@JavierHF te mando los reportes: MALWAREBYTES
Malwarebytes
www.malwarebytes.com
-Detalles del registro-
Fecha del análisis: 5/8/20
Hora del análisis: 2:32
Archivo de registro: 2bce5652-d6b3-11ea-8733-00270e10b89c.json
-Información del software-
Versión: 4.1.2.73
Versión de los componentes: 1.0.990
Versión del paquete de actualización: 1.0.27957
Licencia: Prueba
-Información del sistema-
SO: Windows 7 Service Pack 1
CPU: x86
Sistema de archivos: NTFS
Usuario: System
-Resumen del análisis-
Tipo de análisis: Análisis de amenazas
Análisis iniciado por:: Programador de tareas
Resultado: Completado
Objetos analizados: 230619
Amenazas detectadas: 29
Amenazas en cuarentena: 29
Tiempo transcurrido: 7 min, 12 seg
-Opciones de análisis-
Memoria: Activado
Inicio: Activado
Sistema de archivos: Activado
Archivo: Activado
Rootkits: Desactivado
Heurística: Activado
PUP: Detectar
PUM: Detectar
-Detalles del análisis-
Proceso: 0
(No hay elementos maliciosos detectados)
Módulo: 0
(No hay elementos maliciosos detectados)
Clave del registro: 19
PUP.Optional.MindSpark, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FromDocToPDFTooltab Uninstall Internet Explorer, En cuarentena, 721, 507792, , , ,
PUP.Optional.Claro, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\Claro LTD, En cuarentena, 316, 236587, 1.0.27957, , ame,
PUP.Optional.DataMngr.AppFlsh, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\DataMngr, En cuarentena, 50, 253612, 1.0.27957, , ame,
PUP.Optional.MindSpark.Generic, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\FromDocToPDF, En cuarentena, 1816, 509089, 1.0.27957, , ame,
PUP.Optional.BProtector, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, En cuarentena, 2427, 235981, 1.0.27957, , ame,
PUP.Optional.BProtector, HKU\S-1-5-21-3465487260-1184485110-4284579-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, En cuarentena, 2427, 235981, 1.0.27957, , ame,
PUP.Optional.PCPerformer, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\PERFORMERSOFT\PC Performer, En cuarentena, 1488, 241585, 1.0.27957, , ame,
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\DataMngr, En cuarentena, 50, 253614, 1.0.27957, , ame,
PUP.Optional.SysTweak, HKLM\SOFTWARE\Systweak, En cuarentena, 811, 327155, 1.0.27957, , ame,
Adware.Agent.OL, HKLM\SOFTWARE\CLASSES\Prod.cap, En cuarentena, 6928, 830817, 1.0.27957, , ame,
PUP.Optional.AdvancedSystemProtector, HKLM\SOFTWARE\MICROSOFT\TRACING\advancedsystemprotector_RASAPI32, En cuarentena, 934, 246262, 1.0.27957, , ame,
PUP.Optional.AdvancedSystemProtector, HKLM\SOFTWARE\MICROSOFT\TRACING\advancedsystemprotector_RASMANCS, En cuarentena, 934, 246262, 1.0.27957, , ame,
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\TRACING\RegCleanPro_RASAPI32, En cuarentena, 4441, 253898, 1.0.27957, , ame,
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\MICROSOFT\TRACING\RegCleanPro_RASMANCS, En cuarentena, 4441, 253898, 1.0.27957, , ame,
PUP.Optional.Babylon, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, En cuarentena, 397, 167673, 1.0.27957, , ame,
PUP.Optional.Claro, HKU\S-1-5-21-3465487260-1184485110-4284579-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}, En cuarentena, 316, 167788, , , ,
PUP.Optional.Claro, HKU\S-1-5-21-3465487260-1184485110-4284579-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}, En cuarentena, 316, 167788, 1.0.27957, , ame,
PUP.Optional.Claro, HKU\S-1-5-21-3465487260-1184485110-4284579-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}, En cuarentena, 316, 167789, , , ,
PUP.Optional.Claro, HKU\S-1-5-21-3465487260-1184485110-4284579-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}, En cuarentena, 316, 167789, 1.0.27957, , ame,
Valor del registro: 5
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, En cuarentena, 50, -1, 0.0.0, , action,
PUP.Optional.MindSpark.Generic, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\FromDocToPDF|START PAGE, En cuarentena, 1816, 509089, 1.0.27957, , ame,
PUP.Optional.BProtector, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|BPROTECTORDEFAULTSCOPE, En cuarentena, 2427, 251613, 1.0.27957, , ame,
PUP.Optional.MindSpark, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FromDocToPDFTooltab Uninstall Internet Explorer|PUBLISHER, En cuarentena, 721, 352442, 1.0.27957, , ame,
PUP.Optional.BrowserDefender, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{B64982B1-D112-42B5-B1E4-D3867C4533F8}, En cuarentena, 5104, 558307, 1.0.27957, , ame,
Datos del registro: 1
PUP.Optional.Claro, HKU\S-1-5-21-3465487260-1184485110-4284579-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|BPROTECTOR START PAGE, Sustituido, 316, 293056, 1.0.27957, , ame,
Secuencia de datos: 0
(No hay elementos maliciosos detectados)
Carpeta: 1
PUP.Optional.MindSpark, C:\USERS\USUARIO\APPDATA\LOCAL\FROMDOCTOPDFTOOLTAB, En cuarentena, 721, 507792, 1.0.27957, , ame,
Archivo: 3
PUP.Optional.MindSpark, C:\Users\usuario\AppData\Local\FromDocToPDFTooltab\TooltabExtension.dll, En cuarentena, 721, 507792, , , ,
Generic.Malware/Suspicious, C:\USERS\USUARIO\DOWNLOADS\AA_V3(1).EXE, En cuarentena, 0, 392686, 1.0.27957, , shuriken,
Generic.Malware/Suspicious, C:\USERS\USUARIO\DOWNLOADS\AA_V3.EXE, En cuarentena, 0, 392686, 1.0.27957, , shuriken,
Sector físico: 0
(No hay elementos maliciosos detectados)
WMI: 0
(No hay elementos maliciosos detectados)
(end)
ADWCLEANER
# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build: 07-22-2020
# Database: 2020-07-20.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 08-05-2020
# Duration: 00:00:02
# OS: Windows 7 Professional
# Cleaned: 20
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files\ShowMyPCService
Deleted C:\ProgramData\driver whiz
Deleted C:\Users\Ferreteria\AppData\LocalLow\Claro LTD
Deleted C:\Users\Ferreteria\AppData\Roaming\Performersoft
Deleted C:\Users\usuario\AppData\LocalLow\Claro LTD
Deleted C:\Users\usuario\AppData\Roaming\Performersoft
***** [ Files ] *****
Deleted C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\2p4avdut.default\bprotector_prefs.js
Deleted C:\Windows\System32\roboot.exe
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\SOFTWARE\5ded8dbb66fef43
Deleted HKCU\Software\Microsoft\Internet Explorer\Main|bprotector start page
Deleted HKCU\Software\PERFORMERSOFT
Deleted HKCU\Software\Softonic
Deleted HKCU\Software\YahooPartnerToolbar
Deleted HKLM\Software\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Deleted HKLM\Software\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Deleted HKLM\Software\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Deleted HKLM\Software\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Deleted HKU\.DEFAULT\SOFTWARE\5ded8dbb66fef43
Deleted HKU\S-1-5-18\SOFTWARE\5ded8dbb66fef43
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
Deleted http://www.claro-search.com/?affID=114506&tt=4212_8&babsrc=HP_clro&mntrId=68622c3200000000000000270e10b89c
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2955 octets] - [05/08/2020 08:04:21]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
JUNKWARE
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Professional x86
Ran by usuario (Administrator) on 05/08/2020 at 8:07:17,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 37
Successfully deleted: C:\Program Files\mozilla firefox\defaults\pref\itms.js (File)
Successfully deleted: C:\ProgramData\ammyy (Folder)
Successfully deleted: C:\ProgramData\babylon (Folder)
Successfully deleted: C:\Users\usuario\AppData\Roaming\babylon (Folder)
Successfully deleted: C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\2p4avdut.default\user.js (File)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1QMPBVJS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3ZG6M7GT (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8UC3HHE6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\94DMX6EW (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CA582KW9 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCIWS05V (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYSCPVXG (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FC6KZTPS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JQXEHP8P (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KEIUL9CM (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3NPOWSF (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RQR6G5ND (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U6FAD9FY (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCMV3E1L (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY4GPX48 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\usuario\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y2KH3A2I (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1QMPBVJS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3ZG6M7GT (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8UC3HHE6 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\94DMX6EW (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CA582KW9 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CCIWS05V (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DYSCPVXG (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FC6KZTPS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JQXEHP8P (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KEIUL9CM (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M3NPOWSF (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RQR6G5ND (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U6FAD9FY (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCMV3E1L (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY4GPX48 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Y2KH3A2I (Temporary Internet Files Folder)
Deleted the following from C:\Users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\2p4avdut.default\prefs.js
user_pref(browser.newtab.url, hxxp://www.claro-search.com/?affID=114506&tt=4212_8&babsrc=NT_clro&mntrId=68622c3200000000000000270e10b89c);
user_pref(browser.search.order.1, Claro Search);
user_pref(browser.search.selectedEngine, Claro Search);
user_pref(extensions.BabylonToolbar_i.newTab, true);
user_pref(extensions.BabylonToolbar_i.newTabUrl, hxxp://www.claro-search.com/?affID=114506&tt=4212_8&babsrc=NT_clro&mntrId=68622c3200000000000000270e10b89c);
user_pref(extensions.claro.admin, false);
user_pref(extensions.claro.aflt, babsst);
user_pref(extensions.claro.appId, {C3110516-8EFC-49D6-8B72-69354F332062});
user_pref(extensions.claro.dfltLng, en);
user_pref(extensions.claro.excTlbr, false);
user_pref(extensions.claro.id, 68622c3200000000000000270e10b89c);
user_pref(extensions.claro.instlDay, 15633);
user_pref(extensions.claro.instlRef, sst);
user_pref(extensions.claro.prdct, claro);
user_pref(extensions.claro.prtnrId, claro);
user_pref(extensions.claro.tlbrId, claro);
user_pref(extensions.claro.tlbrSrchUrl, );
user_pref(extensions.claro.vrsn, 1.8.3.10);
user_pref(extensions.claro.vrsni, 1.8.3.10);
user_pref(extensions.claro_i.smplGrp, none);
user_pref(extensions.claro_i.vrsnTs, 1.8.3.1017:24:03);
user_pref(keyword.URL, hxxp://www.claro-search.com/?affID=114506&tt=4212_6&babsrc=KW_clro&mntrId=68622c3200000000000000270e10b89c&q=);
Registry: 1
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\tvncontrol (Registry Value)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05/08/2020 at 8:09:47,78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~