cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Malwarebytes Anti-Malware
www.malwarebytes.org

Date de l'analyse: 25/10/2016
Heure de l'analyse: 14:49
Fichier journal: Malware.txt
Administrateur: Oui

Version: 2.2.1.1043
Base de données de programmes malveillants: v2016.10.25.08
Base de données de rootkits: v2016.09.26.02
Licence: Gratuit
Protection contre les programmes malveillants: Désactivé
Protection contre les sites Web malveillants: Désactivé
Autoprotection: Désactivé

Système d'exploitation: Windows 10
Processeur: x64
Système de fichiers: NTFS
Utilisateur: Alessanndra

Type d'analyse: Analyse des menaces
Résultat: Terminé
Objets analysés: 342523
Temps écoulé: 32 min, 44 s

Mémoire: Activé
Démarrage: Activé
Système de fichiers: Activé
Archives: Activé
Rootkits: Activé
Heuristique: Activé
PUP: Activé
PUM: Activé

Processus: 0
(Aucun élément malveillant détecté)

Modules: 0
(Aucun élément malveillant détecté)

Clés du Registre: 29
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, En quarantaine, [18549ffef5a5f640b38a03072dd8d22e],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, En quarantaine, [18549ffef5a5f640b38a03072dd8d22e],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, En quarantaine, [18549ffef5a5f640b38a03072dd8d22e],
PUP.Optional.Reimage, HKU\S-1-5-21-3552841691-4188109774-2211027560-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10ECCE17-29B5-4880-A8F5-EAD298611484}, En quarantaine, [94d8d1ccb5e56ec89de57185de26da26],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell32, En quarantaine, [a6c6415cc7d325112d4d04f99e654bb5],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell64, En quarantaine, [23492b7247531a1ca4d6da23b54e8080],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell32, En quarantaine, [c5a72578277389adb3c8dc217093a35d],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell64, En quarantaine, [c8a4cecf603a290d730840bd39cac040],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\APPID\PCKElevatedHost.exe, En quarantaine, [1a526e2f3a60201681fbea1309fa8977],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\REI_AxControl.DLL, En quarantaine, [551726774c4ee056274f1cda4db7be42],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, En quarantaine, [006c1d8079215adce1612ddd1aeb44bc],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\WOW6432NODE\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell32, En quarantaine, [da9229743e5cb3835a20ea13c83bfc04],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\WOW6432NODE\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell64, En quarantaine, [05678b125347c86e80fa09f44cb77b85],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\WOW6432NODE\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell32, En quarantaine, [a2caf8a51288c373403b8f6ebf448a76],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\WOW6432NODE\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell64, En quarantaine, [3933f6a77327f046433843ba669dcf31],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\PCKElevatedHost.exe, En quarantaine, [7fede1bc386246f093e9e6179b683fc1],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\REI_AxControl.DLL, En quarantaine, [f6766e2fe5b504326c0a49ad5fa5dd23],
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, En quarantaine, [b0bc613c0b8f50e696ac62a8cc395ba5],
PUP.Optional.Reimage, HKLM\SOFTWARE\REIMAGE\Reimage Repair, En quarantaine, [71fb1b822d6dec4a542f3bdc06ffcf31],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\WOW6432NODE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell32, En quarantaine, [4f1d8b12c1d94fe7a1d908f545be18e8],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\WOW6432NODE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell64, En quarantaine, [6c000a9345557fb7c0bab449729133cd],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\WOW6432NODE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell32, En quarantaine, [c5a77f1e0397f1450c6f6f8ef40f36ca],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\WOW6432NODE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell64, En quarantaine, [5319702d2f6b7db9abd0f30a7f8414ec],
PUP.Optional.PCKeeper, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\PCKElevatedHost.exe, En quarantaine, [7cf0732ae9b11b1b6a1248b53fc4728e],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\REI_AxControl.DLL, En quarantaine, [16564855b9e1c670fe7823d3030132ce],
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, En quarantaine, [a3c9e8b5f2a81521271b8189986d857b],
PUP.Optional.SpyHunter, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ESGSCANNER, En quarantaine, [4d1fd6c73f5b7abc18359374e1245ba5],
PUP.Optional.Reimage, HKU\S-1-5-21-3552841691-4188109774-2211027560-1001\SOFTWARE\LOCAL APPWIZARD-GENERATED APPLICATIONS\Reimage - Windows Problem Relief., En quarantaine, [a0cc7f1e9ffb39fd087848aeb64e7090],
PUP.Optional.PCKeeper, HKU\S-1-5-21-3552841691-4188109774-2211027560-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\5850767A_0, En quarantaine, [8ddf25783f5b38fecc7447b19c678e72],

Valeurs du Registre: 7
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, En quarantaine, [006c1d8079215adce1612ddd1aeb44bc]
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, En quarantaine, [b0bc613c0b8f50e696ac62a8cc395ba5]
PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}\1.0, REI_AxControl 1.0 Type Library, En quarantaine, [a3c9e8b5f2a81521271b8189986d857b]
PUP.Optional.SpyHunter, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ESGSCANNER|ImagePath, system32\DRIVERS\EsgScanner.sys, En quarantaine, [4d1fd6c73f5b7abc18359374e1245ba5]
Hijack.AutoConfigURL.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, 0http://noneblock.info/wpad.dat?1f39fe8d4dc4c23f9ad8765ffa88b7f618520070, En quarantaine, [74f81d805842fc3aa03aec1efe07fc04]
PUP.Optional.PCKeeper, HKU\S-1-5-21-3552841691-4188109774-2211027560-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\5850767a_0, {2}.\\?\hdaudio#func_01&ven_10ec&dev_0233&subsys_104319ad&rev_1000#{6994ad04-93ef-11d0-a3cc-00a0c9223196}\singlelineouttopo/00010001|\Device\HarddiskVolume4\Program Files\Essentware\PCKeeper\PCKeeper.exe%b{00000000-0000-0000-0000-000000000000}, En quarantaine, [8ddf25783f5b38fecc7447b19c678e72]
Hijack.AutoConfigURL.PrxySvrRST, HKU\S-1-5-21-3552841691-4188109774-2211027560-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|AutoConfigUrl, http://noneblock.info/wpad.dat?1f39fe8d4dc4c23f9ad8765ffa88b7f618520070, En quarantaine, [363677263e5ccb6bc01c5eacac59d52b]

Données du Registre: 0
(Aucun élément malveillant détecté)

Dossiers: 0
(Aucun élément malveillant détecté)

Fichiers: 6
PUP.Optional.SpyHunter, C:\Windows\System32\drivers\EsgScanner.sys, Supprimer au redémarrage, [3b32caa07d672f8a2e0df5cb3a873f45],
PUP.Optional.Reimage, C:\Users\Alessanndra\AppData\Roaming\ZHP\Quarantine\ReimageRepair.exe, En quarantaine, [b0bcfda0d7c311250664857146bef40c],
PUP.Optional.Reimage, C:\Users\Alessanndra\AppData\Roaming\ZHP\Quarantine\reimagerepair.exe.VIR, En quarantaine, [cf9d5c41ff9bf1451e4c7d797d87c13f],
PUP.Optional.SpyHunter, C:\Users\Alessanndra\Downloads\SpyHunter-Installer.exe, En quarantaine, [05673568cfcb3303a9d03ccbf80d08f8],
PUP.Optional.PCKeeper, C:\Windows\Installer\3014acb.msi, En quarantaine, [77f569340892d66087a0fcb8ce36966a],
PUP.Optional.PCKeeper, C:\Windows\Installer\3014ad0.msi, En quarantaine, [2547e8b5cfcb4ee83deab7fd4db72ad6],

Secteurs physiques: 0
(Aucun élément malveillant détecté)


(end)

Publicité


Signaler le contenu de ce document

Publicité