HKLM\..\Run : [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\..\Run : [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
04 - [x64] HKLM\..\Run : [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
04 - [x64] HKLM\..\Run : [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3380502224-217511032-4092454543-1000\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-3380502224-217511032-4092454543-1000\..\Run : [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
------------ | Tasks |
Task - CCleaner Update --> C:\Program Files\CCleaner\CCUpdate.exe
Task - CCleanerSkipUAC --> "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Task - GoogleUpdateTaskMachineCore --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
Task - GoogleUpdateTaskMachineUA --> C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
------------ | C:\ %SystemDrive% - Disco fijo (NTFS) |
[03/08/2020 - 18:32:44 | ASH | 3066440 Ko] - hiberfil.sys
[03/08/2020 - 18:32:46 | ASH | 4088588 Ko] - pagefile.sys
[01/08/2020 - 15:32:52 | SHD] - Config.Msi
[29/07/2020 - 23:26:35 | RSH | 0 Ko] - autorun.inf
[03/08/2020 - 18:23:53 | A | 97 Ko] - ebsixc.exe
[14/06/2020 - 09:34:29 | SHD] - $Recycle.Bin
[20/05/2020 - 12:31:08 | D] - 05.20.2020-Datastead URL Source
[13/07/2009 - 23:20:08 | D] - PerfLogs
[14/07/2009 - 01:08:56 | SHD] - Documents and Settings
[05/02/2020 - 15:41:51 | SHD] - Archivos de programa
[05/02/2020 - 15:41:52 | SHD] - Recovery
[05/02/2020 - 15:42:34 | RD] - Users
[05/02/2020 - 15:47:03 | D] - Intel
[05/02/2020 - 21:46:42 | D] - Drivers
[08/07/2020 - 17:58:35 | D] - sim_scan
[30/07/2020 - 00:07:10 | AH | 0 Ko] - 0847085064A9
[01/08/2020 - 16:15:15 | D] - RS
[03/08/2020 - 17:36:17 | RD] - Program Files
[03/08/2020 - 17:40:55 | HD] - ProgramData
[03/08/2020 - 18:31:10 | D] - AdwCleaner
[03/08/2020 - 18:55:01 | D] - Windows
[03/08/2020 - 18:58:43 | RD] - Program Files (x86)
------------ | E:\ - Disco extraíble (FAT32) |
[29/07/2020 - 23:26:36 | RSH | 0 Ko] - autorun.inf
[25/07/2016 - 07:40:34 | A | 355 Ko] - INSTRUCTIVO PARA ENCUADERNAR LOS PROGRAMAS ANALÍTICOS IUTI.docx
[12/01/2017 - 10:31:32 | A | 945 Ko] - PORTADA CICLOBÁSICO.doc
[12/01/2017 - 10:31:54 | A | 946 Ko] - PORTADA CICLOPROFESIONAL.doc
[27/05/2020 - 09:31:14 | D] - MECANICA TERMICA - copia
[23/07/2020 - 12:16:54 | D] - Un troyano ha ocultado los archivos
[01/08/2020 - 11:52:12 | D] - 360 Quarantine Folder
Elemento(s) infectado(s) : 2
Elementos analizados : 68145 en 00h 00m 06s
# UsbFix-Report-01.txt [4505B]
------------ | E.O.F |