cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Malwarebytes Anti-Malware
www.malwarebytes.org

Date de l'analyse: 20/04/2016
Heure de l'analyse: 14:14
Fichier journal: rapport malware.txt
Administrateur: Oui

Version: 2.2.1.1043
Base de données de programmes malveillants: v2016.04.20.03
Base de données de rootkits: v2016.04.17.01
Licence: Gratuit
Protection contre les programmes malveillants: Désactivé
Protection contre les sites Web malveillants: Désactivé
Autoprotection: Désactivé

Système d'exploitation: Windows 7
Processeur: x64
Système de fichiers: NTFS
Utilisateur: Iréna

Type d'analyse: Analyse des menaces
Résultat: Terminé
Objets analysés: 347835
Temps écoulé: 22 min, 12 s

Mémoire: Activé
Démarrage: Activé
Système de fichiers: Activé
Archives: Activé
Rootkits: Activé
Heuristique: Activé
PUP: Activé
PUM: Activé

Processus: 0
(Aucun élément malveillant détecté)

Modules: 0
(Aucun élément malveillant détecté)

Clés du Registre: 26
PUP.Optional.Delta.ShrtCln, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, En quarantaine, [7f94bcf5c2d76bcbf872e6fa2cd6d927],
PUP.Optional.Delta.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, En quarantaine, [7f94bcf5c2d76bcbf872e6fa2cd6d927],
PUP.Optional.Delta.ShrtCln, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, En quarantaine, [7f94bcf5c2d76bcbf872e6fa2cd6d927],
PUP.Optional.BestToolBar, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, En quarantaine, [4ec51899049542f48487c81b8e74e51b],
PUP.Optional.BestToolBar, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, En quarantaine, [4ec51899049542f48487c81b8e74e51b],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\Toolbar.CT1060933, En quarantaine, [da3928890e8bf73f6e9e000ed13356aa],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\conduitEngine, En quarantaine, [a37010a1643593a3429213fb50b4768a],
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\DataMngr, En quarantaine, [49cafdb473262e08ef8420701ce86f91],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Toolbar.CT1060933, En quarantaine, [060d02af2277d75fde2e46c82bd97987],
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C438E7A5-2879-4883-99E7-268D9748E52F}, En quarantaine, [e82b6e4383162b0b77eae53abb498d73],
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}, En quarantaine, [39da2091742534025301e63909fb19e7],
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\RegCleanPro_RASAPI32, En quarantaine, [5db6466b386191a5f2af365bd62e8f71],
PUP.Optional.RegCleanPro, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\RegCleanPro_RASMANCS, En quarantaine, [6fa47839950463d310916d2461a3d12f],
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\TNT2User_RASAPI32, En quarantaine, [070c80316d2c96a03891841731d32bd5],
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\TNT2User_RASMANCS, En quarantaine, [7a993a776a2f360032974e4df60e3fc1],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, En quarantaine, [967da40dc4d588ae3312f06221e2847c],
PUP.Optional.APNToolBar.Gen, HKU\S-1-5-18\SOFTWARE\AskPartnerNetwork, En quarantaine, [749f2988930676c040898db53fc49967],
PUP.Optional.DataMngr.AppFlsh, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\DataMngr, En quarantaine, [d83b5160c5d47abca7ca3c54b351f10f],
PUP.Optional.DataMngr.AppFlsh, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\DataMngr_Toolbar, En quarantaine, [090a644d8f0a5fd71d55eda30ef67e82],
PUP.Optional.Nosibay, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\Nosibay, En quarantaine, [090a377a69300e284df7aa91bc489868],
PUP.Optional.TNT, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\TNT2, En quarantaine, [32e19f124e4bac8ab73666e736ce53ad],
Adware.GibMedia, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\Winsudate, En quarantaine, [3cd7a20f50496dc97203871fe81b27d9],
PUP.Optional.ConduitTB.Gen, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\APPDATALOW\SOFTWARE\conduitEngine, En quarantaine, [cd465d543a5f8aac1fb24cc2ee1611ef],
PUP.Optional.CrossRider, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, En quarantaine, [9281a50c1c7d6dc9ecb23ce6b25214ec],
PUP.Optional.PriceGong, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, En quarantaine, [e92a436ed0c9e551ffa41d22f80cd22e],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-2610507880-2525535702-1854816323-1001\SOFTWARE\SYSTWEAK\ssd, En quarantaine, [0d06e4cddfba350195af6ce6ee15ce32],

Valeurs du Registre: 2
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C438E7A5-2879-4883-99E7-268D9748E52F}|AppPath, C:\Users\Iréna\AppData\Local\Conduit\CT1060933, En quarantaine, [e82b6e4383162b0b77eae53abb498d73]
PUP.Optional.Conduit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1060933, En quarantaine, [39da2091742534025301e63909fb19e7]

Données du Registre: 0
(Aucun élément malveillant détecté)

Dossiers: 13
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
PUP.Optional.OpenCandy, C:\Users\Iréna\AppData\Roaming\OpenCandy, En quarantaine, [f91a5b56d6c3e94d65a679890300ad53],
PUP.Optional.OpenCandy, C:\Users\Iréna\AppData\Roaming\OpenCandy\OpenCandy_294F9878D4404D839461EC3740059CDD, En quarantaine, [f91a5b56d6c3e94d65a679890300ad53],
PUP.Optional.SystemSpeedup, C:\Users\Iréna\AppData\Roaming\systweak\ssd, En quarantaine, [59ba98196d2c21159907788df40fbb45],
PUP.Optional.Nosibay, C:\Users\Iréna\AppData\Roaming\Nosibay, En quarantaine, [0f048f22148532042c7442dd5da630d0],
PUP.Optional.OptimizerPro, C:\Users\Iréna\AppData\Roaming\Optimizer Pro, En quarantaine, [ba597e33badf0630c75df72963a0c739],
PUP.Optional.OptimizerPro, C:\Users\Iréna\AppData\Roaming\Optimizer Pro\Backup, En quarantaine, [ba597e33badf0630c75df72963a0c739],
PUP.Optional.OptimizerPro, C:\Users\Iréna\AppData\Roaming\Optimizer Pro\Log, En quarantaine, [ba597e33badf0630c75df72963a0c739],
PUP.Optional.OptimizerPro, C:\Users\Iréna\AppData\Roaming\Optimizer Pro\Undo, En quarantaine, [ba597e33badf0630c75df72963a0c739],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],

Fichiers: 42
PUP.Optional.OpenCandy, C:\Users\Iréna\AppData\Roaming\OpenCandy\OpenCandy_294F9878D4404D839461EC3740059CDD\LatestDLMgr.exe, En quarantaine, [40d32b867a1fc076ac5c57fef015f40c],
PUP.Optional.BubbleDock, C:\Users\Iréna\AppData\Roaming\Bubble Dock.boostrap.log, En quarantaine, [2ee5b100346539fd2287da412bd931cf],
PUP.Optional.BubbleDock, C:\Users\Iréna\AppData\Roaming\Bubble Dock.installation.log, En quarantaine, [a073c4eda6f364d2acfd1209ff05e020],
PUP.Optional.CrossRider, C:\Users\Iréna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_imonhoeiopfgoncjdldhhfjgocghkbbl_0.localstorage, En quarantaine, [bb58377a178295a16770bb669e660ef2],
PUP.Optional.CrossRider, C:\Users\Iréna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_majjphhgppkndjjkmhhnbgafooenebhd_0.localstorage, En quarantaine, [4ec59c150891f93d1b120d15c93b6d93],
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro\bgNova.html, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro\1293297481.mxaddon, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro\360-54248.crx, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro\54248.crx, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro\54248.xpi, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\Freeven pro\background.html, En quarantaine, [4ec5327f9207092d88fb57cbf0148f71],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus\bgNova.html, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus\1293297481.mxaddon, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus\360-54246.crx, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus\54246.crx, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus\54246.xpi, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
PUP.Optional.CrossRider, C:\Program Files (x86)\MediaPlayerplus\background.html, En quarantaine, [33e0f8b9ebae2115fe8528fa6f95a55b],
Trojan.Agent.Trace, C:\captura.bmp, En quarantaine, [37dc7d34435683b390d74025a95b01ff],
Trojan.Agent.Trace, C:\codigo1.bmp, En quarantaine, [5bb8bbf6376259dd72fe5312ba4aa759],
Trojan.Agent.Trace, C:\codigo2.bmp, En quarantaine, [d83b71403465f73f78f8392c9272e41c],
Trojan.Agent.Trace, C:\codigo3.bmp, En quarantaine, [967d0ea370295fd79fd1c3a29470ca36],
Trojan.Agent.Trace, C:\codigo4.bmp, En quarantaine, [67ac0ba6fc9d0531f779b5b08b79f20e],
Trojan.Agent.Trace, C:\error.bmp, En quarantaine, [ca49535ec0d991a5236eb3b233d19070],
PUP.Optional.OpenCandy, C:\Users\Iréna\AppData\Roaming\OpenCandy\OpenCandy_294F9878D4404D839461EC3740059CDD\1031.ico, En quarantaine, [f91a5b56d6c3e94d65a679890300ad53],
PUP.Optional.OpenCandy, C:\Users\Iréna\AppData\Roaming\OpenCandy\OpenCandy_294F9878D4404D839461EC3740059CDD\RegistryReviverSetup-ppi_.exe, En quarantaine, [f91a5b56d6c3e94d65a679890300ad53],
PUP.Optional.OpenCandy, C:\Users\Iréna\AppData\Roaming\OpenCandy\OpenCandy_294F9878D4404D839461EC3740059CDD\RevStarter.exe, En quarantaine, [f91a5b56d6c3e94d65a679890300ad53],
PUP.Optional.SystemSpeedup, C:\Users\Iréna\AppData\Roaming\systweak\ssd\SSDPTstub.exe, En quarantaine, [59ba98196d2c21159907788df40fbb45],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\92.json, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\uninstallDlg.xml, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\bg1.png, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\button1.png, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\checked.png, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\close.png, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\min.png, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\Thumbs.db, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.WebSearch, C:\Users\Iréna\AppData\Roaming\webssearches\images\unchecked.png, En quarantaine, [3cd7a50c2b6e1a1c7472b17915eef20e],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft\161.crx, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft\161.dat, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft\161.xpi, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft\a.db, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft\b.db, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],
PUP.Optional.Revizer.PrxySvrRST, C:\Program Files (x86)\Re-markit-soft\Re-markitry161.bin, En quarantaine, [58bbe7cab1e8b581421430fe2cd7867a],

Secteurs physiques: 0
(Aucun élément malveillant détecté)


(end)

Publicité


Signaler le contenu de ce document

Publicité